Legal
Last updated: 3 August 2026
Tesoro does not collect your data. There is no account to create, no server of ours to sign in to, and no analytics of ours. Your financial records stay on your device.
This policy explains that in detail, including the few narrow cases where information about you does exist, such as when you email us or export a file.
Tesoro is operated by Daniel Olivan Parrilla, trading as getTesoro.app, in Western Australia, Australia. Contact: hello@gettesoro.app
Everything you record in Tesoro, including transactions, accounts, vehicles, properties, valuables and notes, is stored locally on your device.
We operate no server. We cannot see your financial data, we do not receive a copy of it, and we could not produce it if asked. It is never transmitted to us.
If you turn sync on, your Tesoro data synchronises between your own Apple devices using Apple's CloudKit service, inside your personal iCloud account. It is your storage, under Apple's terms, not ours. We have no access to it.
We want to be precise about the encryption, because the distinction is real:
In every case, we cannot see your data, and neither can any other third party. If you want the strongest available guarantee, turn on Advanced Data Protection in Settings. Sync is optional and Tesoro works fully without it.
Purchases are processed by Apple through the App Store. We never see your payment details, billing address, or Apple Account identity.
Apple provides us with aggregated, anonymised sales and download reporting through App Store Connect, showing totals by country and product. It does not identify individual purchasers and we cannot connect it to any person.
Subscription management, cancellation and refunds are handled by Apple through your Apple Account settings.
Tesoro can remind you about things such as upcoming bills and payments. These reminders are scheduled locally on your device by iOS.
There is no push server involved. No device token is registered with us, no notification passes through any system we operate, and we have no way of knowing what reminders you have set or whether you have set any. You can grant or revoke notification permission at any time in iOS Settings.
If you enable biometric locking, authentication is performed by iOS. Your biometric data never leaves the Secure Enclave and is never accessible to Tesoro. The app receives only a success or failure result.
Tesoro can import and export your records as a CSV file.
An exported CSV is plain text and is not encrypted. It contains whatever you chose to export, in readable form. Once you save it to Files, iCloud Drive, AirDrop it, or send it anywhere else, it is outside the app's protection and its security is in your hands. Treat an export the way you would treat a bank statement saved to your desktop.
Imports and exports happen entirely on your device. No file is sent to us at any point, and we never see its contents. Access to Files is requested only at the moment you choose to import or export, and is limited to the file you select.
Tesoro can accept transaction details from a Shortcut you set up yourself in Apple's Shortcuts app. When you pay with Apple Pay, your Shortcut can capture the merchant name and the amount and pass them to Tesoro, which holds them on your device until you next open the app. Tesoro then creates the transaction using a mapping you have already confirmed, or asks you to create one.
This is not a bank connection and not a Wallet integration. It is an iOS automation you configure and control, running entirely on your phone. Tesoro receives only what your Shortcut passes it, the temporary record is deleted once the transaction is created, and nothing leaves your device.
We collect none of our own.
The only usage and crash information that exists is what Apple collects at the operating system level and shares with developers through App Store Connect. That is controlled by you, in iOS Settings under Privacy & Security, then Analytics & Improvements. It is not enabled unless you have chosen to share analytics with app developers, and it reaches us aggregated and anonymised. We cannot identify any individual from it and we add nothing to it.
There is no third-party crash reporter, no analytics software development kit, and no telemetry of our own design anywhere in the app.
Tesoro does not profile you. It does not make automated decisions that produce legal or similarly significant effects, and there is no scoring, ranking or risk assessment of any kind applied to you or your finances.
Tesoro uses no artificial intelligence or machine learning to process your data. Category suggestions and merchant mappings are simple lookups against your own past entries, made on your device. Nothing is sent to a model, ours or anyone else's.
That is the complete list.
The strongest protection here is structural rather than procedural: there is no central store to breach, because we never receive your data.
No system is perfectly secure, and an exported CSV leaves this protection entirely, as section 6 explains.
gettesoro.app is a static site. It sets no cookies, loads no third-party fonts or scripts, and runs no analytics. The typefaces are the ones already on your device.
The site is hosted on our own server with Hetzner in Helsinki, Finland, inside the European Union, and served by the Caddy web server.
No visitor logs are kept. The server records no IP addresses and no request history, so we have no way of knowing who has visited this site, when, or from where.
If you write to hello@gettesoro.app, we hold your email address and whatever you choose to tell us, for as long as needed to answer you and keep a record of support history.
Mail for the domain is routed by our domain registrar to a Proton Mail account in Switzerland, where it is stored encrypted. Switzerland is recognised by the European Commission as providing an adequate level of data protection.
We use your email only to reply to you. We do not add you to a mailing list and we do not use it for marketing.
Beta distribution is handled by Apple through TestFlight. If you join, Apple collects tester information and beta usage data under Apple's own terms. We receive limited Apple-provided information about testers and builds, plus any feedback you choose to submit through TestFlight, which may include screenshots and device details you chose to send. Your Tesoro financial data does not reach us through TestFlight.
Because your records never reach us, there is no retention period for them to be subject to. They exist for exactly as long as you keep them, and deleting the app removes them from that device. If you have used iCloud sync, you can remove the synced copy in iOS Settings under your Apple Account, then iCloud, then Manage Account Storage.
The only data we hold about anyone is email correspondence. We keep it for up to 24 months after the conversation ends, then delete it, unless a longer period is required by law.
Uninstalling the app stops everything, immediately and completely. There is no residual copy sitting on a server of ours, because there is no server of ours.
To have any email correspondence deleted, write to hello@gettesoro.app and we will action it and confirm.
Tesoro is not directed at children. Because the app collects no personal information from anyone, there is nothing for us to hold regardless of a user's age.
Our Terms of Use require subscribers to be at least 18, since a subscription is a contract. Purchases are made through your Apple Account, and Apple applies its own age requirements to account holders and to Family Sharing.
We handle any personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). You may ask what we hold about you, ask us to correct it, or complain about how we have handled it. If our response does not satisfy you, you may complain to the Office of the Australian Information Commissioner.
Where the Privacy Act 2020 applies, we handle personal information in accordance with the Information Privacy Principles. You may ask what we hold about you, ask us to correct it, or complain to the Office of the Privacy Commissioner.
Where the UK GDPR or EU GDPR applies to you, the controller is Daniel Olivan Parrilla, contactable at hello@gettesoro.app.
In practice the only personal data we hold about a user is an email address, and only if you have written to us. Our lawful basis is legitimate interest in responding to correspondence.
You have the right to request access to that data, to have it corrected or erased, to restrict or object to its processing, and to data portability. You may also complain to your national supervisory authority. In Spain that is the Agencia Española de Protección de Datos (AEPD), and in the United Kingdom the Information Commissioner's Office (ICO).
Because your financial records never reach us, a request to access or erase them is something only you can carry out, by using or deleting the app and by managing your own iCloud storage. The app's CSV export exists partly so that you can take your data with you at any time.
The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information, along with a right not to be discriminated against for exercising them.
We do not meet the revenue or volume thresholds that make those obligations binding on a business, and we do not sell or share personal information under any definition. We honour these rights regardless. Write to hello@gettesoro.app and we will respond within the time the law allows.
Almost nothing we do relies on consent, because almost nothing is processed. Where a feature does need your permission, iOS asks you directly, and you grant it by turning that feature on. Notifications, Face ID, iCloud sync and file access all work this way, and each can be withdrawn at any time in iOS Settings without affecting anything that happened before.
The website is hosted in Finland, within the European Union. Email is stored in Switzerland, which the European Commission has recognised as providing adequate protection. We are based in Australia, so any correspondence we read is read from there.
We hold almost no personal data, which is the point. If a breach did occur affecting personal information we hold, we would notify affected people and the relevant regulators as required under the Notifiable Data Breaches scheme and, where applicable, the GDPR.
We may update this policy. Changes take effect when posted here and the date at the top will be updated. Material changes will be noted in the app's release notes.
Daniel Olivan Parrilla, trading as getTesoro.app
Western Australia, Australia
hello@gettesoro.app
We aim to respond within 48 hours.