Политика конфиденциальности
Effective date: 20.07.2026
Last updated: 20.07.2026
1. Summary — your data stays on your device
Pigles ("Pigles", the "App"; package identifier es.pigl.app) is a personal finance tracking app for Android, iOS and desktop. It is designed to be private by default.
- Your financial data (accounts, operations/transactions, categories, and similar records) is stored only on your device, in a database encrypted with SQLCipher.
- Your financial data is never transmitted to, or stored on, the developer's servers.
- The App has no user accounts and no registration. It contains no advertising, no third-party analytics, no crash-reporting SDKs, no tracking technologies and no cookies.
- Backups are optional, are end-to-end encrypted, and are stored either on your device or in your own cloud account (Google Drive or Apple iCloud). The developer cannot access them or their encryption keys.
Because of this design, in normal use the developer processes almost no personal data about you. This Policy explains the limited situations in which some personal data is processed, why, and what your rights are.
2. Who is responsible for your data (Data Controller)
The App is developed and operated by an individual developer (a natural person) acting as the data controller:
- Controller: Mikhail Lobov (individual developer, trading as Pigl.ES).
- Postal address:
Pigl.ES
Calle Princesa 31, planta 2, puerta 2
28008 Madrid, Spain - Privacy contact: support@pigl.es
You may contact the developer at the email or postal address above for any privacy question or to exercise your rights (see Section 15).
A data protection officer (DPO) has not been appointed, because the App's processing does not meet the criteria that would require one under the GDPR or Spanish Organic Law 3/2018 (LOPDGDD).
3. Scope of this Policy
This Policy covers only the Pigles application (Android, iOS and desktop) and the app-facing services it uses, including the currency exchange-rate server api.pigl.es.
This Policy does not cover the general Pigles website beyond the page on which this Policy is hosted (https://pigl.es/privacypolicy). The page hosting this Policy is served without cookies. Other pages of the website are governed by their own separate notices.
4. What Pigles does NOT do
To be explicit, the App does not:
- require you to create an account or provide your name, email, phone number or any identity information to use it;
- collect or transmit your financial data to the developer;
- contain advertising or advertising SDKs;
- contain third-party analytics or crash-reporting SDKs;
- track you across other apps or websites, or build any advertising or behavioural profile;
- use cookies or similar tracking technologies inside the App;
- sell, rent or monetise your personal data in any way.
5. Data stored on your device
All content you create in the App — accounts, operations, categories, notes, balances, currencies and related settings — is stored locally on your device in a database encrypted with SQLCipher. This data does not leave your device unless you choose to create a backup or (in future) enable an optional sync feature (see Sections 6 and 10).
Because this data remains under your control on your device and is not accessible to the developer, the developer does not "collect" it. Deleting the App, or clearing its data, permanently deletes this on-device data (subject to any backups you created yourself).
6. Backups to your own device or your own cloud
The App lets you create optional encrypted backup files (the ".pig" format), protected with AES-256-GCM encryption. You control where a backup goes:
- Local backup / export: you can export a backup file through your device's system share sheet and store it wherever you choose.
- Google Drive (Android): backups can be stored in the hidden, app-private application data folder (
appDataFolderscope) of your own Google account. This folder is only accessible to the App, is hidden from other apps, and is deleted if you uninstall the App or delete the folder in your Google account. - Apple iCloud (iOS): backups can be stored in your own iCloud account using the CloudKit private database, and the sync/encryption key is stored in your iCloud Keychain. Apple states that for end-to-end-encrypted iCloud services the relevant CloudKit service private keys "are never made available to Apple servers" and that these keys "can't be accessed by Apple or any third party."
In all cases the backup is end-to-end encrypted. The developer has no access to your backups and no access to your encryption keys. These backups are held in infrastructure operated by Google or Apple under your account and under their respective terms and privacy policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
Google API Services Limited Use disclosure. Pigles's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The App requests only the narrow drive.appdata scope, uses that access solely to store and retrieve your own encrypted Pigles backups in the hidden app data folder, does not read any other files in your Drive, and does not transfer this data to the developer or any third party.
7. Currency exchange-rate server (api.pigl.es)
To show up-to-date currency conversions, the App downloads currency exchange-rate snapshots from the developer's server api.pigl.es. This is a one-way distribution of reference data to the App:
- No financial data, account data or personal identifiers are sent to this server as part of this feature.
- Like virtually any internet server,
api.pigl.esgenerates technical connection logs. These logs may include technical data such as an IP-derived value, timestamp, and the requested resource. The developer keeps these logs de-identified where feasible, for a short retention period, and uses them only for security, abuse prevention, rate-limiting and keeping the service reliable. - These logs are not used to identify you, to profile you, or for any advertising or analytics purpose.
Legal basis: the developer's legitimate interests (Article 6(1)(f) GDPR) in operating a secure and reliable service and preventing abuse.
8. Paid subscriptions and in-app purchases
Pigles is free to use. Optional paid features (see below) are sold exclusively through the Apple App Store and Google Play in-app purchase and subscription systems.
- All payment processing is handled by Apple and Google. The developer never receives or has access to your payment card number, bank details or billing address.
- The developer receives only limited, largely anonymised transaction/subscription-status information from Apple or Google (for example, whether a subscription is active), which is necessary to unlock and maintain the paid features.
- Your use of these payment systems is governed by Apple's and Google's own terms and privacy policies.
One current paid feature is a subscription to cryptocurrency exchange-rate feeds. It works exactly like the fiat currency-rate distribution described in Section 7: reference data is delivered to the App and no personal data is collected for this purpose.
Legal basis: performance of a contract (Article 6(1)(b) GDPR) to provide the paid feature you purchased.
9. Support communications
If you email support@pigl.es, the developer will process your email address and the contents of your message for the sole purpose of reading, investigating and answering your request. This information is kept only as long as needed to handle your request and any reasonable follow-up, and is not used for any other purpose.
Legal basis: the developer's legitimate interests (Article 6(1)(f) GDPR) in responding to and supporting users, and, where relevant, taking steps at your request.
10. Future features (only if and when introduced, and only if you enable them)
The developer may introduce the following optional features in the future. They are described here in advance for transparency. None of them is active unless and until it is released and you choose to enable it, and this Policy will be updated with specific details before any such feature processes your data.
- Tier-2 synchronisation / sharing between users (via Pigles servers). If introduced and enabled by you, this would allow syncing or sharing selected data between devices or users through the developer's servers. Any such data would be end-to-end encrypted and pseudonymised / de-identified before it reaches the servers, so that the developer cannot read the content. The server infrastructure (PostgreSQL database and S3-compatible object storage) would be hosted in the European Union. Legal basis: your consent and/or performance of a contract.
- AI receipt recognition (OCR). If introduced and enabled by you, this would let you scan a receipt so the App can extract data (such as amount, date and merchant) to create an entry. It would process only the minimum data necessary for that purpose. Full details, including whether any processing occurs on-device or via a service provider, would be provided before release. Legal basis: your consent.
11. Legal bases for processing (GDPR)
Where the developer processes personal data, it relies on the following legal bases under Article 6(1) of the GDPR:
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention and rate-limiting of
api.pigl.es; responding to support requests. - Performance of a contract (Art. 6(1)(b)) — providing and maintaining paid features you purchase.
- Consent (Art. 6(1)(a)) — optional future features you choose to enable (e.g. sync/sharing, AI receipt recognition). You may withdraw consent at any time.
12. Data retention
- On-device data (including your financial data): kept on your device until you delete it, clear the App's data, or uninstall the App. This is under your control.
- Backups in your own cloud: kept until you delete them or uninstall the App (in the case of the Google Drive app data folder); subject to your Google/Apple account settings.
- Server technical logs (api.pigl.es): kept for a short retention period, then deleted, and used only for security and abuse prevention.
- Support emails: kept only as long as needed to handle your request and reasonable follow-up.
13. Security
The developer uses appropriate technical measures to protect your data, including:
- SQLCipher encryption of the on-device database;
- AES-256-GCM encryption of backup files;
- end-to-end encryption of backups and (in future) any synced data, so that the developer cannot read your content;
- data minimisation by design — the App is built so that personal data is not sent to the developer in the first place.
No system can be guaranteed to be perfectly secure. In particular, if your device is compromised, or if you export an unencrypted copy of your data, or share your credentials or recovery keys, your data may be exposed. Keeping your device, operating system and account credentials secure is your responsibility.
14. International transfers and recipients
The developer's own processing is minimal and, where server infrastructure is used (currency-rate server; future EU-hosted sync), it is located in the European Union / European Economic Area.
The App integrates with the following independent third parties, which act as independent data controllers for the data they handle under their own terms and privacy policies. If you use their services, data may be processed in the countries where they operate, under their own safeguards:
- Apple (iCloud backup storage under your account; App Store payments) — https://www.apple.com/legal/privacy/
- Google (Google Drive backup storage under your account; Google Play payments) — https://policies.google.com/privacy
The developer does not otherwise share, sell or transfer your personal data to any third party, except where strictly required to comply with a valid legal obligation.
15. Your rights
Regardless of where you live, the developer aims to honour the following rights. Under the GDPR and Spanish law (LOPDGDD), if you are in the EU/EEA you have the right to:
- access your personal data;
- rectify inaccurate data;
- erase your data ("right to be forgotten");
- restrict processing;
- object to processing based on legitimate interests;
- data portability;
- withdraw consent at any time, where processing is based on consent, without affecting prior lawful processing.
To exercise any of these rights, contact support@pigl.es. In line with Article 12(3) GDPR, the developer will provide information on action taken without undue delay and in any event within one month of receiving the request; that period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case you will be informed within the first month. Note that most of your data is stored only on your device and is directly accessible, exportable and deletable by you at any time through the App — the developer does not hold it.
Right to complain. If you are in the EU/EEA, you have the right to lodge a complaint with a supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — https://www.aepd.es. You may also contact the supervisory authority in your country of residence.
Users outside the EU/EEA. Privacy rights vary by country. Even where a specific law may not apply to a small individual developer, the developer will make reasonable efforts to honour valid requests to access or delete personal data it actually holds, regardless of where you are located. This Policy does not claim that the developer is a "business" subject to the California Consumer Privacy Act (CCPA), as amended by the CPRA: under Cal. Civ. Code § 1798.140 those obligations apply only to a for-profit business meeting at least one of three thresholds — annual gross revenue above the inflation-adjusted baseline (US $26,625,000 for 2025–2026 under § 1798.199.95(d)), buying/selling/sharing the personal information of 100,000 or more California consumers or households per year, or deriving 50% or more of annual revenue from selling or sharing personal information — none of which the developer meets. The universal commitment above applies instead.
16. Children's privacy
Pigles is a general-audience personal finance tool and is not directed at children. The developer does not knowingly collect personal data from children.
The App is intended for users who are old enough to consent to the processing of personal data under the law of their country. Under Article 8(1) GDPR the default digital-consent age is 16 (member states may lower it to no less than 13); Spain's LOPDGDD (Article 7) sets it at 14; and the U.S. Children's Online Privacy Protection Act (COPPA), enforced by the FTC, governs data collection from children under 13. If you believe a child has provided personal data to the developer (for example, by emailing support), contact support@pigl.es and it will be deleted.
17. Changes to this Policy
This Policy may be updated from time to time, for example to reflect new features or legal requirements. The current version is always available at https://pigl.es/privacypolicy, with the "Last updated" date shown at the top. For material changes, the developer will provide reasonable notice — for example, an in-app notice or a prominent note on this page — and, where a change requires your consent, will ask for it before the change affects you.
18. Contact
Questions, requests or concerns about this Policy or your privacy:
Email: support@pigl.es
Postal address:
Pigl.ES
Calle Princesa 31, planta 2, puerta 2
28008 Madrid, Spain
Controller: Mikhail Lobov (individual developer, trading as Pigl.ES).