Privacy Policy
Qirsh helps groups of travelers track and split shared expenses. It is built so that your trip data lives on your device and in your own iCloud account — not on any server we operate. This policy explains exactly what that means, what device permissions the app uses, and how the optional subscription is handled.
On this page
1. At a glance
Qirsh does not collect analytics, telemetry, advertising identifiers, or any personal data on servers we operate. We do not run any server that stores your trips. There are no user accounts to create — the app uses your device's own iCloud identity. Your trips, expenses, receipt photos, and travelers are stored on your device and, if you have iCloud enabled, synced through your own private iCloud database, which only you (and people you explicitly invite to a shared trip) can access. The limited cases where information leaves your device — Apple's iCloud and geocoding services, public reference data, and anything you choose to export or share — are described below.
2. On-device processing & AI
Qirsh's optional AI features run entirely on your device:
- Speak an expense. When you dictate an expense, audio is transcribed on-device and turned into an editable draft. The audio is used momentarily and is not saved after the draft is produced.
- Scan a receipt. A photographed or selected bill is read on-device to pre-fill an expense draft.
- Ask. Natural-language questions about your trip ("How much did we spend on food?") are answered on-device. In the default "Exact" mode, the AI only interprets your question and the app computes the money figures in ordinary code; an optional "Conversational" mode lets the AI compose the answer itself. Either way, all processing happens on your device.
The on-device AI is powered by machine-learning model files that the app downloads once (see Network activity) and then runs locally. Your voice, photos, expense text, and questions are processed on your device and are not transmitted to us or to any third party for AI processing.
3. What we collect
Nothing on our servers. The app does not integrate analytics SDKs, crash-reporting SDKs, advertising SDKs, or attribution SDKs. We do not maintain user accounts, and we do not ask for your name, email, phone number, or any identifying information. The information you enter — trip names, travelers, amounts, currencies, receipt photos, places — is stored on your device and in your own iCloud, described next.
4. iCloud & shared trips
If iCloud is enabled on your device, Qirsh uses Apple's CloudKit to sync your trips across your own devices and to power shared trips. This works entirely within Apple's iCloud infrastructure under your Apple Account:
- Your data stays in your iCloud. Trips, expenses, receipt photos, and travelers are stored in your private iCloud database. We operate no server in this path and have no ability to read, copy, or inspect your data.
- Shared trips. When you share a trip, Qirsh creates an Apple CloudKit share so the specific people you invite can view that trip. New participants default to view-and-download only; you may optionally grant a participant permission to submit expenses. Only the trip you share is shared — not your other trips. You can stop sharing or remove a participant at any time, and a participant can leave a shared trip themselves. When access is removed, iCloud stops syncing that trip to that person and removes the shared copy from their devices; removing access does not affect your own copy.
- What the people you invite can see. A participant in a shared trip can see that trip's contents (expenses, amounts, travelers, and any receipt photos attached to it). Share a trip only with people you intend to give this access.
- If you don't use iCloud. Qirsh still works fully — your trips simply stay on that one device with no cross-device sync, and shared trips (which rely on iCloud) are unavailable until you enable it.
Apple's handling of iCloud data is governed by Apple's Privacy Policy.
5. Camera, photos, microphone, location & notifications
Qirsh requests these device permissions only when you use the related feature, and only for that purpose:
- Microphone — to let you add an expense or ask a question by speaking. Audio is processed on-device and not retained after the draft or answer is produced.
- Camera — to photograph a receipt when adding an expense.
- Photo Library — to let you pick an existing receipt photo. Qirsh accesses only the photo you choose.
- Location (while using the app) — if you allow it, Qirsh tags a captured expense with the nearby place (for example, "Cairo") so you can ask location-based questions. Location is read only at the moment of capture, is never tracked in the background, and if you decline the app simply leaves the place blank. Only the resolved place name — not your coordinates — is stored with the expense; Qirsh does not keep your GPS coordinates or send them to us. (Turning coordinates into a place name uses Apple's geocoding service — see Network activity.)
- Notifications (optional) — if you turn them on, Qirsh schedules local reminders and alerts on your device: a trip-start reminder, Budget 80% / 100% alerts, and (for shared trips) a heads-up when a traveler submits an expense for your review. These are generated on-device from your own trip data and are never sent to us or anyone else. Because alert text may show an amount or trip name, it can appear on your Lock Screen; you can turn notifications off in iOS Settings or in the app at any time.
Receipt photos and place tags are stored with the expense on your device and in your private iCloud — the same as any other expense detail.
6. Network activity
Qirsh works offline for everyday use. The app makes network requests only in these situations:
- One-time AI model download. If you choose to enable on-device AI, the app downloads the model files it needs over Wi-Fi from a public model host (
huggingface.co). No identifiers or account information are sent beyond what a standard HTTPS file download includes. - Resolving a place name. When you allow location and capture an expense on the spot, Qirsh asks Apple's geocoding service to turn the device's current coordinates into a nearby place name (for example, "Cairo"). Only the place name is kept with your expense; the coordinates are sent to and handled by Apple under Apple's Privacy Policy, and are not stored by Qirsh or sent to us.
- Currency exchange rates. To show an approximate "≈ home currency" conversion, the app fetches public reference rates from
open.er-api.com(with a fallback tocdn.jsdelivr.net). These requests are keyless and send no personal data — only the standard information any HTTPS request includes, such as your IP address, which the rate provider handles under its own policy. Exchange rates are for display only and never change your recorded amounts or who-owes-whom math. - iCloud sync. When iCloud is enabled, syncing and shared trips communicate with Apple's iCloud/CloudKit service under your Apple Account. We do not see this traffic.
- Subscription actions. If you purchase, restore, or manage a subscription, the app communicates with Apple's StoreKit service — see Subscriptions.
- Tapping an external link. If you tap a link in the app (for example, this policy), your browser opens the destination. That request is handled by your browser and the destination server, not by Qirsh.
Beyond these, the app performs no background network activity and sends no analytics.
7. Widgets, exporting & other integrations
- Home-screen widget. If you add Qirsh's widget, the app writes a small summary of your active trip (its balance, spend, and budget figures) to a private on-device app-group container that only Qirsh and its widget can read. Nothing is sent off your device. Because a widget can be shown on your Home Screen or Lock Screen, these trip figures may be visible there — remove the widget if you'd rather they weren't.
- Exporting or sharing a trip. From a trip's Manage screen you can export it as a CSV spreadsheet or a text summary and share it using the system share sheet. When you do, that trip's details leave Qirsh and go to the destination you choose — another app, Files, or a person you send it to. From that point the data is handled by that destination, not by Qirsh.
- Siri & Shortcuts. Qirsh offers a "Log an expense" action to Siri, the Shortcuts app, Spotlight, and the Action button. Using it simply opens the app's capture screen — no expense data is sent to us. When you trigger it through Siri, your interaction with Siri is handled by Apple under Apple's Privacy Policy.
8. Subscriptions
If Qirsh offers a Pro subscription, it is sold as an auto-renewing in-app purchase through Apple's system. The subscription is purchased, billed, renewed, and cancelled entirely through your Apple Account; we do not receive your name, email, credit-card details, billing address, or Apple Account ID. When you subscribe, the app receives from Apple only an anonymous purchase receipt indicating whether you have an active Pro entitlement — it contains no personally identifying information. Its exact length and price are shown on the purchase screen before you buy, and it renews automatically unless you turn off auto-renew; full billing terms are in the Terms of Use. You can view, modify, or cancel your subscription at any time from Settings → Apple Account → Subscriptions on your device.
9. Children's privacy
Qirsh is not directed at children under 13, and we do not knowingly collect data from anyone, including children. If you are under the age of majority in your jurisdiction, please use the app only with the involvement of a parent or guardian.
10. Data retention
Because Qirsh does not transmit your personal data to any server we operate, there is nothing about you on our side to retain or delete. Your trips live on your device and in your own iCloud, under your control. You can delete individual trips or expenses in the app, remove the app's data from iCloud in Settings → Apple Account → iCloud, or delete the app entirely. Removing a shared trip or a participant revokes that participant's access.
11. Third parties
Qirsh uses open-source software and machine-learning model weights published by third parties under their respective licenses. These are bundled in or downloaded by the app and run entirely on your device; they do not transmit your content to their authors. The currency-rate providers named above receive only the standard metadata of an HTTPS request (such as your IP address).
Details of these components, and the licenses that govern them, are shown in the app under Settings → About → Terms & Conditions.
12. Your rights
Because we do not collect your personal data on our servers, most data-protection rights are satisfied automatically: there is no personal data on our side to access, correct, delete, or export. Portability is built in — from a trip's Manage screen you can export it as a CSV spreadsheet or a text summary and take it wherever you like. Data you store in your own iCloud is subject to Apple's controls and your Apple Account settings. If you have questions about your rights under applicable law (GDPR, CCPA/CPRA, PIPEDA, or other frameworks), contact us using the address below and we will respond in good faith.
13. Changes to this policy
We may update this Privacy Policy as the app evolves. When we do, we will change the "Last updated" date at the top of this page. Material changes will also be reflected in the next version of the app. Continued use of Qirsh after an update means you accept the updated policy.