Privacy
Six promises, in plain words.
No analytics, ever.
No analytics SDK, no crash reporter, no account, no advertising identifier. Network calls go only to the Monero daemon the person chooses, to xmrchain.net when explorer mode is chosen, and to CoinGecko for the price line.
View key handling.
The private view key is stored in the Apple Keychain with this-device-only, unlocked-only access. In private node mode it is used on the device; the node sees block requests, not the key. In explorer-assisted mode the view key is sent to xmrchain.net so that service can match outputs. That trade-off is labeled on the import screen and on the Privacy page.
Storage on the device.
Tracked addresses, observed outputs, and transactions live in a local file under Application Support. The view key is not written into that file. iCloud is not used. Nothing is replicated to the developer.
Can never spend.
No spend-key input. No transaction builder. Someone with the device can at most see a balance.
Network surface.
Daemon JSON-RPC for the chosen node. xmrchain.net only when explorer mode is selected. CoinGecko for quotes. Bundled remote node presets are HTTPS. Plain HTTP is allowed only for a daemon on the person’s own machine or local network. Remote cleartext is blocked. The app does not allow arbitrary web loads.
App Privacy label.
The App Store data-collection answer is: data not collected. The developer operates no servers for this app and retains nothing.