Chartilo ("we", "us", "our") is built to be privacy-first. Much of what you do in the App stays on your device. We do not show ads, and we do not sell your personal data. This policy explains what we collect, why, and your choices.
This policy is provided by Chartilo, operated from the United Arab Emirates, which acts as the data controller for the personal data described here. Contact: support@chartilo.app.
The following never leaves your device unless you choose to sign in and sync (see Section 3):
We do not collect your location or GPS coordinates.
Chartilo works without an account. Signing in is optional. You can sign in with Google or Apple, or with an email "magic link" to back up and sync across devices. If you do, we collect and store on our hosting provider (Supabase):
We never receive your password for any sign-in provider. The email "magic link" is sent through our authentication provider (Supabase).
We do not use your data for advertising and do not sell or rent it.
Business transfers. If Chartilo is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction; we will notify you beforehand and any successor will be bound by a policy at least as protective.
Legal bases (EEA / UK). Where the GDPR or UK GDPR applies, we rely on performance of a contract (to provide and sync your account and process purchases), your consent (for notifications), our legitimate interests (security, crash diagnosis, anonymous usage analytics — you can opt out), and compliance with legal obligations.
If you enable notifications, we process the technical information needed to deliver them. You can turn notifications off at any time in your device settings.
To understand how Chartilo is used, we collect a small amount of anonymous, aggregate usage data on our own hosting (Supabase) — never through an advertising network or third-party analytics provider.
Your choice: it's on by default, but you can turn it off any time under Profile → "Share anonymous usage data."
The App reports crashes and errors to Sentry. A crash report contains technical diagnostic data (error type, device/OS type, app version) so we can fix the bug. It is not used to identify you and does not include your notes or other personal content.
We use reasonable technical and organisational measures to protect your data, including encryption in transit and access controls so each account can only reach its own data. No method of transmission or storage is completely secure.
Chartilo involves financial education and is not directed to children under 18 (or the minimum age required in your country). We do not knowingly collect personal data from children.
Our service providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
Depending on where you live (e.g. under the GDPR), you may have rights to access, correct, delete, or export your data, to object to or restrict processing, and to withdraw consent. Contact support@chartilo.app. You may also lodge a complaint with your local data-protection authority.
California residents. We collect identifiers (name, email, a user identifier, if you sign in) and internet or other electronic activity (anonymous, aggregate analytics). We do not sell or share your personal information for cross-context behavioural advertising. You may know about, access, correct, and delete your personal information, and not be discriminated against for exercising these rights. Contact support@chartilo.app.
We may update this policy from time to time. We will update the "Last updated" date and, where appropriate, notify you in the App.
Chartilo
Email: support@chartilo.app