Privacy Policy
Last updated: 2026-09-15
Currency Cushion (“the App”) is a personal capital dashboard. This policy explains what data the App handles and what it does not.
What stays on your device
The App does not require an account and does not sync your portfolio to our servers. The following stay in a local SQLite database on the device:
- balances you enter (cash, cards, deposits, crypto, shares, metals)
- goals, home currency, favorites, theme, language, hidden-amounts setting
- monthly spend you enter (for months of cushion)
- manual rates
- daily snapshots of the home-currency total
- a local ledger of balance deposits and withdrawals (when you put money in or took it out with + / −). That ledger never leaves the device unless you export a backup file yourself
- Pro status, PIN lock, Face ID / fingerprint toggle, encrypted auto-backup toggle
If you add the optional home-screen widget, the App copies a formatted total (or a hidden placeholder) into OS widget storage on this device. That copy is not uploaded. Removing the widget, Delete all data, or uninstalling the app clears it.
The optional app PIN is stored as a salted hash only — never the PIN itself. PIN credentials, the biometrics toggle, and the auto-backup toggle are excluded from backup export/import.
Biometrics
If you turn on Face ID or a fingerprint unlock, the App asks the operating system to confirm it is you. Biometric templates stay in the OS (Secure Enclave / Android keystore). We never receive them, store them, or send them anywhere.
What leaves the device
When you refresh rates, the App requests public quote endpoints. Amounts, pocket names, goals, and the deposit ledger are never sent in those requests.
- National Bank of the Republic of Belarus (
api.nbrb.by) — BYN pairs - open.er-api.com (exchangerate-api.com open endpoint) — other currencies
- CoinGecko (
api.coingecko.com) — public coin prices for the built-in catalog - Yahoo Finance chart API (
query1.finance.yahoo.com) — public share and metal-futures quotes
Shares: the Yahoo request URL includes the ticker of shares you hold (and tickers already in the local rate cache). It does not include quantity or value. If you hold no shares and have none cached, this request is not made.
Metals: the App always asks for the four public futures symbols in the catalog (gold, silver, platinum, palladium). That request does not reveal which metal, if any, you entered.
Responses are cached on the device for offline use.
The App may contact our ops API at api.cushion.foryou.quest to:
- fetch non-personal app configuration (minimum version, announcements, feature flags)
- register a Firebase Cloud Messaging (FCM) device token when notifications are allowed, together with OS name, app language, app version, and store channel (App Store, Google Play, RuStore)
- if you use in-app Support, send your messages so we can reply. That thread also stores OS name, language, app version, store channel, and whether Pro is active. It does not include balances. If notifications are allowed, we may send a push when we reply
The FCM token is not your portfolio. You can deny notification permission on the OS level. You can skip Support and email us instead.
Analytics and crash reports
The App uses Google Firebase Analytics and Firebase Crashlytics to understand which screens people open, whether they hit a free-plan limit or the paywall, whether Pro is active, which store the binary came from, and to diagnose crashes. Events do not include amounts, holdings, tickers, PIN, backup files, the deposit ledger, or advertising identifiers. Collection is not used for ads or tracking across other companies’ apps.
We do not collect the Google Advertising ID or Apple’s Identifier for Advertisers. Firebase Analytics advertising-ID collection is disabled, and the Android Play bundle removes the AD_ID permission. You can still reset those identifiers in Android or iOS Settings. We do not request App Tracking Transparency because we do not track.
Backup
Manual export writes a JSON file you control (pockets, goals, settings that are safe to copy, daily total snapshots, and the local deposit/withdrawal ledger). Import reads a file you choose. The App does not upload that file. Destinations you pick in the system share sheet (Files, Mail, a cloud folder) are governed by those services, not by us.
Pro can keep an encrypted auto-backup (AES-GCM) in the App’s private documents folder. The file is sealed with a key derived from your PIN; that key is kept in the OS keychain / keystore. It is not uploaded. You can share the encrypted file yourself and open it on another phone with the same PIN.
PIN hashes, Pro entitlement, biometrics, and the auto-backup flag are never written into a backup file. Pro is restored only through the store account.
Purchases
On the App Store and Google Play, in-app purchases are processed by Apple or Google. We do not receive your payment card details. The RuStore edition has no in-app purchases.
Advertising
The App does not include advertising SDKs.
Children
The App is not directed at children under 13 and does not knowingly collect data from them.
Deleting your data
Step-by-step instructions, what is deleted vs retained, and retention periods: Delete your data — Currency Cushion.
In the app: More → Delete all data wipes the on-device portfolio immediately (including the local deposit ledger) and asks our API to delete this install’s support thread. Email for.you.quest.sup@gmail.com to request deletion of any FCM device record we still hold. We respond within 30 days. There is no account to close.
Contact
Privacy questions: Support or the publisher contact listed on the App Store / Google Play listing.
Changes
We may update this policy when the App’s data practices change. The date at the top of this page is the source of truth for the current version.