Come l'app Skurda tratta i tuoi dati.
Ultimo aggiornamento: 4 settembre 2026 · Versione app: 1.0
Il titolare del trattamento è Rocco Barletta, in qualità di persona fisica sviluppatrice dell'applicazione.
Per qualsiasi richiesta relativa alla privacy puoi scriverci a feedbacksr@icloud.com. Rispondiamo entro 30 giorni.
Tutto ciò che inserisci nell'app viene salvato in un database locale (SwiftData) nella memoria del tuo iPhone. Non viene trasmesso a noi né a terzi. Rientrano in questa categoria:
Se usi la fotocamera o scegli una foto dalla libreria per registrare una spesa quotidiana a partire da uno scontrino, l'immagine viene analizzata sul dispositivo (tecnologia Vision di Apple) al solo scopo di riconoscere il testo — esercente, importo e data. La foto non viene mai salvata né trasmessa a noi o a terzi: resta solo il testo riconosciuto, che diventa una normale spesa quotidiana modificabile da te.
L'automazione che registra automaticamente i pagamenti effettuati con Wallet è un'automazione dell'app Comandi di Apple che crei e controlli tu: comunica con Skurda tramite un collegamento diretto sul dispositivo, senza passare da alcun server nostro o di terzi.
Se usi Esporta spese, il file XLSX o CSV viene generato sul dispositivo e sei tu a decidere dove salvarlo o a chi inviarlo: noi non ne riceviamo copia. Lo stesso vale, in senso inverso, per Importa spese.
I promemoria sono notifiche locali programmate dal sistema operativo sul dispositivo. Non passano da alcun server e non richiedono l'invio delle tue spese a terzi.
Le tue spese vengono inoltre sincronizzate automaticamente con iCloud, tramite il database privato di CloudKit collegato al tuo Apple Account, così le ritrovi su tutti i dispositivi in cui hai effettuato l'accesso con lo stesso account. È una sincronizzazione diretta tra il tuo dispositivo e il tuo iCloud: i dati restano sotto il controllo di Apple, non transitano dai nostri server e non vi abbiamo accesso — non li vediamo, non li riceviamo e non possiamo recuperarli per te se li elimini. Puoi disattivare la sincronizzazione iCloud per le nostre app in qualsiasi momento da Impostazioni di iOS → [il tuo nome] → iCloud.
Per capire quali funzioni vengono effettivamente usate e dove l'app crea difficoltà, inviamo eventi
statistici a TelemetryDeck, che agisce come responsabile del trattamento per nostro conto.
I dati sono trasmessi in HTTPS all'endpoint nom.telemetrydeck.com.
| Evento | Informazioni allegate |
|---|---|
screen_view | Nome della schermata aperta (es. "DashboardView") |
tap_add_expense | Nessuna |
open_suggestion_helper | Nessuna |
tap_rate_app | Nessuna |
search_performed | Solo il numero di caratteri digitati. Il testo che cerchi non viene mai inviato. |
expense_added | Nome della spesa scelta dal catalogo predefinito dell'app (es. "netflix", "spotify"). Le spese che crei a mano non generano questo evento. |
expense_added_via_siri | Due soli indicatori: se l'app ha riconosciuto automaticamente la categoria e se avevi indicato un importo. Il nome che detti a Siri non viene inviato. |
paywall_view, paywall_purchase_tap, paywall_restore_tap, paywall_close | Nessuna |
open_savings_report, tap_unlock_savings_report, tap_restore_purchases_settings | Nessuna |
dismiss_savings_insight | Solo il tipo di segnalazione ignorata nel report di risparmio (es. "duplicate", "streamingOverlap"). Non il nome, l'importo o altri dettagli della spesa coinvolta. |
Inoltre l'SDK di TelemetryDeck invia automaticamente due eventi tecnici che non dipendono da una tua
azione specifica: TelemetryDeck.Session.started (all'avvio dell'app e quando la riapri dopo
almeno 5 minuti in background) e TelemetryDeck.Acquisition.newInstallDetected (al primo avvio
dopo l'installazione).
Indipendentemente dall'evento, l'SDK allega un insieme fisso di informazioni tecniche sul dispositivo e sull'utilizzo:
| Categoria | Dati |
|---|---|
| Identificativo pseudonimo | Un codice clientUser ottenuto applicando la funzione crittografica SHA-256, insieme a
una stringa fissa aggiunta dall'app (salt), all'identificativo che iOS assegna al nostro
insieme di app su quel dispositivo (identifier for vendor). L'identificativo originale non
viene mai trasmesso: parte solo il codice derivato, che non è riconducibile al tuo nome, al tuo numero
o al tuo Apple Account. Il salt serve a evitare che un terzo in possesso dell'identificativo di un
dispositivo possa ricalcolarne l'hash e riconoscerlo nei nostri dati. È però
stabile nel tempo, quindi permette di riconoscere che più eventi arrivano dallo stesso
dispositivo. Viene azzerato quando disinstalli le nostre app dal dispositivo.
Ogni sessione ha inoltre un codice casuale sessionID, non conservato tra un avvio e l'altro. |
| App | Versione e numero di build; se la copia proviene da App Store o TestFlight; nome e versione dell'SDK. |
| Dispositivo | Modello (es. iPhone16,1), architettura del processore, sistema operativo e versione, risoluzione e fattore di scala dello schermo, orientamento. |
| Lingua e area | Lingua dell'app, lingua preferita di sistema, locale (es. it_IT), Paese impostato sul dispositivo (es. IT) e fuso orario (es. UTC+1). Sono ricavati dalle impostazioni del dispositivo, non dalla tua posizione GPS. |
| Accessibilità e aspetto | Impostazioni di accessibilità attive (riduzione del movimento, testo in grassetto, colori invertiti, contrasto aumentato, riduzione della trasparenza, distinzione senza colore), dimensione del testo preferita, tema chiaro o scuro, direzione di lettura. |
| Utilizzo nel tempo | Data della prima sessione (installazione), numero totale di sessioni, numero di giorni distinti di utilizzo, giorni di utilizzo nell'ultimo mese, durata media delle sessioni e durata della sessione precedente. |
| Data e ora locali | Giorno del mese, giorno della settimana, giorno dell'anno, settimana, mese, trimestre, ora del giorno e se è un giorno festivo del fine settimana. |
Come per qualunque connessione a internet, il server che riceve i dati vede necessariamente l' indirizzo IP da cui arriva la richiesta. Non lo usiamo per identificarti né lo incrociamo con altri dati.
Se il dispositivo è offline, gli eventi vengono messi in coda in un file nella cartella cache dell'app, sul dispositivo, e inviati alla connessione successiva.
Non raccogliamo importi, saldi, note, date di scadenza né gli elenchi delle tue spese. Non raccogliamo nemmeno i nomi che scrivi o detti tu: l'unico nome che può essere inviato è quello di una voce che hai selezionato dal catalogo predefinito dell'app.
La gestione degli abbonamenti Premium è affidata a RevenueCat, responsabile del trattamento per nostro conto. Non trasmettiamo a RevenueCat alcun dato identificativo tuo: non effettuiamo alcun login e non associamo il tuo profilo a un'email o a un nome. RevenueCat genera un proprio identificativo anonimo del dispositivo e tratta:
Il pagamento avviene interamente tramite Apple con il tuo Apple Account. Noi non riceviamo, non vediamo e non conserviamo i dati della tua carta di credito o del tuo metodo di pagamento. Per il trattamento dei dati da parte di Apple si applica la privacy policy di Apple.
Durante l'introduzione iniziale l'app offre il pulsante Accedi con Apple come alternativa a Continua senza account. L'app non richiede il tuo nome né il tuo indirizzo email (nessuno scope viene domandato ad Apple) e non conserva né trasmette l'identificativo restituito: l'esito dell'accesso viene usato solo per proseguire l'introduzione, e non viene creato alcun account presso di noi. In entrambi i casi le tue spese restano su questo dispositivo.
Puoi esercitare il diritto di opposizione alle statistiche d'uso in qualsiasi momento scrivendoci a feedbacksr@icloud.com. Poiché gli eventi sono legati a un identificativo pseudonimo e non al tuo nome, per individuare ed eliminare i dati che ti riguardano potremmo doverti chiedere alcuni elementi (ad esempio il periodo approssimativo di utilizzo o il modello del dispositivo).
Alcuni fornitori possono trattare i dati in Paesi esterni allo Spazio Economico Europeo. In tal caso il trasferimento avviene sulla base delle Clausole Contrattuali Standard approvate dalla Commissione europea o di altra garanzia adeguata prevista dal Capo V del GDPR. I riferimenti privacy dei fornitori sono:
Ai sensi degli articoli 15-22 del GDPR hai diritto di:
Nota pratica. Per i dati che restano sul dispositivo puoi esercitare direttamente accesso, rettifica e cancellazione dall'app: le spese si modificano ed eliminano dalla schermata principale, e Esporta spese ti fornisce una copia in formato leggibile. Per le statistiche d'uso, poiché sono legate a un identificativo pseudonimo e non al tuo nome, per dare seguito a una richiesta potremmo doverti chiedere elementi che ci permettano di individuare i dati che ti riguardano.
L'app non è rivolta a minori di 14 anni e non raccoglie intenzionalmente dati di minori. Se ritieni che un minore ci abbia fornito dati, scrivici e provvederemo a cancellarli.
Se cambiano i dati raccolti o i fornitori coinvolti, aggiorneremo questa pagina modificando la data in alto. Le modifiche rilevanti verranno segnalate anche nelle note di versione dell'app.
Le sezioni precedenti riguardano l'app. Questa riguarda il sito
dontknowif.github.io, che stai leggendo adesso.
Le pagine di presentazione dell'app usano Cloudflare Web Analytics, che agisce come responsabile del trattamento per nostro conto, per sapere quante persone visitano il sito e quali pagine leggono. A differenza degli strumenti di statistica più diffusi, non usa cookie, non scrive nulla nella memoria del browser e non ricostruisce un'impronta del dispositivo: per questo il sito non ti mostra alcun banner di consenso ai cookie, perché non ce ne sono da accettare.
Per ogni visita vengono raccolti: la pagina aperta, l'eventuale sito da cui provieni, il Paese (dedotto dall'indirizzo IP, che non viene conservato), il tipo di browser e di sistema operativo, e alcuni tempi di caricamento della pagina. Non è possibile risalire a te come persona, e non vieni seguito da un sito all'altro. La base giuridica è il legittimo interesse (art. 6.1.f GDPR) a capire se il sito funziona e viene trovato. Riferimenti privacy del fornitore: cloudflare.com/privacypolicy.
Il sito è ospitato su GitHub Pages. Come qualunque server web, l'infrastruttura di GitHub vede l'indirizzo IP da cui arriva la richiesta: è una conseguenza tecnica del funzionamento di internet, non un dato che raccogliamo o consultiamo noi. Riferimenti privacy: docs.github.com/site-policy.
Il sito non contiene moduli, non chiede registrazione e non raccoglie dati che tu debba digitare. Le statistiche del sito sono separate da quelle dell'app descritte al punto 3 e non sono in alcun modo collegate a quelle. Se non vuoi essere conteggiato qui, è sufficiente un qualsiasi blocco-script del browser.
How the Skurda app handles your data.
Last updated: 4 September 2026 · App version: 1.0
The data controller is Rocco Barletta, a natural person and the developer of the application.
For any privacy request, write to feedbacksr@icloud.com. We reply within 30 days.
Everything you enter in the app is stored in a local database (SwiftData) in your iPhone's storage. It is not transmitted to us or to any third party. This includes:
If you use the camera or pick a photo from your library to log a daily expense from a receipt, the image is analyzed on your device (Apple's Vision technology) for the sole purpose of recognizing text — merchant, amount and date. The photo is never saved or transmitted to us or to any third party: only the recognized text remains, becoming a normal daily expense you can edit.
The automation that automatically logs payments made with Wallet is a Shortcuts automation you create and control yourself: it talks to Skurda through a direct on-device link, without going through any server of ours or of any third party.
If you use Export expenses, the XLSX or CSV file is generated on the device and you decide where to save it or whom to send it to: we receive no copy. The same applies, in reverse, to Import expenses.
Reminders are local notifications scheduled by the operating system on the device. They do not pass through any server and do not require sending your expenses to third parties.
Your expenses are also automatically synced with iCloud, through the private CloudKit database tied to your own Apple Account, so you find them on every device signed in with that same account. This is a direct sync between your device and your own iCloud: the data stays under Apple's control, never passes through our servers, and we have no access to it — we do not see it, do not receive it, and cannot recover it for you if you delete it. You can turn off iCloud sync for our apps at any time from iOS Settings → [your name] → iCloud.
To understand which features are actually used and where the app causes trouble, we send statistical
events to TelemetryDeck, acting as processor on our behalf. Data is transmitted over
HTTPS to the endpoint nom.telemetrydeck.com.
| Event | Attached information |
|---|---|
screen_view | Name of the screen opened (e.g. "DashboardView") |
tap_add_expense | None |
open_suggestion_helper | None |
tap_rate_app | None |
search_performed | Only the number of characters typed. The text you search for is never sent. |
expense_added | Name of the expense picked from the app's built-in catalogue (e.g. "netflix", "spotify"). Expenses you create manually do not generate this event. |
expense_added_via_siri | Two indicators only: whether the app automatically recognised the category, and whether you stated an amount. The name you dictate to Siri is not sent. |
paywall_view, paywall_purchase_tap, paywall_restore_tap, paywall_close | None |
open_savings_report, tap_unlock_savings_report, tap_restore_purchases_settings | None |
dismiss_savings_insight | Only the type of insight dismissed in the savings report (e.g. "duplicate", "streamingOverlap"). Not the name, amount, or any other detail of the expense involved. |
In addition, the TelemetryDeck SDK automatically sends two technical events that do not depend on a
specific action of yours: TelemetryDeck.Session.started (on app launch and when you reopen it
after at least 5 minutes in the background) and
TelemetryDeck.Acquisition.newInstallDetected (on first launch after installation).
Regardless of the event, the SDK attaches a fixed set of technical information about the device and its usage:
| Category | Data |
|---|---|
| Pseudonymous identifier | A clientUser code obtained by applying the SHA-256 cryptographic function, together
with a fixed string added by the app (salt), to the identifier iOS assigns to our set of apps
on that device (identifier for vendor). The original identifier is never transmitted: only the
derived code is sent, and it cannot be traced back to your name, phone number or Apple Account. The
salt prevents a third party holding a device's identifier from recomputing its hash and recognising it
in our data. It is however stable over time, so it
allows recognising that several events come from the same device. It is reset when you uninstall our
apps from the device. Each session also has a random sessionID code, not retained between
launches. |
| App | Version and build number; whether the copy comes from the App Store or TestFlight; SDK name and version. |
| Device | Model (e.g. iPhone16,1), processor architecture, operating system and version, screen resolution and scale factor, orientation. |
| Language and region | App language, preferred system language, locale (e.g. it_IT), country set on the device (e.g. IT) and time zone (e.g. UTC+1). These come from device settings, not from your GPS location. |
| Accessibility and appearance | Active accessibility settings (reduce motion, bold text, invert colours, increase contrast, reduce transparency, differentiate without colour), preferred text size, light or dark theme, reading direction. |
| Usage over time | Date of first session (installation), total number of sessions, number of distinct days used, days used in the last month, average session duration and previous session duration. |
| Local date and time | Day of month, day of week, day of year, week, month, quarter, hour of day and whether it is a weekend day. |
As with any internet connection, the receiving server necessarily sees the IP address the request comes from. We do not use it to identify you nor cross-reference it with other data.
If the device is offline, events are queued in a file inside the app's cache folder, on the device, and sent on the next connection.
We do not collect amounts, balances, notes, due dates or the lists of your expenses. Nor do we collect the names you type or dictate: the only name that may be sent is that of an entry you selected from the app's built-in catalogue.
Premium subscription management is handled by RevenueCat, acting as processor on our behalf. We transmit no identifying data about you to RevenueCat: we perform no login and do not associate your profile with an email address or a name. RevenueCat generates its own anonymous device identifier and processes:
Payment happens entirely through Apple with your Apple Account. We do not receive, see or store your credit card or payment method details. Apple's own privacy policy applies to Apple's processing.
During the initial onboarding, the app offers the Sign in with Apple button as an alternative to Continue without an account. The app does not request your name or email address (no scope is asked of Apple) and neither stores nor transmits the identifier returned: the sign-in outcome is only used to continue the onboarding, and no account is created with us. Either way, your expenses stay on this device.
You can exercise your right to object to usage statistics at any time by writing to us at feedbacksr@icloud.com. Since events are tied to a pseudonymous identifier rather than your name, to locate and delete the data concerning you we may need to ask you for a few details (for example your approximate period of use or device model).
Some providers may process data in countries outside the European Economic Area. In that case the transfer takes place on the basis of the Standard Contractual Clauses approved by the European Commission or another adequate safeguard under Chapter V of the GDPR. Providers' privacy references:
Under Articles 15-22 GDPR you have the right to:
Practical note. For data that stays on the device you can exercise access, rectification and erasure directly in the app: expenses can be edited and deleted from the main screen, and Export expenses gives you a copy in a readable format. For usage statistics, since they are tied to a pseudonymous identifier and not to your name, we may need to ask you for details that let us locate the data concerning you before acting on a request.
The app is not directed at children under 14 and does not knowingly collect children's data. If you believe a child has provided us with data, write to us and we will delete it.
If the data collected or the providers involved change, we will update this page and change the date at the top. Significant changes will also be noted in the app's release notes.
The sections above concern the app. This one concerns the site
dontknowif.github.io, the one you are reading right now.
The pages presenting the app use Cloudflare Web Analytics, acting as a data processor on our behalf, so we can tell how many people visit the site and which pages they read. Unlike the more common statistics tools, it uses no cookies, writes nothing into the browser's storage and builds no device fingerprint: that is why the site shows you no cookie consent banner — there are none to accept.
For each visit the following is collected: the page opened, the site you came from if any, the country (derived from the IP address, which is not retained), the browser and operating system type, and some page loading timings. None of it can be traced back to you as a person, and you are not followed from one site to another. The legal basis is legitimate interest (Art. 6(1)(f) GDPR) in understanding whether the site works and is being found. Provider's privacy information: cloudflare.com/privacypolicy.
The site is hosted on GitHub Pages. Like any web server, GitHub's infrastructure sees the IP address a request comes from: that is a technical consequence of how the internet works, not data we collect or consult. Privacy information: docs.github.com/site-policy.
The site has no forms, asks for no registration and collects nothing you have to type. Website statistics are separate from the app statistics described in section 3 and are not linked to them in any way. If you would rather not be counted here, any browser script blocker is enough.