Vest · Privacy Policy
We do not collect your data.
Effective: 1 September 2026 · Last updated: 29 August 2026
The short version
Vest has no account, no server and no analytics. Everything you record stays on your device and, if you have iCloud turned on, in your own private iCloud account, which we cannot read.
We do not collect your data. Not “we collect it and promise to be careful” — there is nowhere for it to go. Vest’s App Store privacy label reads Data Not Collected, and this document exists to show that claim being kept rather than asserted.
Vest never asks for a bank login, never connects to a financial institution on your behalf, and never asks for a credential of any kind.
1. Who this policy is from
Vest is published by Salt and Co. Design Partners LLC (“we”, “us”), 307 Henrys Ln, Bristol, VA, 24202.
Questions about this policy, or about privacy generally: vest@addsaltandco.com.
2. What Vest stores, and where
Vest is a tracker you type into. What it holds is what you put in it:
- People.A display name for each person you track, and a colour. Whatever you type — a first name, an initial, “me” — is what is stored. Vest never asks for a full legal name.
- Bonuses and accounts. The institution, the product name, amounts, dates, fee terms, status, and any free-text notes you write.
- Cards you have held. Issuer, product name, open and close dates, and whether the card was an authorised-user card. This is what the eligibility features count.
- Your own log. Each spend, deposit or action you record against a requirement.
- Settings and preferences, including your chosen interest-rate baseline and whether the app lock is on.
Vest does not ask for and has no field to store: account numbers, card numbers, the last four digits of a card, credentials, PINs, government identifiers, dates of birth, credit scores or credit reports.
Where it lives
- On your device, in an app-group container shared with the Vest widget and the Vest share extension so those can read the same data. It does not leave your device by this route.
- In your own iCloud account, if iCloud Drive is enabled for Vest. Vest uses Apple’s CloudKit to mirror your data into the private database of your iCloud account. This is storage we cannot read, cannot query and have no credentials for; Apple processes it under Apple’s Privacy Policy. If iCloud is unavailable or turned off, Vest falls back to storing everything locally and works exactly the same.
We hold no copy of any of it, on any server, at any time.
That also means we cannot get it back for you. There is no copy on our side to restore from, so if you delete the app without an iCloud or device backup, or lose a device that was not backed up, the records are gone. Apple’s standard iCloud and device backups are the mechanism, and keeping one is your responsibility — the same point is made in clause 3 of the Terms of Service.
3. Every network request Vest makes
This is the complete list. There are no others.
1. The offers list and the issuer-rules list
Vest downloads two static JSON documents from a public content-delivery network (cdn.jsdelivr.net): a curated list of publicly advertised bonus offers, and the issuer application-rule definitions the eligibility feature uses.
Both are read-only public files, identical for every user. The request is an ordinary anonymous GET. It carries no account, no identifier and nothing about you or what you track. The only thing Vest adds is an If-None-Matchheader containing the version tag of the copy it already has, so the server can answer “unchanged” and send nothing.
Like any request to any website, the CDN and its origin can observe your device’s IP address and the standard connection metadata that reaching a server necessarily reveals. We receive no report of this, have no access to those logs, and cannot associate a request with a person. Both documents are also bundled inside the app, so Vest is fully functional with no network at all.
2. Reading an offer page you paste in (Smart Add)
If you paste a link into Smart Add and tap Read, Vest fetches that page so it can read the offer text out of it. This is a normal request to a website you chose: the site can see your IP address in the same way it would if you opened the link in Safari. Vest sends nothing about you or your data. This request only happens when you paste a link and ask for it — pasting the offer text instead makes no network request at all.
3. Purchases
Vest Pro is sold through Apple’s In-App Purchase. Payment is handled entirely by Apple. Vest never sees your payment details, and receives nothing beyond whether an entitlement is currently active.
4. Opening links you tap
“Manage subscription” in Settings opens Apple’s subscription page in your browser. Offer source links open in your browser. These are ordinary links, and they take you to sites governed by their own privacy policies.
5. Reporting a rule that looks wrong
Tapping “This looks wrong” on an issuer rule opens a draft in your own mail app, pre-filled with that rule’s identifier and confidence level. It contains nothing about you, your accounts or anything you track. Nothing is sent unless you choose to send it — and if you do, we receive your email address as we would with any email you send us.
4. What Vest does not do
- No analytics, telemetry, usage statistics or crash reporting.
- No third-party SDKs of any kind. Vest contains no code from any other company.
- No advertising identifier, no IDFA, no tracking across apps or websites, and no App Tracking Transparency prompt, because there is nothing to ask for.
- No user account, no sign-up, no login.
- No connection to any bank, card issuer or financial institution.
- No selling, sharing or disclosure of personal information, because we hold none.
5. Notifications
Deadline and follow-up reminders are local notifications, composed and scheduled on your device by the app. Vest has no push server and sends you nothing remotely. Scheduling them means the reminder text lives on your device, as any local notification does. You can decline the permission and keep using Vest, or change it later in iOS Settings.
6. Things you choose to export
Vest can produce a CSV of your expected tax-form totals. It is handed to the iOS share sheet, and it goes wherever you send it. Once you have sent it somewhere, it is governed by that destination’s terms, not ours.
7. Children
Vest is not directed at children and is not designed for them. It is rated for a general audience but is a tool for adults managing their own financial accounts. We do not knowingly collect information from anyone, of any age.
8. Your control over your data
Because the data is yours and sits in your own storage, you do not need to ask us for it:
- See it — it is all visible in the app.
- Correct or delete any of it — every record can be edited or deleted in the app.
- Delete all of it — delete the Vest app. To remove the iCloud copy as well, use iOS Settings → your name → iCloud → Manage Account Storage.
- Export it — the tax CSV export is described above.
We cannot fulfil a deletion request on your behalf, because we hold nothing to delete. If you have emailed us, you can ask us to delete that correspondence at the address above.
Depending on where you live, you may have statutory rights over personal data — including under the EU/UK GDPR, the California Consumer Privacy Act, and similar laws. Those rights apply to data a company holds about you. We hold none, other than any email you have voluntarily sent us.
9. Changes to this policy
If this policy changes, the updated version will be published at addsaltandco.com/vest/privacywith a new “Last updated” date. Material changes to what Vest does with data will also be described in the app’s release notes.
10. Contact
Vest is not affiliated with, endorsed by or sponsored by any financial institution.