Privacy Policy
This Privacy Policy describes how NIXE Labs (“NIXE Labs”, “we”, “us”, or “our”) handles information in connection with Pico, a personal finance application for iPhone (the “App”).
It is a short policy, because Pico is built so that there is very little to describe. Questions go to nixe.cxt@gmail.com.
The short version
- No account to create. Pico never asks for an email address, phone number or password.
- No servers of ours. We do not receive, store or process your financial data at any point.
- No analytics, no advertising, no tracking. No third-party SDKs are linked into the App.
- One optional permission: Face ID or Touch ID, and only if you switch on App Lock.
- Your data is exportable to a single file, at any time, without asking us.
Who we are (Data Controller)
For the purposes of the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and India’s Digital Personal Data Protection Act, 2023 (DPDP Act), NIXE Labs is the party responsible for this App.
In practice our role is unusually limited. Because the App transmits nothing to us, we do not hold, and cannot produce, any personal data generated by your use of it. Where this policy describes rights of access, correction or deletion, those are exercised by you on your own device rather than by a request to us.
- CONTACTnixe.cxt@gmail.com
- BUNDLE IDnixelabs.Pico
- PLATFORMiOS 26 · iPhone
What Pico stores, and where
Everything you enter into Pico is stored in a local database on your device. It is written by the App and read by the App. The categories of information involved are listed below not because we receive them, but so you know exactly what lives in the file you own.
| What | Examples | Where it lives |
|---|---|---|
| Ledgers and accounts | Book names, account names and types, opening balances, credit limits, the last four digits you choose to record, issuer and card-network labels | On device; mirrored to your iCloud if enabled |
| Transactions | Amount, currency, date, category, account, notes, transfers, refunds, links between entries | On device; mirrored to your iCloud if enabled |
| Plans | Budgets, recurring rules and subscriptions, savings goals, loan and EMI schedules | On device; mirrored to your iCloud if enabled |
| Investments | Holdings, quantities, average cost, and any prices you type in yourself | On device; mirrored to your iCloud if enabled |
| People | Names or labels you add for money lent and borrowed, and which entries relate to them | On device; mirrored to your iCloud if enabled |
| Images you add | An optional picture for an account card, downsized before it is saved | On device; mirrored to your iCloud if enabled |
| Preferences | Base currency, selected book, App Lock on/off, whether you have seen the welcome screens | On device (system preference storage) |
What we collect (nothing)
We collect no personal data through the App. This is not a policy commitment layered on top of a data pipeline; there is no pipeline. The App contains no networking code, so it cannot send anything to us or to anyone else.
| Common in other apps | In Pico |
|---|---|
| User accounts, email, password | Not present. There is nothing to sign up for. |
| Analytics / product telemetry | None. No analytics SDK is linked into the App. |
| Crash and performance reporting | None collected by us. |
| Advertising identifiers, ad networks | None. Pico shows no advertising. |
| Cross-app or cross-site tracking | None. The privacy manifest declares zero tracking domains. |
| Cookies or web beacons | Not applicable. Pico is a native app with no web views for content. |
| Location, contacts, camera, microphone | Never requested. The App declares no such permissions. |
| Push notifications | Pico does not register for or send push notifications. |
Apple requires every App Store app to publish a privacy manifest. Pico’s declares tracking as false, an empty list of tracking domains, and an empty list of collected data types. The only declared API use is the system preference store, for the App’s own settings.
iCloud sync
If you are signed into iCloud on your device, Pico mirrors your books to a private CloudKit database inside your own Apple Account. This is what lets your data appear on a second device and survive a new phone.
What this means for us
A private CloudKit database belongs to the Apple Account holder. NIXE Labs cannot read it, list it, or recover it. We do not receive a copy, a key, or a notification that it exists. If you contact us about a lost book, we will not be able to retrieve it for you, because it was never ours to hold.
What this means for Apple
Apple operates the storage and transport, under the Apple Account terms and Apple’s own privacy policy, the same arrangement that already covers your iCloud Photos or Notes. Turning off iCloud for Pico in iOS Settings stops the mirroring; the App continues to work entirely on device.
Face ID, Touch ID and the App Lock
App Lock is optional and off until you switch it on. When it is on, Pico asks iOS to authenticate you on cold start and whenever the App returns from the background, and it redacts the App Switcher preview so balances are not visible in the multitasking view.
Biometric data is handled entirely by iOS and never reaches the App. Your face or fingerprint template stays in the Secure Enclave; Pico receives only a yes or no. We store no biometric information, and there is nowhere for us to store it. Face ID is the only permission the App ever asks for.
Images you attach
You can attach a picture to an account card. It is chosen through Apple’s system photo picker, which runs outside the App: Pico is handed the single image you selected and is not granted access to your photo library. The image is downsized and stored in your ledger alongside the account, and follows the same path as everything else: your device, and your iCloud if sync is on.
Links that leave the app
Pico carries two outbound links. Both are hand-offs to Safari: the App itself makes no request, which is what keeps the “never our servers” promise literally true.
| Link | Where it goes | What applies there |
|---|---|---|
| “Made with care by nixe.in” on the About screen | nixe.in, our own website | Our website's own terms. It is a static marketing site. |
| The feedback and feature-request board | nixe.canny.io, a public board hosted by Canny | Canny's privacy policy. Anything you post there is public and is governed by their terms, not this one. |
If you choose to file feedback, the App can prepare a short diagnostics line for you to paste in: the App version and build, your iOS version, and the hardware model string such as iPhone17,2. It deliberately does not include the device name (which is usually a person’s own name), any identifier, or anything from your ledger. Nothing is sent automatically; you copy it or you do not.
Exports and backups you create
Pico can write your entire library to a single JSON file: every ledger, account, transaction, budget, recurring rule, savings goal, holding and exchange rate. Where that file goes is entirely your choice: Files, iCloud Drive, AirDrop, email, another app.
Once it leaves the App it is an ordinary document with your financial history in it, unencrypted and readable by anything that can open a text file. Treat it the way you would treat a bank statement. Importing offers a choice of replacing your current data or merging into it; replacing takes a safety copy first.
Retention and deletion
We hold nothing, so we have no retention period to declare. Your data lasts exactly as long as you keep it.
| Action | Effect |
|---|---|
| Delete an entry in the App | It moves to the Recycle Bin and can be restored. |
| Empty the Recycle Bin | The record is permanently removed. This is the App's only irreversible delete. |
| Erase all data in Settings | Your books are cleared on the device, and the deletion propagates through iCloud if sync is on. |
| Delete the App | The local database goes with it. Data already mirrored to your iCloud remains in your Apple Account until you remove it in iOS Settings › your name › iCloud. |
| Ask us to delete your data | There is nothing for us to delete. We never received any. |
Your rights
Under the GDPR, the UK GDPR, the CCPA/CPRA and the DPDP Act you have rights of access, correction, deletion, portability and objection, among others. Because your data never reaches us, these are satisfied directly and immediately inside the App rather than by a request to a company.
| Right | How it is met |
|---|---|
| Access | Every record is visible in the App, on your device, at all times. |
| Portability | Export the whole library to a JSON file whenever you want. |
| Correction | Edit any record directly. |
| Deletion | Delete records, empty the Recycle Bin, erase all data, or delete the App. |
| Objection / restriction of processing | There is no processing by us to object to. |
| Opt out of sale or sharing | We do not sell or share personal information, and have none to sell. |
| Non-discrimination | Pico is free and has no in-app purchases. There is no worse tier to be moved to. |
If you believe we have handled something wrongly you may complain to your local supervisory authority. In India that is the Data Protection Board; in the EU or UK it is your national data protection authority. We would rather you wrote to us first at nixe.cxt@gmail.com.
Children
Pico is a general-audience budgeting tool and is not directed at children. We do not knowingly collect personal information from anyone, children included, since we collect none at all. If a child uses the App on a family device, their entries stay on that device and in that Apple Account under the same terms as anyone else’s.
Security
The App relies on the protections iOS already provides, and adds one of its own.
- Device encryption. Your database sits in the App's sandbox container, encrypted at rest by iOS whenever the device is locked with a passcode.
- Sandboxing. No other app can read Pico's storage.
- App Lock. Optional Face ID, Touch ID or passcode gate on launch and on return from the background, with the App Switcher preview redacted.
- No attack surface in transit. There is no network traffic to intercept, no API key inside the binary, and no server of ours to breach.
- Transport for sync. Handled by Apple's CloudKit, encrypted in transit and at rest under your Apple Account.
No system is perfect, and the honest limit is worth stating: if someone can unlock your phone, they can open Pico unless you have turned App Lock on, and an export file you have saved somewhere is only as protected as the place you saved it.
Changes to this policy
If Pico ever gains a feature that changes any of the above, such as a licensed price feed or an optional service that needs a network call, we will update this policy before that feature ships, change the “last updated” date, and describe the change in plain terms rather than burying it. A feature that would send your financial data anywhere would be opt-in and explained at the point you turn it on.
A financial coach is planned for a future release. As designed, it runs on Apple’s on-device models and performs no network calls, so it would not change this policy; if that design changes, this section is where you will read about it first.
Contact
Questions, corrections, or anything on this page that does not match what you observe in the App:
- EMAILnixe.cxt@gmail.com
- WEBnixe.in
This policy is written to be understood, and to be checkable against the App itself. It is provided for transparency and is not legal advice. It is intended to meet the requirements of the GDPR, UK GDPR, CCPA/CPRA and India’s DPDP Act, 2023.