PICO · LEGAL

Privacy Policy

EFFECTIVE27 August 2026
LAST UPDATED27 August 2026

This Privacy Policy describes how NIXE Labs (“NIXE Labs”, “we”, “us”, or “our”) handles information in connection with Pico, a personal finance application for iPhone (the “App”).

It is a short policy, because Pico is built so that there is very little to describe. Questions go to nixe.cxt@gmail.com.

SECTION 01

The short version

In one paragraph
Pico has no user accounts and no backend. It makes no network requests of any kind. Your financial records are stored on your device. If you are signed into iCloud they are also mirrored to your own private iCloud database, which we cannot read. We operate no servers for this App, we receive no data from it, and there is no analytics, advertising or tracking software inside it.
  • No account to create. Pico never asks for an email address, phone number or password.
  • No servers of ours. We do not receive, store or process your financial data at any point.
  • No analytics, no advertising, no tracking. No third-party SDKs are linked into the App.
  • One optional permission: Face ID or Touch ID, and only if you switch on App Lock.
  • Your data is exportable to a single file, at any time, without asking us.
SECTION 02

Who we are (Data Controller)

For the purposes of the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and India’s Digital Personal Data Protection Act, 2023 (DPDP Act), NIXE Labs is the party responsible for this App.

In practice our role is unusually limited. Because the App transmits nothing to us, we do not hold, and cannot produce, any personal data generated by your use of it. Where this policy describes rights of access, correction or deletion, those are exercised by you on your own device rather than by a request to us.

  • CONTACTnixe.cxt@gmail.com
  • BUNDLE IDnixelabs.Pico
  • PLATFORMiOS 26 · iPhone
SECTION 03

What Pico stores, and where

Everything you enter into Pico is stored in a local database on your device. It is written by the App and read by the App. The categories of information involved are listed below not because we receive them, but so you know exactly what lives in the file you own.

WhatExamplesWhere it lives
Ledgers and accountsBook names, account names and types, opening balances, credit limits, the last four digits you choose to record, issuer and card-network labelsOn device; mirrored to your iCloud if enabled
TransactionsAmount, currency, date, category, account, notes, transfers, refunds, links between entriesOn device; mirrored to your iCloud if enabled
PlansBudgets, recurring rules and subscriptions, savings goals, loan and EMI schedulesOn device; mirrored to your iCloud if enabled
InvestmentsHoldings, quantities, average cost, and any prices you type in yourselfOn device; mirrored to your iCloud if enabled
PeopleNames or labels you add for money lent and borrowed, and which entries relate to themOn device; mirrored to your iCloud if enabled
Images you addAn optional picture for an account card, downsized before it is savedOn device; mirrored to your iCloud if enabled
PreferencesBase currency, selected book, App Lock on/off, whether you have seen the welcome screensOn device (system preference storage)
Note on people you record
If you record a name for someone you lent money to, that is another person’s information sitting in your ledger. It never leaves your device or your iCloud, but you are the one deciding to write it down, so please use whatever label you are comfortable keeping.
SECTION 04

What we collect (nothing)

We collect no personal data through the App. This is not a policy commitment layered on top of a data pipeline; there is no pipeline. The App contains no networking code, so it cannot send anything to us or to anyone else.

Common in other appsIn Pico
User accounts, email, passwordNot present. There is nothing to sign up for.
Analytics / product telemetryNone. No analytics SDK is linked into the App.
Crash and performance reportingNone collected by us.
Advertising identifiers, ad networksNone. Pico shows no advertising.
Cross-app or cross-site trackingNone. The privacy manifest declares zero tracking domains.
Cookies or web beaconsNot applicable. Pico is a native app with no web views for content.
Location, contacts, camera, microphoneNever requested. The App declares no such permissions.
Push notificationsPico does not register for or send push notifications.

Apple requires every App Store app to publish a privacy manifest. Pico’s declares tracking as false, an empty list of tracking domains, and an empty list of collected data types. The only declared API use is the system preference store, for the App’s own settings.

SECTION 05

iCloud sync

If you are signed into iCloud on your device, Pico mirrors your books to a private CloudKit database inside your own Apple Account. This is what lets your data appear on a second device and survive a new phone.

What this means for us

A private CloudKit database belongs to the Apple Account holder. NIXE Labs cannot read it, list it, or recover it. We do not receive a copy, a key, or a notification that it exists. If you contact us about a lost book, we will not be able to retrieve it for you, because it was never ours to hold.

What this means for Apple

Apple operates the storage and transport, under the Apple Account terms and Apple’s own privacy policy, the same arrangement that already covers your iCloud Photos or Notes. Turning off iCloud for Pico in iOS Settings stops the mirroring; the App continues to work entirely on device.

Sync is not a backup
iCloud copies your changes to your other devices, deletions included. If you delete something and empty the Recycle Bin, it goes on every device. The only true undo is a file you exported yourself, which is why Pico prompts you about this on the first run and again in Settings.
SECTION 06

Face ID, Touch ID and the App Lock

App Lock is optional and off until you switch it on. When it is on, Pico asks iOS to authenticate you on cold start and whenever the App returns from the background, and it redacts the App Switcher preview so balances are not visible in the multitasking view.

Biometric data is handled entirely by iOS and never reaches the App. Your face or fingerprint template stays in the Secure Enclave; Pico receives only a yes or no. We store no biometric information, and there is nowhere for us to store it. Face ID is the only permission the App ever asks for.

SECTION 07

Images you attach

You can attach a picture to an account card. It is chosen through Apple’s system photo picker, which runs outside the App: Pico is handed the single image you selected and is not granted access to your photo library. The image is downsized and stored in your ledger alongside the account, and follows the same path as everything else: your device, and your iCloud if sync is on.

SECTION 09

Exports and backups you create

Pico can write your entire library to a single JSON file: every ledger, account, transaction, budget, recurring rule, savings goal, holding and exchange rate. Where that file goes is entirely your choice: Files, iCloud Drive, AirDrop, email, another app.

Once it leaves the App it is an ordinary document with your financial history in it, unencrypted and readable by anything that can open a text file. Treat it the way you would treat a bank statement. Importing offers a choice of replacing your current data or merging into it; replacing takes a safety copy first.

SECTION 10

Retention and deletion

We hold nothing, so we have no retention period to declare. Your data lasts exactly as long as you keep it.

ActionEffect
Delete an entry in the AppIt moves to the Recycle Bin and can be restored.
Empty the Recycle BinThe record is permanently removed. This is the App's only irreversible delete.
Erase all data in SettingsYour books are cleared on the device, and the deletion propagates through iCloud if sync is on.
Delete the AppThe local database goes with it. Data already mirrored to your iCloud remains in your Apple Account until you remove it in iOS Settings › your name › iCloud.
Ask us to delete your dataThere is nothing for us to delete. We never received any.
SECTION 11

Your rights

Under the GDPR, the UK GDPR, the CCPA/CPRA and the DPDP Act you have rights of access, correction, deletion, portability and objection, among others. Because your data never reaches us, these are satisfied directly and immediately inside the App rather than by a request to a company.

RightHow it is met
AccessEvery record is visible in the App, on your device, at all times.
PortabilityExport the whole library to a JSON file whenever you want.
CorrectionEdit any record directly.
DeletionDelete records, empty the Recycle Bin, erase all data, or delete the App.
Objection / restriction of processingThere is no processing by us to object to.
Opt out of sale or sharingWe do not sell or share personal information, and have none to sell.
Non-discriminationPico is free and has no in-app purchases. There is no worse tier to be moved to.

If you believe we have handled something wrongly you may complain to your local supervisory authority. In India that is the Data Protection Board; in the EU or UK it is your national data protection authority. We would rather you wrote to us first at nixe.cxt@gmail.com.

SECTION 12

Children

Pico is a general-audience budgeting tool and is not directed at children. We do not knowingly collect personal information from anyone, children included, since we collect none at all. If a child uses the App on a family device, their entries stay on that device and in that Apple Account under the same terms as anyone else’s.

SECTION 13

Security

The App relies on the protections iOS already provides, and adds one of its own.

  • Device encryption. Your database sits in the App's sandbox container, encrypted at rest by iOS whenever the device is locked with a passcode.
  • Sandboxing. No other app can read Pico's storage.
  • App Lock. Optional Face ID, Touch ID or passcode gate on launch and on return from the background, with the App Switcher preview redacted.
  • No attack surface in transit. There is no network traffic to intercept, no API key inside the binary, and no server of ours to breach.
  • Transport for sync. Handled by Apple's CloudKit, encrypted in transit and at rest under your Apple Account.

No system is perfect, and the honest limit is worth stating: if someone can unlock your phone, they can open Pico unless you have turned App Lock on, and an export file you have saved somewhere is only as protected as the place you saved it.

SECTION 14

Changes to this policy

If Pico ever gains a feature that changes any of the above, such as a licensed price feed or an optional service that needs a network call, we will update this policy before that feature ships, change the “last updated” date, and describe the change in plain terms rather than burying it. A feature that would send your financial data anywhere would be opt-in and explained at the point you turn it on.

A financial coach is planned for a future release. As designed, it runs on Apple’s on-device models and performs no network calls, so it would not change this policy; if that design changes, this section is where you will read about it first.

SECTION 15

Contact

Questions, corrections, or anything on this page that does not match what you observe in the App:

This policy is written to be understood, and to be checkable against the App itself. It is provided for transparency and is not legal advice. It is intended to meet the requirements of the GDPR, UK GDPR, CCPA/CPRA and India’s DPDP Act, 2023.