Privacy Policy
Drachma - Last updated: 31 August 2026
Drachma does not sell your information or share it with advertisers or data brokers. It does not contain advertising SDKs or behavioural analytics.
1. Who We Are
Drachma is a personal finance application and related website operated by Stavros Pournias, trading as Agora Studio (getdrachma.app). The app is available on Android and iOS where distributed through app stores or testing programmes.
Stavros Pournias is the controller responsible for the personal data described in this policy.
Business and correspondence address: Suite RA01, 195-197 Wood Street, London, E17 3NU, United Kingdom
Privacy contact: support@getdrachma.app
2. What Data We Collect
Most information Drachma processes is information you choose to provide. Production builds and the services that operate the app also process limited technical, security and crash data.
Account data
- Email address and account identifier required for sign-in
- Authentication and session tokens, managed by Supabase Auth and stored securely on your device
- If you use Google Sign-In or Apple Sign-In: your name and email as provided by those services
Financial data entered by you
- Transaction records: amounts, dates, categories, notes and payment status
- Account balances and account names
- Budget targets and planned income figures
- Recurring payment schedules
- Receivables (money owed to you) and refund records
- Custom categories and display settings
- Attached files you choose to add to transactions, such as receipt photos, bills, PDFs, screenshots and proof-of-purchase documents
- Imported transactions created from bank statement files you choose to open in the app (CSV or PDF). The statement file itself is never uploaded or stored unless you separately attach it to a transaction.
Budget session and payment data
- If you enquire about or book a paid one-to-one budget session, we may process your name, email address, enquiry and booking correspondence, the agreed price, booking details and payment status.
- During a session, we process financial information you voluntarily discuss or show through screen sharing. Only limited notes needed to provide the session and agreed follow-up are retained; screen-shared material is not automatically copied or stored.
- Sessions take place through Google Meet and are never recorded by us.
- Payments for these sessions are processed by Stripe. Stripe may process payment and billing information and transaction metadata. Drachma does not receive or store your full card number.
App settings
- Currency, theme and language preferences
- Fiscal year and budgeting period configuration
- Privacy mode, transaction filter preferences and summary-view preferences
Support and feedback data
- Feedback messages you submit in the app, stored in Supabase as support tickets
- Optional reply email, feedback type, app version, platform and operating-system version
Crash and error data
- In production builds, errors and crash reports may be sent to Sentry
- Reports can include stack traces, app version, platform, operating-system version and technical error context
- We do not intentionally attach your financial records or transaction content to crash reports
Service and security data
- Hosting and infrastructure providers may process IP addresses, request timestamps and technical logs needed to authenticate requests, secure the service, investigate abuse and diagnose failures
3. How We Use Your Data
Your data is used to provide and operate the app and related services, including:
- Authenticating your identity and maintaining your session
- Storing and displaying your financial records across devices
- Calculating budgets, summaries and wealth reconciliation
- Applying recurring payment schedules
- Reading bank statement files you select, on your device, to prepare transactions for review
- Uploading, viewing, sharing, saving and deleting attachments you choose to add
- Generating transaction spreadsheet exports and full ZIP backups on request
- Sending transactional account and security emails, such as account confirmation and password reset/change messages
- Arranging and delivering budget sessions, taking limited working notes and providing agreed follow-up
- Handling support and feedback messages
- Diagnosing and fixing crashes via Sentry
- Administering the service, preventing abuse and resolving security or operational issues
We do not use your financial data for advertising, profiling or unrelated analytics.
Our legal bases
- Contract: to create your account, provide the app features you request, arrange and deliver paid budget sessions, process payments for those sessions, and provide related account or booking communications.
- Legitimate interests: to secure and maintain the service, prevent abuse, diagnose crashes and respond to support or feedback, provided those interests do not override your rights.
- Legal obligations: where processing or disclosure is required by applicable law.
4. How Your Data Is Stored
Financial records and settings are stored on Supabase (PostgreSQL). Attachments are stored in private Supabase Storage paths tied to your user account.
- Row-Level Security: policies restrict authenticated access to records belonging to the signed-in user.
- Encrypted in transit: communication between the app and Supabase uses HTTPS/TLS.
- Encrypted at rest: Supabase encrypts data at rest on the underlying infrastructure.
- On-device protection: the app supports biometric lock and Privacy Mode.
Your device also stores session details, including your email address and authentication tokens, using operating-system secure storage. App preferences and temporary files may be stored locally. Exports and backups are saved only when you request them.
Drachma is not currently end-to-end encrypted. As the service operator, we may have technical access to stored user data through our infrastructure providers. Access is limited to operational purposes such as support, security, service maintenance or legal obligations.
5. Third-Party Services
Drachma uses the following providers and discloses only the data needed for each configured purpose.
Database, authentication and file storage. Financial data, account details and authentication records are stored on Supabase infrastructure.
Supabase privacy policy →Website hosting and delivery. When you visit getdrachma.app, Vercel may process your IP address, approximate location derived from that address, request timestamps, browser or device information, and technical logs needed to deliver, secure and operate the website.
Vercel privacy notice →Transactional app-email delivery. Your email address and delivery metadata may be processed to send account confirmation, password reset or change, and similar account/service messages.
Resend privacy policy →Email hosting for session enquiries and related correspondence sent to or from our @getdrachma.app addresses. Namecheap may process sender and recipient details, message content, attachments and delivery metadata.
Namecheap privacy policy →Payment processing for paid one-to-one budget sessions. Stripe may process your name, email address, billing and payment information, payment status and transaction metadata. Drachma does not receive or store your full card number.
Stripe privacy policy →Crash and error reporting in production builds. Reports may include stack traces, app version, platform, operating-system version and technical error context. We do not intentionally attach financial records or transaction content.
Sentry privacy policy →Optional. If you sign in with Google, your Google account email and name are passed to Supabase Auth to create or match your account.
Google privacy policy →Optional. If you sign in with Apple, your Apple-provided email or relay address is passed to Supabase Auth.
Apple privacy policy →Video calls for one-to-one budget sessions. Google may process your display name or account email if you join while signed in, meeting participation and technical data, and the audio, video or screen content transmitted during the call. Sessions are never recorded by us.
Google privacy policy →Issue tracking for in-app feedback. If you submit feedback, its title, message, type, app version, platform and operating-system version may be mirrored to our issue tracker. Reply email addresses and account IDs are not included in the issue body, but free text may still identify you.
GitHub privacy statement →International processing
These providers may process data outside your country. Where international-transfer rules apply, we use providers subject to applicable data-protection terms and safeguards.
6. Data Retention
Your data is retained while your account is active. When you request account deletion, your account enters a 30-day grace period during which you can cancel the request.
After 30 days, your account and active data in Supabase - including transactions, budgets, accounts, categories, settings, attachments and support tickets - are deleted. Limited security logs or encrypted provider backups may remain until their normal retention cycles expire.
Attachments are kept until you delete them or delete your account. A feedback message mirrored to GitHub may remain as issue history after the Supabase ticket is deleted; contact us to request that personal content in a mirrored issue be located and deleted or redacted.
Crash and error reports held by Sentry may be retained for up to 90 days under the configured retention. Resend may retain limited delivery, security and suppression records under its normal service practices.
Session enquiries that do not lead to a booking are deleted within 6 months of the last correspondence. Booking correspondence and limited session notes are deleted or anonymised within 12 months after the session, unless they are still needed for an active complaint or legal dispute. Sessions are never recorded by us.
Payment and accounting records are kept for at least 5 years after the 31 January tax-return deadline for the relevant tax year, or longer where required by an HMRC enquiry or another legal obligation. These records do not include your full card number.
7. Your Rights
Depending on the law that applies to you, your rights can include access, correction, deletion, portability, restriction, objection and other data-protection rights.
- Access: most account data is visible in the app; contact us for other personal data we hold.
- Export: use the transaction spreadsheet export or full ZIP backup in Settings.
- Correction: edit transactions, categories, accounts and settings in the app.
- Deletion: use Settings → Delete Account or the web deletion page.
- Restriction and objection: where the law provides these rights, you can ask us to restrict or object to qualifying processing.
Contact support@getdrachma.app to exercise a right that is not available in-app. We may need to verify your identity. You may also complain to the UK Information Commissioner's Office or your local data-protection authority.
Drachma does not make decisions about you using solely automated processing that produces legal or similarly significant effects.
8. Data Sharing & Selling
We disclose data to the providers identified above only for the purposes described. We may also disclose data if required by law or where necessary to protect users, our rights or the security of the service.
9. Children's Privacy
Drachma is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
10. Changes to This Policy
We may update this policy from time to time. We will change the “Last updated” date above and, for significant changes, notify users through an appropriate channel such as the app or email.
Contact support@getdrachma.app.