← Back to OatsPrivacy policy

OatsPrivacy Policy

Last updated On-device only · no account, no server

Oats is an offline personal finance tracker. This policy is short because the app does very little with your data: it keeps it on your device and leaves it there.

The short version

Oats collects nothing and transmits nothing. Your financial records live in a private database on your device, are excluded from cloud backup, and leave only in a file you export yourself.

What Oats collects

Nothing. Oats has no account system, no analytics, no crash reporting, no advertising SDK and no telemetry of any kind. The developer cannot see your data, because it is never transmitted.

What Oats stores, and where

Everything you enter — transactions, categories, budgets, savings goals, repeating entries, merchant names, currency rates and app settings — is written to a SQLite database in Oats' own private storage area on your device. On both Android and iOS this area is readable only by Oats itself.

Network access

Oats makes no network requests. It does not contain code to do so. You can verify this by putting the device in aeroplane mode: every feature continues to work exactly as before.

Cleartext (unencrypted HTTP) networking is explicitly disabled in the Android build configuration.

Device backups

Android's automatic cloud backup is disabled for Oats (allowBackup=false). Your financial data is therefore not copied to Google Drive.

This is a deliberate trade-off: if you lose or reset your device, your data is gone unless you exported it yourself. Settings → Backup → Export backup produces a file you control. We recommend making one periodically.

Files you export

When you export a backup or a CSV, Oats writes the file to a temporary location and hands it to your device's share sheet. Where it goes next is your choice, and outside Oats' control — if you send it to a cloud drive or an email, that service's policies apply.

Exported files are deleted from Oats' temporary storage as soon as the share sheet closes.

Permissions

PermissionWhy
USE_BIOMETRIC / USE_FINGERPRINTOnly if you turn on the app lock. Authentication is performed by the operating system; Oats receives a yes/no answer and never sees your biometric data.
POST_NOTIFICATIONSOnly if you turn on the weekly digest. The notification is generated and scheduled entirely on-device.
VIBRATEHaptic feedback on button presses.

Oats explicitly blocks the storage, camera, microphone, location, contacts and advertising-ID permissions, so it cannot request them even if a future dependency tries to add one.

Notifications

If you enable the weekly digest, it is a local notification composed on your device. By default it contains no figures, because notifications can be displayed on a locked screen. You can opt into showing amounts in Settings → Preferences → Digest detail.

Children

Oats is not directed at children, and collects no data from anyone — so there is no children's data for us to hold.

Deleting your data

Settings → Erase all data removes every record and then compacts the database file, so deleted rows are not left recoverable on disk. Uninstalling Oats also removes everything.

Changes to this policy

If this policy changes, the updated version ships with the Oats release it applies to and the date at the top changes. Material changes are surfaced in the app before they take effect.

Contact

Questions about this policy, or about the data the app holds on you, go to karandivyansh01@gmail.com. The data controller is Divyansh Karan, trading as Stelr Studio (Remote · India).

This policy covers Oats only. Other Stelr apps have their own policies, listed on the apps page.