Privacy policy
Effective 24 September 2026
In short: your records never leave your phone unless you back them up or export
them yourself. There is no account, no ads, no analytics and no crash reporting. The one exception
is contributions: if you open the contribution jar, our payment provider RevenueCat loads the
prices and processes any contribution you choose to make.
Who we are
WhereItWent is developed by Lockin Technologies (“we”, “us”). For any privacy question or request,
email support@lockinapp.org.
Your records stay on your device
Everything you enter (expenses, income, accounts, categories, budgets, scheduled records, notes
and settings) is stored in a database on your phone. We have no server, and we never receive, see
or store this data.
- Backups and exports. If you create a backup or a CSV export, the app writes the
file on your phone to the place you pick, such as a folder, a files app or a cloud drive. What
happens to it next is up to you and that service.
- Phone backups. On Android, the app opts out of automatic backup and
device-to-device transfer, so your records are not copied to your Google account. On iPhone
and iPad, your records are part of the device backup you make to iCloud or to a computer, like
any other app’s data. That backup belongs to your Apple account; we never see it.
- Passcode. If you set a passcode, it is stored only on your phone, as a hash
in the system’s secure storage.
Contributions (in-app purchases)
You can leave an optional contribution as a thank-you. Every feature is free either way.
Contributions are paid through Google Play or the Apple App Store and processed by
RevenueCat, Inc., which confirms the purchase
with the store for us. RevenueCat acts as our service provider and receives:
We use this only to process contributions. We never sell it, and never use it for advertising
or tracking. Your payment details (card, billing address) go to Google or Apple, never to us
or RevenueCat. See the Google privacy policy
and the Apple privacy policy.
The app does not contact RevenueCat until you first open the contribution jar. From then on it
connects each time the app starts, to load prices and finish any purchase that was interrupted.
That request includes the random app user ID and the device information above, even if you never
buy anything.
What we do not do
- No accounts or sign-in.
- No advertising, and no advertising ID.
- No analytics, crash reporting or tracking SDKs.
- No selling or sharing of personal data.
Keeping and deleting your data
- On your phone: Settings → Backup → Delete all data removes your records, or
uninstall the app to remove everything. On iPhone and iPad, a passcode left in the system
keychain after an uninstall is erased the next time the app is installed and opened.
- With RevenueCat: purchase records are kept as long as needed for accounting
and legal obligations. To ask us to delete them, email us with the order number from your
Google Play or App Store receipt, so we can find the right record.
To request deletion of the data RevenueCat holds for WhereItWent:
- Email support@lockinapp.org
with the subject “WhereItWent data deletion”.
- Include the order number from your receipt, if you made a contribution: from Google Play it
starts with “GPA.”; from the App Store it is the order ID in Apple’s receipt email.
- We delete the random app user ID and device information linked to that installation within
30 days and confirm by email. Purchase records needed for tax and accounting are kept for as
long as the law requires, then deleted.
Children
WhereItWent is not directed at children under 13, and we do not knowingly collect data from
them.
Changes
If this policy changes, we will update this page and its effective date.