1. Controller and contact
Alsen Digital Ltd., registered in the United Kingdom, is the controller of personal data processed through Aris. Contact info@alsendigital.net with privacy questions or rights requests.
2. Scope
This policy covers the Aris Android and iOS apps, the server services used by the mobile app, and this legal centre. This site requires no sign-in, cannot access your Aris account, portfolio or financial data, and uses no advertising or analytics cookies.
3. Categories of data we process
Account and profile data
Email address, display name, profile image, username, language and preference information.
Financial and user-provided data
Portfolio assets, transactions, cash and liability records, income and expenses, budgets, goals, notes and other content you add.
Bank connections
If you choose Open Banking, authorised account and transaction data may be processed through licensed providers. Aris does not see or store your online banking passwords.
Subscription and store data
Subscription state, product and entitlement information, and store transaction identifiers. Full card details are processed by Apple or Google and are not stored by Aris.
Device, security and diagnostics
App version, device and operating system information, push tokens, session and integrity signals, IP address, and error/performance logs used for security, fraud prevention and troubleshooting.
4. Why we use data
- Create your account, authenticate you and protect sessions.
- Provide portfolio, budgeting, notification, analysis and personalised insight features.
- Verify subscription entitlements and provide customer support.
- Diagnose faults, secure the service and prevent abuse.
- Meet legal obligations and protect our rights.
Processing relies, as applicable, on performance of the service contract, consent, legal obligations, or legitimate interests in operating the service securely.
6. Security
Data in transit is protected using HTTPS/TLS. We use technical and organisational controls such as access restrictions, session security, device-integrity checks, logging and monitoring, backups and appropriate encryption. No system can guarantee absolute security; please report suspected issues to our support address.
7. Retention and deletion
We retain account and financial data while your account is active and as needed to provide the service. When an account is deleted, related data is removed from active systems or irreversibly anonymised. Limited security records, backups, or records required by law may remain with restricted access only for their necessary purpose and are removed through the ordinary retention cycle.
Use Settings → Delete Account in the app or start a deletion request on the web.
8. Your rights
Depending on applicable law, you may have rights to access, correct or erase data, restrict or object to processing, receive portable data, and withdraw consent. We may need to verify that a request comes from the account holder. You may also complain to the relevant data-protection authority.
9. International transfers
Aris and its providers may operate in different countries. Where data is transferred internationally, applicable transfer safeguards and contractual protections are used.
10. Changes to this policy
We may update this policy as the product or legal requirements change. The current version is published here with a revised date. Material changes may also be communicated in the app where appropriate.