Balance Sheet

Privacy Policy

Effective 8 September 2026 · BA Systems Ltd

Balance Sheet keeps your financial data on your device. We never see what you own, owe, earn or spend. An account, if you create one with Sign in with Apple, holds only your Apple identifier, name, email and any marketplace subscription. The only things that leave your phone are what you choose to send to the advisor you picked, the ticker symbols used to fetch prices, an anonymised monthly outcome record if you opt in, and a dispute bundle if you open one. With the default Balance Sheet advisor, each request passes through our server to the model on its way out; we count the tokens and keep nothing else.

1. Who we are

Balance Sheet (the "App") is published by BA Systems Ltd, a company incorporated in Georgia ("we", "us"). This policy explains what the App does with your information and the choices you have. It applies wherever you use the App.

We honour the data-protection laws that apply to our users, including the EU and UK General Data Protection Regulation, alongside the law of Georgia, where we are incorporated. Your financial data never reaches our systems, so most of your rights over it are exercised directly through the controls in the App. For the small account record described in section 3 we are the controller and you can delete it in the App at any time.

2. What the App stores, and where

Everything you enter is stored on your device only:

This data is kept in the App's private storage on the device. On iOS and Android your API keys are kept separately in the operating system's secure keystore (the Keychain on iOS). On the web version, data and keys are kept in the browser's local storage for that site.

We never receive any of it. There is no account, no sign-in, no cloud copy and no backup on our side. If you use Apple's or Google's device backup, the App's data may be included in that backup under their terms, which you control in the device settings.

3. Your account (optional)

You can use the App without an account. An account is needed only to subscribe to an advisor from the marketplace or to open a dispute. Accounts are created with Sign in with Apple; we support no other method.

When you sign in, Apple gives us a stable identifier for you, your name if you agree to share it, and your email address or an Apple relay address if you chose to hide it. We store those, the date you joined, your credit balance and a record of each charge to it (model, token counts, cost, never the content), your subscription records (which advisor, the agreed price, whether you share outcomes, when it started and ended), a usage log for relayed requests (time, model and token counts, never the content), a monthly ledger of what is owed, any outcome records you chose to share, and any dispute you opened.

This account record lives on our server, hosted with a reputable cloud provider, and is kept until you delete the account. Settings → Your account → Delete account removes it immediately: subscriptions are cancelled and the record is anonymised. Deleting the App does not delete the account; deleting the account does not delete anything on your device.

If no account server is configured in the version you are running, the App tells you so, keeps the account on the device only, and none of the above is sent anywhere.

4. What leaves your device, and to whom

The App talks to third parties in these situations. In each, we see only what this section says we see.

When you approve an email action, the App opens Gmail, your mail app or a mailto link with the draft filled in. When you approve a calendar action, it creates an event in the calendar you chose on the device. In both cases nothing is sent until you tap send or save in that other app, and what happens next is governed by that app and its provider.

5. Advisor rankings and outcome sharing (optional)

The App can contribute to a ranking of advisors by outcome. This is off unless you turn it on, and you can turn it off at any time in Settings. Turning it off changes nothing about how your advisor works.

If it is on, once a month the App sends a single record containing:

The ranking record contains no name, email address, device identifier, IP-derived location or any other stable identifier, and it cannot be linked back to you by us. Settings shows the exact record that would be sent this month.

Outcome sharing with a marketplace advisor is a separate, second choice. If you subscribe to an advisor and turn on "share outcomes for a discount", the same monthly record is sent through our server to that advisor, linked to your subscription so the discount can be applied. The advisor sees the record and your subscription id, not your name or email. The discount depends on the record being an honest reflection of the data you entered; see the Terms of Use.

In the current version there is no ranking service, so the ranking record is not sent whatever the toggle says. Outcome sharing operates only once an account server is configured.

6. Disputes

If you open a dispute about a marketplace advisor, the App builds a dispute bundle and our server sends it to Recourse (https://recourse.so), an independent adjudication service operated by a company in which our founder holds an interest, which decides it under the Recourse Standard Rules. The bundle contains: your subscription terms, your statement of what went wrong and what you want, the amount in dispute, a log of when analysis runs happened and whether they succeeded, and the titles and status of the insight cards delivered during the subscription. It never contains your assets, figures, contacts or goal text. Recourse processes the bundle under its own privacy policy and its ruling is returned to you in the App. A provider who opens a dispute about your shared outcome records sends those records, which are anonymised as described above.

7. What we do not do

Apple and Google may provide us with aggregated, anonymous statistics about downloads and, if you have opted in on your device, crash diagnostics. Those are collected by them under their own privacy terms. Where the App is distributed through TestFlight, Apple collects the information described in the TestFlight terms.

8. Your choices and rights

For your financial data, requests for access, correction, portability or erasure are fulfilled entirely by these controls, because we never hold it. For the account record, the account screen shows what we hold and deletes it on request; write to us for a copy. Data you sent to an advisor or a price service is held by that provider under its own policy, and any request about it should go to them; the App names the advisor on every card so you always know who that is.

If you believe we have handled your data in a way that breaks the law, you can contact us using the details below or complain to your local data-protection authority.

9. Other people's data

You may enter information about other people, such as a tenant's name, a letting agent's email address or a co-owner's share. You are responsible for having a lawful basis to record that information and to share it with your advisor. Consider using the hide-field option for details the advisor does not need.

10. Children

The App is intended for adults managing their own finances and is not directed at anyone under 18. We do not knowingly collect any data from children; as set out above, we collect no data through the App at all.

11. Security

API keys are stored in the device's secure keystore, which is encrypted and protected by the device passcode or biometrics. Account sessions are signed tokens that expire. All network connections made by the App use HTTPS. The security of the data on your device otherwise depends on the security of the device itself: a passcode, up-to-date software and a trusted backup are the best protection.

12. Changes to this policy

If we change what the App does with data, we will update this policy and change the effective date at the top. Where a change involves sending anything new off the device, the App will ask before doing so.

13. Contact

Questions about privacy: support@massage.st. Please do not include API keys or account details in your message.