Privacy Policy — Wallop
Last updated: 3 July 2026
1. Who we are
Wallop ("we", "us", "our") is a personal budgeting application available on iOS. This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, and what rights you have over it.
If you have any questions about this policy or our data practices, contact us at: george.cowlrick.wallop@gmail.com
2. What information we collect
2.1 Information you give us directly
Account details — your name and email address when you create an account.
Financial data you enter manually — spending transactions you log, categories you assign, stash (budget pot) names and amounts, weekly budget figures, goals and target amounts, income band, monthly fixed costs, pay frequency, and payday date.
Net worth data — account nicknames, account types, and balance figures you enter in the net worth tracker.
Character and display preferences — your chosen active character, any character purchases you make, and your pig's name.
2.2 Information collected automatically when you use the app
Session and authentication data — session tokens, IP address, and device user agent string, stored to keep you securely signed in.
Usage activity — spending streaks, weekly budget survival outcomes, payday cycle history, and goal contribution history, which are all created as a natural result of using the app's core features.
App crash and diagnostic data — error reports sent automatically to help us identify and fix bugs. These do not include your financial figures.
2.3 Information from connected bank accounts (TrueLayer)
If you choose to connect a bank account, we receive from TrueLayer:
A list of your bank accounts (account names, types, and balances).
Your recent transaction history (merchant name, amount, date, category).
An encrypted access token and refresh token to maintain the connection.
The consent expiry date associated with your authorisation.
We never receive, store, or have access to your bank login credentials, passwords, or PINs. The bank connection is handled entirely by TrueLayer's secure Open Banking infrastructure. You can disconnect your bank at any time from within the app, which permanently revokes our access.
2.4 Information from couples / partner mode
If you use Wallop with a partner:
Your account is linked to your partner's account via an invite code.
Shared stash names, amounts, and transactions are visible to both partners.
Each partner's active character, spending history outside shared stashes, and personal financial data remain private to that individual. Partner mode shares only what is explicitly designated as shared.
2.5 Information from in-app purchases (RevenueCat)
When you make an in-app purchase (a character unlock or a Pro subscription):
RevenueCat processes the purchase via Apple's StoreKit infrastructure.
We receive confirmation of what was purchased and your RevenueCat anonymous customer ID.
We do not receive or store your payment card details. All payment processing is handled entirely by Apple.
Purchase history (specifically which character product IDs appear in your non-subscription transaction history) is used solely to determine which characters you have unlocked.
2.6 Information we do not collect
We do not collect your actual bank credentials or passwords.
We do not read your contacts, messages, camera, or microphone.
We do not track your location.
We do not run advertising or build advertising profiles.
We do not sell your data to any third party.
3. Why we collect this information (legal basis)
PurposeData usedLegal basisProviding the budgeting serviceTransactions, stashes, goals, budgets, bank dataPerformance of a contractKeeping your account secureSession tokens, IP, user agentLegitimate interestsRemembering your preferencesActive character, pig name, currencyPerformance of a contractCouples modeShared stash data, partnership linkPerformance of a contractImproving the appAnonymised crash data, aggregate usage patternsLegitimate interestsProcessing purchases and restoring entitlementsRevenueCat transaction historyPerformance of a contractComplying with legal obligationsAny data required by applicable lawLegal obligation
4. How long we keep your data
Data typeRetention periodAccount and authentication dataUntil you delete your accountFinancial transactions and budgetsUntil you delete your accountBank connection tokensUntil you disconnect your bank or delete your accountSession records30 days after session expiryPurchase history (character unlocks, Pro)Until you delete your accountAnonymised crash reports90 days
When you delete your account, all personally identifiable data is permanently deleted from our systems within 30 days. Anonymised aggregate data (which cannot be linked back to you) may be retained for product analytics.
5. Who we share your data with
We share your data only with the following categories of third-party service providers, and only to the extent necessary to deliver the service:
5.1 Infrastructure and database
Neon (Neon Inc.) — our cloud PostgreSQL database provider. Your data is stored securely in their infrastructure. Neon is SOC 2 compliant.
5.2 Authentication
Better Auth — provides the authentication layer for account sign-in. Handles session tokens and password hashing.
5.3 Open Banking / bank connection
TrueLayer — regulated Open Banking provider used to connect your bank account. TrueLayer is authorised and regulated by the Financial Conduct Authority (FCA) in the UK. Your bank credentials are handled exclusively by TrueLayer; we never see them.
5.4 In-app purchases and subscription management
RevenueCat — processes purchase receipts, manages subscription entitlements, and handles purchase restoration. RevenueCat does not receive your payment details; these remain with Apple.
Apple (StoreKit) — processes all payments. Apple's privacy policy governs how they handle payment data.
5.5 Error monitoring
Sentry — used for crash reporting and error diagnostics. Reports are pseudonymised and do not include your full financial data.
5.6 File hosting / asset delivery
Uploadcare / AWS CloudFront — used to serve app image assets (character images). No personal data is transmitted to these services.
We do not share your data with data brokers, advertisers, or analytics companies that track you across other apps or websites.
6. International data transfers
Some of our service providers operate in or transfer data to countries outside the UK and European Economic Area (EEA), including the United States. Where this happens, we ensure appropriate safeguards are in place — including Standard Contractual Clauses or equivalent mechanisms — as required by UK GDPR.
7. Data security
We take the following measures to protect your data:
All data in transit is encrypted using TLS 1.2 or higher.
Passwords are hashed using Argon2 and are never stored in plaintext.
Bank access tokens are stored in encrypted form.
Database access is restricted to authenticated application services only.
We use session expiry and token rotation to reduce the risk of session hijacking.
No system is completely immune to security risks. If you believe your account has been compromised, contact us immediately at privacy@wallop.app.
8. Your rights
Depending on where you are located, you may have the following rights over your personal data:
8.1 For users in the UK and EEA (UK GDPR / GDPR)
Right of access — you can request a copy of all personal data we hold about you.
Right to rectification — you can ask us to correct inaccurate data.
Right to erasure — you can request deletion of your account and all associated personal data.
Right to restriction — you can ask us to restrict processing of your data in certain circumstances.
Right to data portability — you can request your data in a structured, machine-readable format.
Right to object — you can object to processing based on legitimate interests.
Right to withdraw consent — where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, contact us at privacy@wallop.app. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have mishandled your data.
8.2 For users in California (CCPA / CPRA)
You have the right to know what personal information we collect and how it is used.
You have the right to delete personal information we hold about you.
You have the right to opt out of the sale of personal information. We do not sell personal information.
You have the right to non-discrimination for exercising your privacy rights.
To submit a CCPA request, contact us at privacy@wallop.app.
8.3 Account deletion
You can delete your account from within the app settings. This permanently and irreversibly removes all your personal data from our systems within 30 days.
9. Children's privacy
Wallop is not directed at children under the age of 13 (or 16 in the EEA/UK). We do not knowingly collect personal information from anyone under these ages. If you believe a child has created an account, contact us at privacy@wallop.app and we will delete the account promptly.
10. Bank connection — additional disclosures
When you connect a bank account through TrueLayer:
You are granting Wallop read-only access to your account information and transaction history. We cannot initiate payments or move money.
Your consent is time-limited. TrueLayer will prompt you to re-authorise the connection when your consent period expires (typically every 90 days, depending on your bank).
You can revoke access at any time in two ways: (a) from within the Wallop app settings, or (b) directly from your bank's app or website through their connected services / open banking permissions section.
Transaction data synced from your bank is stored in your Wallop account and subject to the same retention policy as manually entered data.
11. Push notifications
If you grant Wallop permission to send notifications, we may send you:
Spending reminders and weekly budget summaries.
Payday and goal milestone alerts.
You can revoke notification permission at any time in your iOS Settings. Revoking permission does not affect your account or data.
12. Cookies and local storage
The Wallop mobile app does not use browser cookies. The app uses:
Secure token storage on your device to maintain your authenticated session.
AsyncStorage for local caching of character unlock state and display preferences.
This data is stored locally on your device and is not transmitted to third parties.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to our practices or for legal reasons. When we make material changes, we will notify you in-app and update the "Last updated" date at the top of this policy. Continued use of the app after notification constitutes acceptance of the updated policy.
14. Contact us
For any privacy questions, data subject requests, or concerns:
Email: george.cowlrick.wallop@gmail.com
We aim to respond to all enquiries within 5 business days and to fulfil all data rights requests within 30 calendar days.