Privacy Policy
Effective 18 August 2026
MidRate does not collect personal data. The app has no accounts, no analytics, no advertising, and no tracking of any kind. Its App Store privacy label reads “Data Not Collected”. This page states why that is true, and exactly what the app’s network requests do carry.
No accounts
There is nothing to sign up for. MidRate has no registration, no login, and no cloud sync. We hold no record of who uses the app and could not connect any data to you if we wanted to.
No analytics, no tracking
The app contains no third-party analytics, advertising, or tracking code. It does not read your device’s advertising identifier, does not fingerprint your device, and sends us no usage data. What you convert, which currencies you follow, and how you use the app never leave your device.
What stays on your device
Your preferences (chosen currencies and display settings) and the subscription state the app checks are stored only on your device. They are included in the device backups Apple manages for you; they are never transmitted to us.
What leaves your device
The app fetches currency rates over HTTPS. Like every request on the web, a rate request necessarily shows the answering server an IP address, and it names the currency table being asked for. Beyond that it carries no cookie, no account, and nothing that identifies you personally; the one addition, on premium requests, is the App Attest assertion described below. Rate requests go to three places:
- Rate vendors, directly. Daily rates are fetched
straight from two vendors’ public endpoints:
ExchangeRate-API (
open.er-api.com) and Frankfurter (api.frankfurter.dev). This is how free features get every rate and premium features get some of theirs. Those vendors see the request as any web server does, under their own privacy policies. - Our own endpoint. Premium features fetch rates
from
api.midrate.app. We do not log requests there and do not store IP addresses: the service answers from cached rate tables and keeps nothing about who asked. - Apple. Subscriptions and App Attest, described below, involve Apple’s servers under Apple’s privacy policy.
Premium requests and App Attest
Requests to our endpoint carry an App Attest assertion: a cryptographic proof, issued through Apple, that the request comes from an unmodified copy of MidRate on genuine Apple hardware. It exists to keep abusive traffic off our rate service, and it proves only what it says: the app is genuine. It carries no purchase information and no identity we can read. No name, no Apple ID, no payment details.
Subscriptions
MidRate Premium is bought through Apple. Apple processes the payment, runs the free trial, and manages renewal and cancellation. We never see your payment details, your name, or your Apple ID. Your purchase is a matter between you and Apple; the app verifies it on the device, and that state never leaves the device except as the App Attest assertion above.
This website
midrate.app is a static site and sets no cookies. Its
traffic is measured with Cloudflare Web Analytics, which our host
Cloudflare injects into these pages: a cookieless page-view count
that does not follow you across sites and shows us only aggregate
numbers. The site and api.midrate.app are served
through Cloudflare, which processes requests in transit as
described in
Cloudflare’s
privacy policy. The app is unaffected: as stated above, it
carries no analytics at all.
Your rights
Privacy laws such as the GDPR and the CCPA give you rights over the personal data an organization holds about you. We hold none, so there is nothing for us to disclose, export, correct, or delete. If you believe otherwise, or have any question about this policy, write to us and a human will answer.
Changes
If a future version of MidRate ever collects more than this page describes, for instance by adding a software component that collects anything, this policy and the app’s App Store privacy label will change together, before that version ships. The effective date above marks the last revision.