Ocean Creative ← Back to site
Deft — Legal

Privacy Policy

Deft (formerly Memoney) is a personal finance app for iPhone, built by Ocean Creative LLC, an independent software studio in Pennsylvania. This policy explains what the app keeps on your phone, what our server actually sees, and what we do — and do not do — with any of it.

01

Who we are

Deft is made by Ocean Creative LLC, a limited liability company registered in Pennsylvania, United States. For the purposes of state privacy laws, Ocean Creative LLC is the business responsible for the information described in this policy.

One address reaches us: hello@oceancreative.app. It is read by the person who builds the app.

02

What stays on your device

Deft is built around local storage. The ledger itself — your transactions, amounts, payees, notes, categories, budgets, accounts, and app settings — is written to the app's own storage on your iPhone.

If you use Deft manually, without connecting a bank, there is no sign-up, no password, and no email address on file. Entries you type yourself are not uploaded to us, and we have no way to read them.

Two ordinary exceptions are worth naming. If you have iPhone or iCloud backups enabled, app data may be included in those backups, which are handled by Apple under Apple's terms rather than ours. And if you export or share a file from the app yourself, where it goes from there is up to you.

03

What our server receives

Deft only talks to our server for features that cannot work on the device alone. Today that means bank sync and subscription status. Here is everything that reaches us.

  • A device identifier. On first launch the app generates a random device identifier and an accompanying token, and uses them to authenticate its requests to our API. It is not derived from your hardware, and it is not linked to a name or an email address, because we do not collect either one today. If we ever add real accounts, we will update this policy before doing so.
  • Bank connection records, if you turn on sync: which institution you linked, which accounts are in scope, the state of the connection, and the Plaid access token that authorizes it. The access token is encrypted at rest.
  • Transaction and balance data in transit. When sync runs, the data Plaid returns passes through our server on its way to your iPhone. The copy you actually work with is the one on your device. Anything the server holds exists to operate the sync — delivering it to your phone and avoiding needless re-fetching — and for nothing else.
  • Subscription status from Apple. Apple tells us whether a subscription or trial is active so the app can unlock sync. Apple handles the payment; we never receive your card number, billing address, or Apple ID password.
  • Ordinary server logs. Like any web service, our server records request metadata such as IP address, timestamp, and the endpoint called. We use these for security, abuse prevention, and debugging, and we keep them only for a limited period.

Separately from the app: if you write to us, we have your email address and whatever you chose to put in the message, and we keep the correspondence for as long as it takes to help you and for a reasonable period afterwards.

04

Bank connections and Plaid

Bank sync is part of Deft Plus, our optional paid subscription. It is off unless you turn it on, and Deft works as a manual ledger without it.

When you connect a bank, the connection is made through Plaid Inc., a financial data provider used by a large share of US finance apps. You enter your bank credentials inside Plaid's own interface, and they go to Plaid directly. We never see, receive, or store your bank username, password, security answers, or one-time codes. What comes back to us is an access token that permits reading the accounts you chose, plus the account and transaction data itself.

Plaid is a separate company and its own handling of your information is governed by its policy, which is worth reading: Plaid End User Privacy Policy.

You can disconnect an institution from inside Deft at any time. Doing so removes that connection on our side, including its access token, and sync for those accounts stops.

05

What we do not do

Deft contains no advertising, no advertising identifiers, no third-party analytics SDKs, and no trackers. Nothing in the app reports your behavior to another company.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in California and other state privacy laws. We have not done so in the past twelve months. We do not use your financial data to build marketing profiles or to train machine learning models.

These are commitments, not just current facts. If any of them ever needs to change, we will say so on this page with a new effective date before the change takes effect, and we will ask for your consent where the law requires it.

06

Who we share with

Only the parties that make the app work, and only with what they need:

  • Plaid Inc. — to establish and operate bank connections, if you use sync.
  • Apple Inc. — App Store distribution, and the billing and receipt validation behind subscriptions.
  • Hosting and infrastructure providers that run our sync server, under contracts that limit them to processing data on our instructions.

We may also disclose information if the law requires it — a valid subpoena, court order, or comparable legal process — or if it is necessary to protect our rights or someone's safety. If Ocean Creative LLC were ever sold or merged, information could transfer as part of that transaction, and this policy would continue to apply to it until you were told otherwise.

07

Keeping and deleting data

  • Disconnect a bank. The connection and its access token are removed from our server, and we stop receiving anything from that institution.
  • Delete the app. Your local ledger goes with it. iOS removes the app's storage, the data is not recoverable by us, and we never had a copy of your manual entries in the first place.
  • Ask us to delete server-side records. Email hello@oceancreative.app and we will delete the sync records associated with your device and confirm when it is done. Because we do not hold your name or email, we may need one detail from the app to locate the right records; we will tell you exactly which one, and we will not ask for anything more than that.
  • Server logs expire on a rolling schedule and are not kept indefinitely.

We keep the rest only as long as it is needed to run the service, or longer where a law requires us to.

08

Security

Traffic between the app and our server is encrypted in transit with TLS. Plaid access tokens are encrypted at rest. Access to production systems is limited to the people who operate them, which today is a very short list.

The most useful security property of Deft is architectural rather than procedural: your ledger lives on your phone, so there is no central store of everyone's finances to breach. That said, no method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If a breach ever affects your information, we will notify you as required by law.

09

Your privacy rights

Depending on where you live, state privacy laws — including the California Consumer Privacy Act as amended, and comparable laws in states such as Colorado, Connecticut, Virginia, Texas, and others — give you the right to know what personal information we hold about you, to get a copy of it, to correct it, to have it deleted, and not to be treated differently for exercising any of those rights.

Because we do not sell or share personal information for cross-context behavioral advertising, there is no opt-out for you to exercise; you are welcome to confirm that with us anyway. We do not use your information for profiling that produces legal or similarly significant effects.

To exercise any right, email hello@oceancreative.app. We will respond within the time the applicable law allows, generally forty-five days, and will tell you if we need an extension. You may use an authorized agent, in which case we will ask for reasonable proof of that authority. If we have to decline a request, we will explain why and how you can appeal.

10

Children

Deft is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete it promptly. A parent or guardian who believes a child has provided us information should write to hello@oceancreative.app and we will take care of it.

11

Where data is handled

Deft is offered to users in the United States, and the servers and service providers that support it are located in the United States. If you use the app from elsewhere, you are sending your information to be handled here.

12

Changes to this policy

We may update this policy as the app changes. The effective date at the top always reflects the current version. If a change is material — anything that meaningfully affects what we collect or what we do with it — we will say so in the app or by a notice on this page before it takes effect, and we will not apply it retroactively to information already collected without your consent where consent is required.

13

Contact

Questions about this policy, a deletion request, or anything else about how Deft handles your data:

hello@oceancreative.app
Ocean Creative LLC, Pennsylvania, United States

Companion document — Terms of Service. Both take effect August 1, 2026.