Dibsly for iPhone

Privacy Policy

Last updated: October 10, 2026

Dibsly is a local-first personal finance tracker for iOS. A Dibsly account is optional: with it, your data is kept in your account and on all your devices, on the website and, if you connect it, in Claude.

Data Stored by the App

Dibsly stores the financial information you enter in the app, including accounts, categories, transactions, transfers, currencies, notes, monthly plans and allocations, recurring payment schedules and their expense links, payment drafts received through Shortcuts and their confirmation state, investment assets and activity, and data imported from Dibsly, Monefy, Freedom Finance, or Interactive Brokers files, from bank statement files, or from the monobank personal API. Imported operations are stored together with a record of each imported statement row (its identity, date, amount, and what it became in Dibsly), the merchant categories you asked Dibsly to remember, and the mapping between monobank cards or jars and your Dibsly accounts. This information is stored locally on your device. If you sign in to a Dibsly account and sync is on, it is also kept in your account on Dibsly's server, as described in “Dibsly Account, Sync, Website and Claude” below.

Data Collection

Without a Dibsly account, Dibsly does not collect personal data, financial data, analytics data, tracking data, or usage data on Dibsly-operated servers, and nothing leaves your device except as described in this policy.

The app does not require a Dibsly account and does not add its own general-purpose analytics, advertising, or tracking service. Only if you sign in to a Dibsly account does Dibsly's server receive your account details and, with sync, your finance data. This version offers backup to iCloud Drive only: Google Drive backup is not available, Dibsly does not sign in to Google and does not send data to Google.

Dibsly Account, Sync, Website and Claude

The account (free). You sign in with Apple, in the app or on Dibsly's website (my.dibslyapp.com). Dibsly receives from Apple a stable identifier for you, the email address Apple gives (your own or a private relay address) and, the first time only, your name. Dibsly keeps them, an optional profile photo you choose, and a token Apple issues so the sign-in can be revoked when you delete the account. For each device signed in — an iPhone, a browser, a Claude connection — Dibsly keeps its name (such as “iPhone” or “Chrome · Mac”), its kind, the app version, when it was last seen, and a random key the device keeps itself; sessions are kept only as hashes of their tokens. The website keeps its session in a cookie that page scripts cannot read; it has no analytics or advertising cookies.

Sync and the website (Dibsly Premium). With sync, your finance data — the records listed in “Data Stored by the App”, the app's settings that belong to the account, and what you enter on the website or through Claude, such as monthly savings, salary and sole-trader records, rates and goals — is kept in your account's space on Dibsly's server, so every device you sign in to and the website show the same data. Dibsly's server computes the figures the website shows (balances, the portfolio, dividends, savings and taxes) from that data. To value your investments it fetches the last market price of the symbols you hold from Yahoo Finance; only the symbols are sent, and these prices are kept as shared market data, not as part of your account. To check Premium, the app sends the App Store's signed record of your subscription; Dibsly keeps its transaction identifier, product, environment and expiry, never payment details.

Where it is kept. Dibsly's server runs on Cloudflare. Your account, its devices and sessions, and your space's data are stored in Cloudflare's European Union locations and encrypted at rest. Dibsly's server logs only the address of a request, its result and a short reason, never its content; Cloudflare receives standard network metadata such as an IP address. Dibsly does not use your data for anything other than providing the service to you: it does not look at it, sell it, or use it for advertising or for training AI. The developer can technically reach the stored data, and does so only to keep the service running and secure or when you ask for help with your account.

Claude (optional, Dibsly Premium). You can connect Claude, Anthropic's assistant, to your account; Dibsly asks you on its own page and shows the connection among your devices, where you can remove it at any time. Once connected, Claude can read your dashboard, accounts and operations when you ask it to, and save the records described above (savings months, salary and sole-trader records, rates, goals, notes) after you confirm them in the chat; your accounts, operations and investments in Dibsly are read-only for Claude. What Claude reads is processed by Anthropic under your agreement with Anthropic and its privacy policy. The connection's tokens are stored only as hashes, and its grant (which account and connection it belongs to, encrypted with a key only the token unlocks) in Cloudflare's global key-value store.

Deleting. “Remove from this iPhone” signs that device out and keeps your account. Removing a device or a Claude connection on the website ends its access. “Delete account” in the app erases your account, its devices and sessions, your profile photo and every record of your space on Dibsly's server, revokes Sign in with Apple, and signs out every device; the data on your devices is erased too.

Market Data Requests

When you search for an investment symbol, refresh a quote, or open portfolio history, Dibsly contacts public market-data endpoints, currently including Nasdaq services and Yahoo Finance historical chart data. A request can include the ticker, search text, requested date range, chart interval, and standard network metadata visible to the provider, such as an IP address. Dibsly does not send account balances, transaction history, notes, or imported broker files with these requests.

Currency Rate Requests

Dibsly retrieves current reference exchange rates from the National Bank of Ukraine. This request does not include account balances, transactions, plans, notes, or imported files. The provider can receive standard network metadata such as an IP address.

Recurring Payments and Local Notifications

Recurring schedules and their links to recorded expenses stay on the device and are included in optional encrypted backups. Searching past expenses to suggest a payment name, category and estimated amount happens on the device; it does not send transaction history to a search service.

If you grant notification permission and enable a reminder, Dibsly schedules local notifications through iOS. Their text includes the payment name, estimated amount/currency and expected date. App Lock and Hide amounts do not redact these notification previews. You control notification permissions and lock-screen previews in iOS Settings. Opening Dibsly from a reminder still respects App Lock. No Dibsly remote-push service or bank connection is used.

Apple Pay Drafts through Shortcuts

If you enable Apple Pay capture and configure a personal automation in iPhone Shortcuts, the Dibsly action stores the inputs supplied by that automation: available amount and currency, merchant, selected Dibsly account, optional card name and payment date, and a derived retry key when a source event identifier is supplied. Dibsly does not directly read your Wallet transaction history or connect to your bank. The automation is configured and managed in Apple’s Shortcuts app.

Payments wait locally as drafts until you confirm or link them to an expense. Note/category suggestions search recent expenses on the device. Drafts and handled-payment receipts are included in optional encrypted Dibsly backups; iOS personal automations are not included. Capture returns a generic result without payment details, while viewing and confirming payments follows the app’s existing lock and amount-privacy settings. This feature adds no Dibsly server or new remote recipient.

Turning Apple Pay off stops new captures and hides Activity while keeping existing drafts. It does not disable the iOS automation. Discarding or confirming a draft retains a local receipt, including its captured details and retry key, to prevent explicit event retries from recreating it. To remove all draft and receipt data, use Delete All Data; existing cloud backups remain governed by the backup/deletion controls below.

Data Sharing

Dibsly does not sell or rent your data and does not share it for advertising or cross-app tracking.

Financial records can leave your device only when you choose to export, share, enable backup, sign in to a Dibsly account with sync, connect Claude, or use Dibsly's AI features. The account, sync and Claude are described above; optional iCloud Drive backup and the AI features are described below. Market-data requests are limited as described above.

Optional Backup & Recovery

Dibsly supports optional encrypted backup to iCloud Drive. Backup is not live synchronization, and the app remains usable without it.

You choose the iCloud Drive folder for backups through Apple's file-provider interface; the backup files stay visible there in the Files app. Apple may receive the encrypted backup file and standard account, device, and network information under your Apple agreement and privacy settings. Dibsly has no server in between and does not use iCloud to synchronize your finance database.

Backup files are encrypted and integrity-protected before upload. The recovery password is not stored beside a backup; when automatic backup is enabled, the routine credential is stored only in this device's data-protection Keychain. Automatic backup is opt-in and best-effort: after setup, eligible Daily or Weekly attempts run when the app becomes active and, when iOS allows it, in the background (usually while the device is idle), only if backed-up data has changed; setup or an explicit retry can also trigger an attempt. iOS decides when background attempts run, so exact timing is not guaranteed.

Automatic retention keeps the newest 5 automatic backups created by this installation in each backup location when cleanup succeeds. Automatic backups made by another device or an earlier installation, manual backups, and files not recognized as Dibsly automatic backups are never removed by this cleanup. Provider failures may delay cleanup.

Disconnecting iCloud Drive in Dibsly stops backups there but does not delete existing backup files. Deleting all local Dibsly data turns automatic backup off and does not delete existing cloud backups.

Before managed restore or CSV Replace mutates local data, Dibsly creates and verifies an encrypted emergency snapshot in the app's local Application Support storage. Its local-only encryption credential is held in the device Keychain. Dibsly does not upload these emergency files or their credentials. After a new snapshot is verified, Dibsly keeps the five newest Dibsly-managed emergency snapshots on a best-effort basis and does not remove unrelated files. Only exact pre-restore-<UUID>.dibslybackup and pre-replace-import-<UUID>.dibslybackup names are eligible for this pruning.

File Import and Export

Dibsly can import and export CSV files and import supported broker CSV/XLSX reports when you explicitly select those actions. Files selected through the iOS document picker remain under your control.

Bank Statement Import

Dibsly can read bank statement files you select yourself (monobank CSV, XLS and PDF; UKRSIBBANK, PrivatBank and KredoBank PDF). The file is read entirely on your device: it is never uploaded, and no part of it is sent to Dibsly or to any other service. Dibsly reads only the fields it needs — dates, operation details, amounts, currencies, balances, card masks and the account IBAN — and never parses the tax number, passport data, date of birth or registration address that bank statements print in their headers. The account holder's name is used in memory only, to recognize transfers between your own accounts, and is then discarded. Card masks and a masked form of the IBAN (country code and the last digits) are stored so later imports recognize the same account; full card numbers and full IBANs are not stored. Import History keeps the bank, the file name you chose, the period and the counts, not the operations themselves.

monobank Connection

If you connect monobank, Dibsly uses the personal token you create yourself at api.monobank.ua. The token is stored in the Keychain of that device only (available after first unlock, this device only). It is never included in a backup, a CSV export, Import History, a diagnostic report, or anything sent to Dibsly; Dibsly has no server that could receive it.

Synchronization starts only when you connect monobank or tap Sync; a longer history import you started can continue in the background, paced by monobank's request limits. Dibsly calls api.monobank.ua directly from your device with your token and asks for your accounts and jars and for the operations of the accounts you mapped, within the period shown on screen. monobank receives the request and standard network metadata such as an IP address; it does not receive anything you entered in Dibsly. The answer — your cards, jars, balances and operations — stays on the device and is shown in a preview before anything is written.

Disconnecting deletes the token and the card and jar mapping from the device; operations already imported stay in your data. Revoking the token itself is done in your monobank cabinet at api.monobank.ua.

AI Features (optional)

Dibsly's AI is OpenAI (the maker of the GPT models), reached through Dibsly's own relay server. Receipt photos use it in the free version (10 receipts a month); bank notifications read by the AI, AI categorization, up to 300 receipts a month and voice entry with the AI are part of Dibsly Premium. Nothing is sent until you allow the AI on a screen that names the receiver; it appears the first time a feature needs the AI. The AI's switch is in Settings → Preferences → AI; without Premium the AI is used only when you read a receipt. Reading bank statements, Investments, Apple Pay through Wallet and voice entry your phone understands by itself work without the AI.

AI categorization (Dibsly Premium). AI categorization helps with the operations Dibsly could not categorize itself: imported operations when you tap Sort with AI, and new payments captured from bank notifications or Apple Pay, whose category it proposes before you save them. Once you allow the AI, Dibsly sends to OpenAI, through Dibsly's own relay server, the names of those merchants as your bank wrote them (for a bill paid to a company through internet banking: the company and the service, without an address, a phone number or an account number), the names of your categories, and up to eight merchants you already filed under each category. Long numbers are removed from every name before it is sent. Amounts, dates, accounts, balances, notes, card or account numbers are never sent, and transfers to and from people are never sent at all: Dibsly files them as transfers itself. Your device proves it runs a genuine copy of Dibsly through Apple's App Attest. Dibsly's relay, run on Cloudflare, passes each request to OpenAI and keeps none of its content — only an anonymous key of your device and how many requests it made this month and today, to hold the AI's limits; the relay and OpenAI receive standard network metadata such as an IP address. Requests are sent with storage off; under OpenAI's API terms the data is kept for at most 30 days for abuse monitoring and is not used to train models.

Bank notifications read by the AI (Dibsly Premium, iOS 27 or later). If you set up the Dibsly automation for your bank apps in Shortcuts and allow Dibsly's AI, each notification from those apps that names an amount with a currency is saved on your device and its text is sent the same way to OpenAI, which reads the amount, the currency, the merchant or sender, the card's last digits and any fee. Full card numbers, IBANs and phone numbers in the text are replaced before it is sent; the rest of the notification — which can include your balance and the name of a person who sent you money — is sent as it is. Notifications without an amount, such as codes and offers, are not sent. The result becomes a draft in Activity that you confirm or discard; a notification that could not be read yet waits on your device for up to a week. The same OpenAI terms apply: the data is kept for at most 30 days and is not used to train models.

Voice entry (free; the AI with Dibsly Premium). When you tap the microphone or ask Siri to record in Dibsly, Apple's speech recognition turns what you say into text — on your device when your iPhone supports it for the chosen language, otherwise through Apple's servers under Apple's privacy policy. Dibsly asks for the microphone and speech recognition only for this and keeps no recording. The text is read on your device first; only when Dibsly cannot find the amount or the category itself, and only with Dibsly Premium and the AI allowed, the phrase is sent the same way to OpenAI together with the names of your accounts and categories (no balances, amounts or history). The result is saved as an operation you can undo or edit at once.

Receipt photos and split bills (10 receipts a month free, up to 300 with Dibsly Premium). Receipts are read by the AI in the free version too, after you allow it. A receipt you photograph or choose is straightened on your device, and the photo and the names of your expense categories are sent the same way to OpenAI, which returns the shop, the date, the total and each item with its category; neither Dibsly nor its relay keeps the photo. The result becomes drafts in Activity that you confirm or discard. If you share a split bill, the receipt itself — the shop, the items, their amounts and the total, not your accounts — is sent to Dibsly's server, which keeps it for 30 days under a short code so the link you send (dibslyapp.com/s/…) can open it; nothing else is stored with it, not your account or device. Without the network the app shares a longer link that carries the receipt inside the part of the address after #, which browsers do not send to any server. Dibsly's page that opens either link runs in your friend's browser, and the items they tap stay on their device. The same OpenAI terms apply: the data is kept for at most 30 days and is not used to train models.

The answers (a category, a confidence and a readable merchant name per merchant, which Dibsly shows in lists instead of the bank's text) and a record of which operations the AI filed are kept on your device only; they are not part of backups or exports and are erased by Delete All Data. Usage counters for the AI allowance (numbers of merchants, phrases and receipts, not their contents) are kept in the device Keychain. You can switch the AI off at any time in Settings → Preferences → AI; without Premium nothing goes to the AI unless you read a receipt. Every category the AI chose can be changed like any other.

Dibsly Premium Subscription

Dibsly Premium (bank notifications of any bank read by the AI, AI categorization, up to 300 receipts a month and voice entry with the AI) is an auto-renewable subscription sold through the App Store, with a 7-day free trial for new subscribers. Apple processes the purchase, the payment and the renewals under your Apple account; Dibsly never receives your payment details, and the purchase does not give Dibsly your name or email. On your device Dibsly reads only whether the subscription or the trial is active and until when, through Apple's StoreKit. You manage and cancel the subscription in iOS Settings → your name → Subscriptions. Everything else, including Investments, is free. Your data stays on your device whether or not you subscribe: when Premium ends, the Premium features stop and receipts return to 10 a month, and nothing is deleted.

Data Retention and Deletion

Local data remains on your device until you edit it, delete it, remove the app, or use Dibsly's Delete All Data action. Data in a Dibsly account remains until you delete it or delete the account; shared split bills are deleted after 30 days. Cloud backups remain in your iCloud Drive until you delete them there, from Dibsly's backup list, or through automatic retention described above. Dibsly does not control Apple's own retention practices.

Your Choices

You can use Dibsly without an account, without backup, disable automatic backup, disconnect iCloud Drive, delete Dibsly backups, export your data, or delete all local Dibsly data from the app. With an account you can remove any device or Claude connection, and delete the account with everything in it. Bank statement import, the monobank connection and the AI features are optional: you can use Dibsly without them, disconnect monobank at any time, and revoke its token in your monobank cabinet.

Contact

For privacy questions, contact:

dibslysupport@gmail.com

Public policy: https://dibslyapp.com/privacy.html