← Steady

Privacy

Effective 23 August 2026

Steady is a quiet money journal. The short version: your ledger is yours, we store only what makes the app work, and nothing is sold or shared for advertising.

What Steady stores

Your account: the email address and name that Google or Apple shares when you sign in.

Your journal: the accounts, transactions, goals, and reminders you create. Your phone keeps the original copy; when you're signed in, a backup is stored on our servers so your journal can follow you to a new phone.

Your devices: turn on SMS capture and we store one key per phone you set it up on, with the name that phone gives itself, so Automatic capture can list them and you can revoke any one. Revoking always stops our server accepting anything more from that key — the phone itself may keep trying to send regardless, and every attempt is simply refused, unread. A revoked key is kept 30 days as the record of what happened, then deleted by an automatic daily job.

Your push address: if you allow notifications, we store the push token Expo issues for that phone. We use it to tell you when a transaction is logged or a capture fails, to send the evening reminder to log your spending, and occasionally a message from us. The transaction-logged notification is not blank: it can show the amount, who it was with, and the balance the text quoted. The capture-failed notification is not blank either: it can name the sender the unreadable text came from. The token goes when your account goes.

SMS capture

SMS capture is optional and off until you set it up. When it's on, the text of money-related SMS alerts (Mobile Money and bank alerts) is sent to our server, parsed into a transaction, and stored together with the original message so you can always check the source.

On Android, filtering happens on your phone — only messages that look like money alerts ever leave the device. On iPhone, the shortcut you install forwards only messages matching money keywords (GHS, GHC). We never see the rest of your inbox.

Stored messages are encrypted and kept for 90 days, then permanently deleted by an automatic daily job. We keep them that long for one reason: when Steady reads a text wrong, or can't read it at all, the only way to fix it is to look at the text itself. The copy your journal keeps of that same text also travels in your backup, and lasts as long as that entry does, not 90 days.

When we do look, we see the message with its numbers masked and most names written in capitals blanked — enough to see the format, not your balance. A name typed in ordinary case is not masked and can still come through. Reading the original words takes a deliberate action, and our system records every time someone does it, with one exception: the failure alert and a matching line in our server logs, both described under Who processes your data. We use this to fix how Steady reads messages, and for nothing else: your messages are not used to train AI models, and are never sold or shared for advertising.

How a message gets read

Most messages are read by pattern rules running on our own servers. When those rules don't recognise a format, the message text and the sender's name are sent to Anthropic's Claude API to be read, and the result comes straight back to your phone. Anthropic processes the message on our behalf and does not use it to train their models.

Revoking a device — the mechanics are described under What Steady stores — keeps anything it still sends out of your journal, and you can always type transactions in by hand instead. To stop the phone itself from forwarding, not just your journal from receiving it: on iPhone, delete the two Messages automations you added; on Android, revoke the device while using that same phone. There's no other off switch anywhere in Steady.

Pasting a text is not a way around it: a pasted message takes the same road as a captured one — read by our rules, sent to Anthropic when our rules cannot read it, and stored encrypted for 90 days under the same masking and the same daily deletion. If you want none of a text on our servers, type the amount in yourself.

Reading a text is automatic; nothing else is

Deciding what a money text says — the amount, the direction, who it was with — is done by software, not by a person, and the entry appears in your journal without anyone approving it. That is the whole point of the app.

Nothing else about you is decided that way. There is no scoring, no profiling, no eligibility or creditworthiness judgement, and no decision with a legal or financial consequence for you: the only output is a line in your own journal, which you can edit or delete like any other. If Steady reads something wrong, tell us and we will fix the reading — the Send feedback thread described below is the fastest route.

What we record about using Steady

So we can tell whether the app is working, we keep a record of the days your app was open, and of changes to your journal — that an entry was added, edited or deleted, whether it came from a text or you typed it in, and when. These records hold no amounts, no notes, no names, and no descriptions of what you spent money on.

They do say which entry changed, though, and your backup holds what that entry says. So when a support or audit question needs the answer, we can open that one entry and read it — the amount, the note, who it was with. It takes a deliberate action, we record every time it happens, and it is one entry at a time rather than a way to read your journal.

The same backup holds the goals you set, and those we can see as a list rather than one at a time: each goal by the name you gave it, the target you chose, what you have put aside against it, and how many times money has moved in or out of it and when it last did. The totals are worked out inside our database, so no individual entry is handed out to show them, and nothing there says what you spent money on. Looking is recorded, the same as opening an entry.

The journal-change records are deleted after 90 days by the same daily job that deletes stored messages. The list of days you opened the app is dates and nothing else, and we keep that for as long as your account exists rather than for 90 days — it goes when your account goes, on the schedule below.

Unlike those records, a message you send us can carry the Steady app version you're running, your phone's operating-system version, and its device model — the app shows you those values before you send, and a bug report is close to unfixable without them. Those values are columns on the feedback thread itself, and follow its deletion schedule, described below.

No bank or Mobile Money logins — Steady never asks for them. No contacts, no location, no advertising trackers, and no profile of you sold to anyone.

When you write to us

Send feedback in Preferences opens a thread. What you type is stored on our servers as you wrote it, unmasked, because the whole point of it is that a person can read it and reply in the same thread.

Your words are not used to train AI models, and they are never sent to Anthropic. We don't show them to anyone outside Steady. The Claude API sees money texts our own rules could not read, as described above.

A thread is kept for 365 days after it is closed, then permanently deleted by an automatic daily job — sooner if you delete your account, on the schedule below. A thread that is still open is never deleted for being old — deleting a conversation you are still having would be worse than keeping it.

Reporting a particular transaction attaches the captured text that entry came from, and nothing else out of your journal: no balances beyond whatever the text itself quotes, no other entries, and no screenshots — the app has no way to attach one.

Cookies and analytics

This website sets no cookies of its own and runs no analytics, advertising or tracking scripts. There is no consent banner because there is nothing to consent to. Our hosting provider records ordinary web-server request logs, as any host does.

The app has no advertising identifiers and no third-party analytics either. What we record about a working app is the short list under What we record about using Steady, and nothing beyond it.

Why we are allowed to hold this

Ghana's Data Protection Act, 2012 (Act 843) is the law that applies to Steady, and it asks us to name a reason for holding each thing. Ours are these.

Your consent, for anything you switch on: SMS capture and notifications are both off until you turn them on, and turning either off withdraws that consent for anything after it — the mechanics are under SMS capture above.

To give you what you signed up for: your account, and the backup that lets your journal follow you to a new phone. Without those there is no service to provide.

Our own legitimate interest, for three narrow things: fixing how Steady reads texts (which is why a stored message is kept for 90 days), keeping the service secure and working, and answering a support or audit question about one account — which can mean opening a single entry from your backup to see what it says, amount and note included, and seeing the goals you set for yourself, each by the name you gave it, with what you have put aside against it. Both of those are deliberate actions and both are recorded every time. None of the three involves selling anything, and none of them builds a profile of you.

Where the law requires something of us, we follow it.

How we keep it safe

Everything travels between your phone and our servers over an encrypted connection. Stored message text is encrypted in the database itself, separately from the rest of the row, and reading the original words takes a deliberate action that is recorded every time — described under SMS capture above.

The largest thing protecting you is what we never ask for. Steady has no bank or Mobile Money login, no card number, no PIN and no one-time code, so there is nothing of that kind here to lose.

No system is perfect, and we would rather say that plainly than list reassuring words. If personal data here is ever exposed, we will tell you and Ghana's Data Protection Commission without undue delay, as Act 843 requires.

Deleting your account

Delete your account in Account & data and it is deactivated immediately. After a 30-day grace period, your account and everything attached to it — your backup, your stored texts, your device keys, your push addresses, and any thread you wrote to us — are permanently erased from our servers. Email us to expedite this.

Who processes your data, and where

Our servers run on cloud hosting providers. Sign-in is handled by Google and Apple. Messages our own rules can't read are read by Anthropic's Claude API, as described above. Push notifications are delivered through Expo, Apple and Google, and a notification can show the amount, who it was with, and the balance the text quoted, as described above. None of them can read your journal for their own purposes.

We also run a private Telegram channel our server posts to, so a signup or sign-in, a broken capture, or a new feedback thread is noticed the same day rather than the same month. Those notes name the account by the email address on it and the provider you signed in with, and carry counts — devices paired, texts captured, how big the backup is. No entries leave the backup this way, but a note can carry the amount and who it was with, and when we cannot read a text at all, it carries the text itself, described below. A new feedback thread's note carries the app version and platform you sent it from, whether it was a general note or a report about one transaction, and the thread's id — it never quotes what you wrote. If you joined the waiting list on the website, that email address went to the same channel and to a Google Sheet.

Several of those companies are outside Ghana — Anthropic, Expo, Google and Apple all process in the United States and elsewhere, and our hosting is not in Ghana either. So using Steady means the things described above leave the country. Each of them handles that data only to do the job we hired them for, under their contract with us, and none may use it for their own purposes.

One of those notes is blunter than the rest: when Steady cannot read a money text at all, the alert carries the text itself, because a format nobody can read has to be seen to be fixed. That is the one time a message is seen unmasked without the recorded reveal described above — the alert, and a matching line in our own server logs, both carrying the same raw text, and only when reading fails.

Your rights, and how to use them

Act 843 gives you rights over what we hold. Here is what each one means in practice, rather than a list of words.

See what we have: your journal is already on your phone, which is the bulk of it. For everything on our servers — your account, your backup, your stored texts, your device keys, your threads to us — email us and we will send it to you.

Correct it: you edit your journal yourself, in the app. Your name and email come from Google or Apple, so those change where you change them there. Anything else, email us.

Delete it: Account & data, described above. You do not need a reason and you do not need to ask us.

Object, or change your mind: turn off SMS capture, turn off notifications, or delete your account. Each stops the thing it names, and none of them costs you the journal on your phone.

Complain: tell us first — we would rather hear it and fix it. If that does not satisfy you, you can take it to Ghana's Data Protection Commission, which supervises us under Act 843, and you do not need our permission to do so.

We answer these ourselves, at the address at the foot of this page, and we do not charge for any of them.

Changes

If this policy changes in a way that matters, we'll say so in the app before the change takes effect.

Contact

Questions or requests: abubakasaddik1@gmail.com