Privacy policy

Cashout keeps your records on your phone. There is no account, no server of ours, and nothing about what you earn leaves the device.

Last updated September 28, 2026

What the app stores, and where

Shifts, tip out rules, jobs, stations, hours and notes are written to a database inside the app’s own container on your iPhone. They are not uploaded to DM Apps. There is no login, no password and no profile attached to them.

The iCloud Drive backup

Automatic backup is on by default. Cashout writes a single JSON file to the app’s folder in your iCloud Drive. That file is under your Apple ID, governed by Apple’s terms, and readable only by you and by the app on your devices. DM Apps cannot see it, does not receive a copy, and has no service that reads it. Turning the backup off in Settings stops the writes; deleting the file in iCloud Drive removes it.

You can also save a backup file yourself through the share sheet and keep it wherever you like. Both files use the same format.

Anonymous usage events

The app records a small set of product events — a screen was opened, a shift was saved, a paywall was shown, a backup succeeded. These carry counts, flags and fixed option names only.

Never included in an event, by rule:

  • Dollar amounts of any kind — tips, sales, tip out, wages, overrides.
  • Percentages you entered in your rules.
  • Names of your workplace, roles, stations or sections.
  • Note text, shift dates and hours worked.

The line is simple: if you typed the value, it does not go into an event. If we defined the value — a screen name, a rule type from a fixed list, a yes/no flag — it may. There is no automatic screen capture and no session recording.

These events are processed by PostHog, an analytics service, on servers in the United States. They are not tied to a name, an email or an account, because Cashout has none of those. They are not used for advertising and are not shared with anyone else.

You can switch this off. Settings has a toggle that stops collection and discards anything still waiting to be sent. The app works exactly the same with it off.

Which ad brought the install (Apple Ads)

If you installed Cashout after tapping one of our ads in App Store search, the app asks Apple once, on first launch, which of our ad campaigns that was. It uses Apple’s AdServices framework: the phone creates a one-time token and sends it to Apple’s own attribution service, and Apple answers with numbers — our campaign, ad group and keyword ids — or with “not from an ad”.

Those numbers are attached to the anonymous usage events described above, so we can see whether our ads bring people who actually use the app. No dollar amount, no name, no Apple Account, no advertising identifier (IDFA) and nothing that links you across other apps or websites is involved, which is why there is no App Tracking Transparency prompt. With the analytics toggle off, the app does not ask Apple at all.

Purchases

Subscriptions are handled by Apple through the App Store. DM Apps receives no card details and no billing address. The app knows only whether an entitlement is active.

What the app never does

  • No ads inside the app, no advertising identifier (IDFA), no ad networks. The only advertising-related data is the Apple Ads attribution above.
  • No selling or sharing of data with third parties.
  • No tracking across other apps or websites.
  • No contacts, photos, location or health access.

Deleting everything

Settings has a delete option that clears the database on the device and the backup file in iCloud Drive. Removing the app from the phone leaves the iCloud Drive file in place until you delete it there; the delete option inside the app removes both.

Children

Cashout is a tool for people who work in restaurants and bars. It is not directed at children and collects nothing that would identify anyone.

Changes

If this policy changes, the date at the top changes with it, and the change is described in the app’s release notes.

Contact

Questions about any of this go to support@dmapps.app. See also the support page.