OatsPrivacy Policy
Oats is an offline personal finance tracker. This policy is short because the app does very little with your data: it keeps it on your device and leaves it there.
The short version
Oats collects nothing and transmits nothing. Your financial records live in a private database on your device, are excluded from cloud backup, and leave only in a file you export yourself.
What Oats collects
Nothing. Oats has no account system, no analytics, no crash reporting, no advertising SDK and no telemetry of any kind. The developer cannot see your data, because it is never transmitted.
What Oats stores, and where
Everything you enter — transactions, categories, budgets, savings goals, repeating entries, merchant names, currency rates and app settings — is written to a SQLite database in Oats' own private storage area on your device. On both Android and iOS this area is readable only by Oats itself.
Network access
Oats makes no network requests. It does not contain code to do so. You can verify this by putting the device in aeroplane mode: every feature continues to work exactly as before.
Cleartext (unencrypted HTTP) networking is explicitly disabled in the Android build configuration.
Device backups
Android's automatic cloud backup is disabled for Oats (allowBackup=false). Your financial data is therefore not copied to Google Drive.
This is a deliberate trade-off: if you lose or reset your device, your data is gone unless you exported it yourself. Settings → Backup → Export backup produces a file you control. We recommend making one periodically.
Files you export
When you export a backup or a CSV, Oats writes the file to a temporary location and hands it to your device's share sheet. Where it goes next is your choice, and outside Oats' control — if you send it to a cloud drive or an email, that service's policies apply.
Exported files are deleted from Oats' temporary storage as soon as the share sheet closes.
Permissions
| Permission | Why |
|---|---|
USE_BIOMETRIC / USE_FINGERPRINT | Only if you turn on the app lock. Authentication is performed by the operating system; Oats receives a yes/no answer and never sees your biometric data. |
POST_NOTIFICATIONS | Only if you turn on the weekly digest. The notification is generated and scheduled entirely on-device. |
VIBRATE | Haptic feedback on button presses. |
Oats explicitly blocks the storage, camera, microphone, location, contacts and advertising-ID permissions, so it cannot request them even if a future dependency tries to add one.
Notifications
If you enable the weekly digest, it is a local notification composed on your device. By default it contains no figures, because notifications can be displayed on a locked screen. You can opt into showing amounts in Settings → Preferences → Digest detail.
Children
Oats is not directed at children, and collects no data from anyone — so there is no children's data for us to hold.
Deleting your data
Settings → Erase all data removes every record and then compacts the database file, so deleted rows are not left recoverable on disk. Uninstalling Oats also removes everything.
Changes to this policy
If this policy changes, the updated version ships with the Oats release it applies to and the date at the top changes. Material changes are surfaced in the app before they take effect.
Contact
Questions about this policy, or about the data the app holds on you, go to karandivyansh01@gmail.com. The data controller is Divyansh Karan, trading as Stelr Studio (Remote · India).
This policy covers Oats only. Other Stelr apps have their own policies, listed on the apps page.