Last updated: August 10, 2026
This Privacy Policy explains how Diego Pais (“we”, “us”, or “Dribs”) handles information in connection with the Dribs mobile application (the “App”). We built Dribs to be private by design: your financial data lives on your device and, if you choose, in your own iCloud account, never on our servers.
The controller for the limited processing described in this policy, within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR/DSGVO), is:
Diego Pais
Charlottenburger Str. 140
13086 Berlin, Germany
hello@dribs.app
We are not required to appoint a Data Protection Officer under Art. 37 GDPR or § 38 BDSG. Privacy questions go directly to the address above.
Dribs lets you record financial information such as accounts, ledgers, transactions, balances, categories, and the people you share a ledger with. This content is created and controlled entirely by you.
We do not receive, collect, or have access to the financial content you enter. Because this content never reaches us, we do not process it as a controller; it stays under your control on your device and in your Apple account.
To keep the App stable, we collect limited diagnostic information. This is consistent with the privacy information published on our App Store listing.
| Data | Purpose | Linked to you? | Used to track you? |
|---|---|---|---|
| Crash data | App functionality & stability | No | No |
| Other diagnostic data (e.g. performance) | App functionality & stability | No | No |
This diagnostic data is processed on our behalf by Sentry under a data processing agreement, on infrastructure located in the European Union. It is not linked to your identity and is not used to track you. See Sentry’s Privacy Policy.
Crash reporting is on by default, and you can turn it off at any time in the App under Settings → Crash Reports. Reports are scrubbed on your device before they are sent and never include the financial content you enter.
If you contact us by email, we receive your email address and whatever you choose to tell us, so that we can answer you.
If you buy a subscription or other paid feature, Apple tells the App whether a purchase is active. We receive aggregated sales and payout reporting from Apple; we do not receive your name, address, or payment details.
Where we process personal data, we rely on the following legal bases under Art. 6(1) GDPR:
| Processing | Legal basis |
|---|---|
| Crash and diagnostic data, to keep the App stable and secure | Legitimate interest, Art. 6(1)(f): our interest in a working, reliable App (see also Recital 49). You may object at any time under Art. 21, most easily by turning off crash reports in the App’s settings. |
| Providing paid features you have purchased | Performance of a contract, Art. 6(1)(b) |
| Answering your support emails | Performance of a contract or our legitimate interest in responding, Art. 6(1)(b) and (f) |
| Retaining records where tax or commercial law requires it | Legal obligation, Art. 6(1)(c) |
The financial content you enter is not covered by this table because we never receive it, as explained in Section 2.
To convert between currencies, the App requests exchange-rate data from Open Exchange Rates. These requests contain only the currency information needed to fetch rates. They do not include your transactions, balances, or any personal or financial details. As with any network request, the receiving server sees the IP address the request comes from.
Sync and sharing rely on Apple iCloud. Data handled through iCloud is subject to Apple’s Privacy Policy.
Sentry provides crash and diagnostic reporting as our processor under Art. 28 GDPR, on EU-based infrastructure.
You can optionally protect the App with Face ID (or your device passcode). Biometric authentication is handled entirely by Apple’s operating system on your device; your biometric data never leaves your device and is never accessible to us.
We use the limited information described above only to:
We do not use your information for advertising, profiling, or cross-app/website tracking, and we do not sell or rent it. We do not make automated decisions producing legal or similarly significant effects within the meaning of Art. 22 GDPR.
Because your financial data is stored on your device and in your iCloud account, you remain in control of it. You can delete it at any time by deleting records within the App, removing the App, or managing the Dribs data in your iCloud settings.
| Data | Kept for | Stored where |
|---|---|---|
| Everything you enter (accounts, ledgers, transactions) | Until you delete it | Your device and, if enabled, your iCloud account |
| Crash and diagnostic events | Up to 90 days | Sentry, EU region |
| Support emails | Until your request is resolved, and up to 12 months afterwards | Our mailbox |
| Records subject to statutory retention | As required by German tax and commercial law | Our records |
Your data is protected primarily by your own device and Apple account security: device encryption, your passcode or Face ID, and the protections Apple applies to iCloud. Because we operate no servers holding your financial data, there is no central store of it to breach. Data transmitted by the App is sent over encrypted connections. Keeping your device and Apple Account secure, and your device software up to date, remains an important part of protecting your data.
Dribs is intended for users aged 16 and over, and we do not knowingly collect personal data from children under that age. If you believe a child has provided us with personal data, please contact us and we will delete it.
If you are in the European Economic Area, the GDPR gives you the following rights over personal data we hold about you. Because we do not hold your financial content and the diagnostic data we receive is not linked to your identity, most of your data is already under your direct control, but these rights apply to anything we do hold, such as support correspondence.
To exercise any of these, email hello@dribs.app. We will respond within one month, as required by Art. 12(3) GDPR, and there is no charge.
If you think we have handled your data improperly, we would like the chance to put it right, but you always have the right to complain to a data protection supervisory authority under Art. 77 GDPR. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin, Germany
datenschutz-berlin.de
You may also complain to the supervisory authority in your own country of residence or place of work.
We keep processing within the European Union wherever we can: crash and diagnostic data is processed on EU-based infrastructure. Where a service provider processes data outside the EEA, we rely on an adequacy decision or on Standard Contractual Clauses under Art. 46 GDPR. Data you sync through iCloud is handled by Apple under its own terms and safeguards.
The Dribs website sets no cookies and uses no analytics or tracking scripts. The App contains no advertising or attribution SDKs and does not access the advertising identifier.
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. If a change materially affects how we handle your data, we will give notice in the App or by other appropriate means before it takes effect.
If you have any questions about this Privacy Policy or your data, contact us at:
hello@dribs.app
Diego Pais
Full provider details are set out in our Impressum.
This policy applies to the Dribs app for iOS.
© 2026 Diego Pais. All rights reserved.