Effective date: 15 September 2026
TWAZ Privacy Policy
TWAZ helps you understand what you can spend today. TWAZ 1.0 is designed so core personal finance data is processed locally on your iPhone as much as practical.
Who we are and scope
This policy applies to the TWAZ 1.0 iPhone app, TWAZ widget, and public TWAZ privacy/support pages. TWAZ is the service and responsible party for this policy. Contact us at a@twaz.org.
Data that stays on device
In TWAZ 1.0, core finance data is processed locally on your device, including salary, commitments, transactions, notes, and cycle settings.
TWAZ supports two ways to record a transaction from a bank message, and both are read and parsed on your device only:
- Manual paste: you paste the message text yourself into the app. The app receives that text only when you tap the paste button; it does not inspect the clipboard in the background or read it automatically.
- An Apple Shortcuts automation: you build this yourself in Apple's Shortcuts app — a "When I Get a Message" automation you define — which hands the matching message's text to TWAZ's own bank-message action. TWAZ has no direct or background access to your Messages inbox; Shortcuts, an iOS feature from Apple and not part of TWAZ, is what delivers the text, and only when the automation you built runs.
Either way, the text is parsed on your device only to create a transaction or a review item inside the app, and a one-way digest (hash) is kept to prevent duplicates. The raw message text is never uploaded or stored, by the app or by any TWAZ server.
What we do not ask for
Do not send raw bank SMS, card data, passwords, OTPs, banking credentials, secrets, or sensitive screenshots. TWAZ does not send raw bank SMS to TWAZ backend services, and does not send merchant text, SMS content, or personal finance payloads to any third party.
Optional iCloud backup
TWAZ offers an optional iCloud backup. It is off by default and does nothing until you turn it on inside the app.
- Your on-device data stays authoritative: the backup is a copy kept for recovery, not the source of your data. The app keeps working from your local data whether or not backup is enabled.
- Encrypted on your device before upload: the snapshot is encrypted on your iPhone and leaves it only in encrypted form.
- Stored in your own iCloud: in the CloudKit Private Database belonging to your iCloud account. TWAZ has no access to it, cannot read it, and it never passes through any TWAZ server.
- The backup key is separate from the local storage key: the local storage key is bound to your device and never leaves it. The backup key is a separate key, held in your own Keychain and synced through your iCloud Keychain so you can restore after a reinstall or on another device signed into the same account. TWAZ holds no copy of either key.
- Raw bank message text is not uploaded: the backup contains your in-app financial records and settings. It does not contain raw bank message text — that text is never stored anywhere to begin with.
- You can delete it from inside the app: the "delete backup from iCloud" control removes the cloud copy.
- Deleting the cloud backup does not delete your on-device data: your local data is untouched by a deletion.
- Turning it off only stops future backups: if you disable backup, no new snapshots are uploaded, and any existing copy in iCloud remains there until you explicitly delete it.
- No TWAZ account is required: this works through your Apple iCloud account. TWAZ has no registration, no account, and no sign-in.
If there is no iCloud account on the device, or iCloud Keychain is not enabled, the feature does not operate and the app tells you so, rather than creating a backup that could never be opened again.
Service providers
The only path by which your financial data leaves your device is the optional iCloud backup described above, which goes to your own iCloud account through Apple. In this build the app does not send your financial data to any TWAZ server.
The app does not request exchange rates from any external provider. A foreign-currency transaction stays pending and out of the arithmetic until the bank supplies the settled amount or you confirm it yourself.
TWAZ uses operational services outside the app where needed: Apple for iOS, App Store, TestFlight and iCloud; and Supabase, Resend and Admin infrastructure to run the service internally and answer support. The app does not upload your personal finance data to Supabase, Resend or Admin.
Storage and security
TWAZ uses local encrypted storage and iOS platform security including Keychain and CryptoKit. No digital service can promise absolute security.
Support and retention
If you email support, your inquiry contains whatever you choose to send. Support inquiries are normally retained for up to 12 months, then deleted unless longer retention is reasonably required for legal, security, dispute, or compliance obligations.
Your rights
Under the Saudi PDPL framework and SDAIA guidance, you may have rights to be informed, request access, correction, or destruction where applicable, withdraw consent where processing is consent-based, and contact us for privacy requests or complaints. Email a@twaz.org.
International processing and age
Some operational or support processing may occur outside Saudi Arabia through service providers where applicable. TWAZ is not directed to children under 13.
Changes to this policy
We may update this policy if the app or operations change and will publish a new effective date.