1. Introduction
Strata Veritate LLC (“Company,” “we,” “us,” or “our”) operates the Summa mobile application (“App”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
We are committed to protecting your privacy and financial data. This policy is designed to comply with applicable data protection laws, including the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR) where applicable, and Apple’s App Store Review Guidelines.
Please read this Privacy Policy carefully. By using the App, you consent to the practices described herein. If you do not agree with this Privacy Policy, please do not use the App.
2. Information We Collect
2.1 Information You Provide Directly
| Data Category | Examples | Purpose |
|---|---|---|
| Account Information | Name, email address, profile photo URL | Account creation, identification, communication |
| Financial Data | Transactions, amounts, merchants, categories, notes, budgets, savings goals, investment holdings, cost basis | Core app functionality: budgeting, tracking, analysis |
| Account Configuration | Preferred currency, language, notification preferences, theme settings, accessibility settings | Personalization and user experience |
| Support Messages | Messages you send us through in-app support chat, and our replies | Answering your questions and resolving issues. Stored on our servers so the conversation persists across your devices. Please do not include account numbers or credentials in a message. |
| Referral Participation | Your referral share code, the code you were referred by (if any), and reward status | Operating the referral program and issuing rewards |
2.2 Information Collected Through Third-Party Services
2.2.1 Plaid (Bank Synchronization, Pro+Connect Only)
If you opt in to bank synchronization, Plaid, Inc. collects and provides us with:
- Account names, types, and balances
- Transaction history (amounts, dates, merchants, categories)
- Account and routing number fragments (masked, for identification only)
- Institution names and logos
We do NOT receive or store your bank login credentials. Plaid access tokens are stored exclusively on our server-side infrastructure, in documents that no client application can read, and are never transmitted to or stored on your device.
For Plaid’s data practices, see: Plaid’s Privacy Policy
2.2.2 Firebase Services (Google)
| Service | Data Processed | Purpose |
|---|---|---|
| Firebase Authentication | Email, auth provider identifiers, authentication tokens | Secure user identity management |
| Cloud Firestore | Cloud Backup & Sync (see section 4.2): your accounts, transactions, budgets and budget groups, savings goals, recurring items, investment portfolios, labels, categorization rules and learning examples, CSV import history, and financial health history. Also: Plaid sync metadata, subscription state, Shared Spaces connection metadata, promotional code and referral records, in-app support messages, and analytics health metrics | Cross-device sync and device restore; server-side data coordination |
| Firebase Storage | Shared Spaces profile photos, if you set one | Displaying your avatar to people you share with. Stored with private access controls. |
| Firebase Cloud Functions | Plaid API proxy calls, subscription verification, Shared Spaces connection management, market data proxy, push notification delivery | Secure server-side business logic |
| Firebase Analytics | Anonymized product usage events (feature interactions, screen views, session data) | Product improvement and performance monitoring |
| Firebase Crashlytics | Crash reports, device model, OS version, app version, stack traces | App stability monitoring and bug fixing |
| Firebase Cloud Messaging (FCM) | Device push tokens | Delivering push notifications |
| Firebase App Check | Device attestation tokens | Preventing abuse and unauthorized API access |
Firebase Analytics and Crashlytics data are processed under Google’s data processing terms. We do not use Firebase Analytics for advertising or ad targeting.
2.2.3 Apple Services
| Service | Data Processed | Purpose |
|---|---|---|
| StoreKit | Subscription status, transaction receipts, Apple ID account token | In-app purchase management |
| AdServices & SKAdNetwork | Apple Search Ads attribution token; privacy-preserving install and milestone conversion values reported to Apple | Measuring which advertising campaigns lead to installs. No IDFA and no cross-app tracking are involved. |
| Sign in with Apple | Apple user identifier, optional name and relay email | Authentication |
| Apple Push Notification Service (APNs) | Device tokens, notification payloads | Local and remote notification delivery |
2.3 Information Collected Automatically
| Data Category | Details | Purpose |
|---|---|---|
| Device Information | Device model, operating system version, app version (via Crashlytics) | App compatibility and crash diagnosis |
| Usage Analytics | Feature usage patterns, session duration, screen views (anonymized via Firebase Analytics) | Product improvement |
| Performance Data | App launch times, error rates, crash frequency | Performance optimization |
2.4 Information We Do NOT Collect
- Advertising identifiers (IDFA): We do not use the Identifier for Advertisers.
- Location data: The App never requests location permission and does not access GPS, Wi-Fi, or cellular location services. The one narrow exception: when you select an existing photo for receipt scanning, any GPS coordinates already embedded in that photo’s EXIF metadata may be read on your device to help infer the correct currency. This happens entirely on-device, is never stored, and is never transmitted.
- Contact lists: We do not access your contacts, call logs, or messages.
- Biometric data: Biometric authentication (Face ID / Touch ID) is handled entirely by Apple’s LocalAuthentication framework on your device. We never receive, transmit, or store biometric templates or data.
- Browsing history: We do not track your web browsing activity.
- Microphone or camera data: The camera is accessed only when you explicitly initiate receipt scanning. Images are processed in-memory using Apple’s Vision framework for on-device OCR and are never saved, uploaded, or transmitted.
3. How We Use Your Information
3.1 Core Service Delivery
- Providing personal finance tracking, budgeting, and analysis features
- Synchronizing your data across your devices via your personal iCloud account
- Processing and categorizing transactions
- Generating financial forecasts, cash flow analysis, and net worth calculations
- Managing your subscription and account
3.2 Service Improvement
- Analyzing anonymized usage patterns to improve features and user experience
- Monitoring app stability and fixing crashes and bugs
- Measuring feature adoption to prioritize product development
3.3 Communication
- Delivering push notifications you have enabled (budget alerts, bill reminders, goal milestones, etc.)
- Sending service-related communications (subscription status, security alerts)
3.4 Security
- Authenticating your identity
- Preventing fraud and unauthorized access via Firebase App Check
- Monitoring for suspicious activity
4. On-Device Processing and Machine Learning
A core architectural principle of Summa is data minimization through on-device processing.
4.1 On-Device Machine Learning
All machine learning features operate entirely on your device:
- Transaction categorization: CoreML BERT models classify transactions locally
- Smart recurring detection: Pattern recognition runs on-device
- Merchant identification: Heuristic and ML-based merchant matching occurs locally
- Receipt OCR: Apple Vision framework processes receipt images in-memory; images are never persisted or transmitted
No financial data is sent to any external machine learning service, including our own servers, for inference or model training.
4.2 Where Your Financial Data Is Stored
Your device is the primary copy. Your financial data (transactions, accounts, budgets, goals, recurring items, investment holdings) is stored on your device using Apple’s SwiftData framework, protected by iOS file-level encryption.
Cloud Backup & Sync. So that your data survives a lost device and appears on every device you sign in to, the App also mirrors these records to Cloud Firestore, a Google Cloud database that we operate. The copy is stored under your account identifier, is isolated from other users by enforced server-side security rules, and is encrypted at rest by Google Cloud. Your device remains the source of truth; the cloud copy exists to restore and synchronize it.
Two things follow from this, and we want to be explicit about both. First, unlike a purely on-device app, a copy of your financial records is held on infrastructure we control. Second, because we operate that infrastructure, our administrative systems are technically capable of accessing it. We access it only where necessary to operate the service, to resolve a support request you raise with us, or where we are legally required to. We do not use it for advertising, we do not sell or rent it, and we do not analyze it to build profiles about you.
Shared Spaces data is different. Anything you publish to a Shared Space is end-to-end encrypted on your device before it is uploaded, and we cannot read it. See section 6.3.
Historical note. Earlier versions of the App used Apple’s iCloud/CloudKit for cross-device sync. That mechanism has been retired and is no longer used. If you used a prior version, any data previously mirrored to your private CloudKit database remains under your control in your Apple account and can be removed through your device’s iCloud settings.
5. Encryption and Security
5.1 Encryption at Rest
- On-device: All local data benefits from iOS hardware-level encryption (Data Protection class). Sensitive items are stored in the iOS Keychain with
kSecAttrAccessibleWhenUnlockedThisDeviceOnlyprotection. - Hierarchical key architecture: The App employs a Secure Enclave-backed root key → Key Encryption Key (KEK) → per-record Content Encryption Key (CEK) hierarchy for sensitive on-device data encryption using AES-256-GCM.
- Server-side: Firestore data, including the Cloud Backup copy of your financial records, is encrypted at rest by Google Cloud’s default encryption and isolated per user by enforced security rules.
- Bank access tokens: Plaid access tokens are held server-side in dedicated Firestore documents that are unreadable and unwritable by any client application, enforced by security rules that deny all client access. They are used only by our Cloud Functions and are never transmitted to or stored on your device.
5.2 Encryption in Transit
All network communications use TLS 1.2 or higher. App Transport Security (ATS) is enforced, ensuring no plaintext HTTP connections.
5.3 Shared Spaces End-to-End Encryption
Data shared through the Shared Spaces feature is protected by end-to-end encryption:
- Key Agreement: P256 Elliptic Curve Diffie-Hellman (ECDH)
- Symmetric Encryption: AES-256-GCM authenticated encryption
- Key Storage: Private keys are stored in the iOS Keychain with device-only access (
kSecAttrAccessibleWhenUnlockedThisDeviceOnly) - Zero-Knowledge Server: Our servers transport only ciphertext. We have no ability to derive the shared secret or decrypt Shared Spaces data.
5.4 Plaid Security
- Bank credentials are provided by you directly to Plaid and are never transmitted to or stored by us.
- Plaid access tokens are held server-side in documents that no client application can read.
- All Plaid API calls are proxied through Firebase Cloud Functions; no direct Plaid API communication occurs from your device.
- When you remove a bank connection or delete your account, we programmatically revoke the associated Plaid access tokens.
6. Data Sharing and Disclosure
6.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information or financial data to any third party. We do not share your data with advertisers. We do not engage in data brokerage.
6.2 Third-Party Service Providers
We share data with the following categories of service providers, solely to the extent necessary to operate the App:
| Provider | Data Shared | Purpose |
|---|---|---|
| Plaid, Inc. | Bank connection tokens (server-side only) | Bank account synchronization |
| Google (Firebase/GCP) | Authentication data, anonymized analytics events, crash reports, Firestore documents, push tokens | Infrastructure, analytics, stability |
| Apple | Purchase receipts, subscription status, Sign in with Apple identifiers, push tokens, ad attribution and conversion values | App Store billing, authentication, notifications, advertising measurement |
| Yahoo Finance (via server proxy) | Stock ticker symbols (no personal data) | Market data retrieval |
| Brandfetch (via server proxy) | Institution and company names or domains only (no personal data) | Retrieving bank and company logos |
6.3 Shared Spaces: User-Directed Sharing
When you use the Shared Spaces feature, you direct us to make encrypted financial data available to your designated Trusted Contacts. This sharing is initiated and controlled entirely by you. We transport only encrypted ciphertext and cannot access the plaintext content.
6.4 Legal Obligations
We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to:
- Comply with a legal obligation, subpoena, or court order;
- Protect and defend the rights or property of Strata Veritate LLC;
- Prevent or investigate possible wrongdoing in connection with the App;
- Protect the personal safety of users or the public.
6.5 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via in-app notice or email before your information becomes subject to a different privacy policy.
7. Data Retention
7.1 Active Accounts
We retain your data for as long as your account is active and as needed to provide you with the App’s services.
| Data Type | Retention Period |
|---|---|
| On-device financial data (SwiftData) | Until you delete it or delete your account |
| Cloud Backup copy of financial data (Firestore) | Until you delete the record or delete your account |
| Other Firestore server-side data | Until account deletion |
| In-app support messages | Until account deletion |
| Shared Spaces profile photo | Until you remove it or delete your account |
| Referral records (codes, attribution, rewards) | Until account deletion, plus any period required to honor an issued reward |
| Firebase Analytics data | Retained per Google’s standard analytics retention (up to 14 months) |
| Crashlytics reports | Retained per Google’s standard Crashlytics retention (90 days) |
| Plaid access tokens | Until you disconnect the bank or delete your account |
| Subscription records | For the duration of the subscription plus applicable legal retention periods |
| Push notification tokens | Until logout or account deletion |
7.2 Deleted Accounts
When you delete your account, we execute a comprehensive data removal pipeline:
- Firebase Authentication account: permanently deleted
- Plaid connections: all access tokens are programmatically revoked and deleted
- Firestore data: all user documents are permanently deleted, including the Cloud Backup copy of your financial records, support messages, and referral records
- Shared Spaces: your published encrypted snapshots and the per-recipient keys are purged, and any profile photo is deleted from Firebase Storage
- Local on-device data: all SwiftData records are purged
- Encryption keys: all Keychain-stored keys (root key, KEK, Shared Spaces private keys) are destroyed
- Session state: all cached state and session tokens are cleared
Certain aggregated, de-identified data that cannot be used to identify you may be retained for analytical purposes.
7.3 Ephemeral Data
Receipt images captured for OCR scanning exist only in device memory during processing and are never persisted to disk, uploaded, or transmitted.
8. Your Rights and Choices
8.1 Access and Portability
You can view all your financial data within the App at any time. Pro subscribers can export transaction data via CSV export for data portability.
8.2 Correction
You can edit your transactions, accounts, budgets, goals, and profile information directly within the App at any time.
8.3 Deletion
You can:
- Delete individual transactions, accounts, budgets, or goals within the App;
- Delete your entire account and all associated data using the account deletion feature in Settings;
- Request deletion by contacting us at the address below.
8.4 Notification Preferences
You have granular control over notifications. You can enable or disable individual notification categories (budget alerts, bill reminders, goal milestones, savings nudges, etc.) and configure Quiet Hours to suppress notifications during specified periods.
8.5 Bank Connection Management
You can disconnect individual bank connections at any time, which revokes the associated Plaid access token. You may also remove all bank connections simultaneously through account deletion.
8.6 Data Sharing (Shared Spaces) Control
You can revoke Shared Spaces data sharing with any Trusted Contact at any time, immediately terminating their access to your encrypted data.
8.7 Analytics Opt-Out
In the App: Firebase Analytics collects anonymized usage data. You may limit collection by adjusting your device’s privacy settings under Settings > Privacy & Security > Analytics & Improvements.
On our website: summaone.com uses first-party Google Analytics 4 (via Firebase) to measure page visits and App Store link clicks. In regions that require consent, website analytics stays off until you allow it. You can change your decision at any time using the “Privacy choices” link in the website footer.
8.8 Rights Under GDPR (EEA/UK Users)
If you are located in the European Economic Area or United Kingdom, you have the right to:
- Access the personal data we hold about you;
- Rectification of inaccurate personal data;
- Erasure (“right to be forgotten”) of your personal data;
- Restrict processing of your personal data;
- Data portability to receive your data in a structured, machine-readable format;
- Object to processing based on legitimate interests;
- Withdraw consent at any time where processing is based on consent;
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at the address below.
8.9 Rights Under CCPA (California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose;
- Delete your personal information;
- Opt out of the sale of personal information (we do not sell personal information);
- Non-discrimination for exercising your privacy rights.
To exercise these rights, contact us at the address below.
8.10 Rights Under LGPD (Brazilian Residents)
If you are located in Brazil, you may have rights under the Lei Geral de Protecao de Dados Pessoais (“LGPD”), including the right to:
- Confirm whether we process your personal data;
- Access the personal data we hold about you;
- Correct incomplete, inaccurate, or outdated personal data;
- Request anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed personal data;
- Request portability of your data, subject to applicable legal and commercial secrecy requirements;
- Request information about the public and private entities with which we have shared your personal data;
- Request information about the possibility of denying consent and the consequences of such denial, where consent is the legal basis for processing;
- Revoke consent at any time where processing is based on consent;
- Petition Brazil’s National Data Protection Authority (ANPD) regarding our processing of your personal data.
To exercise these rights, contact us at the address below.
8.11 Rights Under DPDPA (India Users)
If you are located in India, you may have rights under the Digital Personal Data Protection Act, 2023 (“DPDPA”), subject to applicable law, including the right to:
- Access a summary of the personal data we process about you and information about the related processing activities;
- Correct, complete, and update your personal data;
- Request erasure of your personal data in accordance with applicable law;
- Withdraw consent at any time where processing is based on consent;
- Seek grievance redressal by contacting us using the contact details below;
- Nominate another person to exercise your rights in the event of your death or incapacity, where applicable under law.
To exercise these rights, contact us at the address below.
8.12 Rights Under KVKK (Turkey Users)
If you are located in Turkey, you may have rights under the Turkish Personal Data Protection Law No. 6698 (“KVKK”), including the right to:
- Learn whether your personal data is processed;
- Request information if your personal data has been processed;
- Learn the purpose of processing and whether your personal data is used in accordance with that purpose;
- Know the third parties in Turkey or abroad to whom your personal data is transferred;
- Request correction of incomplete or inaccurate personal data;
- Request deletion or destruction of personal data where the legal conditions are satisfied;
- Request notification of correction, deletion, or destruction to third parties to whom your personal data has been transferred, where required by law;
- Object to a result against you arising exclusively from analysis by automated systems;
- Claim compensation for damages arising from unlawful processing of personal data.
Where required by applicable Turkish law, we will maintain any required KVKK disclosures or VERBIS-related registrations. To exercise these rights, contact us at the address below.
9. Children’s Privacy
The App is not intended for use by children under the age of sixteen (16) or the minimum age of digital consent in the applicable jurisdiction, whichever is higher. We do not knowingly collect personal data from children below these age thresholds.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately. If we become aware that we have collected personal data from a child below the applicable minimum age, we will take prompt steps to delete such data from our systems.
11. International Data Transfers
Your data may be processed in the United States and other countries where our service providers maintain facilities (including Google Cloud regions for Firebase services). Where data is transferred internationally, we rely on standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms to ensure appropriate safeguards are in place.
12. Third-Party Links and Services
The App may contain links to third-party websites or services (e.g., your bank’s website, Apple’s subscription management). We are not responsible for the privacy practices or content of these third-party services. We encourage you to review the privacy policies of any third-party services you access.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Updating the “Last Updated” date at the top of this policy;
- Providing an in-app notification where practicable;
- Sending an email notification for material changes that significantly affect how we handle your data.
Your continued use of the App after any modifications to this Privacy Policy constitutes acceptance of the updated policy.
14. Data Protection Officer
For privacy inquiries, data subject access requests, or to exercise any of your rights, contact our data protection team:
Strata Veritate LLC, Data Protection
Email: security@summaone.com
Website: https://summaone.com/support
We will respond to all legitimate requests within thirty (30) days, or within the timeframe required by applicable law.
15. Contact Information
For general questions about this Privacy Policy, please contact us at:
Strata Veritate LLC
Email: support@summaone.com
Website: https://summaone.com/support