← Pondaro

Pondaro — Privacy Notice

Last updated: 2026-08-19

Your portfolio is stored on your device and syncs through your own private iCloud — there is no Kalmaro server and nothing about your holdings is sent to one. The app’s only outbound requests go to the price provider you have given it a key for, and each one carries an instrument’s ticker and that key: never a value, a quantity or anything about you. With no key entered, the app makes no outbound requests at all.

Where your portfolio is kept

Everything you enter — accounts, holdings, every transaction with its date, quantity, price and fees, goals, earmarks and brought-forward losses — is stored in a database on your device, which the app mirrors to your own private iCloud so it is available on your other devices. That is Apple’s private database, tied to your Apple Account: Kalmaro cannot see it, does not have an account with it and has no server of its own anywhere in this app. If iCloud is unavailable the app falls back to storing everything locally and carries on. Sync is not a switch you turn on, and there is no setting to turn it off — it is how the database is built. Two details worth stating plainly, because they are more personal than the rest: where a holding is recorded against a named person, that record holds their name, their tax band and, if you enter one, their date of birth; and the app reads whether an iCloud account is available, which tells it nothing about who you are.

The dated archive in your iCloud Drive

Once a day, when you leave the app, it writes a dated snapshot of your data to its own folder in your iCloud Drive, keeping the last fourteen. This is a safety net for you, not a transmission to anyone — the folder is yours, it appears in the Files app so you can open, copy or delete anything in it, and it goes where the rest of your iCloud Drive goes. A snapshot is skipped when nothing has changed since the last one.

What leaves your device, and who receives it

Only price lookups, and only for holdings that actually trade on an exchange. The app fetches quotes and price history from the market-data provider you have configured — today those are Financial Modeling Prep and Twelve Data, and that list can change as the app’s data sources change. Each request is an ordinary HTTPS GET carrying the instrument’s ticker symbol, the exchange it trades on, and the API key you created yourself. It carries no portfolio, no quantities, no values, no account, no name, no email, no device identifier and no advertising identifier. Fund prices and cash are never fetched — you type those in. Requests are made with caching switched off so nothing is written to a shared cache, precisely because the key travels in the address. Kalmaro receives none of this: the request goes from your device to the provider directly. The provider will, of course, see that a request was made and the internet address it came from, as any website does.

With no key, there are no requests

Both providers require a key, and the app checks for one before it builds an address — so if you have not entered a key, Pondaro makes no outbound requests at all and every price is one you have typed in yourself. That is a real mode of using the app, not a technicality, and it is enforced in the code rather than left to chance.

Your API key

The key is stored in your device’s Keychain, marked as available only after first unlock and only on that device — it is not synced to iCloud Keychain and it is not carried in an encrypted backup to another device. It is used for nothing but the price requests described above.

Permissions and notifications

Pondaro requests no permissions at all except one: notifications, and only when you switch them on. It declares no location, camera, photo, contacts, microphone or health usage — those prompts cannot appear, because the app never asks. Notifications are off by default; the permission prompt appears at the moment you turn the toggle on in Settings, never at launch. There are exactly three, all built on your device from figures already calculated there: a nudge that prices have gone stale, a dividend or interest payment to confirm, and a reminder before the end of the UK tax year if your Capital Gains allowance is unused. There is never a price-movement alert. Nothing is sent to a notification server, and turning the toggle off cancels everything already scheduled. Separately, the app is set up to receive the silent messages Apple uses to tell a device that its own iCloud data has changed — that is how private iCloud sync knows to update, and it carries none of your data.

Exports, sharing and the widget

You can export a full archive or a CSV of transactions, holdings, price history or capital gains. The file is written to a temporary folder on your device and handed to the share sheet, so it goes wherever you send it — and an archive contains everything, including any owner names. Nothing is uploaded in the process, and your API key is not included in any export. Tapping a holding’s identifier copies its ticker or ISIN to your clipboard, which is a normal copy and is visible to other apps in the usual way. The widget reads a small summary — a total, a previous total and a timestamp — from a container shared with the app on the same device; it makes no network request, and it is set to hide amounts by default.

No third-party code, no analytics, no purchases

Pondaro links no external packages of any kind: no analytics, no crash reporting, no advertising, no attribution SDK. There is no advertising identifier and no tracking, and the app declares no tracking domains. There is also no purchasing code in the app — no in-app purchases and no subscription — and a settings switch lets you blur every figure on screen when you would rather they were not visible.

What the App Store label says, and who to ask

Pondaro declares no collected data types: nothing it holds is sent to Kalmaro, because there is nowhere for it to be sent. If you have a question about privacy, see the main privacy policy, which carries the contact address.