Tick

Privacy Policy — Tick

Last updated: 30 August 2026

Türkçe

This document has not been reviewed by a lawyer. It was written from the application's actual data flows rather than from a template, which makes it accurate but not a substitute for professional review — particularly for KVKK, where the Turkish text is the one that governs. Have both versions reviewed before launch.

Tick is an expense tracker published by Arkon Technology. This policy explains exactly what the app stores, where it goes, and what you can do about it.

The short version

Tick stores the expenses you type in and, if you attach them, photographs of receipts. It does not connect to your bank, does not read your messages or photos beyond the ones you pick, contains no advertising, and includes no analytics or tracking of any kind. Your data is not sold, rented, or shared with anyone for their own purposes.

What is stored

Your account. An email address and a password. The password is never stored in readable form — only a one-way hash produced by our authentication provider. We cannot read it and cannot recover it for you.

Your expenses. For each one: the amount, its currency, the exchange rate at the moment you entered it, the converted amount, the date, and whichever of these you chose to add — a category, a place name, an account name, tags, and a note.

Your receipts. Only photographs you explicitly attach. They are stored in a private area that only your account can read.

Your settings. Interface language, light or dark theme, base currency, and your list of favourite currencies.

Nothing else. No advertising identifier, no location, no contacts, no device fingerprint, no usage analytics, no crash telemetry, no third-party SDK that collects anything.

Where it is stored

Everything is written to your device first, so the app works with no connection. When you are signed in it is also synchronised to a database operated by Supabase, hosted in Frankfurt, Germany (AWS eu-central-1) — inside the European Union.

Access is enforced at the database level by row-level security: every query is filtered by your account identifier, and receipt files are keyed by it. This is verified rather than assumed; a second account cannot read, change, or delete your rows.

Who else sees anything

Three processors, each doing one thing:

ProcessorWhat it receivesWhy
SupabaseEverything aboveDatabase, authentication, receipt storage
ResendYour email address and the message bodySending confirmation and password-reset codes. Nothing else is ever emailed to you.
Frankfurter (ECB rates)The currency codes you use — for example TRY, EURFetching daily exchange rates. No account identifier, no amounts, and no personal data are sent; the request reveals only which currencies you have.

When you subscribe, the payment is handled entirely by Apple or Google. We never see your card details. We receive only whether a subscription is active and when it expires.

That is the complete list. There is no analytics provider, no advertising network, and no data broker.

How long it is kept

Until you delete it. Deleting an expense removes it. Deleting your account removes everything on the server — profile, expenses, categories, places, tags, templates and receipt files — permanently and immediately, not after a retention window.

The copy on your own device is left alone when you delete your account, so you do not lose your records by leaving the service. Removing the app removes that copy.

What you can do

Under the GDPR and KVKK you also have the right to object to processing, to restrict it, and to complain to a supervisory authority. The first two are exercised by deleting your account, since the processing described here is what the app *is*. For anything else, write to the address below.

Children

Tick is not directed at children and we do not knowingly collect data from anyone under 16.

Security

Sessions are stored in the device keystore — the iOS Keychain or the Android Keystore — rather than in ordinary application storage. Traffic is encrypted in transit. Data is encrypted at rest by the hosting provider. Passwords are hashed with bcrypt and are not recoverable.

No system is perfect, and claiming otherwise would be the least trustworthy thing in this document. If you find a security problem, please write to us before publishing it.

Changes

If this policy changes in a way that affects what is collected or who receives it, the app will say so before the change takes effect. The date at the top always reflects the current version.

Contact

Arkon Technology Email: hello@tickexpense.com

For privacy requests, write from the address on your account so we can identify you without asking for further personal information.