Trust & safety

Security Practices

How the current Cashrou build approaches the protection of your information.

Local-first by current design: Cashrou stores its app records on your iPhone and does not currently operate a Cashrou cloud database or active bank connection.

iOS app sandbox

Cashrou relies on iOS application sandboxing to separate its local app data from other apps.

Device protection

Your passcode, Face ID or Touch ID settings and Apple account protections are important parts of securing access to local Cashrou data.

No bank credentials

The current app does not ask for or store online-banking usernames or passwords.

No advertising trackers

The current documented build does not include advertising tracking or a Cashrou analytics backend.

Local erase controls

Cashrou includes an erase-all-data control in Settings so users can clear local records and reset onboarding.

Roadmap features are not active

Face ID app lock, cloud sync, widgets, bank linking and export tools appear in development planning but should not be assumed active until released.

Your responsibilities

Security limitations

No method of storage or software protection is completely secure. Cashrou cannot guarantee that local data will never be lost, accessed or exposed, particularly if a device is unlocked, compromised, shared, backed up or restored.

Reporting a vulnerability

Send a clear description of the issue to info@xcavargroup.com. Do not access, alter or retain another person’s data, and do not publicly disclose an unresolved vulnerability before allowing a reasonable opportunity to investigate.

Future changes

This page will be updated before Cashrou introduces material online services such as authentication, cloud synchronization, bank connectivity, analytics or remote notifications.