Privacy Policy
Drachma - Last updated: 18 September 2026
Drachma does not sell your information or share it with advertisers or data brokers. It does not contain advertising SDKs. Limited subscription and paywall activity is described below.
1. Who We Are
Drachma is a personal finance application and related website operated by Stavros Pournias, trading as Agora Studio (getdrachma.app). The app is available on Android and iOS where distributed through app stores or testing programmes.
Stavros Pournias is the controller responsible for the personal data described in this policy.
Business and correspondence address: Suite RA01, 195-197 Wood Street, London, E17 3NU, United Kingdom
Telephone: +44 7438 984160
Privacy contact: [email protected]
European Representative under Article 27 of GDPR
We have appointed EU Rep as our Representative under Article 27 of the EU General Data Protection Regulation (“GDPR”). All GDPR queries from EU Data Subjects or Data Protection authorities should be submitted to eurep.ie via their dedicated form. BizLegal Ltd trading as EU Rep have their registered office at 27 Cork Road, Midleton Co. Cork, Ireland. Company number 635921.
2. What Data We Collect
Most information Drachma processes is information you choose to provide. Production builds and the services that operate the app also process limited technical, security and crash data.
Account data
- Email address and account identifier required for sign-in
- Authentication and session tokens, managed by Supabase Auth and stored securely on your device
- If you use Google Sign-In or Apple Sign-In: your name and email as provided by those services
Financial data entered by you
- Transaction records: amounts, dates, categories, notes and payment status
- Account balances and account names
- Budget targets and planned income figures
- Recurring payment schedules
- Receivables (money owed to you) and refund records
- Custom categories and display settings
- Attached files you choose to add to transactions, such as receipt photos, bills, PDFs, screenshots and proof-of-purchase documents
- Imported transactions created from bank statement files you choose to open in the app (CSV or PDF). The statement file itself is never uploaded or stored unless you separately attach it to a transaction.
Drachma Plus subscriptions
We use RevenueCat to display subscription plans, verify purchases and keep Plus access linked to your Drachma account. When subscriptions are enabled in your version of the app, RevenueCat receives your Drachma account identifier and limited technical information when you sign in, even if you have not purchased Plus.
- Your account identifier, platform, app and operating-system information, language preference and service activity such as the last time the app connected
- For purchases: the product and store, purchase and transaction identifiers, store receipts or purchase tokens, purchase and expiry dates, and trial, renewal, cancellation, refund and billing status
- Price, currency and country information where supplied by the store or purchase service
- Interactions with the subscription screen, such as viewing plans and starting a purchase, where collected by RevenueCat's paywall service
RevenueCat sends purchase updates to our Supabase backend, where we store your Plus access status and purchase-event records to keep access accurate and investigate purchase problems. We do not send your budgeting transactions, balances, bank statements or attachments to RevenueCat, and we do not configure your name or email as RevenueCat customer attributes. Your account identifier can nevertheless be linked to you through our account records.
Apple or Google processes in-app payments using your store account. Neither Drachma nor RevenueCat receives your full payment-card details through this purchase flow.
Budget session and payment data
- If you enquire about or book a paid one-to-one budget session, we may process your name, email address, enquiry and booking correspondence, the agreed price, booking details and payment status.
- During a session, we process financial information you voluntarily discuss or show through screen sharing. Only limited notes needed to provide the session and agreed follow-up are retained; screen-shared material is not automatically copied or stored.
- Sessions take place through Google Meet and are never recorded by us.
- Payments for these sessions are processed by Stripe. Stripe may process payment and billing information and transaction metadata. Drachma does not receive or store your full card number.
App settings
- Currency, theme and language preferences
- Fiscal year and budgeting period configuration
- Privacy mode, transaction filter preferences and summary-view preferences
Support and feedback data
- Feedback messages you submit in the app, stored in Supabase as support tickets
- Optional reply email, feedback type, app version, platform and operating-system version
Crash and error data
- In production builds, errors and crash reports may be sent to Sentry
- Reports can include stack traces, app version, platform, operating-system version and technical error context
- We do not intentionally attach your financial records or transaction content to crash reports
Service and security data
- Hosting and infrastructure providers may process IP addresses, request timestamps and technical logs needed to authenticate requests, secure the service, investigate abuse and diagnose failures
3. How We Use Your Data
Your data is used to provide and operate the app and related services, including:
- Authenticating your identity and maintaining your session
- Storing and displaying your financial records across devices
- Calculating budgets, summaries and wealth reconciliation
- Applying recurring payment schedules
- Reading bank statement files you select, on your device, to prepare transactions for review
- Uploading, viewing, sharing, saving and deleting attachments you choose to add
- Generating transaction spreadsheet exports and full ZIP backups on request
- Sending transactional account and security emails, such as account confirmation and password reset/change messages
- Arranging and delivering budget sessions, taking limited working notes and providing agreed follow-up
- Handling support and feedback messages
- Diagnosing and fixing crashes via Sentry
- Administering the service, preventing abuse and resolving security or operational issues
We do not use your financial data for advertising, profiling or unrelated analytics.
Subscriptions and purchase support
We use subscription information to show available plans, verify and restore purchases, enable Plus features, keep access up to date after renewals, cancellations or refunds, and resolve billing problems. RevenueCat also provides subscription and paywall reports, such as purchase totals and plan conversion, for understanding how the subscription service performs. These records are separate from the personal spending and account balances you track in Drachma.
We rely on performance of our contract for purchase verification and delivery of Plus, legitimate interests for preventing purchase fraud, diagnosing purchase failures and reviewing subscription performance, subject to your rights, and legal obligations for any required accounting records.
Our legal bases
- Contract: to create your account, provide the app features you request, arrange and deliver paid budget sessions, process payments for those sessions, and provide related account or booking communications.
- Legitimate interests: to secure and maintain the service, prevent abuse, diagnose crashes and respond to support or feedback, provided those interests do not override your rights.
- Legal obligations: where processing or disclosure is required by applicable law.
4. How Your Data Is Stored
Financial records and settings are stored on Supabase (PostgreSQL). Attachments are stored in private Supabase Storage paths tied to your user account.
- Row-Level Security: policies restrict authenticated access to records belonging to the signed-in user.
- Encrypted in transit: communication between the app and Supabase uses HTTPS/TLS.
- Encrypted at rest: Supabase encrypts data at rest on the underlying infrastructure.
- On-device protection: the app supports biometric lock and Privacy Mode.
Your device also stores session details, including your email address and authentication tokens, using operating-system secure storage. App preferences and temporary files may be stored locally. Exports and backups are saved only when you request them.
Drachma is not currently end-to-end encrypted. As the service operator, we may have technical access to stored user data through our infrastructure providers. Access is limited to operational purposes such as support, security, service maintenance or legal obligations.
5. Third-Party Services
Drachma uses the following providers and discloses only the data needed for each configured purpose.
Database, authentication and file storage. Our project's primary storage for financial records, account and authentication data, and attachments is in the EU (AWS eu-west-1, Ireland). Support access and processing by Supabase and its subprocessors may take place outside the EU.
Supabase privacy policy →Subscription verification, purchase restoration, Plus access management and the subscription screen. RevenueCat processes the account identifier, purchase information and limited technical and subscription-screen activity described above on our behalf. It does not receive the financial records you track in Drachma.
RevenueCat privacy information →In-app billing and subscription management. The store processes your payment and provides purchase information needed to verify access. Apple and Google also process store-account, payment and transaction records under their own privacy policies and retention requirements.
Apple privacy policy →Google privacy policy →
Website hosting, content delivery and security through Cloudflare’s global network. When you visit getdrachma.app, Cloudflare may process your IP address, approximate location derived from that address, request timestamps, browser or device information, and technical logs needed to deliver, secure and operate the website.
Cloudflare privacy notice →Transactional app-email delivery. Your email address and delivery metadata may be processed to send account confirmation, password reset or change, and similar account/service messages.
Resend privacy policy →Email hosting for session enquiries and related correspondence sent to or from our @getdrachma.app addresses. Namecheap may process sender and recipient details, message content, attachments and delivery metadata.
Namecheap privacy policy →Payment processing for paid one-to-one budget sessions. Stripe may process your name, email address, billing and payment information, payment status and transaction metadata. Drachma does not receive or store your full card number.
Stripe privacy policy →Crash and error reporting in production builds. Reports may include stack traces, app version, platform, operating-system version and technical error context. We do not intentionally attach financial records or transaction content. We use Sentry’s EU region (Germany) for error-event data and related backups. Some account, integration and organisation metadata may be stored in the United States.
Sentry privacy policy →Optional. If you sign in with Google, your Google account email and name are passed to Supabase Auth to create or match your account.
Google privacy policy →Optional. If you sign in with Apple, your Apple-provided email or relay address is passed to Supabase Auth.
Apple privacy policy →Video calls for one-to-one budget sessions. Google may process your display name or account email if you join while signed in, meeting participation and technical data, and the audio, video or screen content transmitted during the call. Sessions are never recorded by us.
Google privacy policy →Issue tracking for in-app feedback. If you submit feedback, its title, message, type, app version, platform and operating-system version may be mirrored to our issue tracker. Reply email addresses and account IDs are not included in the issue body, but free text may still identify you.
GitHub privacy statement →International processing
Drachma is operated from the United Kingdom. Our providers may process data outside your country, including outside the EU and the UK. The EU storage locations described above refer to our primary app storage and Sentry error-event storage; they do not mean that all access or processing takes place within the EU. International processing can include support access, service metadata and processing by subprocessors.
Where international-transfer rules apply, transfers require an applicable adequacy decision or other permitted safeguards, such as Standard Contractual Clauses and, where needed, the UK Addendum. Supabase and Sentry describe their transfer arrangements in their Supabase Data Processing Addendum and Sentry Data Processing Addendum.
RevenueCat stores customer data in the United States. Its Data Processing Addendum describes its processing and international-transfer safeguards. You can contact us for information about the safeguards applicable to your data.
6. Data Retention
Your data is retained while your account is active. When you request account deletion, your account enters a 30-day grace period during which you can cancel the request.
After 30 days, your account and active data in Supabase - including transactions, budgets, accounts, categories, settings, attachments and support tickets - are deleted. Limited security logs or encrypted provider backups may remain until their normal retention cycles expire.
Attachments are kept until you delete them or delete your account. A feedback message mirrored to GitHub may remain as issue history after the Supabase ticket is deleted; contact us to request that personal content in a mirrored issue be located and deleted or redacted.
Crash and error reports held by Sentry may be retained for up to 90 days under the configured retention. Resend may retain limited delivery, security and suppression records under its normal service practices.
Subscription records and account deletion
Your Plus access record and purchase-event history in Supabase are retained while your account remains active and are removed when account deletion completes after the 30-day grace period. Cancelling a subscription alone does not delete these records, since they may still be needed to restore purchases or resolve a purchase problem.
When your account is processed for deletion after the 30-day grace period, we automatically request deletion of your RevenueCat customer record and associated subscription data. You do not need to send a separate request. RevenueCat processes deletion asynchronously. If a service failure prevents cleanup, we retry it and retain the information needed to complete the deletion until it succeeds. Contact [email protected] if you need help with a deletion request. Apple and Google may retain their own payment records under their policies and legal obligations. Any separately retained accounting records follow the accounting period stated below.
Account deletion does not cancel an Apple or Google subscription. Cancel it separately in your store's subscription settings to stop future renewals.
Session enquiries that do not lead to a booking are deleted within 6 months of the last correspondence. Booking correspondence and limited session notes are deleted or anonymised within 12 months after the session, unless they are still needed for an active complaint or legal dispute. Sessions are never recorded by us.
Payment and accounting records are kept for at least 5 years after the 31 January tax-return deadline for the relevant tax year, or longer where required by an HMRC enquiry or another legal obligation. These records do not include your full card number.
7. Your Rights
Depending on the law that applies to you, your rights can include access, correction, deletion, portability, restriction, objection and other data-protection rights.
- Access: most account data is visible in the app; contact us for other personal data we hold.
- Export: use the transaction spreadsheet export or full ZIP backup in Settings.
- Correction: edit transactions, categories, accounts and settings in the app.
- Deletion: use Settings → Delete Account or the web deletion page.
- Restriction and objection: where the law provides these rights, you can ask us to restrict or object to qualifying processing.
Contact [email protected] to exercise a right that is not available in-app. We may need to verify your identity. If you are in the EU or EEA, you can also contact our Article 27 representative, named in section 1 above. You may also complain to the UK Information Commissioner's Office or your local data-protection authority.
Drachma does not make decisions about you using solely automated processing that produces legal or similarly significant effects.
8. Data Sharing & Selling
We disclose data to the providers identified above only for the purposes described. We may also disclose data if required by law or where necessary to protect users, our rights or the security of the service.
9. Children's Privacy
Drachma is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
10. Changes to This Policy
We may update this policy from time to time. We will change the “Last updated” date above and, for significant changes, notify users through an appropriate channel such as the app or email.
Contact [email protected].