Ruply Ruply

Privacy Policy

Last updated: August 23, 2026

Introduction

Ruply ("we", "us", "Ruply") is a personal expense tracker built and operated by Mehul Bhargava, an independent developer based in India. We've built Ruply with one principle that everything else flows from: your money data belongs to you, and nobody else needs a copy of it.

This Privacy Policy explains, in plain language, what data Ruply handles, where it lives, and what you can do about it. We've tried to keep it short. If anything here is unclear, email mebhargava02@icloud.com.

1. The short version

2. Data we handle

2.1 Data you provide directly

2.2 Data Apple provides to Ruply

2.3 What we do NOT collect

3. Where your data lives

Ruply keeps your personal finance data local-first. It is stored in three places:

The data we hold on our servers is: your encrypted personal-data backup (above), your household's shared data (Section 5), your splits (Section 5b), a minimal account and contact record (Sections 7b, 7c), your subscription record (Section 7), and anonymous usage analytics (Section 8). Each is stored solely to run that feature. No one at Ruply reads or uses your data, and none of it is ever sold or shared — with anyone, ever.

Two kinds of data live on our servers because they have to reach other people: your household (Section 5) and your splits (Section 5b). Both are held in readable form so the shared features actually work — the server is what keeps every member's balance consistent. No one at Ruply reads or uses this data, and it is never sold or shared.

If you delete the app, your local copy is removed; your iCloud copy and your Ruply backup remain, so signing in again brings everything back. Deleting your account from inside Ruply (Settings → Delete Account & Data) removes all three: device, iCloud, and our servers.

4. AI features and our stateless proxy

A handful of Ruply features use cloud AI: AI Quick Add, Ask Ruply, Receipt Scanning, Bank Statement Import, Money Story, AI Compare, and Log by Voice. These features send a single request to our AI proxy, which is a stateless Cloudflare Worker that:

What is sent depends on the feature:

What is NOT sent: your Apple ID, your real name (unless you typed it into a note), your email, your phone number, your device identifier, your location, your friend identities, your household member identities, or any data outside the scope of the request you triggered.

Provider sub-processors: Anthropic (Claude) and Sarvam (Saaras V3) process the data they receive under their own privacy and retention policies. Cloudflare provides the network layer for the Worker.

5. Household sharing

If you create or join a Household in Ruply, your household's shared data is stored on a service we operate on Cloudflare. (It moved off Apple's CloudKit Sharing in version 2.5, so households work reliably across everyone's devices — and, in future, across platforms.) What this means:

If you leave a household or the financier dissolves it, your household data is deleted. When you tap Delete Account & Data, your household records tied to your hashed identifier are deleted from our servers.

5b. Splits (server-held)

From app version 2.7.0, splits run on a central service we operate — the server is the single source of truth for split expenses and settlements, and it computes every balance. We moved to this model deliberately: it is what makes balances provably consistent on every phone, lets a friend's change appear instantly, and means your splits survive a lost or new device. Here is exactly what the service holds:

The promise that matters: this data is stored solely to run Splits. No one at Ruply reads, accesses, or uses it, and it is never sold, shared, or used to train AI — ever.

The splits service does not hold your real name from Apple or your Apple ID. Your personal (non-split) expenses live separately, in the encrypted backup described in Section 3. Encrypted records from earlier systems — the relay-based splits of versions 2.1–2.6 and the encrypted group event log used before version 2.8 — remain stored as ciphertext until deleted and are being retired.

When you delete a split or a settlement, your device instructs the service to delete it for everyone in it. When you tap Delete Account & Data, everything tied to your hashed identifier is deleted from the service.

Infrastructure: the service runs on Cloudflare Workers, with Cloudflare D1 (SQLite) holding split records and metadata, and Cloudflare R2 (object storage) holding friend profile images. Cloudflare processes data on Ruply's behalf and does not use it for its own purposes.

If you do not use Splits, no data is sent to the splits service.

6. Push notifications

Local notifications. Daily reminders, streak nudges, EMI alerts, recurring-expense reminders, and similar prompts are scheduled locally on your device using iOS's notification framework. We do not transmit these to any server.

Push notifications for households and splits. When you take an action affecting another user — joining a household, dissolving it, a financier's subscription ending, settling a split, marking a household expense as paid — Ruply sends a notification to the affected user's device via Apple Push Notification service (APNs). The push request is signed by a Cloudflare Worker using our Apple developer key.

For both splits and households, the recipient's APNs device token is held on our server alongside their hashed identifier, so the server can wake their device when you take an action that affects them. Notification payloads carry no plaintext expense content — your device fetches the record and renders the alert locally.

Notifications can be turned off per-type in iOS Settings → Ruply → Notifications, or as a master switch in Ruply → Settings → Notifications.

7. Subscription verification record

Ruply offers an optional Ruply+ subscription via Apple In-App Purchase. When you subscribe (individual or household), we keep a minimal server-side record so we can verify your entitlement and, for the Household plan, extend Plus to your household members.

This record contains:

It does not contain your name, email, device identifier, expense data, financial data, or any personally identifying information.

The record is updated when Apple's Server-to-Server Notification V2 webhook reports a subscription state change (renewal, cancellation, billing failure, refund). Its only purpose is to allow Ruply to revoke Plus features promptly across household members when a financier's plan ends, so members are not silently using paid features they no longer have access to.

You can request deletion of this record at any time by emailing mebhargava02@icloud.com. Deletion is also triggered automatically when you tap Delete Account & Data inside Ruply.

7b. Your contact record (email address)

From app version 2.3.3, Ruply keeps one piece of contact information on our server: the email address associated with your Sign in with Apple (which may be a real address or Apple’s private-relay address, depending on what you chose at sign-in).

7c. Your Ruply account (Sign in with Apple)

From app version 2.4, signing in with Apple creates a minimal account on our server. It holds identity only — never your financial data — and exists to keep your access secure and, in future, to let your data follow you across devices and platforms.

8. App-usage analytics

Ruply uses two privacy-respecting analytics tools to understand which features people use and where the app can be better: TelemetryDeck (based in Germany) and PostHog (based in the United States). Signals include:

These signals never contain your expenses, monetary amounts, merchant names, notes, budgets, or any financial data. We never send your name, email, or raw Apple ID to an analytics provider.

To measure product funnels and retention per person — not just in aggregate — PostHog events are tagged with the same one-way SHA-256 hash of your Apple identifier used elsewhere in this policy. This hash is a pseudonymous key: it cannot be reversed to your Apple ID, name, or email, by us or by PostHog. It lets us answer questions like "how many people who saw the paywall started a trial" and "do people who log daily stick around", so we build the right things. TelemetryDeck signals remain fully anonymous, with no identifier at all.

We never sell this data, use it for advertising, or track you across other apps. Ruply contains no ad SDKs. Analytics providers process data on our behalf under their own privacy and retention policies.

Opting out: deleting your account (Settings → Delete Account & Data) removes your analytics identity. You can also email mebhargava02@icloud.com to opt out of analytics collection entirely.

9. Backup to iCloud Drive

Ruply automatically writes a weekly encrypted JSON backup of your expense data to your own iCloud Drive in a folder labelled "Ruply". This is your data, in your iCloud, accessible via the Files app. We do not have access to this backup. You can disable automatic backup in Settings → iCloud & Backup. You can delete the backup files from Files.app at any time.

10. Your rights

You can, at any time and without contacting us:

You can also stop using Ruply at any time by deleting the app. Your iCloud copy remains under your control in Apple's storage management, and your Ruply backup stays until you delete your account from inside the app (Settings → Delete Account & Data), which removes it from our servers.

If you are a resident of a jurisdiction that grants you additional rights under data protection law (e.g., GDPR, India's DPDP Act), you can exercise those rights by emailing mebhargava02@icloud.com.

11. Data retention

Your iCloud data is retained for as long as you keep it; you control its lifecycle through Apple. Your Ruply backup, your splits, and your household data are retained for as long as your account exists, and are deleted when you delete your account from inside the app.

Two pieces of data have a Ruply-side retention policy:

12. Changes to this policy

If we change this policy materially, we'll update the date at the top, post the new version at this URL, and surface the change inside the app the next time you open it. Material changes do not take effect retroactively for data already collected.

13. Contact