Privacy policy
Last updated 24 September 2026
Wastly is a personal finance app for macOS. This policy explains what data the app touches, what leaves your Mac, and why. The short version: your financial data stays on your computer; the only things we store are the email address of an account you choose to create and the status of your subscription.
Who we are
Wastly is developed and operated by Misha S, a sole proprietor registered in Ukraine (“we”). You can reach us at support@wastly.app.
Data that stays on your Mac
Everything you enter or import is stored in the app’s data folder on your Mac (under ~/Library/Application Support) and is never sent to us:
- transactions, bank accounts and balances, categories, auto rules, notes;
- income sources and payments, recurring bills, savings goals;
- bank statement files you import and the ids of imported rows;
- your Monobank personal token, if you connect Monobank;
- your Anthropic or OpenAI API key, if you use Ask;
- the app’s diagnostic log.
Backups you export are ordinary files that you control. Deleting the app’s data folder removes all of this.
Data we store if you create an account
An account is optional. It exists only to attach a Wastly Pro plan to you. When you log in with Google (or, later, Apple), we receive from the identity provider your email address, your display name and your profile picture URL. We store:
| Data | Purpose | Kept |
|---|---|---|
| Email address, provider identity id | Identify your account; link the same person across providers | Until you delete the account |
| Trial end date | Run the 7-day free trial once per account | Until you delete the account |
| Subscription status, plan, period end, the payment provider’s subscription id | Decide whether Pro features are unlocked; handle renewals, cancellations and refunds | Until you delete the account |
Your name and picture are shown inside the app and are not stored by us beyond the identity provider’s record. The account service is hosted by Supabase (data centres in the EU). We do not store your ledger, your bank data or your API keys on any server.
You can delete your account from inside the app (Settings → Profile → Delete account). This removes your profile and subscription records immediately. An active paid subscription must be cancelled with the payment provider first; the app tells you if that is the case.
Payments
Purchases made through this website are processed by Paddle.com Market Ltd as merchant of record. Paddle collects your payment details, billing country and email, handles taxes and issues invoices under its own privacy policy. We never see your card number. Paddle tells us the status of your subscription and the email used at checkout so we can unlock Pro for the right account.
Purchases made inside the App Store version are processed by Apple under Apple’s terms. Apple tells us only that a subscription exists and its status.
Third parties the app talks to
| Service | When | What is sent |
|---|---|---|
| Supabase (account backend) | Only when you log in | Your login session, the email from your identity provider |
| Google (sign-in) | When you log in with Google | Standard OAuth sign-in in your system browser |
| Paddle | When you buy Pro on the website | Checkout handled on Paddle’s pages |
| Anthropic or OpenAI | Only when you use Ask, with your own API key | Your question and the financial summaries you have allowed Ask to see (scope toggles in the app), sent directly from your Mac to the provider you chose under its terms. Nothing passes through our servers. |
| Monobank API | Only if you connect Monobank | Your personal token, to fetch your own statements directly |
| frankfurter.app and the National Bank of Ukraine | When converting currencies | Currency codes and dates only. No personal data. |
What we do not do
- No analytics, tracking pixels, advertising SDKs or crash reporters in the app or on this site.
- No selling, renting or sharing of your data with anyone other than the processors above.
- No reading of your ledger. It never reaches us.
Legal basis and your rights
We process account data to perform the contract with you (providing the trial and subscription) and, for the minimal records payment providers require, to meet legal obligations. If you are in the EU, UK or another jurisdiction with data protection law, you have the right to access, correct, export and erase your data and to complain to your supervisory authority. Deleting the account in the app exercises erasure; for anything else, email support@wastly.app.
Children
Wastly is not directed at children under 16 and we do not knowingly collect data from them.
Changes
We will post any changes to this policy on this page with a new date. Material changes affecting account holders will also be announced in the app.