Privacy policy

Last updated: 29 August 2026

This policy describes what the Topf app and this website do with personal data. It is written to match what the code does, not what is customary to write.

Who is responsible

The controller for the processing described here is Andrey Fedyukov, Mecumstraße 52, 40225 Düsseldorf, Germany.

For any question about your data, write to [email protected]. You can also lodge a complaint with a data protection supervisory authority in the EU country where you live.

What we store

Account data, when you create one: your email address, the identifiers of the sign-in method you used (Apple or Google, when you sign in that way), and the technical timestamps of your sessions.

The book itself: operations, accounts, categories, recurrence rules, planned payments, currency settings and the notes you write. If you share a book, the membership of that group and its one-time invitation codes.

That is the whole list. There is no advertising identifier, no device fingerprint, no behavioural analytics and no third-party tracking SDK in the app.

Using the app without an account

Topf can be used without signing up. In that mode the book stays on your device only, nothing is uploaded, and we hold no data about you at all. Voice input is the single exception — it needs a network, and it is described below.

Why we may process it, and on what basis

To provide the product you asked for: keeping your book, synchronising it between your devices and restoring it on a new one. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

To sign you in: sending the one-time code to your email address. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

To keep the service working and to stop abuse of the voice endpoint. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

Where the data is

A full copy of your book is on your device, in a local database, and it works there without a network.

When you have an account, the same data is stored in a PostgreSQL database hosted by Supabase in Frankfurt, Germany (AWS eu-central-1), and reaches your devices through the PowerSync synchronisation service. Access is restricted per user by row-level security: an account can read its own book and, if it belongs to a shared one, that book.

Voice input

When you use voice input, your phrase is normally recognised by the speech recognition of your device, and only the resulting text is sent to our server, together with the context needed to make sense of it: your interface language, today’s date, your time zone, your main currency and the names of your active accounts and categories.

That text is passed to OpenAI, which turns it into drafts of operations. The drafts come back to your phone and are shown to you; nothing is written to your book until you confirm it.

When the recognition of the device is unavailable, the recording itself is sent instead and transcribed by the same provider. In both cases the audio and the text pass through our function in memory and are not stored by us — not in the database, not in a file, not in a log.

OpenAI processes this data on our instructions as a processor. Its API is used in the mode that does not train models on submitted data; the provider may retain a request briefly for abuse monitoring. Do not dictate anything you would not want a processor to see.

Email

Sign-in codes are sent through Amazon Simple Email Service (AWS, Frankfurt, Germany). The service receives your email address in order to deliver the message. We do not send marketing email and there is no mailing list.

Exchange rates

Daily exchange rates come from the public service api.frankfurter.dev. The request is made by our server once a day for everybody, not by your device — so using multiple currencies tells that service nothing about you.

This website

The site is static and hosted on Cloudflare Pages. It has no forms, no cookies, no analytics and no embedded third-party content. Cloudflare processes the technical data any web server sees — your IP address, the requested address, the user agent — to deliver the page and to protect the service.

Who else sees the data

Only the processors named above, each for the one job it does:

  • Supabase — hosting of the database and the authentication service;
  • PowerSync — synchronisation between the database and your devices;
  • OpenAI — turning a spoken phrase into drafts;
  • Amazon Web Services — email delivery, and the infrastructure the database runs on;
  • Cloudflare — hosting of this website and the domain.

Your data is not sold, not rented, not shared with advertisers and not used to train anybody’s models.

How long we keep it

For as long as your account exists. Deleting the account deletes the book on the server; a copy that has already been synchronised to your own devices is removed when you sign out or remove the app.

Operations you delete inside the app are kept briefly in a recoverable state so that deleting by mistake is not final, and are then removed for good.

Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest.

Deletion is built into the app: Settings → Account → Delete account removes your data on the server and, when you signed in with Apple, revokes that grant as well. For anything else, write to [email protected].

Children

Topf is not directed at children and is not intended for use by anyone under 16.

Changes

When this policy changes, the date at the top changes with it. A change that materially affects how your data is handled will be announced in the app before it takes effect.