Worthwhile · Public policy

Privacy policy

Worthwhile is designed so that its developer does not need to receive your financial records. This policy explains what the app processes locally, what leaves the app only at your direction, and the limited information involved if you visit this website or contact the publisher.

Effective and last updated:
App: Worthwhile · Publisher: Tobiashii

The short version

Worthwhile has no user accounts, bank connection, cloud sync, advertising, analytics, telemetry, or financial-data upload service. Financial records are processed and saved locally on your device. The developer does not receive your balances, account names, notes, backups, passcode, or biometric information.

1. Who and what this policy covers

Worthwhile is an independently published local-first net worth tracker for web, Android, and iPhone. It is published under the developer name Tobiashii. This policy covers the Worthwhile app and this public information site.

Worthwhile is a record-keeping tool, not a bank, financial adviser, investment service, or credit provider. It does not connect to financial institutions or execute transactions.

2. Information processed locally

You may choose to enter and store information including:

  • asset and debt account names, categories, balances, dates, and notes;
  • dated snapshots and calculated net-worth history;
  • account status, inclusion, archive, and display preferences;
  • undo and redo history and automatic safety copies;
  • currency, theme, reminder, dashboard, and app-lock settings; and
  • encrypted backup files or deliberately unencrypted CSV exports you create.

The app processes this information on your device to display, calculate, search, edit, compare, export, and restore your tracker. Tobiashii does not receive this information.

3. Collection, sharing, advertising, and tracking

Worthwhile does not create a developer-controlled account or transmit financial records to a Worthwhile server. It does not sell or share your financial information and contains no advertising, cross-app tracking, analytics, crash-reporting, or telemetry SDK.

Production web builds block app-initiated network connections. The Android app does not request the Android Internet permission. Opening this public privacy policy is a deliberate navigation to GitHub Pages and does not attach tracker records to the request.

4. Storage and encryption

Android and iPhone

Saved tracker state is encrypted at rest using AES-256-GCM. The encryption key is protected by Android Keystore or iOS Keychain and is not stored in the tracker database or portable backups.

Web app

Tracker data is stored in the browser's IndexedDB storage. If the optional encrypted browser vault is enabled, saved state is encrypted using AES-256-GCM with a key derived from the vault passphrase. Without the vault, Worthwhile relies on browser-profile security and device-disk encryption rather than adding app-level encryption.

While the app is unlocked

Values must be decrypted in device memory while Worthwhile displays or edits them. Device access, operating-system updates, screen security, and backups therefore remain important.

5. Device features and permissions

  • Biometrics: when enabled, Android or iOS performs the biometric check. Worthwhile receives only the success or failure result and never receives biometric data.
  • Passcode: the app does not store the passcode itself. It stores a salted, computationally hardened verifier; mobile lock settings are held inside encrypted app state.
  • Notifications: optional update reminders are scheduled locally by the operating system. Notification text contains no balances or account details.
  • Files: file access is used only when you choose to save, share, import, or restore a backup or export.
  • App state: foreground and background state is used locally for app locking.

6. Backups, imports, and exports

Encrypted .worthwhile backups use a passphrase chosen by you. The passphrase is not stored and cannot be recovered by Tobiashii. Automatic safety copies stay within app storage.

CSV exports are deliberately unencrypted and are labelled as such before creation. Any file you save, share, copy, upload, or import is then subject to the security and privacy practices of the location or service you choose. Worthwhile does not automatically upload these files.

7. Retention and deletion

App data remains on your device until you change or delete it, use Erase all data, clear the browser's site data, or uninstall the app. Worthwhile also provides controls to delete individual snapshots and automatic safety copies.

Erase all data removes the local tracker, snapshots, account notes, safety copies, undo and redo history, reminder schedule, app-lock settings, Worthwhile preferences, and the Android Keystore or iOS Keychain encryption key, then returns the app to first-launch setup. Because Tobiashii does not hold a server copy, there is no developer-held financial account or cloud record to delete.

Files exported outside Worthwhile remain wherever you placed them and must be deleted through that device, storage provider, or recipient.

8. This public website and GitHub

This site is hosted by GitHub Pages. It contains no Worthwhile analytics, advertising, cookies, forms, or tracking scripts. When you visit it, GitHub may process ordinary web-request information, such as an IP address, browser details, and request time, under the GitHub General Privacy Statement.

If you submit a GitHub enquiry, GitHub processes your GitHub account information and message. A normal issue may be publicly visible. Tobiashii uses enquiry information only to understand and respond to the request or to improve this policy and Worthwhile.

9. Third-party software and platform services

Worthwhile uses React, Capacitor, browser storage APIs, and operating-system services needed to run the app. The included Capacitor plugins provide app lifecycle, file, browser, local-notification, and native platform integration. Worthwhile does not configure these components to transmit financial records to Tobiashii.

Your operating system, browser, app store, device-backup provider, or a service you deliberately use to store or share an export may process information independently under its own terms and privacy policy.

10. Children

Worthwhile is not directed to children and does not knowingly collect children's personal information. The app does not create user accounts or operate a service that receives tracker records.

11. Changes to this policy

This policy will be updated when Worthwhile's features, permissions, storage, hosting, or data-handling practices materially change. The effective date at the top will be revised, and the public Git history provides an additional record of changes.

12. Privacy contact

Use the Worthwhile privacy enquiry form for questions about this policy or the app's data handling. No personal email address is published or required.

Open a privacy enquiry on GitHub

GitHub issues may be public. Do not include balances, account names, backup files, passcodes, contact details, or any other personal or financial information. For a sensitive security vulnerability, use the repository's private vulnerability-reporting option instead.