Afford Privacy Policy
Last updated October 6, 2026
Afford is built so that your financial life stays yours. The short version: we run no servers, require no account, and collect nothing. Everything below is the long version of that sentence.
Who we are
Afford is made by Bryan Weber, publishing as BradiaLabs. This policy covers the Afford app for iPhone, iPad and Mac, and this website.
What we collect
Nothing. Afford has no user accounts, no sign-up, and no analytics, advertising, crash-reporting or tracking of any kind built into the app — no third-party SDKs that phone home. We operate no backend servers, so there is nowhere for your data to be sent to us — by design, we cannot see your budgets, transactions, balances, or anything else you do in the app.
The only things that ever leave your device go to services you choose — Apple’s iCloud, SimpleFIN, and optionally an AI service or server you set up — each described below.
Where your data lives
- On your device. Your budgets — envelopes, accounts, transactions (including the bank’s original description text for synced transactions), payee rules and settings — are stored in a local database in the app’s private container on your iPhone, iPad or Mac.
- In your iCloud. If you’re signed into iCloud and Sync with iCloud is on, Afford syncs your budgets between your devices through Apple’s CloudKit, in your private iCloud database, protected by Apple’s iCloud security. Your personal display preferences are kept there too, so your devices look the way you like. This data is accessible to you and not to us. You can turn sync off in Settings.
- Shared budgets. If you share a budget with family, it’s shared through Apple’s native CloudKit sharing, from the owner’s iCloud, only with the people invited. Everyone in the share sees that budget’s accounts, envelopes and transactions. Your personal preferences and your bank connection are never part of a shared budget.
Deleting a budget you own deletes its data from your devices and from iCloud — for everyone it was shared with. Leaving a budget someone shared with you removes it from your devices; it stays with its owner. Deleting the app removes its local data; iCloud data can be removed by deleting budgets first, or via iCloud storage management.
Afford’s tour and demo budget use sample data that stays on your device and never touches iCloud or your bank. Imports and exports happen only when you pick a file, and go only where you put them.
Bank connections (SimpleFIN)
Connecting your banks is optional and happens through SimpleFIN Bridge, a third-party service you sign up for directly:
- Your device talks to SimpleFIN directly — there is no Afford server in between, and your bank credentials are never entered into Afford at all.
- The SimpleFIN access URL (a read-only token) is stored in your Keychain, which follows your own devices through iCloud Keychain, and is also kept — in an encrypted field — in your private iCloud database, so your other devices can sync without re-entering it. It is never placed in a budget you share.
- The token can read balances and transactions only; it cannot move money. You can revoke it at any time from your SimpleFIN Bridge dashboard.
- The accounts, balances and transactions it downloads (including each transaction’s description text from your bank) are stored and synced like the rest of your budget, as described above.
SimpleFIN has its own privacy policy covering the data it handles; see simplefin.org.
The AI assistant
By default, Afford’s assistant (Penny) runs entirely on your device — via Apple Intelligence or a locally downloaded Gemma model. In the default configuration, nothing you ask the assistant, and none of your financial data, ever leaves your device. Downloading the Gemma model fetches the model files from Hugging Face; nothing of yours is sent in that download.
Apple’s Private Cloud Compute. On iOS and macOS 27, Apple offers apps a larger model that runs on Apple’s Private Cloud Compute servers. This version of Afford does not use it — every request stays on your device. If a future version does, it will be controlled by the Private Cloud Compute switch in Settings → Penny, and we’ll update this policy before that version ships.
Online AI services and your own server. If you choose to configure an online AI service (ChatGPT, Claude, Gemini, OpenRouter or Hugging Face) in Settings → Penny → Online services, then while the assistant is answering, the conversation, a snapshot of your budget, and the results of what the assistant looks up are sent to that service under your own API key, subject to that provider’s privacy policy. If you instead point the assistant at a server you run yourself, the same information goes to that server’s address and nowhere else. This never happens unless you set it up; the app states it plainly in Settings and in the assistant while it’s active. Your API keys are stored in your Keychain (synced to your own devices through iCloud Keychain). The “Send a test question” check sends only a simple arithmetic question. Turning the engine back to an on-device option stops all network use by the assistant.
Purchases (Afford Pro)
Afford Pro is sold as an in-app purchase through the App Store. Apple handles the payment and your payment details; we never see them. Afford checks your Pro status with Apple’s StoreKit on your device — it doesn’t send your purchase information to us or to anyone else. Like every App Store developer, we receive sales reports and statistics from Apple that don’t identify you.
Notifications and permissions
Afford uses iCloud’s silent push notifications internally to keep devices in sync; it doesn’t show you notifications. If you set up an AI server on your local network, Afford asks for Local Network permission so it can reach that server — that’s the only reason it uses it. It does not access your contacts, location, photos, camera, microphone, or anything else unrelated to its job.
This website
bradialabs.com is a static website. It does not set cookies for the Afford pages, loads no analytics or third-party scripts on them, and does not profile visitors. Standard web server logs (IP address, page requested) may be kept briefly by our hosting provider for operational purposes.
Children
Afford is a general-audience finance app and does not knowingly collect any personal information — from children or anyone else.
Changes to this policy
If the app ever changes in a way that affects this policy, we’ll update this page and note the date below the title. Given the architecture — no servers, no accounts — meaningful changes would be visible in the app itself, not buried in fine print.
Contact
Questions about privacy, or anything else: bradialabs@gmail.com.