Wafra Privacy Policy

Last updated: 15 September 2026

Wafra ("the app") is a personal money manager for Android and iOS published by Nasidaapps LLC ("Wafra", "we", "us").

Launch draft. Have counsel review this before publishing. Any jurisdiction-specific transfer language required for the final distribution territories must still be confirmed before release.

The short version

Message-access choices

Android SMS access is optional. If the user keeps it off, Wafra cannot scan the SMS inbox at all; manual entry and user-initiated imports remain available. If the user enables automatic SMS history, Android necessarily gives the app permission to read message text on that phone. Wafra checks the text locally to decide whether it is supported financial activity. Other content is discarded before app storage and is never uploaded. The no-permission option remains available for users who prefer manual entry.

On iPhone, leaving automatic capture unconfigured gives Wafra no Messages access. If the user enables Wafra Local Capture, Apple's personal automation can pass a newly received Message from a bank sender the user selects to Wafra on that iPhone. The raw body and sender can therefore remain briefly in Wafra's protected local queue until the app classifies the record. They are not uploaded, logged, used for analytics or written to the ledger. Unsupported content is discarded after classification. A record the app has not yet processed expires after 30 days and is physically removed on the next queue access; iOS does not promise an exact background cleanup time.

Android bank-alert access

SMS (READ_SMS, RECEIVE_SMS). If permission is granted, Wafra reads bank transaction alerts to extract an amount, merchant, date, card or account tail, direction and any quoted balance. Inbox scanning and parsing happen on the Android device. Wafra does not maintain a second raw-SMS delivery archive; the Android system inbox remains the source read during import.

Messages that do not look financial are ignored. When the parser cannot confidently understand a bank format, Android may keep a short local excerpt so the user can review or report it. That excerpt is not uploaded automatically and can be deleted in Settings.

Wafra does not request Android Accessibility access and does not use SMS to reply, enter codes, approve prompts or control another app.

Bank-app notifications (optional). If notification access is enabled, Wafra places candidate bank-app alerts in a bounded, short-lived queue encrypted with Android Keystore. The app deletes each queued alert after durable local classification. This is off until the user enables it.

iPhone automatic capture

Apple does not give third-party apps access to the SMS inbox. Wafra therefore uses a personal automation that the user creates in Apple's Shortcuts app:

  1. The user chooses Message, explicitly selects a bank sender, selects Run Immediately, and passes the complete Received Message to Wafra Local Capture. Apple requires an explicit sender or phrase; Wafra does not use an empty Any Sender trigger.
  2. The Shortcut passes the Message's sender, body, Apple identifier and date to Wafra's background App Intent on the same iPhone. The identifier is reduced to a stable opaque value before storage.
  3. Wafra stores the record in an app-private, backup-excluded queue protected by iOS complete-until-first-authentication file protection. No network action exists in this Shortcut.
  4. When iOS next permits Wafra to run, the app uses its local financial parser. Supported transactions enter the encrypted ledger or review flow; promotions, OTPs and unsupported content do not.
  5. After the result is durably handled, Wafra deletes the raw queued record. Records not yet handled expire after 30 days and are removed on a later queue access.

The automation can stage a new Message while Wafra is closed, but Apple controls when personal automations and background App Intents run. Wafra therefore does not promise that the ledger updates at an exact time. Opening Wafra drains any available protected queue.

Older TestFlight builds used a separately paired relay-backed Shortcut. During migration, that old automation can continue sending previously selected alerts until it is deleted or its token is retired. The current local Shortcut contains no relay URL or credential. A saved local-only preference blocks relay processing in the app but does not disable local automatic capture. An old automation must still be removed or have its token retired.

iPhone message-history import

On iOS 26 or later, the user can separately run Wafra's message-history Shortcut. It uses Apple's Find Messages action to request at most 1,500 newest and 1,500 oldest retained Messages. It verifies both sort extremes and requires at least one stable Message-identifier overlap before continuing. If the results do not overlap—including when the phone retains 3,000 or more Messages—it erases partial staging instead of presenting a knowingly incomplete history. It also enforces a 24 MiB protected-import safety limit. Apple does not provide Wafra with a direct SMS-inbox permission or API. Large histories can take 20–25 minutes or more depending on the phone and retained history, and the iPhone must remain unlocked with Shortcuts open until Wafra opens.

The Shortcut passes Message text, sender, date and Apple's Message identifier to Wafra one record at a time from each bounded result. The identifier is hashed before the first protected disk write. Prepared records stay on the device, use iOS complete file protection, are excluded from device backups and are not sent to the relay, analytics or an AI service. Wafra parses them locally and shows a preview before changing the ledger. Raw Message text and sender are not written to the ledger.

When the user confirms, Wafra first saves the structured results to its encrypted database and then deletes the staged batches. Cancelling also deletes them. If deletion is interrupted, staged batches become eligible for local cleanup after one hour and Wafra removes them the next time the history bridge runs. An unfinished per-Message preparation remains recoverable for up to three hours so large runs can finish, then becomes eligible for the same opportunistic cleanup. iOS does not guarantee that fallback cleanup happens at an exact wall-clock time. Messages already deleted by the user, removed by Messages retention settings or unavailable to Apple's search cannot be recovered or imported.

What is stored on the device

Transactions, accounts, cards, budgets, bills, goals and settings are stored in the app's private encrypted storage. The iPhone relay private key and foreground credentials are stored with iOS Keychain through Expo SecureStore. A least-privilege sync credential and separate SQLCipher inbox key are available only after the first unlock; neither contains the Shortcut ingest token or email-forwarding token.

iOS Keychain items can survive an uninstall. To erase the relay registration and its local key deterministically, use Settings → Erase all data while online before uninstalling. If the relay cannot be reached, Wafra keeps the key so the user can retry deleting the remote registration.

Biometrics

If app lock is enabled, Wafra asks the operating system to authenticate with the enrolled face, fingerprint or device credential. The operating system performs that check and returns success or failure. Wafra does not receive or store biometric templates.

Other network activity

Wafra does not include advertising, third-party analytics or crash reporting.

Automated processing

Wafra extracts transaction fields and suggests a merchant and category. These labels are visible only to the user, have no legal or financial effect and can be corrected. Wafra does not use bank alerts for advertising, credit decisions or training a server-side model. Ordinary user feedback is not sent to a third-party AI. A tester may separately and explicitly authorize GitHub Actions and Anthropic Claude to process the redacted parser templates described above.

Security and retention

Network traffic to the iPhone relay uses HTTPS. Queued structured rows use X25519, HKDF-SHA-256 and AES-256-GCM so the relay cannot decrypt them after sealing. Bearer tokens are stored by the relay only as SHA-256 hashes.

No system is risk-free. A relay security incident could expose transient raw text while a request is being processed, sealed queue data, public keys and token hashes. It should not expose a stored raw-message archive because no such archive exists.

Processing location

Nasidaapps LLC uses Cloudflare Workers and D1 for Wafra's optional relay-backed features. Internet routing and infrastructure may process data outside the user's country. The main Android and iPhone local-capture paths described above do not upload bank-message text to this relay. Where local law requires more specific international-transfer or data-location disclosure, that disclosure must be added for the affected storefront before distribution there.

Your choices and deletion

The user can:

Acknowledged relay rows are deleted immediately. Unacknowledged structured rows expire within 30 days. A disconnected device registration is deleted immediately; an abandoned one expires after one year.

Exported files remain wherever the user saved or shared them and must be deleted there separately.

Children

Wafra is not directed at children and is intended for users aged 18 or older.

Changes

If this policy changes, the date at the top changes with it. Material changes will be surfaced in the app.

Contact

Email: support@nasidaapps.com

Back to Wafra