Skip to content
Enis Erdoğan
  • Works
  • About
  • Contact
  1. CashierX
  2. /
  3. Privacy policy

CashierX

CASHIERX — PRIVACY POLICY

Last updated: 2 September 2026

CashierX ("the App") is an iOS app for counting the cash in a till. This policy explains in detail which data is processed and where, who it is shared with, how long it is kept and what your rights are.

NOTE: This is the same policy shown inside the App under Settings > Privacy Policy. The two texts are kept identical.

In short: your counts, history, profiles and settings are stored only on your device and are never sent to us. If you switch on iCloud sync, your records and your profile list are also kept in your own Apple Account, and they still never reach us. Three things leave your device: what Google AdMob processes in order to show ads, the request the Exchange Rates screen makes to our rate service, which carries nothing you entered, and anything you choose to share yourself. Each section below covers one of these in full.

1. Controller and contact

The controller is the developer of the App, Enis Erdogan (Türkiye). The single point of contact for every privacy question, request or complaint is the email address at the end of this page. No separate data protection officer has been appointed; the App does not process data on a scale or of a kind that would require one.

2. What the App does not collect

The App does not ask you to create an account and never asks for your name, phone number, email address, postal address, location or any identity document. We keep no user database and no cloud storage of your records, so no copy of your counts exists on our side. The one service we do run, the exchange rate service described in section 8, answers every device with the same public rate table and receives nothing you entered. The iCloud sync you can switch on uses your own Apple Account, never ours. The App runs no analytics of its own, gathers no usage statistics, sets no cookies, and requests access to no sensitive source such as contacts, photos, microphone, camera, location or health data.

3. Data stored on your device

The following is kept only in your device's own storage:

Counts: how many of each note and coin you entered, the currency, the calculated total and, if you entered one, the expected amount (Z report) together with the difference.

History: for each saved count the amount, date, time, currency and shift, the card takings if you entered them, the float carried over from the previous day, and a void mark if it was voided. The same ledger also holds the drawer movements you record, that is money put into the drawer, safe drops and payouts together with the reason you pick for them, the opening check of the day, and the day notes you write yourself, which are free text and contain whatever you type into them. Every row also carries the profile that saved it and a mark if it was entered later or edited afterwards.

The history is a single ledger for the whole device rather than one ledger per profile. Everyone using the App on that device sees every row, and the name on the row shows who saved it; the Admin Panel gathers the same rows per profile. If you do not want your records seen by other people, do not share the device.

Profiles: the profile names you choose. Profile passcodes and recovery answers are stored as a salted secure hash (salted SHA-256) rather than plain text, as is the Admin Panel passcode, and the passcode itself cannot be recovered from those hashes.

Settings: your language, currency, theme, money layout, simple mode, shifts, haptics, business size, business day start, chart preferences, iCloud sync preference and app lock preferences.

Technical values: the moment the last ad was shown, kept only to limit how often ads appear, and the last exchange rate table received, kept so that the rates screen still works without a connection. The rate table is public data about currencies and holds nothing about you.

None of this is transmitted to us and none of it is readable by us.

4. Biometric authentication

You can lock the App with Face ID, Touch ID or your device passcode. Your biometric data is handled entirely by iOS inside the device's secure hardware; the App never accesses, sees or stores it. All the App receives is whether the authentication succeeded.

5. iCloud sync, iCloud backup and device transfer

The App has an iCloud sync that you switch on yourself, and it stays off until you do. While it is on, your saved records and your profile list are also kept in your own Apple Account, so that your other devices signed in to the same account have them. The records are the ones described in section 3, with the notes and the names they carry; the profile list includes the hashed passcodes and recovery answers, and markers for the records you deleted so that the deletion reaches your other devices as well. Your language, theme, admin passcode and the count on screen are not included and stay on the device. Apple holds that data under its own terms, we have no access to it and it never reaches us. Switching the sync off stops it at once. The rule that your data stays on your device therefore has two exceptions: this sync, which you control, and the device backup performed by iOS, which the rest of this section describes. If iCloud Backup is enabled, the App's data on your device is copied, encrypted, to Apple's servers as part of the system backup. The same applies to backups made to a computer and to transfers to a new device. Apple manages that backup; we can neither access it nor see its contents, and it is governed by Apple's privacy terms. If you prefer otherwise, you can exclude CashierX from the backup list in your device settings.

6. Widgets

The home screen and lock screen widgets read the summary they display, which is the currency, the float set aside for the next day, when your business day starts and whether amounts are hidden because the App is locked, from a shared app group area inside the device. The count on screen is not written there. Only CashierX and its own widget extension can reach that area, and its contents are never sent off the device.

7. Sharing you start yourself

Sharing a summary, copying it, exporting CSV, printing and taking a full backup all happen only when you use them. When you share a summary, the content goes to the app you pick (messaging, email, notes and so on) and from that moment it is subject to that app's and the recipient's terms. The full backup in the Admin Panel writes a single file holding your history, your profile list with those hashes and your settings, and you choose through the share sheet where that file goes; from then on it stays where you put it, under the terms of whatever you saved it to, and restoring reads it back from a file you pick. You start every one of these transfers; the App never sends any content on its own and we never see any of it.

8. Exchange rates

The Exchange Rates screen shows the daily rate of the currencies the App counts. Those rates come from a small service we run on Cloudflare Workers, at cashierx-rates.imdevs.workers.dev. The request is sent only when you open that screen and the table on your device is more than two hours old, or when you pull the list down to refresh it, and it carries nothing you entered: no counts, no history, no settings, no identifier and no account. The service answers every device with the same public rate table, keeps no record about users and writes no log about you. Like any request on the internet it does reach Cloudflare together with your IP address and the ordinary technical details of the connection, which Cloudflare processes as our infrastructure provider in order to deliver the response and protect the service from abuse. The table received is kept on your device so the screen still works without a connection. If you never open that screen, no request is ever sent.

9. Advertising and Google AdMob

Unless you buy a subscription, the App shows interstitial ads through Google AdMob. To serve, measure and protect ads from fraud, Google may process device identifiers including the advertising identifier (IDFA), an approximate location derived from your IP address (country and city level), data about how you interact with ads and with the App, technical information such as device model, operating system version, language and network type, and the performance and diagnostic data produced by the ad SDK. Google collects this under its own responsibility; we never see it in raw form. For details see Google's privacy policy: https://policies.google.com/privacy

The first time you open the App, Apple's App Tracking Transparency prompt asks whether the App may track you. If you decline, the IDFA is not accessed and ads are not personalised; you can change your answer at any time in your device settings. Every feature of the App works the same either way.

If you are in the European Economic Area, the United Kingdom or Switzerland, a consent form from Google's certified consent management platform is shown before any ad is requested, and you choose there how your data may be used. If consent is refused or withdrawn, no ad request is ever sent. You can change that choice at any time from the Privacy Options row in Settings.

Ad content is limited to the general audience rating. With an active subscription no ads are shown, the ad SDK is never started and no request is sent for advertising purposes.

10. Subscriptions and Apple

The subscription that removes ads is sold through the Apple App Store. Apple handles payment, invoicing and refunds; we have no access to your card details, your name or your billing address. The App receives from Apple only whether the subscription is active and stores that on the device. You manage and cancel the subscription from your Apple account in your device settings.

11. Purposes and legal bases

Counts, history, profiles and settings that stay on the device are processed so the App can do what you asked of it; the basis is the performance of the usage relationship between us. Because that data never reaches us, no processing arises on our side.

The exchange rate request: the basis is our legitimate interest in showing you a current rate table without every device having to query the source itself. The request carries nothing about you, and the connection data that reaches Cloudflare is processed for delivery and security.

Personalised advertising and the measurement attached to it: the basis is your consent, collected through the consent form where one is required and through Apple's tracking prompt.

Non-personalised advertising and fraud prevention: the basis is our legitimate interest in keeping a free, ad-supported app viable.

Support correspondence: the basis is our legitimate interest in answering your request.

12. Recipients and international transfers

We do not sell, rent or pass your data to third parties for marketing. Data is shared only with the following parties and only to the extent described above: Google Ireland Limited and Google LLC for advertising, Apple Inc. and Apple Distribution International for payment and distribution, Cloudflare, Inc. as the infrastructure provider of the exchange rate service, and our email provider if you write to us for support. These companies may process data outside the European Union, including in the United States. Such transfers rely on those companies' own commitments, the European Commission's standard contractual clauses and adequacy decisions. Where the law requires it, for example under a court order, we may share the information we hold with the competent authorities; since your counts are not held by us, there is nothing of that kind to share.

13. Retention

History entries are kept on your device with no time limit; nothing is deleted automatically once a period has passed, and you remove them yourself by deleting the profile or clearing it from the Admin Panel. Counts, profiles and settings stay on the device until you delete them or remove the App. Removing the App deletes all of it from the device, and because we hold no copy that deletion is permanent and cannot be reversed by us. Two copies you made yourself outlive it: if iCloud sync is on, what is in your Apple Account stays there until you delete the records or switch the sync off, and a backup file you saved yourself stays wherever you put it. The exchange rate table on the device is replaced by the next one and holds nothing about you. Support correspondence is kept for at most 24 months after your request is resolved. Retention on the advertising side is governed by Google's own policies.

14. Your rights

Depending on where you live, for example under the General Data Protection Regulation in the European Economic Area and the United Kingdom or the Personal Data Protection Law in Türkiye, you have the right to learn whether your data is processed, to access it, to have it corrected or erased, to have processing restricted, to object to processing, to receive your data in a portable form, to withdraw consent you have given and to seek compensation for damage. Since we neither collect nor hold personal data about you, there is no record for us to produce or erase on your behalf; the data on your device you can delete yourself. For data processed for advertising you can address your request to Google and withdraw your consent from the Privacy Options row. If you write to the address on this page we will answer within 30 days at the latest. If you are not satisfied with the outcome, you retain the right to complain to the data protection authority in your country, and in Türkiye to the Personal Data Protection Board.

15. Children

The App is rated 4+ and is not directed at children; it is designed for cashiers and business owners. We do not knowingly collect personal data from children. The child-directed treatment flag is not used on the advertising side because the App does not fall into that category, but ad content is still limited to the general audience rating. If you believe data belonging to a child has been processed, write to us and we will act on it.

16. Automated decisions and profiling

The App produces no automated decision that has legal effects concerning you or similarly significantly affects you. Its calculations rest solely on the numbers you enter. If you allow it, the personalisation of ads happens on Google's side, and you can reverse that choice at any time.

17. Security

Because your data is stored only on your device, its protection depends largely on the security of that device. Passcodes and recovery answers are kept as salted hashes and exist in clear text nowhere. Apart from the iCloud sync you switch on and the rate request described in section 8, the App sends no data of its own over the network; the rate request runs over an encrypted connection, as does the advertising and purchase traffic that goes to Google and Apple. We recommend keeping your device passcode and biometric lock enabled, keeping the operating system up to date, and not using the App on modified (jailbroken) devices, which weaken the data protection iOS provides.

18. Data breaches

Since no personal data reaches us, a breach on our side is not expected. Should a breach nonetheless affect data you have sent us, we will notify the competent authority within the period the applicable law prescribes and will inform you as well where the risk is high.

19. Changes to this policy

This policy may be updated as the App evolves. The current version is always published inside the App and at the web address below, and the date at the top shows the last update. When a significant change is made we will also announce it inside the App.

20. Contact us

You are welcome to write to us about anything concerning privacy at the address below.

imdevstudios@gmail.com

CashierX · Enis Erdoğan·Terms of Use·Support
EmailGitHubLinkedIn