Legal

Privacy Policy

Last updated: October 2026

Silo is a personal finance tracker for iPhone, with an Android version on the way. This policy describes what happens to your information when you use it.

The short version: Silo collects nothing. There is no account to create, no server to sync with, and no analytics. Everything you enter stays on your phone, and in your own iCloud if you turn on Copy to iCloud.

What we collect

Nothing. We do not collect, transmit, sell, or store any personal information.

Silo has no backend. The app makes no network requests to display or store your finances. It never contacts a server we run, because we do not run one, and it does not transmit your financial data to any analytics or advertising service. There is no sign-up, no login, no email capture, and no user account of any kind.

What Silo stores, and where

Everything you enter (accounts, balances, transactions, budgets, categories, recurring rules and your display name) is written to your device's local app storage. It never leaves the phone unless you export it (see Backups and exports below) or turn on Copy to iCloud (below).

Silo itself never sends this data anywhere. Your phone's own backup, if you use one (iCloud Backup or a backup on a computer), includes Silo's data the way it includes any app's: the encrypted records, and the weekly copies Silo keeps beside them. On iPhone, the key that unlocks the records is kept in the iPhone's keychain, which Apple carries to another iPhone only in an encrypted backup on a computer. Silo has no copy of its own anywhere.

Deleting the app removes this data from the phone. Without an export, a phone backup or a copy in iCloud, deleting the app is permanent.

Copy to iCloud

On iPhone, Silo asks once whether to keep a copy of your records in your iCloud, and it is off until you say yes (Settings → Backup & export). When it is on, Silo writes one copy a day, when your records change, into Silo's own private space in your iCloud account. Apple moves and stores the file; Silo contains no networking code of its own, and the developer has no access to your iCloud and never sees the copy. The space is not shown in the Files app. The copy holds your records, not your receipt photos, and Silo keeps the last few days of copies from each of your devices.

Only Silo on a device signed in to the same Apple Account can read it, to offer it when you set up a new iPhone or reinstall. Turning the switch off stops the copies and lets you delete the ones already in iCloud; Erase all data deletes this device's copies too.

On Android, Silo asks the system's own backup (Android Auto Backup, to your Google account) to include only the weekly copies described below, never the database or its key.

Analytics, tracking and advertising

There are none. Silo contains no analytics SDK, no crash reporter, no advertising identifier, no tracking pixels, and no third-party marketing tools. We cannot see how you use the app, whether you use it, or that you installed it.

Silo requests no tracking permission and carries no advertising identifier on any platform, because it does not track you.

Backups and exports

Silo can export your data as a JSON backup file, a CSV spreadsheet, or a per-account statement (PDF or CSV) for a date range you choose. Every export, the PDF included, is built on your device from your own records; the PDF is rendered on-device and its template loads nothing from the network. These exports are:

  • Started by you, never automatic.
  • Handed to your device's share sheet, so you choose the destination: your files, iCloud Drive, AirDrop, a messaging app, or anywhere else.
  • Not encrypted. A backup file is readable by anything that can open it. Store it somewhere you trust.

Once a file leaves Silo through the share sheet, it is governed by whatever service you sent it to, not by this policy. We never see it.

Silo also keeps a weekly copy of your records on the phone, for recovery. Like an export, the weekly copies and the iCloud copy are not encrypted by Silo itself: they are protected by your phone's and Apple's own encryption.

App lock and biometrics

If you turn on the app lock, Silo asks your device to verify you using its biometrics (Face ID, Touch ID, or fingerprint or face unlock) or your device passcode. This happens entirely on-device through the operating system's own authentication framework. Silo never receives, stores, or transmits your biometric data; it only receives a yes-or-no answer from the system.

To be precise about the layers that protect your data:

  • The app lock gates the screens. It decides who can open Silo; it is not, by itself, what encrypts the data.
  • The ledger is encrypted at rest. In the shipping build, Silo's transaction database is stored using SQLCipher encryption, on top of your device's own encryption.
  • Widget and shortcut summaries live in a small private on-device container shared only between Silo's own components (see below), separate from the encrypted ledger.
  • Exported backups are plaintext. Encryption protects data inside the app, not a file you have exported out of it. Store exports somewhere you trust.

The app lock is not a substitute for your device passcode.

Widgets, Siri and Shortcuts

If you add Silo's widgets or use its Siri and Shortcuts actions, a small summary of your data (for example, the balance the widget shows, or an expense you dictated) is passed between the app and the widget or shortcut through a private on-device container that only Silo's own components can read. Nothing about this involves a network: the widget renders from data already on your phone, and a shortcut writes into the same local storage the app uses.

Bank notifications (iOS 27, Beta). If you build a Shortcuts automation that runs when your bank or e-wallet app sends you a notification, Shortcuts hands the text of that one notification to Silo's Log Bank Notification action. Silo never reads other apps' notifications itself; you choose the app, and Shortcuts does the handing over. Silo reads the amount, the direction and the shop from the text on your phone, with its own rules. No AI service is involved, and nothing is sent anywhere. The text is kept on the phone only until the entry is logged (or, if Silo needs to ask you something about it, until you answer), and is not stored with the transaction. So that you can later tell Silo "this wasn't a transaction" and have it ignore messages like it, Silo keeps an outline of the last 100 notifications it logged or asked you about: the bank's name and up to twelve words, with every number and date taken out. A notification that logged nothing leaves no outline. The outlines, and the messages you told Silo to ignore, stay on your phone, are never put in a backup, and are deleted by Erase all data.

After a shortcut logs something, Silo may show a local notification ("Logged ₱X") so you know it worked. This is generated on your device by the operating system. Silo uses no push notifications; it has no server to push from.

The same is true of Silo's scheduled reminders. When you turn on notifications (Settings → Notifications), Silo works out which bills, reminders, budget and housekeeping alerts are coming up from the ledger already on your phone and schedules them with the operating system, on the device. Nothing about your finances is sent anywhere to make this happen. When app lock is on (or, on iPhone, when you have chosen to hide details on the Lock Screen), the alerts omit amounts and names. You can turn any group off, or all of them, on that screen.

Receipt scanning

When you scan a receipt, the photo is read on your device by the text recognition built into iOS (or, on Android, the one bundled with the app). The photo and its text are not sent anywhere. The photo is kept with the transaction only if you save it, in the same local storage as the rest of your data.

On an iPhone with Apple Intelligence you can also switch on Read receipts with Apple Intelligence (Settings, Beta, off by default). Silo then asks Apple's language model on your iPhone to help with a receipt that did not add up. That model runs on the device; Silo does not use Apple's cloud models, and the receipt's text does not leave the phone.

Images bundled with the app

Silo shows bank, e-wallet and shop logos to identify your accounts and entries. These images are downloaded once by the developer during the build and shipped inside the app. Choosing an institution does not contact that bank, and the app makes no network request to display a logo.

Children

Silo is not directed at children and collects no information from anyone, including children under 13.

Your rights

Because Silo holds no data about you on any server, there is nothing for us to look up, export, correct, or delete on your behalf. You have direct and complete control:

  • Access and export: Settings → Backup & export.
  • Deletion: Settings → Erase all data, or delete the app.

If you are in the Philippines, the Data Privacy Act of 2012 (RA 10173) grants rights over personal information held by others. We hold none.

Changes to this policy

If this policy changes, the updated version will be published at the same address and the date at the top will change. If Silo ever gains a feature that transmits data off your device, that will be stated here plainly and in the app before the feature does anything.

Contact

Questions about this policy: support.siloapp@gmail.com