Privacy

Your financial data stays yours.

Last updated August 27, 2026

The short version

MonthMade is local-first. It has no advertising, analytics, tracking, third-party crash-reporting SDK, or MonthMade account. Your working data stays in the app’s sandbox on your Mac unless you explicitly enable private iCloud Sync.

Local by defaultYour SQLite database starts and works on this Mac.
Sync is optionalA first-run lookup is read-only; only your choice enables private iCloud Sync.
No analytics or trackingMonthMade does not build or send a usage profile.

Data MonthMade stores

The authoritative local store is a Core Data SQLite database in MonthMade’s sandbox. It contains settings, income sources and rate plans, schedules and calendar overrides, payments and adjustments, completed time entries, and Pomodoro presets. An active or paused timer uses a separate local recovery file. Reports, dashboard totals, and other calculated views are derived in memory from those records; MonthMade does not store a separate report dataset.

First-run lookup and optional iCloud Sync

After Welcome, an eligible fresh installation may read one root record from the private CloudKit database of the Apple Account already signed in on the Mac. This lookup only checks whether compatible MonthMade data exists. It does not create or modify a CloudKit zone or record, upload local data, restore anything, or enable sync.

Only choosing Use iCloud Data restores the private copy. MonthMade suppresses outgoing changes while it reads and adopts that data; after a successful local adoption, it publishes a new current generation and enables automatic sync. Choosing Keep This Mac’s Data instead replaces the cloud copy only after confirmation.

When sync is enabled, encrypted CloudKit payload fields can contain income names and amounts, rates and plans, schedules and calendar changes, payments, notes, adjustments, completed time sessions, Pomodoro preset names, and shared calculation, currency, calendar, language, forecast, and Realtime settings. Records also contain ordinary app-generated entity and generation identifiers, a stable random device-writer identifier, and sync timestamps. That writer identifier is not a hardware or advertising identifier.

Active timers, reports, logical backups, exports, notification settings, device-only display and privacy preferences, login-item settings, and Auto Privacy detector metadata do not sync. MonthMade has no separate cloud account or developer-operated data warehouse. Signing out of iCloud or changing Apple Accounts disables sync but does not automatically replace the local SQLite dataset.

Purchases

Apple processes Pro purchases, renewals, cancellations, refunds, subscription management, and restoration through StoreKit and the App Store. MonthMade uses localized product information and verified current entitlements to display purchase options and select Free or Pro features. It does not receive Apple Account credentials or full payment-card details, keep a custom receipt, order, payment, or license database, or link purchase state to the local dataset or private CloudKit records. Restore Purchases restores access through Apple without restoring or enabling iCloud data.

Auto Privacy and Hidden mode

Auto Privacy is optional and best effort. Without permission, it can use public display-mirroring state. If you click Enable in Settings → Privacy, macOS asks for its broad Screen & System Audio Recording permission; after granting it, you must quit and reopen MonthMade. MonthMade never requests Accessibility access.

The Enable action asks the public ScreenCaptureKit API for shareable-content metadata only to invoke the system permission flow, then immediately discards the result. MonthMade creates no capture filter or stream and never receives, saves, logs, or uploads screenshots, screen pixels, video, window contents, or system audio. After relaunch, it checks once per second only the in-memory name and process identifier of a macOS Control Center indicator window.

That Control Center indicator is an undocumented aggregate signal, not a guaranteed screen-sharing API. Camera, microphone, or system-audio activity can cause conservative hiding when no screen is being shared, and some sharing can be missed. Normal macOS screenshots and window capture include MonthMade. During automatic hiding the app shows a privacy shield and asks macOS to exclude affected windows—including a detached Summary window—from capture, but capture tools may ignore that request.

Manual Hidden is always available. Show Values, or choosing Amounts or Percentages during automatic hiding, reveals values and removes capture exclusion across the app only until the current continuous detection ends; the next detection hides them again. This override stays in memory and also resets when you relaunch MonthMade. These display protections do not delete or redact stored data or exports.

Notifications and diagnostics

Pomodoro notification access is requested only after you opt in. Scheduled notifications use generic text and contain no source name, activity, note, or financial amount. MonthMade uses Apple Unified Logging for local diagnostics; potentially identifying error details are marked private. It has no analytics, advertising, tracking, custom telemetry, or third-party crash-reporting service.

Export and deletion

A complete JSON export is written only to a file you select. It can include settings, financial data, complete time history, Pomodoro presets, and archived or deleted-record markers. Privacy display mode does not redact the file, so treat every export as sensitive.

Reset All Data requires confirmation. It replaces the working dataset with fresh state, removes financial and historical entities, the logical backup, and the active-timer checkpoint, and keeps device preferences such as calendar, language, display/privacy, login-item, forecast, and notification choices. If iCloud Sync is enabled, reset first requests deletion of MonthMade’s private CloudKit zone, resets sync state, and disables sync. If sync is already disabled, local sync metadata or corruption-recovery copies can remain and may contain a cached record mirror.

For cloud cleanup, run Reset All Data while sync is enabled before deleting MonthMade. Deleting the app alone may leave its local container or private CloudKit zone. User-selected exports are never deleted automatically. Reading existing data, export, and deletion remain available independently of Pro access.

App Privacy disclosure

For App Store privacy disclosure, MonthMade classifies its current data flows as Data Not Collected. It does not transmit personal or usage data in a way that lets the developer or an integrated third-party partner access it. Local-only data stays on this Mac. If you enable iCloud Sync, encrypted records are stored only in the private CloudKit database tied to your Apple Account; only the user can access that database by default, and its contents are not visible in the developer portal.

This does not mean the app is network-free: CloudKit handles the read-only lookup and optional sync, and Apple handles StoreKit payments and purchase history. MonthMade has no developer-operated backend and uses no data for tracking, advertising, analytics, marketing, or product personalization. It receives no captured photos, video, audio, screen contents, or full payment-card details.

Network boundaries

MonthMade’s outbound network paths are limited to Apple’s StoreKit and App Store services, CloudKit for the read-only lookup and explicitly enabled sync, and Apple push delivery used by CloudKit. There is no developer-operated account, payment, updater, analytics, advertising, crash-reporting, or other backend, and the app accepts no incoming network connections.

Contact

Questions about privacy or data handling can be sent through the Contact page or directly to support@monthmade.com. For practical help, see the Support page.