Privacy Policy — Tick
Last updated: 30 August 2026
This document has not been reviewed by a lawyer. It was written from the application's actual data flows rather than from a template, which makes it accurate but not a substitute for professional review — particularly for KVKK, where the Turkish text is the one that governs. Have both versions reviewed before launch.
Tick is an expense tracker published by Arkon Technology. This policy explains exactly what the app stores, where it goes, and what you can do about it.
The short version
Tick stores the expenses you type in and, if you attach them, photographs of receipts. It does not connect to your bank, does not read your messages or photos beyond the ones you pick, contains no advertising, and includes no analytics or tracking of any kind. Your data is not sold, rented, or shared with anyone for their own purposes.
What is stored
Your account. An email address and a password. The password is never stored in readable form — only a one-way hash produced by our authentication provider. We cannot read it and cannot recover it for you.
Your expenses. For each one: the amount, its currency, the exchange rate at the moment you entered it, the converted amount, the date, and whichever of these you chose to add — a category, a place name, an account name, tags, and a note.
Your receipts. Only photographs you explicitly attach. They are stored in a private area that only your account can read.
Your settings. Interface language, light or dark theme, base currency, and your list of favourite currencies.
Nothing else. No advertising identifier, no location, no contacts, no device fingerprint, no usage analytics, no crash telemetry, no third-party SDK that collects anything.
Where it is stored
Everything is written to your device first, so the app works with no connection. When you are signed in it is also synchronised to a database operated by Supabase, hosted in Frankfurt, Germany (AWS eu-central-1) — inside the European Union.
Access is enforced at the database level by row-level security: every query is filtered by your account identifier, and receipt files are keyed by it. This is verified rather than assumed; a second account cannot read, change, or delete your rows.
Who else sees anything
Three processors, each doing one thing:
| Processor | What it receives | Why |
|---|---|---|
| Supabase | Everything above | Database, authentication, receipt storage |
| Resend | Your email address and the message body | Sending confirmation and password-reset codes. Nothing else is ever emailed to you. |
| Frankfurter (ECB rates) | The currency codes you use — for example TRY, EUR | Fetching daily exchange rates. No account identifier, no amounts, and no personal data are sent; the request reveals only which currencies you have. |
When you subscribe, the payment is handled entirely by Apple or Google. We never see your card details. We receive only whether a subscription is active and when it expires.
That is the complete list. There is no analytics provider, no advertising network, and no data broker.
How long it is kept
Until you delete it. Deleting an expense removes it. Deleting your account removes everything on the server — profile, expenses, categories, places, tags, templates and receipt files — permanently and immediately, not after a retention window.
The copy on your own device is left alone when you delete your account, so you do not lose your records by leaving the service. Removing the app removes that copy.
What you can do
- See everything you have. Every field is visible and editable in the app.
- Take it with you. Export to CSV or PDF at any time, from Reports or Settings. The CSV contains every field, in a form a spreadsheet can read.
- Correct it. Any expense can be edited or deleted.
- Delete your account. Settings → Account & sync → Delete account. It is immediate and cannot be undone.
- Use the app without an account? No. An account is required, because synchronisation and backup are what it provides. Nothing else about the app depends on being online.
Under the GDPR and KVKK you also have the right to object to processing, to restrict it, and to complain to a supervisory authority. The first two are exercised by deleting your account, since the processing described here is what the app *is*. For anything else, write to the address below.
Children
Tick is not directed at children and we do not knowingly collect data from anyone under 16.
Security
Sessions are stored in the device keystore — the iOS Keychain or the Android Keystore — rather than in ordinary application storage. Traffic is encrypted in transit. Data is encrypted at rest by the hosting provider. Passwords are hashed with bcrypt and are not recoverable.
No system is perfect, and claiming otherwise would be the least trustworthy thing in this document. If you find a security problem, please write to us before publishing it.
Changes
If this policy changes in a way that affects what is collected or who receives it, the app will say so before the change takes effect. The date at the top always reflects the current version.
Contact
Arkon Technology Email: hello@tickexpense.com
For privacy requests, write from the address on your account so we can identify you without asking for further personal information.