Kettle Money
ENDE
App Store

Kettle Money

Privacy

effective 3 October 2026

  1. Kettle Money
  2. Privacy

Privacy Policy

  • Trackers0
  • Ads0
  • Data sold0
  • Total0

Your household ledger lives on your iPhones and in your own iCloud. Optional bank connections need additional connection and security data. We do not sell data, show ads or track you.

Kettle Money app and this website · effective 3 October 2026 · version 1.1

Who is responsible

Kettle Money is published by:

Mama Bloom UG (haftungsbeschränkt)
Oskarstr. 14, 01219 Dresden, Germany
Represented by its Managing Director, Claudia Nowack
HRB 47918, Amtsgericht Dresden · VAT ID DE462097561
Privacy: privacy@mamabloom.app · Phone: +49 152 5826 2078

Given our current scale of processing, a Data Protection Officer is not formally appointed under Art. 37 GDPR or § 38 BDSG. The Managing Director is responsible for data protection.

Our representative in the United Kingdom under Article 27 UK GDPR is Prighter Group: app.prighter.com/portal/19873577792.

What Kettle Money is

Kettle Money helps adults plan household money and time. It is a planning ledger. It never holds, moves, pays or transfers money, and it makes no purchases for you. You need no separate app account or sign-in with us. The app contains no advertising, tracking or analytics SDKs.

What Kettle Money processes, why, and on what legal basis

What you add

Plans, names, balances, transactions, tasks, notes and the sources you scan, choose, paste, share or type. They are stored on your iPhone and, if you use iCloud, in your own iCloud account. We do not operate a store of your household ledger data. Optional bank connections and messages to us are described separately below. Purpose: to provide the app you asked for (Art. 6(1)(b) GDPR).

Your private copy in iCloud

When private iCloud backup is enabled and available, Kettle Money saves a copy of what is yours alone (your private accounts and transactions, receipts and letters you captured, orders, remembered prices, your shopping list and your categories) in your own private iCloud database, once a day when something has changed. If you are the only adult in a household you never shared, the household itself (its plans, budgets and records) is in the copy too. Financial and planning fields are encrypted; original source files are stored as private iCloud assets. This private copy is not shared with other adults through household sharing. Kettle Money tries to remove older copies and keep the three newest. Failed removal stays pending and is retried. You can switch this off, or restore a copy, under Settings → Private iCloud backup. Deleting your data erases local data and requests removal of your private iCloud copies. The app shows pending cloud deletion separately and offers a retry. An app still active on another device can upload new data; stop using those devices before deletion. Basis: Art. 6(1)(b) GDPR.

Orders, prices and your shopping rhythm

Order messages you share, the prices on receipts you scan, how often you buy things and the shops you teach Kettle Money to sort stay on your iPhone and, if private iCloud backup is enabled, in your own iCloud. They are used to remind you before a return window closes, find refunds among your bank lines, compare prices from your own receipts and suggest what may be running low. Basis: Art. 6(1)(b) GDPR.

A shared household

If you invite another adult, household plans, decisions, shared ledger records, saving pots, contribution pledges and your household membership status are shared with the adults you invited, through Apple’s iCloud sharing. Your private accounts, statement lines and source files are not shared. Basis: Art. 6(1)(b) GDPR.

On-device intelligence

Text recognition, Ask (the app’s question box) and the optional Apple Intelligence extraction run on your iPhone. No question or document is sent to a cloud model.

Apple Wallet accounts

If you connect an Apple Wallet account, Kettle Money reads the balances and transactions of the accounts you choose, on your iPhone, through Apple’s FinanceKit. Nothing is sent to Mama Bloom UG. Basis: Art. 6(1)(b) GDPR. This feature is in preparation and only available where Apple offers it.

European bank accounts

This feature is in preparation and switched off until it launches. If you choose it when available, Enable Banking Oy (Finland), a registered account information service provider regulated by the Finnish Financial Supervisory Authority, provides read-only bank access. You approve access on your bank’s own page. Balances and transactions pass through Kettle Money’s relay to your iPhone; the relay does not store their contents. The prepared relay uses Vercel Inc. and is configured for Frankfurt, Germany. Enable Banking and your bank receive IP address and device information needed for their bank requests. Enable Banking’s privacy notice describes its own processing. Basis: Art. 6(1)(b) GDPR and the consent you give your bank.

The relay does retain limited connection and security data: an installation identifier, public verification key, verification environment and replay counter; consent, session and account identifiers linked to the verified app installation; access end dates; and a short-lived completion reply containing account holder name, currency, account type, hashed identification and the last four IBAN characters. These records verify the app, prevent replay, restrict access to the installation that opened the connection, recover interrupted requests and withdraw unused connections. Bank access lasts at most 180 days. Retention limits are set out below.

Disconnecting a bank, abandoning a completed connection or deleting your Kettle Money data requests withdrawal. If that fails, the app keeps a protected local recovery record containing only the original local owner identifier, provider, session identifier, access end date and retry status. It survives deletion of the local ledger and retries when the app opens. It is not shared with your household and contains no balances or transactions. It is removed after confirmed withdrawal, or at a later check once the grant has expired. Expiry ends access but is not confirmation of an earlier withdrawal. Removing the app can remove this recovery record. A reinstall or reset of installation verification cannot take over an old connection: connect again and withdraw the old consent in your bank’s app.

Before activation, we must verify the deployed retention settings, identify the Redis storage provider, review hosting-log retention and redaction, configure and verify scheduled recovery, and complete the necessary provider agreements and any international-transfer safeguards. The prepared defaults below are not a statement that a production bank service has been configured or approved.

Addresses you type

When you ask for a travel time, the address is sent to Apple Maps to find it and plan the route. Basis: Art. 6(1)(b) GDPR.

Calendar, notifications, widgets, Apple Watch

These features are optional. Calendar access and notifications need your permission; you choose whether to set up widgets or the Watch app. If you enable conflict checking, Kettle Money reads events for the reviewed week from all calendars it can access. A saved receipt for a plan you apply can include conflicting event titles, event identifiers and overlap times. For a household that has never been shared, these details can be included in your private iCloud backup when enabled. They can also be included in an export you choose to save or share. Ordinary household sync does not automatically send your device’s calendar entries to the other adults. Calendar events are shown for review before they are written. When another adult changes your household, Apple’s push service quietly wakes Kettle Money so it can read the change; the push itself carries no household content. Notifications show only what is yours: answers, handovers, tasks due. Quiet hours apply.

Purchases

Subscriptions are sold and billed by Apple. Kettle Money receives verified transaction information from Apple, including a random identifier linking the purchase to the paying adult. The app shares the confirmed membership period with other adults through the household’s iCloud data. Mama Bloom UG never receives your payment details. Basis: Art. 6(1)(b) GDPR.

This website

This website sets no cookies, uses no storage in your browser, embeds no analytics or advertising scripts and loads nothing from other servers; even the font is hosted here. Our hosting provider keeps standard server logs (IP address, browser identifier, time, page requested, status code) for security and operation. Basis: Art. 6(1)(f) GDPR, our legitimate interest in running the site securely. These logs are not used for advertising or behavioural profiling.

If you write to us

If you email us, we use your message and address to answer you (Art. 6(1)(b) or (f) GDPR). We delete the correspondence when it is no longer needed, at the latest three years after the end of the year of our last contact, unless the law requires us to keep it longer. Please don’t send us statements or household data; we don’t need them to help.

Recipients

  • Apple Inc. and its affiliates: the App Store, subscriptions, iCloud (for your own data, in your account), push notifications, Apple Maps and FinanceKit.
  • Our hosting provider for this website (server logs).
  • Once European bank accounts are available: Enable Banking Oy and Vercel Inc. (relay configured for Frankfurt; production deployment still to be verified), plus the Redis storage provider to be identified before activation, as described above.

We don’t sell data, and we share nothing with advertisers or data brokers.

How long data is kept

  • Local and iCloud data is kept until you delete it or request deletion in Kettle Money. The app targets three private backup copies; failed cleanup remains pending and can be retried. Minimal local recovery information can remain while cloud deletion or bank withdrawal is pending. Previously exported files remain under your control.
  • The prepared relay does not store balance or transaction contents. Consent state, temporary authorisation codes, hashed replay reservations and the trimmed completion reply expire within 20 minutes; the authorisation code is removed once its created session has been durably recorded.
  • Account ownership records last until the bank grant ends. Session ownership can last until that end plus 30 days to support failed withdrawal. A confirmed withdrawal clears account mappings and retains only a minimal ended-session record for at most 30 further days within the original limit.
  • A completed connection remains in an installation-bound recovery inventory until the app acknowledges that its protected local recovery record is saved. Unacknowledged delivery becomes eligible for withdrawal after 20 minutes; interrupted session staging after one minute. Recovery retains the session, consent state, claim/retry status, access end and timing metadata until acknowledgement or cleanup. Later verified requests can retry withdrawal. A separate maintenance worker can process due recovery even if the device does not return, but its production secret, schedule and monitoring must be configured and verified. Individual recovery ends at grant end plus 30 days. Shared inventory expires after its latest grant plus 30 days, and new jobs can extend that deadline. Maintenance must prune earlier entries; timely removal depends on a configured and monitored schedule.
  • New installation verification keys and replay counters have a rolling 365-day default, renewed only by a verified new request; configuration permits 211–730 days. Aggregate verification counters have a fixed seven-day default, configurable from one to 30 days. Challenges last five minutes and request nonces 15 minutes. New attestation receipts are not retained. Actual production settings and migration of older records still require verification before activation.
  • Hosting request logs are separate: paths can contain session or account identifiers, and callback URLs can contain a temporary authorisation code. Their actual retention and redaction must be confirmed before bank access launches.
  • Bank grants end after at most 180 days. Local withdrawal recovery is kept until confirmation or a later check after grant expiry; removing the app may interrupt retries. You can withdraw consent in your bank’s app.
  • When you leave a shared household, its history stays with the other adults, including your name on earlier decisions.
  • Emails to us: as described under “If you write to us”.

Your rights

You may ask for access, correction, erasure, restriction or portability, or object to processing, and you may withdraw a consent at any time (Articles 15–21 GDPR). In Kettle Money you can export your data (JSON, CSV and source files) and delete it under Settings → Your data. For anything else, write to privacy@mamabloom.app; we answer within one month (Art. 12(3) GDPR).

You may also complain to a supervisory authority: our lead authority is the Sächsische Datenschutz- und Transparenzbeauftragte (datenschutz.sachsen.de); you can also go to the authority where you live, or in the UK to the ICO.

Children

Kettle Money is for adults. Children can be named as participants in an adult’s plans; they have no account and no access. Kettle Money infers nothing about participants’ health, behaviour or location.

Security

Kettle Money stores your data with iOS’s complete data protection: while your iPhone is locked, it is encrypted. Between the devices of a household, Kettle Money uses Apple’s iCloud sharing.

Changes

If this policy changes, the new version is published at this address with a new date. Material changes are also noted in the app’s release notes.