Skip to content
Nettat

Integrity Policy

How Nettat handles
money and data.

Nettat keeps shared expense records. If you turn on collaboration, it also processes personal data. This policy explains what happens, what does not happen, and what you can control.

Version 1.1 Effective 13 August 2026 Scope Internal TestFlight testing

The rules Nettat follows.

A plan is not a payment

Nettat never treats a Payment Plan as proof that money moved. Only saved expenses and recorded payments change a balance.

Private unless you share

A private Group works without an account. Collaboration and read-only web links stay off until you choose them.

No ads or tracking

No ads, third-party analytics, cross-app tracking, sale of personal data, or marketing profiles.

01

Scope and status

This policy covers the Nettat iPhone app, its optional collaboration service, and read-only secure Group pages. It describes the verified behavior of the current internal build and service.

Private and collaborative Groups use different services. The sections that apply depend on the features you turn on. This policy does not reduce rights you have under applicable data-protection law or replace Apple’s terms for TestFlight, iCloud, or your Apple Account.

The website contact form is the public contact channel. Before public launch, this policy will be completed with the data controller’s full legal identity, legal bases, processor details, and international transfer disclosures. Those details remain open rather than guessed.

02

Financial accuracy

Nettat is a record-keeping and calculation tool. It does not hold, send, receive, or confirm money.

  • A Payment Plan is calculated from the Group’s recorded balances. It suggests how to bring them to zero.
  • Record Payment is used only after a person confirms that money actually moved. Nettat does not infer a payment from a message, link, price, or intention.
  • A Group is settled only when its recorded balances are zero. Editing or undoing an expense or payment recalculates the plan.
  • Nettat keeps the original expense amount and its settlement-currency value visible. Rounding is an explicit Group setting and must remain balanced.

03

What data is handled, and why

Private Groups

Private Groups use SwiftData on your device and may use your private iCloud and CloudKit storage when those Apple features are available and enabled. They do not require a Nettat collaboration identity and can work offline.

Collaborative Groups

Collaboration starts only when you turn it on. The owner creates or imports a shared copy. Nettat then processes the data needed to synchronize the Group and control access:

  • a private, account-free collaboration identity, device sessions, recovery, and records of who made a change;
  • display names, optional phone numbers, Group settings, roles and memberships;
  • expenses, payers, splits, line items, currencies, balances, Payment Plans and recorded payments;
  • size-limited receipt images and the records needed to authorize, attach, download and delete them; and
  • limited records used for security, request limits, change history, and audits.

Nettat uses this data for app functionality, synchronization, collaboration, access control, security, recovery and support. It is not used for advertising, cross-app tracking, marketing profiles, or sale.

Infrastructure

Nettat currently uses Apple services for the app, TestFlight, and optional private iCloud sync. Optional collaboration uses Cloudflare D1 and private R2 storage. The app contains no third-party advertising or analytics SDK.

Website contact form

If you use the website contact form, Nettat processes the name, reply email address, message, and selected site language you submit. Nettat’s website service sends that information through Cloudflare Email Service to the owner’s protected mailbox. The submission is not written to Nettat’s D1 database, used for marketing, or shared with Group members.

04

Contacts and receipts

Contacts

Contacts access is optional and controlled by iOS. Nettat can search only the contacts you have allowed the app to see, on your device. It saves only the person you select: a name and, if you choose, a phone number. The collaboration service never receives a copy of your address book or a list of its contacts.

Phone numbers are optional. They can help with invitations and payment messages and may identify the recipient of a current transfer in a secure read-only page. They are never used for sign-in, discovery, identity recovery, or access to a Group.

Receipts

Receipt recognition uses Apple Vision on the iPhone. Apple Intelligence refinement starts only when you choose it for that receipt and stays on the device. Nettat keeps a size-limited copy of the receipt image with source metadata removed.

In a private Group, that derivative follows the Group’s local and optional private iCloud storage. In a collaborative Group, it is uploaded to a private R2 bucket so authorized members can view it through short-lived, membership-authorized URLs.

05

Collaboration, sharing and access

Each collaborative Group has roles and a Group code. Anyone with the code can ask to join, but an owner or admin still has to accept them. Owners and admins can replace the code without changing existing members.

A secure read-only web link is a separate sharing choice. The link is reusable and forwardable. Anyone who receives it can read the limited set of Group details listed below until an owner or admin replaces or revokes the link, or archives the Group.

The secure page can show display names, expense titles and dates, paid and share amounts, line-item details, recorded payments, balances, and the selected Payment Plan. A current transfer may show the receiving person’s full stored phone number. It excludes receipt images, notes, collaboration codes, memberships, authorship, and internal identifiers.

The secret in the link is stored only in the device Keychain. The service stores a cryptographic hash that cannot be used to recover the link. Share a secure link only with the people who should read it.

06

Security commitments

  • Production collaboration and secure-page URLs are required to use HTTPS.
  • Recovery credentials, sessions, invitations, and secure-link access use long, randomly generated secrets. The service stores only keyed hashes or SHA-256 hashes.
  • Device credentials and secure links are kept in the appropriate iOS Keychain scope; private and shared stores remain separate.
  • Roles, version checks, change locks, size-limited uploads, and short-lived receipt URLs restrict access and conflicting changes.
  • Secure-link attempts use keyed IP and token hashes for rate limiting. Those attempt rows are deleted after 24 hours.
  • The website contact form validates length and origin, silently rejects a hidden spam field, and uses a Cloudflare rate-limit binding keyed from the connection. It does not write the message or email address to service logs or the app database.
  • Credentials, phone numbers and receipt URLs are excluded from audit logging.

No service can promise absolute security. During internal testing, suspected security or privacy problems should be reported through TestFlight feedback so they can be investigated.

07

Retention and deletion

  • An active collaborative Group is retained while its owner keeps it. A deleted Group has a 30-day recovery window. It is then permanently deleted with its people, invitations, expenses, receipts, and change records that contain phone numbers.
  • Receipt objects queued for deletion remain inaccessible and are retried until storage deletion is confirmed. Pending or unattached uploads expire after 24 hours.
  • Invitations expire after 14 days and can be revoked earlier. Secure-link access-attempt rows expire after 24 hours.
  • Deleting a collaboration identity first requires transferring or deleting Groups it owns. The deletion revokes sessions and invitations, disables recovery, leaves joined Groups and anonymizes the profile. Non-personal financial and audit references may remain where recorded history requires them.
  • Deleting a collaboration identity does not delete private iCloud Groups or receipts. Those remain under the app and Apple storage controls for the relevant devices and Apple Account.
  • When a Group is archived, the service may temporarily retain only the secure-link hash needed to show a generic archived state to that exact link. Restoring the Group deletes that row and does not reactivate the old link.
  • A contact-form message remains in the owner’s protected mailbox only as long as needed to respond and follow up, unless applicable law requires longer retention. You can use the same form to ask for an earlier deletion.

08

Your choices and rights

  • Use Nettat privately and offline without enabling collaboration.
  • Decline Contacts access, limit which contacts iOS shares, or enter people manually.
  • Edit Group data, correct expenses, undo recorded payments, remove optional phone numbers, and replace or revoke secure links when your role permits it.
  • Leave a collaborative Group or delete your collaboration identity. Saved financial history can require expenses or payments to be corrected first so the record remains accurate.
  • Owners can transfer ownership or delete a collaborative Group.

Depending on applicable law, you may also have rights to information, access, correction, erasure, restriction, portability, objection and complaint to a supervisory authority. Use the website contact form, or TestFlight feedback while testing, to make a request. The public release notice will also identify the legally responsible controller.

09

Contact, accountability and changes

Nettat is owned and maintained by Alexander da Silva. Use the contact form on the Nettat website for questions about privacy, security, your data, support, or how the product works. Invited testers may also use Send Beta Feedback from Nettat’s TestFlight page. The responsible controller’s complete legal details will be added before public release.

Nettat gives this policy a version and effective date whenever it changes. Material changes will be explained before they apply. If a change affects data already collected, Nettat will not quietly reduce the promises made here.

Last reviewed13 August 2026