Inunity
Inunity
Sign inBeta
Inunity
Inunity

Privacy Policy

For the Inunity app for iPhone and the Inunity web command center.

Effective
17 August 2026
Published by
Zubair Muwwakil
Contact
zmuwwakil1@gmail.com

1.The short version

PickMe tells you which credit card in your wallet earns the most on the purchase you are about to make. There are two separate places your information can live, they work very differently, and the difference is the most important thing on this page.

On your iPhone. The app keeps a detailed record of the merchants you confirm, the advice it gave you, and your corrections to it. That record is never uploaded. There is no code in the app that sends it anywhere.

On the server, but only if you create an account. A PickMe account is optional. If you make one, the web hub at moneytalks.zubairmuwwakil.com holds the data you put into it, and — if you set up the optional Wallet Shortcut — a record of your card transactions, including the amount, the merchant, and the card used.

You can use PickMe on your iPhone without ever creating an account. If you never sign in, nothing about your shopping reaches the server, because there is nothing to send it to and no account to attach it to.

Neither the app nor the server ever connects to your bank or your card issuer. Nothing here asks for card numbers, PINs, or online banking credentials, and no screen anywhere accepts them.

2.Who is responsible

PickMe and the MoneyTalks web hub are built and published by Zubair Muwwakil, an individual developer, not a company. There is no incorporated entity behind this, no team, and no data protection department.

That means the person responsible for the protection of your personal information is Zubair Muwwakil, reachable at zmuwwakil1@gmail.com. Requests and complaints go to the same address, because there is nobody else to route them to.

Being a one-person project is a fact about the service, not a reduction of your rights. The obligations described in this policy apply in full.

3.Two stores, two owners

The most common way to misread a privacy policy like this one is to conclude that PickMe holds nothing at all. That is true of the server for people who never sign in. It is not true of your iPhone, and it is not true of the server once you have an account.

On your iPhoneOn the server
ExistsAlways, from first launchOnly if you create an account
HoldsMerchants you confirmed with their coordinates, every recommendation made, your correctionsEverything attached to your account, including Wallet Shortcut transactions
Can I read itNo. It is never uploadedYes. It is on a server I administer
Erased byErase This iPhone's History, or deleting the appDelete my data, or Delete account

Apple's App Privacy labels describe the on-device store as data not collected, because Apple treats information that is processed only on the device and never sent off it as uncollected. That is a correct answer to Apple's question. It is not a claim that the app holds nothing — it plainly does, and this policy describes it in detail below.

4.What PickMe stores on your iPhone

All of this is written to a database inside the app's own storage area on your device, and it stays there.

Your cards

Which card products you picked from the catalogue built into the app — for example an American Express Cobalt Card. The catalogue ships with the app; choosing a card from it tells nobody anything.

The app never asks for and never stores card numbers, expiry dates, security codes, PINs, cardholder names, or online banking credentials. There is no field anywhere in the app that accepts them. If any screen ever appears to ask you for a card number, it is not this app.

Your card settings

  • which card is your everyday default
  • which cards you keep at home rather than in your wallet
  • bonus categories you selected with your issuer, where a card offers that choice
  • whether a paid plan or subscription tier is active on a card
  • the month the account was opened, where a card's bonus limits reset on that anniversary
  • your own estimates of how much you have spent toward each card's monthly or annual bonus cap — approximate spending figures that you enter yourself
  • what you believe your points are worth, in cents per point, including any figure you edit

Merchants you confirm

  • the merchant name
  • the Apple Maps place identifier, where one exists
  • the merchant's latitude and longitude
  • the purchase category you confirmed for it
  • how many times you have confirmed it, and when it was last used

Every recommendation the app has made

  • the date and time
  • the merchant name and identifier
  • the category the app predicted, how confident it was, and why
  • the card it recommended and the dollar value it calculated, and the runner-up
  • the point valuation in force at that moment
  • the explanation text you were shown
  • the purchase amount, only if you chose to enter one — entering an amount is always optional and always skippable

Your corrections

  • which card you actually paid with
  • the category the purchase actually coded as
  • a classification of what went wrong, if anything
  • any free-text note you write
  • the date you confirmed it

What this adds up to, stated plainly

Taken together, this is a running record of where you shopped, when, roughly how much you spent, and which card you used — including precise coordinates sitting at rest on your phone. Your card settings also include approximate figures for your annual spending in certain categories. That is genuinely personal information, and it is treated as such.

That is exactly why the app is built so this record never leaves your device. The design decision came first; this policy describes it rather than promising it.

5.What actually leaves your iPhone

This section replaces a claim in earlier drafts of this policy, written before accounts existed, that Apple Maps was the only network activity the app performed. That stopped being true when account sync shipped, and the correction matters more than the tidier sentence did.

When you are signed out

Searching for nearby merchants sends a request to Apple, which answers it. Nothing else goes anywhere. See the Apple Maps section below.

When you are signed in

The app talks to the MoneyTalks server, and this is the complete list of what it sends:

  • your Clerk sign-in token, which identifies your account on every request
  • {"label": "..."} — a name you type, such as “my iPhone”, when you create a Wallet Shortcut installation token
  • {"scope": "account"} — when you ask to delete your account

That is the entire outbound payload surface of the app. Cap usage and feedback sync is a pull: the app asks the server for figures and receives them. It does not push your prediction log, your confirmations, or your saved merchant locations, because no code in the app reads those models for transmission.

The Wallet Shortcut is a separate thing from the app, and it does send transaction data. It is covered in its own section below, because it is the one part of this system most likely to surprise you.

6.Location on your iPhone

With your permission, the app takes a single location reading to ask Apple Maps which shops are near you, so you can pick the one you are standing in from a short list instead of typing its name.

  • Location is off until you turn it on. The app does not ask on first launch and does not work around a refusal.
  • The app requests While Using the App permission. It never requests Always.
  • Each reading is a one-time fix, taken when you tap to find nearby merchants. The code requests single fixes and never starts continuous background updates.
  • Your coordinates are not saved as a trail. What is saved is the location of a merchant you confirmed, so it can be offered to you again next time you are there.

If you turn on ambient alerts, the app also asks iOS to watch geofences around up to twenty merchants you have already confirmed, so it can offer advice as you arrive. Those geofences are set on your device, evaluated by iOS, and removed when you erase your local history.

If you say no to location, the app remains fully usable. Every feature is reachable by searching for a merchant by name. Declining costs you the shortcut, not the product. You can revoke permission at any time in iOS Settings, under Privacy & Security, then Location Services.

7.Apple Maps

When you look for nearby merchants or search for one by name, iOS sends that request to Apple to answer it. I do not receive that request, I am not told what you searched for, and I get no copy of the result.

Apple's handling of those requests is governed by Apple's Privacy Policy, not by this one. Because no copy reaches me, there is nothing on my side to delete.

8.If you have a PickMe account: what the server holds

Creating an account is optional and the app works without one. If you create one, the following is stored on the server against your user record.

  • Sign-in details, handled by Clerk, my authentication provider: your email address and the credentials or third-party sign-in you chose. Passwords are held by Clerk, not by me, and I never see them.
  • Whatever you enter in the web hub: purchases, returns, subscriptions, bills, receipts and their uploaded files, investments, and notification preferences.
  • Transactions captured by the Wallet Shortcut, if you set it up — see the next section.
  • Cap usage ledgers and accruals, which track progress toward your cards' bonus limits.
  • Your card and merchant settings as held server-side, and the alias tables that map raw transaction text to a known card or merchant.
  • Wallet Shortcut installations: the label you gave each one and a hashed copy of its token. The token itself is not stored in a form I can read back.
  • If you connect an email account, the connection details described in the email section below.

There is no analytics SDK, no advertising, no ad identifiers, no cross-app or cross-site tracking, and no data broker anywhere in this system. Your information is not sold, rented, or shared for anyone else's purposes. It is used to operate the features you are using.

The server does not connect to your bank or card issuer, and it holds no payment instrument of yours. It cannot move money.

9.The Wallet Shortcut

The Wallet Shortcut is an Apple Shortcut you build and install yourself, on your own device. It is optional, it is off unless you set it up, and it is the route by which your actual card transactions reach the server. It is worth reading this section carefully even if you skipped the rest.

When it runs — typically as an automation after an Apple Pay tap — it posts to the wallet-events endpoint on the server, authenticated by an installation token you created. It sends:

  • the merchant name and transaction description as Apple Wallet renders them
  • the amount and currency
  • the card description as Apple Wallet renders it
  • the time of the transaction, with your device's time zone
  • your latitude and longitude at that moment, if you included the Get Current Location action when you built the Shortcut

The payload is also kept verbatim as received, so that improved parsing can re-read your history later rather than silently misreading it once. That means a raw copy of the above is retained alongside the interpreted version.

About the coordinates

If your Shortcut sends location, those coordinates are stored precisely and kept as part of your transaction history. They are not blurred or discarded after the merchant is identified. The reason is that the complete record is the product — location is what lets the server tell a coffee shop from a gas station when the transaction text is unreadable. But it means the server holds a map of where you paid for things, and you should decide about that deliberately rather than by default.

You control this when you build the Shortcut. Delete the Get Current Location action and everything else still works; captures simply arrive without coordinates. You can also revoke a Shortcut installation at any time from the web hub, which stops that device from posting anything further.

The Shortcut is a transport, not an observer. It reads what you hand it at the moment it runs. It does not have access to your Apple Wallet history, your bank, or your card account, and it cannot run on its own without the automation you configured.

10.Connecting an email account

The web hub can read receipts and order confirmations out of your mailbox so purchases, returns, and subscriptions fill themselves in. This is optional and off until you connect an account. It is also the most invasive permission in the whole system, so here is the unflattering version.

Gmail

Connecting Gmail requests the gmail.readonly scope, along with basic profile and email address. That scope grants read access to your entire mailbox — every message, including bodies and attachments, not only receipts. It does not grant permission to send, modify, or delete anything.

The scan mode setting in the web hub — all messages, receipts only, shipping only, or subscriptions only — narrows what the server actually processes. It does not narrow what Google authorized. That is a genuine gap between the permission and the practice, and you should judge the permission, because it is the part that is enforced.

What is kept

From scanned mail the server keeps what it extracted — merchants, amounts, dates, order and tracking numbers, line items, and the linked purchase, return, or subscription records. Access tokens are encrypted at rest.

You can disconnect an email account at any time from Settings, then Privacy & Data, in the web hub. Disconnecting removes the stored credentials. Records already extracted remain until you delete your data, so that your purchase history does not develop holes; deleting your data or your account removes them.

11.How long information is kept

On your iPhone

Until you erase it. There is no expiry, and I cannot reach it to remove it on your behalf — it was never uploaded, so there is nothing on my side to act on. Deleting the app removes its database with it, in the ordinary iOS way.

If you back up your iPhone to iCloud or to a computer, that backup may include the app's data, as it does for other apps. Those backups are controlled by your own iOS and iCloud settings and by Apple. If you want the data gone from a backup, manage or delete the backup itself.

On the server

Until you delete it. Account data is kept for as long as the account exists, because it is the history the product is for. There is no automatic expiry, and old transactions are not aged out.

When you delete your data or your account, deletion is immediate rather than scheduled, and it is not a soft delete — the rows are removed. No shadow copy is retained, and no record of the deletion survives it. If a deletion fails partway, a record of the failure remains so you can retry, because in that case your account still exists.

12.Deleting your information: three controls

Because there are two stores, there are separate controls, and one of them deliberately does not require an account.

ControlWhereAccount neededWhat it removes
Erase This iPhone's HistoryPickMe, gear icon, This iPhoneNoThe entire on-device store: recommendations, corrections, saved merchants and their coordinates, mute list, counters, and any live geofences
Delete my dataWeb hub, Settings, Privacy & DataYesEvery server record belonging to you. Your account and sign-in survive, so you can start over with an empty slate
Delete accountPickMe, gear icon, Danger zone — and the web hub, Settings, Privacy & DataYesYour entire server record and the account itself, including the sign-in held by Clerk

The local erase is not gated on being signed in, on purpose. The app has never required an account, so somebody who has never signed in still has a local history — and should not have to create an account, or delete one, in order to erase it.

Deleting your account does not erase this iPhone's history unless you ask it to. The account deletion screen offers that as a separate, explicit choice, and defaults to keeping it. Your local record never left the phone, so the account has no claim on it, and an accidental deletion should cost you the account rather than your own record of what the app advised.

There is no per-record delete. Earlier drafts of this policy described one; it was never built, and the claim has been removed rather than left to imply a control that is not there. What exists is the whole-store erase above.

13.Your rights under Canadian and Quebec law

Canadian federal privacy law (PIPEDA) and, if you are in Quebec, Law 25 give you rights over your personal information. Where they apply to information on your own device, you exercise them yourself, immediately, without asking anyone. Where they apply to information on the server, write to me.

RightOn your iPhoneOn the server
Know what is heldListed in full above, and visible on screen in the appListed above; the web hub shows a live count of every record type held for you
Access and portabilityNo export control exists in the iOS app today. If one ships, this policy will say soThe web hub exports your data as a structured file you can keep or take elsewhere
CorrectionEdit cards, settings, valuations, and merchant categories at any timeEdit your records in the web hub, or write to me
DeletionErase This iPhone's History, or delete the appDelete my data, or Delete account
Withdraw consentTurn off Location in iOS SettingsDisconnect your email, revoke a Wallet Shortcut installation, or delete your account
Earlier drafts said that a request for your data would find nothing to send. That was written when no server existed and is no longer true: if you have an account, I hold the information described above and can produce it.

A limitation about corrections, stated honestly

The app deliberately never rewrites a recommendation after the fact. If a prediction was wrong, your correction is stored beside it rather than over it, so accuracy is measured against what you were actually told at the time rather than a tidied-up history. You can erase a prediction; you cannot silently edit one — and neither can I.

Automated decisions

The recommendation engine makes automated calculations, but it does not make decisions about you: it does not score you, rank you, grant or refuse you anything, and nothing it produces has a legal or similarly significant effect. It tells you which card pays more and shows its arithmetic. If that ever changes, Law 25 requires that you be told, and you will be.

Where information is held

The server and its database are operated through service providers who may store or process data outside Canada, including in the United States, where local authorities may be able to compel access under their own laws. Authentication is handled by Clerk. Information on your iPhone stays on your iPhone.

Breaches

If a confidentiality incident occurs that presents a risk of serious injury, you will be notified, and the regulators will be notified, as PIPEDA and Law 25 require. I will not wait to be asked, and I will tell you what I actually know rather than a reassuring summary of it.

14.Security

On your iPhone, your data sits in the app's private storage area, protected by the iOS app sandbox and file protection. Those protections lean on your device having a passcode or biometric lock. If your iPhone has no passcode, its local data is much less protected — true of every app, including this one.

On the server, traffic is encrypted in transit, sign-in is handled by Clerk rather than by hand-rolled password code, Wallet Shortcut tokens are stored only as hashes, and email credentials are encrypted at rest.

What I do not claim: there has been no third-party security audit or certification, I hold no compliance certifications, and I will not describe any of this as bank-level or military-grade. It is a carefully built one-person system, which is a real thing but not the same thing as an audited one. You are entitled to weigh that.

15.Children

This is built for adults who hold credit cards. It is not directed at children, and I do not knowingly create accounts for them. If you believe a child has created an account, write to me and I will delete it.

16.Advice, not a guarantee

Recommendations are calculated from a catalogue of published card terms and from your own settings. Card terms change, and merchants code purchases in ways nobody outside the payment network can see in advance. Each recommendation shows when its rules were last verified and how confident it is.

It is a calculator you can audit, not a promise about what your issuer will pay you, and it is not financial advice.

17.Changes to this policy

Updated versions are posted at https://moneytalks.zubairmuwwakil.com/privacy with a new effective date.

If a future version ever collects something materially new, you will be told in the app or the web hub before it starts, and asked separately, rather than finding this page quietly rewritten. This version exists because an earlier draft had drifted out of step with the code; keeping the two aligned is the standard being held to here.

18.Contact, and how to complain

Questions, or to exercise any right above: zmuwwakil1@gmail.com. This reaches Zubair Muwwakil, who is the person responsible for the protection of personal information.

No response-time commitment is published here, because a one-person project should not promise a service level it cannot guarantee. Statutory deadlines still apply: PIPEDA and Law 25 both require a response to an access request within thirty days.

If you are not satisfied with how a request was handled, you can complain to a regulator, and you do not need permission to do so:

The long-form working document behind this policy, including the notes reconciling it against what the code actually does, is maintained alongside the source. If you find a statement on this page that the software contradicts, that is a bug worth reporting to zmuwwakil1@gmail.com.