Flower 1.1
Privacy Policy
Effective September 3, 2026
Flower is designed to keep personal-finance information private. This policy describes the Flower 1.1 configuration.
Information stored on your device and in iCloud
Flower stores transactions, categories, wallet and card information, recurring items, budgets, investment accounts, instruments, activity and plans, prediction history, app preferences, and installed visual skins on your device. Flower does not sell this information or use it for advertising.
If you enable Flower Plus iCloud sync, Flower also stores the ledger, wallets, categories, tags, card-holder customization, earned embossing marks, category artwork, and synced app settings in your private iCloud database so your Apple devices can present the same state. The private database belongs to your iCloud account, counts toward your iCloud storage, and is not visible in the developer portal. Flower does not copy this data to a separate account or financial-data server operated by Flower. Device-only settings such as transient UI and session state remain local.
Optional location context may be used to improve on-device transaction predictions. Camera and photo access may be used to scan receipts. These features are processed locally and their content is not uploaded by Flower.
Exchange rates and network metadata
Flower downloads public exchange-rate files from the Currency API through the jsDelivr content-delivery network, with a Cloudflare-hosted fallback, when rates refresh automatically or when you request a refresh. The request identifies the selected base currency in the URL and includes ordinary network metadata.
The delivery providers may process the IP address, requested CDN URL, request date and time, client type, unique device identifiers, and diagnostic data to deliver, secure, and troubleshoot the exchange-rate service. Flower does not send transactions, amounts, balances, wallet names, categories, notes, receipts, photos, or location data with these requests.
This network metadata is used only for app functionality and service operation. Flower does not use it for advertising or tracking. jsDelivr acts as a service provider and states that it does not sell personal data. Its data-processing terms are available at https://www.jsdelivr.com/documents/data-processing-agreement.pdf.
Optional online investment icons
Flower includes a bundled investment-icon catalog that works without a network request. If you deliberately search for an additional icon, Flower sends the search term or ticker symbol to LoadLogo over HTTPS. If you select an online result, Flower requests its image using the returned company domain. The image is cached on your device for up to 30 days. Flower does not attach transactions, units, prices, balances, notes, or your name to these requests.
LoadLogo states that its request logs can include queried domains or ticker symbols, IP addresses, user-agent strings, and timestamps; that these logs are retained for 30 days for rate limiting, abuse prevention, and service improvement; and that its brand search may use third-party infrastructure, including OpenRouter for AI-powered brand resolution. This processing occurs only when you use an online icon or Flower needs to reload one you selected. It is used for app functionality, not Flower advertising or tracking. LoadLogo's current policy is available at https://www.loadlogo.com/privacy.
Face ID
If you enable Wallet privacy, iOS may use Face ID to confirm that you can reveal protected amounts. Flower receives the authentication result, not biometric data. Biometric data is managed by Apple and never becomes available to Flower.
Purchases
Purchases are processed by Apple. Flower may read a cryptographically verified entitlement status so that it can unlock eligible features. Flower does not receive your payment-card number.
On-device intelligence
Category prediction and receipt recognition run on device. Flower does not send financial documents to a third-party AI service.
Tracking and analytics
Flower 1.1 does not track you across apps or websites and does not include advertising. The exchange-rate delivery providers process the limited network metadata described above, and LoadLogo processes optional icon queries and request metadata, for app functionality rather than Flower analytics or advertising. Optional private iCloud synchronization uses Apple's CloudKit service; Flower does not collect that private database into a developer-owned analytics, advertising, or financial-data service.
Data control
You can edit or delete records and assets in Flower. Removing the app normally removes its local container. If iCloud sync was enabled, your private iCloud database and Apple-managed device or computer backups may retain copies according to Apple's storage and deletion behavior. Back up important records before deleting the app.
For questions or applicable access or deletion requests concerning third-party network metadata, contact Flower using the address below. Flower will route a valid request to the relevant delivery provider when necessary.
Children
Flower is a general personal-finance tool and is not directed to children under 13. Flower does not knowingly collect children's data.
Changes
Material changes will be reflected by a new effective date and, when required, an in-app notice. Users should review the policy supplied with each release.
Contact
For privacy questions, contact Zhiwen Huang at zhiwen.build@gmail.com.