Madriss Privacy Policy
Last updated: September 18, 2026
Madriss is a personal budgeting app. This policy explains what data the app handles and how. The short version: your financial data belongs to you, we collect the minimum needed to run the app, and we never sell data or show ads.
Data you provide
- Transactions, budgets, and categories you record in the app — amounts, merchant names, categories, and dates.
- Account details if you sign in with Apple: your Apple user identifier and, if you choose to share them, your name and email address.
Signing in with Google (Android)
On Android you can sign in with Google instead of Apple. When you do, we receive your Google
account's email address and a unique identifier from Google, which we store in our backend
(hosted on Supabase) to keep your transactions, budgets, and categories in sync across your
devices. We do not receive your Google password, contacts, or any other Google data. You can use
Madriss without signing in — tap Continue without an account — and everything stays on
your phone.
Automatic logging (iPhone)
Madriss can record purchases automatically through one or both of two optional automations that
you create in Apple's Shortcuts app. Neither is enabled by default. iOS gives
apps no background access to your messages; a shortcut runs only when the automation you created
matches, and you can delete it at any time in Shortcuts, which stops it immediately.
- Apple Pay purchases. A Wallet automation passes the amount, merchant, and card
of a tap-to-pay purchase to Madriss, which records it.
- Bank SMS. Purchases made with mada, online, in-app, or by subscription never
reach the tap-to-pay trigger, but most banks text you about them. You can create a Messages
automation that runs when an incoming message contains a phrase you choose (for example
"Purchase"). Shortcuts then passes the text of that message to Madriss.
- The message text is read on your device to extract the amount, merchant,
currency, and the last digits of the card. Only that extracted transaction is saved — and
synced if you are signed in. The message itself is never stored by Madriss and never
transmitted anywhere.
- Messages that are not completed purchases — one-time passcodes, transfers, balance and payment
reminders, and personal texts — are discarded without being recorded.
- If a bank uses a format Madriss cannot yet read, the app shows an error inviting you to email
the message to support so the format can be added. Sending it is your choice; nothing is sent
automatically.
Automatic logging from payment notifications (Android)
On Android, Madriss records purchases automatically by reading the payment notifications your bank
and wallet apps already show you (for example "Purchase SAR 45.00 at Jahez"). This uses Android's
Notification access permission, which you grant in system settings only after Madriss
explains the feature; you can revoke it at any time under
Settings → Notifications → Device & app notifications.
- Notification text is analysed on your device to extract the amount, merchant,
currency, and the last digits of the card. The resulting transaction is stored like any other
purchase you record.
- When a notification is read successfully, its original text is discarded and is not uploaded
anywhere. When a payment notification is in a format Madriss cannot read, the notification's
title and text (up to 500 characters) are saved to that transaction's note, so you can see what
was captured and correct the amount. That note is stored with the transaction and syncs with
your other data if you are signed in; you can edit or delete it like any other note.
- Notifications from messaging, social, and email apps are excluded by default and are not read
unless you explicitly switch an app on in Automatic logging → Sources.
- Madriss does not use Android's SMS permissions and cannot read your text messages. On Android
it reads only notifications, and only from the apps you allow.
Contacts (Qattah)
When you split an expense, you can pick people from your address book. Madriss asks for the
Contacts permission at that moment and reads your contacts only to show the picker. Only the
name and phone number of the people you select are saved, on your device, so their balance can
be tracked. Your address book is never uploaded. If you decline the permission you can still add
people by name.
Sharing with friends (Qattah)
If you send a Qattah request while signed in, the friend who opens your link sees the merchant,
the amount they owe, and the display name you chose. That request is stored in our backend
until it is settled or withdrawn, and expires after 90 days if never opened.
Appearance and language
Your language, currency, appearance (light/dark), and app-lock preferences are stored on your
device only.
How your data is stored
- Guest mode: everything stays on your device. Nothing is sent to our servers.
- Signed in: your transactions, budgets, and categories are stored in our backend (hosted on Supabase) so they can sync across your devices. Data is transmitted over HTTPS and associated only with your account.
What we don't do
- No advertising, and no data is ever sold or shared with data brokers.
- No tracking across other apps or websites, and no third-party analytics SDKs.
- No access to your bank accounts or cards. Purchases logged via the Apple Pay shortcut are recorded from the details you confirm on your device — Madriss never sees your card number.
App Lock and Face ID
If you enable App Lock, authentication happens entirely on your device through Apple's Face ID / Touch ID system. Madriss never receives or stores your biometric data.
Data retention and deletion
You can delete individual transactions, erase all local data (guest mode), or permanently delete your account and all associated data from Settings → Delete account. Account deletion is immediate and irreversible. Full instructions, including how to delete without the app installed, are on the account deletion page.
Children
Madriss is not directed at children under 13 and does not knowingly collect data from them.
Changes
If this policy changes, the updated version will be posted at this address with a new "last updated" date.
Contact
Questions about privacy? Email amanmaher@gmail.com.