Privacy Policy
Last updated: 17 August 2026
This Privacy Policy explains how the mobile application Horizn Spica: Budget Planner ("Spica", "the app", "we"), published under the Horizn brand, handles your information.
In short: Spica is an offline-first budgeting app. It has no user accounts and no server of ours. Your budgeting data stays on your device, encrypted. The only information that leaves your device is what is strictly needed to process a subscription purchase (handled by Apple and RevenueCat), the message you choose to send, and a diagnostic block shown before sending (SID, app version/build, platform, and OS version). We do not run ads, analytics, tracking, or a crash reporter, and we do not sell your data.
1. Who is responsible for your data
The data controller for the limited processing described below is the developer of Horizn Spica: Budget Planner:
- Developer (data controller): Sławomir Dyduch, a sole proprietor (Polish jednoosobowa działalność gospodarcza) trading under the business name "Sławomir Dyduch" (a "trader" for DSA purposes)
- Address: Mazańcowice 73, 43‑391 Mazańcowice, Poland
- Tax ID (NIP): 9372581357 · REGON: 243568459
- Contact: info@horizn.world (technical support: help@horizn.world)
Because Spica stores your budgeting data only on your device and we operate no backend, we cannot access, read, or recover that data. For the parts that do involve third parties (purchases), those providers act as described in Section 5.
2. Data stored on your device only
The following stays on your device and is never sent to us:
- Financial and budgeting data — transactions, budgets, goals, plans, missions, categories and related settings. This data is stored encrypted (AES‑256) with a key held in the device Secure Enclave / Keychain (iOS Keychain), and protected by an integrity check.
- Attachments — any photo you attach to a transaction, kept inside the app's private storage area (sandbox).
- Access code (PIN) and security settings — if you set a PIN, only a salted, one‑way hash is stored (never the PIN itself). Biometric unlock (Face ID) is handled by the operating system; we never receive your biometric data.
3. Data that leaves your device
Spica transmits information only in these cases:
- Subscription purchases — see Section 5. Handled by Apple and RevenueCat.
- Feedback you send us — the app can open your device's email client with a
pre‑filled message to help@horizn.world. Before sending, it shows and
automatically appends a diagnostic block containing the SID, app version and
build number, platform, and OS version. The block contains no budgeting data
or PIN. The email is sent by your email provider, not by us, and you can
review and edit the entire message before sending. We use the feedback and
diagnostics only to respond, correlate reports from the same installation,
and improve the app. The SID is a cryptographically random token generated on
the device (for example
HRZN‑AB12‑CD34); it remains stable for that installation and disappears when you uninstall the app or use "Delete all data". - System device backup (iCloud) — if you have iCloud Backup enabled in iOS, the operating system may include Spica's on‑device data in your personal device backup. This backup is controlled by you and Apple, under Apple's terms; we have no access to it.
4. Permissions we request, and why
Spica asks for a permission only at the moment a feature needs it, and each feature works without it where possible:
- Camera — to take a photo to attach to a transaction.
- Photo library — to attach an existing photo to a transaction.
- Face ID / biometrics — to confirm your identity when unlocking the app or resetting your PIN. Biometric matching happens in the operating system; we receive only a success/failure result.
- Notifications — to show local reminders (e.g. upcoming bills) that are scheduled on your device. Spica does not use a push server.
You can change or revoke any of these in iOS Settings at any time.
5. Subscriptions (In‑App Purchases)
Spica offers an optional Pro subscription. Purchases are processed by Apple through the App Store, and subscription status is managed on our behalf by RevenueCat, Inc.
- Apple processes your payment and manages the subscription tied to your Apple Account. We never receive your payment card details. See Apple's Privacy Policy: https://www.apple.com/legal/privacy/.
- RevenueCat receives the purchase information needed to determine and restore your subscription entitlement — for example an anonymous app‑user identifier, purchase receipts, subscription status and history, and technical data such as device/OS type and IP address (used to infer approximate region). RevenueCat acts as our processor. See RevenueCat's Privacy Policy: https://www.revenuecat.com/privacy/.
We use this information only to (a) unlock Pro features you paid for, (b) restore your purchase on the same or a second device using the same Apple Account, and (c) handle renewals, cancellations, expiration, refunds, billing retries and grace periods. You can manage or cancel the subscription any time in the App Store: https://apps.apple.com/account/subscriptions.
6. What we do NOT do
- No user accounts, no sign‑in, no backend of ours.
- No advertising and no ad networks.
- No third‑party analytics or usage tracking, and no App Tracking Transparency prompt, because we do not track you.
- No crash‑reporting SDK.
- We do not sell, rent, or share your personal data.
7. Legal basis and your rights (EEA/UK — GDPR)
Where GDPR applies, our limited processing relies on:
- Performance of a contract — to provide the Pro subscription you buy (Section 5).
- Legitimate interests — to answer support messages you send us and to keep the app secure and working.
You have the rights of access, rectification, erasure, restriction, objection and portability. In practice:
- For the data on your device: you are in full control. Use "Delete all data" in the app (Profile → Danger zone) to erase everything locally, or uninstall the app.
- For subscription data held by Apple/RevenueCat: exercise your rights through Apple and RevenueCat using the links above, or contact us and we will help.
You also have the right to lodge a complaint with your local supervisory authority (in Poland: the President of the Personal Data Protection Office, UODO).
8. Data retention and deletion
We keep no copy of your data. On‑device data lives until you delete it (via "Delete all data") or uninstall the app. Purchase records held by Apple and RevenueCat are retained under their respective policies for as long as needed for subscription management, accounting and legal obligations.
9. Children
Spica is a personal‑finance tool intended for adults and is not directed to children under 16. We do not knowingly collect data from children.
10. International transfers
If you use the subscription features, Apple and RevenueCat may process the related data on servers outside your country, including the United States, under the safeguards described in their privacy policies.
11. Changes to this policy
If we change how the app handles data, we will update this page and its "Last updated" date, and — for material changes — surface a notice in the app.
12. Contact
Questions about this policy or your data: info@horizn.world.