Privacy Policy
Effective 24 September 2026
Contents
This policy explains what Outlayr collects, where it goes, how long it stays, and what you can do about it.
The short version
- Your ledger is stored on your device. You can use Outlayr without an account, and then your entries, amounts, and notes never leave the phone.
- An account (Sign in with Apple or Google) turns on merchant suggestions, voice entry, and receipt scans. With Outlayr Pro it also turns on sync, which keeps a copy of your ledger and photos on our servers until you delete your account.
- Voice entries, receipt scans, and merchant suggestions are processed by xAI. We don’t store your recordings or scanned photos, and we never send xAI your name, email, or account ID.
- Merchant suggestions and web lookups are on by default. You can object to either by turning it off in Settings › Feature Lab.
- No ads, no analytics, no tracking. We don’t sell or share your personal information.
- You can delete your account and everything synced to it from the app at any time: Settings › Account › Delete account.
Who we are
Outlayr is made by danestves LLC, a Delaware limited liability company. We decide how the personal data described here is used, which makes us its controller. You can reach us at [email protected] or by mail at 651 N Broad St, Suite 201, Middletown, DE 19709, USA.
This policy covers the Outlayr app, the servers that support it, and this website. “We” and “us” mean danestves LLC. Our Terms of Use cover everything else about using Outlayr.
Data at a glance
Every kind of data Outlayr handles, in one place. The sections below explain each row.
| Data | When | Where it goes | Kept |
|---|---|---|---|
| Your ledger and its photos | Always | Your device | Until you erase it |
| Synced ledger, deleted entries, photos | Sync on (Pro) | Our servers | Until account deletion |
| Email, name, provider ID | Sign-in | Our servers | Until account deletion |
| Sessions, IP address, device type | Sign-in | Our servers | Until sign-out or account deletion |
| Merchant and category names | Smart fill | Our servers, xAI | Until answered |
| Voice recording | Voice entry | Our servers, xAI | Not kept |
| Transcript and draft | Voice entry | Our servers, xAI | Until closed, or 1 hour idle |
| Receipt photo | Receipt scan | Our servers, xAI | Not kept |
| File descriptions | CSV import | Our servers, xAI (Pro) | Not kept |
| Web address, IP address | Logos | Logo.dev, Google | Their policies |
| Purchase records, user ID | App opens, Pro | RevenueCat, Apple, our servers | Until account deletion |
| Install ID, app version, errors | Update checks | Expo | Expo’s policy |
| Your emails | You write | Our inbox | As long as needed |
What stays on your device
Outlayr keeps your ledger in a database inside the app on your device: your entries (amount, currency, date, merchant or note, category, tags, account, repeat schedule, and any photos), accounts and their balances, transfers, budgets, savings goals, categories, tags, and settings. Entries you delete wait in Recently Deleted on the phone, where you can restore them.
You don’t need an account to use Outlayr. Without one, none of your ledger is sent to us.
Features that stay on your device
- Widgets on iPhone show totals, budgets, and recent entries on your Home Screen and Lock Screen. They read from storage shared only between Outlayr and its own widgets.
- Search: on iPhone, Outlayr adds your 500 most recent entries and your budgets to the on-device Spotlight index so you can find them from Search. To stop this, turn off Show Content in Search for Outlayr in the iOS Settings app.
- Reminders (a daily nudge and upcoming subscription charges) are scheduled on your device. Outlayr never sends notifications from a server and doesn’t register for push notifications.
- Siri and Shortcuts actions on iPhone (log a transaction, check a budget, get a spending summary) run on the device. Apple handles Siri requests under its own privacy policy.
- App lock (Settings › Authentication) puts Outlayr behind your device’s biometric lock (Face ID or Touch ID on iPhone). The system checks your face or fingerprint, and Outlayr only learns whether the check passed.
What the app sends even without an account
- Exchange rates. The app downloads market rates from our server. The request needs no account and carries no ledger data. Our server reads the rates from public sources (Frankfurter and CotizaVE), which receive nothing about you.
- Logos. To show a logo for a merchant or bank, the app asks Logo.dev for it by web address (for example, netflix.com), and Google’s favicon service if Logo.dev has none. The request comes from your device, so those services see your IP address. It never includes amounts, notes, or who you are. Logos are then cached on the phone.
- App updates. When the app starts, it asks Expo, the platform we use to ship updates, whether a newer version of the app’s code is available. The request includes a random ID created for this install (not linked to your account), the app version, and your IP address. If an update failed to start last time, it also includes a short error message.
- Purchase status. The app checks with RevenueCat whether you have Outlayr Pro, using a random anonymous ID until you sign in. See Outlayr Pro.
Your account
You can sign in with Apple or with Google. We receive:
- With Apple: your email address, or a private relay address if you choose Hide My Email, and an identifier for your Apple account. The app doesn’t send us your name.
- With Google: your name, email address, a link to your Google profile photo, and an identifier for your Google account.
We create an Outlayr account ID, a random string, and link it to that identity. We also store the tokens needed to keep you signed in and to revoke access when you delete your account. Each sign-in creates a session, which can record your IP address and your device’s user agent. A session stops working after seven days without use, and signing out deletes it.
Signing in doesn’t change the ledger on your device. Signing out ends the session on that device and leaves the ledger where it is.
Sync and photos
Sync is part of Outlayr Pro. When you’re signed in with Pro, Outlayr copies your ledger to our servers and sends it to your other signed-in devices. You can stop a device from syncing in Settings › Sync.
What syncs
- Entries, transfers, accounts, budgets, savings goals, categories, tags, and the amounts, currencies, dates, merchants, notes, and exchange rates on them.
- Photos attached to entries and images set on accounts, uploaded to our file storage on Cloudflare R2. Each account has a 2 GB photo limit.
- Settings that describe you rather than the phone, such as your currency, display preferences, and whether suggestions and web lookups are on.
- A random ID for each device, used to order edits made on different devices.
Settings tied to one phone stay on it: notifications, app lock, number entry, and light or dark mode.
Deleted entries
When you delete an entry on a synced device, our servers keep a deletion record so your other devices can remove it too. That record keeps the entry’s last contents, and any photo it had, until you delete your account.
Turning sync off
Turning sync off stops that device from sending changes. It doesn’t remove what’s already on our servers. To remove it, delete your account.
Suggestions, voice, and receipts
These features need an account. Each request goes to our server first, which checks your account and limits, then forwards only the content listed below to xAI. None of them send xAI your name, email, or account ID.
Merchant suggestions (Smart fill)
When you type, speak, scan, or log from Apple Pay a merchant Outlayr doesn’t recognize on the device, the app sends our server the merchant name, whether the entry is an expense or income, its currency code, your language and device region, and the names of your categories. Never the amount, date, notes, or account.
Our server first checks a shared list of known merchants (below). If the merchant isn’t there, it asks xAI’s Grok model, and the answer (a category, tags, an emoji, and the merchant’s web address) comes back to your device. Saved entries that still have no logo may be looked up again in the background. Those requests wait on our server only until your device collects the answer.
On by default. Turn it off in Settings › Feature Lab › Suggest Category and Tags.
Web lookup of new merchants
If the model can’t place a merchant and you have Pro, our server may ask xAI to search the web for it. xAI’s model runs the searches, using the merchant name and sometimes a country or city. It receives the merchant name, expense or income, currency code, language, and region, and for background lookups, your category names too. A web lookup usually improves the answer for the next entry with that merchant rather than the one you’re typing.
On by default. Turn it off in Settings › Feature Lab › Look Up New Merchants. The app sends your choice with every request, and our server also honors the synced setting, so no web lookup runs for you while it’s off.
The shared merchant list
When an answer names a clear business with a web address and a general category, we add it to a shared list so the next lookup of that merchant is instant. Each item holds the merchant name, its web address, a category from a fixed general list, an emoji, and tags, filed under the merchant name and currency. It doesn’t record who asked and isn’t linked to any account. Items are refreshed after 30 days, or 90 days when confirmed by a web source.
Voice entry
When you speak an entry, the app records the clip on your device and sends it to our server with your account names, category names, your ledger’s currency, your language, and today’s date. xAI transcribes the clip, and xAI’s Grok model turns the text into a draft entry for you to review.
We never save the audio. The transcript and the draft are kept on our server as a short conversation so you can correct the entry by speaking again. It’s deleted when you close the voice screen, or one hour after your last message if the app closes first.
Receipt scan
When you scan a receipt, the app compresses the photo on your device and sends it to our server with your account names, category names, ledger currency, language, region, and today’s date. xAI’s Grok model reads the merchant, total, date, and line items. We don’t store the photo, and the scan doesn’t attach it to the entry. The entry it creates holds the merchant, amount, date, and the items as notes.
CSV import
The file is read on your device. With Suggest Category and Tags on, descriptions Outlayr can’t match on the device are sent to our server, and with Pro, on to xAI to suggest categories: at most 200 at a time, with any run of four or more digits removed, together with your category names and device region. Amounts, dates, and the rest of the file stay on your device. With web lookup on, some descriptions may also be looked up on the web as described above.
Who xAI is
xAI is the US company that makes the Grok AI models. It processes these requests for us as a service provider under its API terms. We don’t use your data to train AI models.
If a request to xAI fails, our server’s error log can include the merchant name involved, so we can find the problem.
Apple Pay and Shortcuts
On iPhone, Outlayr can log card purchases for you through Apple’s Shortcuts app. You install our shortcut from an iCloud link in Settings › Apple Pay and turn on the automation yourself.
When the automation runs, Shortcuts gives Outlayr the amount, merchant, and card name of an Apple Pay purchase, or the title and text of a notification from an app you pick, such as your bank. Outlayr reads the amount and merchant on your phone, matches the card to one of your accounts by name, and adds the entry. Nothing from the automation is sent to us. The new entry is then like any other: it syncs if sync is on, and its merchant name can be used for a merchant suggestion.
Outlayr Pro
Payments for Outlayr Pro go through your app store (Apple’s App Store on iPhone). We never see your card details or your app store account details.
RevenueCat manages subscription status for us. When the app opens, RevenueCat’s software checks whether you have Pro. Before you sign in it uses a random anonymous ID. After you sign in it uses your Outlayr account ID, which is not your name or email. RevenueCat receives your app store purchase and subscription records and basic technical details, such as the app and operating system versions.
Our server asks RevenueCat about your account ID to confirm Pro, and RevenueCat tells our server when your subscription changes. We keep a copy of your subscription records, such as the product, dates, price, and store country, and delete it with your account.
Device permissions
On iPhone, the app asks for each permission the first time a feature needs it. You can change them in iOS Settings.
- Camera: taking a photo of a receipt to scan.
- Photos: choosing a receipt to scan, or a custom image for a transaction or account.
- Microphone: recording an entry you speak, only while you speak.
- Face ID: unlocking Outlayr when the lock is on.
- Notifications: the reminders you turn on.
Outlayr doesn’t ask for your location or contacts, or for permission to track you.
Service providers
These companies help run Outlayr. Each receives only what its job needs.
- Hetzner hosts the servers in Helsinki, Finland, that run our database and server functions. They hold your account and synced data, and handle every request to our server.
- Cloudflare stores the photos you attach to entries and accounts (Cloudflare R2), when photo backup is on.
- xAI provides the Grok AI models behind suggestions, voice entry, receipt scans, CSV import, and web lookups. It receives the content described in Suggestions, voice, and receipts.
- RevenueCat tracks subscription status. It receives an anonymous ID or your account ID, and your purchase records.
- Apple provides Sign in with Apple, App Store payments, and iOS features such as Siri and Shortcuts, under its own policy.
- Google provides Sign in with Google, under its own policy, and is a fallback source for logos, for which it receives a web address and your IP address.
- Logo.dev provides merchant and bank logos. It receives a web address and your IP address.
- Expo delivers app updates. It receives a random install ID, the app version, your IP address, and update error messages.
Frankfurter and CotizaVE publish the exchange rates our server reads. They receive nothing about you.
No ads, analytics, or tracking
Outlayr contains no advertising, analytics, or crash-reporting software. It doesn’t use your device’s advertising identifier and doesn’t track you across other companies’ apps or websites.
We don’t sell your personal information, share it for targeted advertising, or use it to build a profile of you. We don’t use your data to train AI models.
This website
This website sets no cookies and uses no analytics, advertising, or third-party scripts. Its fonts, images, and video are served from the site itself.
The company that hosts the site may keep standard request logs, such as your IP address, browser user agent, the page requested, and the time, to deliver and protect the site. Links to other sites, such as the App Store, lead to services with their own policies.
Legal bases
If you’re in the European Economic Area or the United Kingdom, we rely on these legal bases:
| Purpose | Legal basis |
|---|---|
| Your account, sync, photo storage, voice entry, receipt scans, CSV import, and Pro | Contract: we need this data to provide what you ask for. |
| Merchant suggestions, web lookups, the shared merchant list, and logos | Legitimate interests: making entries faster to file. Suggestions and web lookups are on by default, and turning either off in Feature Lab is how you object. |
| Sessions, usage limits, error logs, and update checks | Legitimate interests: keeping Outlayr secure, working, and free of abuse. |
| Camera, microphone, photos, biometric lock, and notifications | Your permission, given when your device asks and withdrawn in its settings (iOS Settings on iPhone). |
| Answering lawful requests and keeping records the law requires | Legal obligation. |
You can object to any processing based on legitimate interests by writing to [email protected].
How long we keep data
The table above lists how long each kind of data is kept. A few details behind it:
- Synced data, including deletion records for entries you deleted, and backed-up photos are kept until you delete your account.
- Voice conversations are deleted when you close the voice screen, or one hour after your last message.
- Recordings and receipt photos pass through our server to xAI and are not stored by us.
- Merchant suggestion requests aren’t kept once answered. Ones queued in the background wait on our server until your device collects the answer.
- Usage counters that enforce limits on scans, voice entries, and suggestions hold counts only, keyed to your account ID, and are deleted with your account.
- Items in the shared merchant list aren’t linked to anyone. They’re refreshed after 30 or 90 days.
- Our providers, including xAI, Apple, Google, and Expo, keep the data they receive under their own retention policies.
Deleting and exporting
Delete your account
Open Settings › Account › Delete account. You may be asked to sign in again to confirm. Deletion then runs in this order:
- Outlayr’s access to your Apple or Google sign-in is revoked. For Apple, our server asks Apple to revoke it. For Google, the app does.
- Your synced ledger, deletion records, backed-up photos, and pending suggestion requests are deleted from our servers.
- Your customer record at RevenueCat and our copy of your subscription status are deleted.
- Your usage counters, open voice conversations, sessions, sign-in links, and account are deleted.
It starts right away and runs from your device. If it’s interrupted, open Settings › Account again and the app picks up where it stopped. If you can’t use the app, write to [email protected].
Afterward, a record that a deletion happened, with no link to you, is removed within two days of it finishing.
Deleting your account doesn’t cancel an Outlayr Pro subscription, because your app store (Apple’s App Store on iPhone) bills it. On iPhone, cancel it in the iOS Settings app under your name, then Subscriptions. Your app store keeps its own purchase records.
Erase this device
Your ledger on the phone stays after you delete your account, unless you choose Delete account and erase this device. That also removes Outlayr’s database, photos, widget data, Spotlight entries, scheduled reminders, and stored sign-in details from the device. The system keeps control of permissions and widget placement.
Without an account
Nothing of your ledger is on our servers. Settings › Erase Data clears your transactions, and your budgets if you choose, from the phone. Entries already in Recently Deleted stay there. Deleting the app removes the whole ledger.
Export first
Settings › Export Data offers two files. Export CSV is a readable copy of your transactions for a spreadsheet. Export a full archive carries every entry, category, and budget in full and can restore your ledger later. You choose where either file goes.
Your rights
Depending on where you live, you have the right to:
- know what personal data we hold about you and get a copy;
- correct it;
- delete it;
- receive it in a portable format;
- restrict or object to how we use it;
- withdraw a permission you gave, without affecting what happened before.
Most of this works in the app: edit or delete entries, export your data, turn features off, or delete your account. For anything else, write to [email protected]. We may ask you to write from the email address on your account so we can confirm the request is yours. We answer within one month.
In the EEA or UK, you can also complain to your local data protection authority, or in the UK, the Information Commissioner’s Office. We’d like the chance to help first.
US state privacy rights
If you live in California or another US state with a privacy law, this is what we collected in the past 12 months and who received it for a business purpose.
| Category and examples | Received by |
|---|---|
| Identifiers: name, email, account ID, install ID, IP address | Hetzner, RevenueCat, Expo, Logo.dev, Google |
| Commercial information: subscription and purchase records | Apple, RevenueCat, Hetzner |
| Audio and visual information: voice clips, receipt scans, attached photos | xAI (clips and scans), Cloudflare (photos) |
| Internet or network activity: IP address, user agent, request logs | Hetzner, Expo, our website host |
| Records you create: synced entries, amounts, merchants, notes, budgets | Hetzner; merchant, category, and account names to xAI |
It comes from you, your device, Apple, and Google, and we use it for the purposes described in this policy. We keep it for the periods in Data at a glance.
We don’t sell personal information or share it for cross-context behavioral advertising, and we haven’t in the past 12 months. We don’t use sensitive personal information to infer anything about you.
You can ask to know, delete, or correct your personal information, and you won’t be treated differently for asking. An authorized agent can ask for you if we can confirm you gave permission. If we turn down a request, reply to our answer to appeal.
Because we don’t sell or share, there is nothing for a Global Privacy Control signal to opt you out of, but we treat one as a valid opt-out request. This site doesn’t track you, so it works the same with or without Do Not Track.
Security
- Traffic between the app, our servers, and our providers travels over encrypted HTTPS connections.
- Every request for your data is tied to your signed-in session, and our server decides whose data a request can touch. One account can’t read or write another’s ledger or photos.
- Sign-in refresh tokens are encrypted before we store them.
- Requests to xAI carry no name, email, or account ID.
- You can lock Outlayr behind your device’s biometric lock (Face ID or Touch ID on iPhone).
No system is perfectly secure. If you find a security problem, write to [email protected], and if a breach affects your data we’ll tell you as the law requires.
International transfers
Our servers are in Helsinki, Finland, in the European Union. danestves LLC is a US company, and xAI, RevenueCat, Expo, Cloudflare, Logo.dev, Apple, and Google process the data they receive mainly in the United States, whose laws may protect it differently from your own. Write to [email protected] for details of the safeguards that apply.
Children
Outlayr isn’t directed at children under 13, and we don’t knowingly collect their personal data. If you live in the EEA or UK and are under 16, or under the age of digital consent where you live, don’t create an account without a parent’s or guardian’s permission. If you believe a child has given us personal data, write to [email protected] and we’ll delete it.
Changes
When this policy changes, we’ll post the new version here and update the effective date above.
Contact
Questions about this policy or your data go to [email protected]. For help with the app itself, see Support.
We keep emails you send us as long as we need them to help you, and delete them if you ask. Report Bug and Feature Request in Settings open an email that already lists the app version, operating system version, and device type, which you can edit before sending.