Ekiloa Privacy Notice

Effective date: 20 September 2026 · Last updated: 20 September 2026

We invite you to read this Privacy Notice to understand how Ekiloa Sàrl is committed to respecting your privacy and protecting your personal data.

This notice applies to the mobile applications, websites, and related services currently provided by Ekiloa Sàrl. Some features described below are only available in certain products or regions.

The short version. Our apps and websites are free: there is no subscription, no in-app purchase and no payment of any kind, so we never collect card, bank or billing details. We do not connect to your bank — the financial figures in the app are the ones you type in yourself. We do not sell or share your personal data, we run no advertising, and we embed no third-party advertising or tracking SDKs. You can delete your account, and the data attached to it, directly in the app.

1. Contact information

Data Controller

Ekiloa Sàrl

Rue du Port-Franc 22

1003 Lausanne

Switzerland

Company identification number (UID): CHE-198.984.723

Email: [email protected]

Privacy contact

Ekiloa Sàrl - Privacy

Rue du Port-Franc 22

1003 Lausanne

Switzerland

Email: [email protected]

We aim to answer every privacy request within 30 days. We have not appointed a data protection officer, because the scale and nature of our processing do not require one under Article 37 GDPR; privacy requests are handled by the contact above.

2. Data controllership and applicable law

Ekiloa Sàrl ("Ekiloa", "we", "us") is the operator and controller in connection with the services covered by this notice, unless we expressly state otherwise.

We process personal data in accordance with the Swiss Federal Act on Data Protection (nFADP/nLPD) where Swiss law applies, the EU General Data Protection Regulation (GDPR) and UK GDPR where those laws apply, the California Consumer Privacy Act as amended by the CPRA where it applies, and other applicable privacy legislation where our services are used elsewhere.

Apple, Google, app stores, and other third-party providers referenced in this notice may process personal data under their own privacy notices as independent controllers for their own services.

3. Processed personal data

Depending on the product and the features you use, we may process the following categories of personal data:

  • Account information: display name, email address, account identifier, the sign-in methods linked to your account (email one-time password, Sign in with Apple, Sign in with Google) and the identifier the provider gives us, plus records needed to manage sign-in and account security such as failed-attempt counters and lockout times.
  • Device and application information: a device identifier generated by the app, platform, device model, operating-system version, preferred language, time zone, app version and build number, push-notification token, and related technical request metadata.
  • Budget and personal finance data (in our budgeting product): the figures and labels you enter yourself — your stated monthly income and the day it lands, an estimate of essential expenses, account balances you record, monthly and annual bills, expenses, categories, savings envelopes, their targets and the movements between them, and the currency you use. We never connect to a bank account and never import bank statements or transactions. This data is not payment data: it describes your own plan, not a means of payment.
  • Learning data (in our learning product): selected goals, dashboard settings, generated sessions, learning attempts, and practice selections.
  • Usage and service data: analytics events, viewed screens or pages, timestamps, referrer information, notification status, customer-support interactions, and the feedback you send us.
  • Website information: the page viewed, locale, time zone, referrer, and browser user-agent collected by our own first-party analytics on public pages. Our marketing pages set no advertising cookies and use no third-party analytics.
  • Security and anti-abuse data: IP address and user-agent attached to security-relevant events, app-integrity signals from Apple App Attest and Google Play Integrity, validation results, hashed device and subject identifiers, and records relating to suspected abusive or fraudulent behaviour.

What stays on your device. If you set an app lock code, it is stored only in your device's secure keystore (iOS Keychain / Android Keystore) and never sent to us. Biometric data (Face ID, Touch ID, fingerprint) is handled entirely by your operating system; we never receive or store it.

We do not intentionally collect special categories of data (health, religion, political opinions, and similar). Please do not put such information into free-text fields such as an envelope name or a feedback message.

4. What we never do with your data

  • We do not sell your personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law.
  • We show no advertising and we embed no advertising, attribution, or third-party tracking SDKs in our apps.
  • We collect no payment data. Our apps and websites are free, so there is no card number, bank account, billing address, or purchase history to collect.
  • We do not build advertising or marketing profiles from your budget, your finances, or your learning activity, and we do not use that content to target you.
  • We do not make solely automated decisions that produce legal or similarly significant effects about you.
  • We do not use your content to train third-party AI models.

5. Processing purposes and legal basis

We collect and process personal data only in connection with the services covered by this notice. The table below sets out each purpose and the legal basis we rely on under the GDPR and equivalent Swiss rules.

Purpose Data used Legal basis
Create, administer, and secure your account; authenticate you and your device Account, device, security data Performance of a contract (Art. 6(1)(b) GDPR)
Provide the product features you use, including your budget, your bills and envelopes, or your learning path Budget and personal finance data, learning data, account data Performance of a contract (Art. 6(1)(b) GDPR)
Send push notifications and reminders you have enabled Device token, notification status Consent given in your device settings (Art. 6(1)(a) GDPR)
Handle your support requests and feedback Account data, the content of your message Performance of a contract and our legitimate interest in supporting users (Art. 6(1)(b) and (f) GDPR)
Measure how the product is used so we can maintain, debug, and improve it Usage and service data, website information Legitimate interest in understanding and improving our own service (Art. 6(1)(f) GDPR)
Ensure security and stability, and detect and prevent fraud, spam, and abuse Security and anti-abuse data, device data Legitimate interest in protecting the service and its users (Art. 6(1)(f) GDPR)
Send optional product communications where you asked for them Email address Consent (Art. 6(1)(a) GDPR)
Comply with legal, tax, accounting, regulatory, and litigation-related obligations Any of the above, as required Legal obligation and establishment or defence of legal claims (Art. 6(1)(c) and (f) GDPR)

Where we rely on consent, you may withdraw it at any time for future processing — for example by turning notifications off in your device settings or unsubscribing from an email. Where we rely on a legitimate interest, you may object; we will then stop unless we have compelling legitimate grounds that override your interests.

6. Automated checks and abuse prevention

We use limited automated checks to validate sign-in credentials, device and app-integrity signals, and suspicious request or usage patterns. These checks help us protect the service, prevent abuse, investigate misuse, and maintain platform security.

Where a request or device cannot be validated, access to certain features may be rejected, limited, or delayed until the issue is resolved. We do not rely on solely automated decision-making to make decisions that produce legal or similarly significant effects about you. If an automated check blocks you and you believe it is wrong, write to us and a person will review it.

7. Security

We protect personal data against foreseeable risks and unauthorised access with appropriate technical and organisational measures, including:

  • encryption in transit for all traffic between the app, our websites, and our servers, and between our own systems;
  • encryption at rest for sensitive stored values;
  • strict database-level isolation so that one account's records cannot be read from another account's session;
  • device-bound sessions and short-lived sign-in codes, with app-integrity attestation (Apple App Attest, Google Play Integrity) before sensitive operations;
  • least-privilege access for our own staff and systems, and logging of security-relevant events;
  • regular dependency and supply-chain integrity checks on the software we ship.

No method of transmission or storage is completely secure. If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you, without undue delay. If you believe your account or device has been compromised, please contact us promptly.

8. Data sharing and international transfers

We do not sell personal data and we do not disclose it for anyone else's marketing. We share it only with the service providers we need to run the product, and with professional advisers, authorities, or a transaction partner where this is necessary to comply with law, prevent abuse, protect rights, or support a business transaction such as a merger or acquisition.

Our primary systems and databases are hosted in Switzerland. The providers we rely on, and what each of them receives, are:

Provider Role Data involved Processing location
Exoscale (Akenes SA) Hosting of our servers, databases, and stored files All data described in Section 3 Switzerland (Geneva)
Cloudflare Content delivery, TLS termination, and protection against attacks for our websites and API Connection metadata such as IP address, user-agent, and requested URL Global edge network, with the closest location serving the request
Resend Delivery of transactional email (sign-in codes, service notices) Email address, message content European Union and United States
Sentry Error and crash monitoring Technical error context, app and device metadata, account identifier European Union and United States
Apple App distribution, Sign in with Apple, push notifications (APNs), App Attest integrity checks Account identifier from Apple, device token, integrity signals United States and worldwide
Google App distribution, Sign in with Google, push notifications (FCM), Play Integrity checks Account identifier from Google, device token, integrity signals United States and worldwide

Analytics for our apps and websites are collected and stored by us on our own infrastructure; we use no third-party analytics service.

Where personal data leaves Switzerland or the EEA, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses together with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, plus any additional measures the transfer requires. You may ask us for a copy of the safeguards in place.

9. Account creation and sign-in via Apple or Google

We may offer account creation and sign-in using Apple or Google. If you use one of these single sign-on methods, we may receive information such as your account identifier, your email address, and basic account-profile data made available by that provider. With Sign in with Apple you may choose to hide your email address, and we will work with the relay address Apple gives us.

We do not control the scope of processing carried out by Apple or Google for their own services. Please consult their privacy notices for more information. If you delete your Ekiloa account, we also ask Apple to revoke the sign-in grant that linked your Apple account to ours.

10. Customer contact

We may contact you about service-related topics such as account security, changes to the service, product information directly related to your use, and customer-support matters. These messages are part of the service and cannot be turned off while you have an account.

If you request optional product communications, we process your contact details on the basis of your consent. You can opt out at any time by using the unsubscribe method included in the communication or by contacting us.

11. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by legal, regulatory, tax, accounting, security, dispute-resolution, or backup obligations. Our current periods are:

Category Retention
Account information, budget and personal finance data, learning data While your account exists; erased when you delete your account
Email one-time sign-in codes 10 minutes, then unusable; deleted with your account
Sign-in sessions (refresh tokens) Expire after 30 days without use, and after 180 days in any case
Security and anti-abuse event records 90 days, then deleted automatically
Usage and analytics events 24 months, then deleted automatically
Support conversations and feedback Up to 24 months after the exchange ends
Encrypted backups Rotated out within 90 days of a deletion
Records kept for legal, tax, or accounting reasons For the statutory period that applies to them, typically 10 years under Swiss law

When you delete your account, the erasure runs immediately and covers your profile, your sign-in methods and sessions, your devices and push tokens, and your budget, learning, feedback, and notification records. Security event records are kept without your account identity for the remainder of their 90-day window, analytics events already collected remain in aggregate form until their retention expires, and encrypted backups age out on the schedule above.

12. Your rights

Depending on applicable law and your location, you have the right to request access to your personal data, its correction, its deletion, a restriction of processing, a portable copy, and to object to processing based on our legitimate interests. You may also withdraw consent where we rely on consent, without affecting processing already carried out.

Deleting your account. You do not need to ask us: open the app, go to the settings screen, and choose to delete your account. The deletion is carried out as described in Section 11.

Other requests can be sent to [email protected]. We may ask for information needed to verify your identity before fulfilling a request, and we answer within 30 days. Exercising your rights is free, and we will never treat you differently for having done so.

13. Children

Our services are not directed to, and not intended for, children under 16, unless a lower digital-consent age applies under local law and valid authorisation exists. We do not knowingly collect personal data from a child below that age. If you believe a child has given us personal data, contact us and we will delete it.

14. California privacy information

If you are a California resident, this section supplements the rest of the notice. In the preceding 12 months, the categories of personal information described in Section 3 may have been collected from you, from your device or browser, from Apple or Google when you use their services, and from our own systems as you use the service. We use these categories for the business and commercial purposes described in Section 5, disclose them to the service providers listed in Section 8, and retain them for the periods stated in Section 11.

No sale, no sharing. We have not sold personal information and we have not shared personal information for cross-context behavioural advertising in the preceding 12 months, and we do not do so today. We therefore operate no "Do Not Sell or Share My Personal Information" mechanism; because we never sell or share, an opt-out preference signal such as Global Privacy Control has nothing to opt out of on our services, and we honour it as a matter of course.

Sensitive personal information. We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted without an opt-out right under the CPRA.

California residents may request to know, access, correct, and delete personal information, and to obtain a portable copy, subject to applicable exceptions. Use the same channels described in Section 12. An authorised agent may submit a request on your behalf with proof of authorisation. We will not discriminate against you for exercising any of these rights.

15. Right to lodge a complaint

If you have concerns about our processing of personal data, please contact us first so we can try to resolve the issue. You may also lodge a complaint with the competent supervisory authority in your jurisdiction — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EEA, the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement; in the United Kingdom, the Information Commissioner's Office (ICO).

16. Changes to this notice

We may update this Privacy Notice from time to time. The "Last updated" date at the top of this page always reflects the current version. If a change materially affects how we use your personal data, we will tell you by email or in-app notice before it takes effect, and where the law requires it we will ask for your consent.