Privacy Policy

Effective as of 6 May 2026.
1. Overview

DebtVest is an educational financial scenario-modelling app. This Privacy Policy explains how DebtVest handles information when you use the DebtVest mobile app, website, and related services.

DebtVest is not a financial adviser, investment adviser, tax adviser, credit provider, mortgage broker, or legal adviser. The app is a modelling tool only.

In this Privacy Policy, "DebtVest", "we", "us", and "our" refer to Lunara, the operator of the DebtVest app and website.

2. Information you enter into the app

DebtVest allows you to enter financial scenario assumptions including:

  • debt balances;
  • interest rates;
  • loan terms;
  • minimum repayments and surplus cash flow;
  • lump sums, offset, or redraw assumptions;
  • investment return assumptions;
  • capital growth and income yield assumptions;
  • tax jurisdiction and tax-rate settings;
  • volatility assumptions;
  • comparison horizon settings;
  • saved scenario labels;
  • check-in records; and
  • optional investment portfolio values.

This information is stored locally on your device. DebtVest does not intentionally transmit your detailed scenario inputs, saved scenarios, loan balances, portfolio values, check-in values, or detailed financial assumptions to DebtVest-controlled external servers.

If you delete the app, clear app storage, change device, or lose access to your device, locally stored scenarios and check-in history may be permanently lost unless preserved by your device-level backup settings, such as iCloud or Google backup.

3. Information we collect automatically and how we use it

DebtVest may automatically collect limited technical, diagnostic, and usage information to operate, secure, improve, and support the app. This may include:

  • app version;
  • device type and operating system;
  • anonymous or pseudonymous app identifiers;
  • crash reports, performance data, and diagnostic information;
  • screen views and navigation flow;
  • button taps and feature usage;
  • onboarding progress and completion;
  • selected general financial goal category;
  • broad debt type selection;
  • selected jurisdiction setting;
  • subscription and entitlement status; and
  • general product analytics information.

For information specific to notifications and reminders, see Section 5 below.

DebtVest may use analytics and diagnostic tools including PostHog or similar services for these purposes. We use this information to improve the app, troubleshoot errors, understand feature engagement, improve the user experience, and maintain service quality.

We do not intentionally send detailed financial inputs, saved scenario values, loan balances, portfolio values, income figures, or sensitive financial details to analytics providers. If our data collection practices change materially in the future, we will update this Privacy Policy and any applicable app store privacy disclosures.

4. Purchases and subscriptions

DebtVest may offer paid features through Apple App Store and Google Play in-app purchases. Purchase processing, payment handling, billing, renewals, cancellations, and refund processing are managed by Apple, Google, RevenueCat, and their related service providers.

DebtVest does not receive or store your full credit card number, bank account details, complete payment credentials, or app store account password.

DebtVest may receive or process limited purchase and entitlement information, including:

  • product identifiers;
  • purchase and subscription status;
  • renewal and entitlement status;
  • store environment information;
  • anonymous or pseudonymous app user identifiers; and
  • information needed to unlock paid features.

Your subscription is managed through your Apple App Store or Google Play account. To cancel, manage billing, or request a refund, you must do so through your app store account settings. DebtVest cannot directly process app store refunds, cancellations, or billing changes.

5. Notifications and reminders

If you enable notifications or check-in reminders, DebtVest may use your device's notification system to send reminders, updates, or app-related messages. DebtVest may request notification permission so it can send check-in prompts, scenario reminders, subscription-related messages, or other app-related notifications.

Depending on your device and configuration, notification delivery may involve Apple Push Notification service, Firebase Cloud Messaging, Expo notification services, Google Play services, RevenueCat, or related infrastructure providers.

DebtVest may process limited technical information required to deliver and manage notifications, including:

  • notification permission status;
  • device notification tokens or push tokens;
  • anonymous or pseudonymous app user identifiers;
  • app version, device type, and operating system;
  • reminder preferences;
  • notification delivery status; and
  • notification open and interaction events.

DebtVest does not intentionally include detailed financial scenario inputs, loan balances, portfolio values, or sensitive financial information in notification payloads. You can disable notifications at any time through your device settings.

6. Website and support contact

If you contact DebtVest by email, support form, or another support channel, we may collect the information you choose to provide, including your name, email address, message content, app version, device type, operating system, screenshots you choose to send, and other information you voluntarily provide.

Please do not send sensitive financial information, identity documents, bank details, tax file numbers, social security numbers, passwords, or private account credentials by email or support message.

We use support information to respond to your request, troubleshoot issues, improve the app, manage disputes, maintain business records, and comply with legal obligations.

7. Device permissions

DebtVest may request the following device permissions:

PermissionPurpose
NotificationsTo send check-in reminders, scenario reminders, product updates, or app-related messages
Local storageTo save scenarios, assumptions, and check-in history on your device

DebtVest does not currently require access to your camera, microphone, contacts, precise location, photos, health data, or biometric identity data. If this changes, we will update this Privacy Policy and relevant app store disclosures.

8. Data sharing, disclosure and third-party services

DebtVest does not sell your personal information.

DebtVest may share limited information with service providers used to operate, distribute, secure, support, and improve the app, including providers for app distribution, in-app purchase and subscription management, analytics and diagnostics, crash reporting, push notifications, customer support, email hosting, website hosting, cloud infrastructure, and legal or professional services. These providers may include Apple, Google, RevenueCat, PostHog, Expo, Firebase, website hosting providers, email providers, and similar service providers.

These third-party providers process information under their own terms and privacy policies. You should review the privacy practices of Apple, Google, RevenueCat, PostHog, Expo, Firebase, and any other third-party services made available through the app. DebtVest is not responsible for the privacy practices of third-party platforms, payment processors, or external services we do not control.

DebtVest may also disclose information:

  • where required by applicable law, regulation, legal process, court order, or government request;
  • to protect the rights, property, safety, security, or integrity of DebtVest, our users, or the public;
  • to investigate fraud, abuse, security incidents, or technical issues;
  • to enforce our terms or protect our legal interests; or
  • in connection with a merger, acquisition, restructuring, or sale of business assets, where the receiving party agrees to handle information consistently with this Privacy Policy or applicable law.
9. Data retention

Detailed scenario inputs, saved scenarios, and check-in records are stored locally on your device and remain there until you delete them, delete the app, clear app storage, or your operating system removes local data. Because this information is stored locally, DebtVest does not directly control how long it remains on your device.

Support emails and related records may be retained for as long as reasonably necessary to respond to your request, maintain business records, resolve disputes, comply with legal obligations, investigate bugs or misuse, and improve the app.

Analytics, diagnostic, notification, and purchase-entitlement data may be retained by DebtVest and its service providers for periods determined by operational, security, legal, and service-provider requirements.

10. Data security

DebtVest uses reasonable technical and organisational measures appropriate to the nature of the app and the information processed. Scenario data stored on your device benefits from the security protections of your device operating system and storage encryption where enabled. However, no method of electronic storage or transmission is completely secure, and DebtVest cannot guarantee absolute security.

You are responsible for:

  • securing your device with a passcode, Face ID, fingerprint lock, or similar protection;
  • maintaining the security of your Apple ID, Google account, email account, and app store account;
  • enabling device-level encryption and backups where appropriate;
  • keeping your app store credentials confidential;
  • avoiding insecure networks or compromised devices; and
  • protecting any cloud backups connected to your device.

DebtVest is not responsible for unauthorised access caused by compromised devices, shared accounts, weak passwords, malware, phishing, insecure backups, or other security practices outside our control.

11. Your choices and rights

You can:

  • stop using DebtVest at any time;
  • delete locally stored data by deleting the app or clearing app storage;
  • disable notifications through your device settings;
  • manage or cancel subscriptions through Apple App Store or Google Play;
  • contact us with privacy questions; and
  • request access to, correction of, or deletion of personal information we hold about you, subject to identity verification and applicable legal requirements.

If you are located in Australia, you may have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles to request access to or correction of personal information we hold about you.

To make a privacy request, contact: support@debtvest.app

12. International and regional users

DebtVest may be available in multiple countries. Your information may be processed in countries other than where you live, including jurisdictions where service providers such as Apple, Google, RevenueCat, PostHog, Expo, and Firebase operate. By using DebtVest, you acknowledge that information may be processed in jurisdictions outside your country of residence, subject to applicable laws and service-provider terms.

UK and EEA users

If you are located in the United Kingdom or European Economic Area, the following additional information applies to personal data subject to the UK GDPR or EU GDPR.

Legal bases for processing

To the extent DebtVest processes personal data subject to the UK GDPR or EU GDPR, we may rely on:

  • contract performance — to provide app functionality, subscription management, and support;
  • legitimate interests — to improve the app, understand usage, diagnose issues, maintain security, and prevent misuse;
  • consent — where required for notifications or certain analytics settings; and
  • legal obligation — where processing is required to comply with applicable laws.

Your rights

You may have rights to:

  • access your personal data;
  • correct inaccurate personal data;
  • request deletion of personal data;
  • restrict or object to processing;
  • request data portability;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with a data protection supervisory authority.

To exercise your rights, contact: support@debtvest.app

International transfers

Where service providers process data outside the UK or EEA, we rely on appropriate safeguards, contractual protections, adequacy decisions, or other lawful transfer mechanisms where required.

13. Children

DebtVest is intended for adults only and should not be used by anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided personal information to DebtVest, contact us at support@debtvest.app and we will take reasonable steps to delete it where required.

14. Changes to this policy

DebtVest may update this Privacy Policy from time to time. The updated version will be posted at the Privacy Policy URL provided in the app and store listings. The "Effective as of" date will show when the Policy was last changed. Continued use of DebtVest after an updated Policy is posted means you accept the updated version.

15. Contact

For privacy questions, support requests, or data requests, contact:

DebtVest Support
We aim to respond to privacy enquiries within a reasonable period and, where applicable, within timeframes required by law.