Logo
blankee
Install

Privacy Policy

Last updated September 17, 2026

Blankee is a self-hosted budgeting app. That one fact shapes everything on this page: your budget lives on a server you run, or one you chose, and not with us. This policy covers the Blankee iOS app, the Blankee server software, and the two services that blankee.io runs itself. It is written by the people who made the app, in plain words, and it says what actually happens rather than what a lawyer would let us get away with.

The short version

  • Your financial data is stored on your Blankee server and nowhere else.
  • The iOS app has no analytics, no advertising, and no third-party tracking of any kind.
  • The one thing the app sends to blankee.io is what it needs to receive push notifications: a device token and a random secret. Never the content of a notification.
  • We do not sell, rent, or share personal data with anyone.

The iOS app

When you first open the app it asks for the address of your Blankee server. From then on the app is a window onto that server: every page you see, and everything you type, goes to that server and to no one else. The app keeps a few things on your phone so it can do its job:

  • The address of your server.
  • Your signed-in session, the same as a web browser would.
  • A widget token your server issues, so the home screen widgets can show your day without opening the app. It is stored in the phone's keychain.
  • A random secret for push notifications, also in the keychain, explained below.

The app uses no analytics or crash-reporting services and includes no third-party code that phones home. It asks for permission to send notifications; if you decline, everything else works as before.

Push notifications, and the relay

Apple only delivers a push notification to an app from a key held by the app's maker. Your own server cannot hold that key, so blankee.io runs a small service, the push relay at push.blankee.io, that forwards a nudge to Apple on your server's behalf. It is designed to know as little as possible.

  • When the app receives its device token from Apple, it registers that token with the relay together with a random secret it makes up, and gives the same secret to your server. The relay stores the token, whether it belongs to Apple's test or production environment, and a one-way hash of the secret.
  • When your server has a notification for you, it asks the relay to push, presenting the token, the secret, and the notification's number on your server. If the secret matches, the relay tells Apple to wake your phone with that number and nothing else. The relay never receives the notification's text, the amounts involved, or the address of your server.
  • Your phone then fetches the notification from your own server, using its own credentials, and shows it.
  • The relay keeps a count of pushes per device to limit abuse, and its web server keeps ordinary access logs, including IP addresses, for a short time for troubleshooting. A device is forgotten when Apple reports it gone, or when the app registers again with a new secret.

The relay's source code is published with the rest of Blankee, so you can read exactly what it does.

Your Blankee server

Whoever runs a Blankee server is responsible for the data on it. If that is you, this section describes what the software stores so you know what you are keeping. The server holds your account (email address, name, a hashed password), your budget (categories, entries, forecasts, balances), your notifications, and the settings you choose. Some features send data elsewhere, and only when you turn them on:

  • Bank connections use SimpleFIN. Your server retrieves your transactions and balances from SimpleFIN with a token you obtain from them; that data flows between SimpleFIN and your server, and blankee.io is not involved. SimpleFIN's own privacy policy governs their side.
  • Categorization with Claude sends the description, amount, and direction of each imported transaction, together with the names of your categories, to Anthropic's API using an API key you provide. Nothing is sent unless you enable it. Anthropic's privacy policy governs their side.
  • Email notifications are sent through a mail server you configure, to the address you configure.

Automatic updates fetch the new version of the software from GitHub. That request carries no personal data.

Servers that blankee.io runs

If you use an account on a server that blankee.io operates, such as one we provide for evaluation, then we are the ones holding the data described above. We use it only to run the service for you, we do not look at it except to fix a problem you report, and we delete the account and its data on request. We do not sell it or use it for advertising.

Children

Blankee is not directed at children under 13, and we do not knowingly collect information from them.

Changes

If this policy changes, the new version will be published here with a new date at the top. Changes that reduce your privacy will not be applied quietly.

Contact

Questions about privacy, or a request to delete an account on a server we run, go to info@blankee.io.

Logo
Contact info@blankee.io
Socials LinkedIn Facebook
Legal Privacy Policy
Donate Buy me a coffee