Privacy Policy
This Privacy Policy describes how the Our Wallet mobile application (the "App") handles information when you use it. By using the App, you agree to the practices described below. If you do not agree, please do not use the App.
1. Information We Collect
The App requires an account. When you use the App, we collect and store the following information:
- Account information — when you sign in with Apple or Google, we receive an account identifier and, depending on your provider settings, your email address. We do not receive your password.
- Profile — the display name you choose inside the App (for example, a nickname shown to your partner) and, if you choose to set one, a profile photo.
- Household budgeting data — the data you enter to use the App: expenses (date, category, amount, payer, burden ratio, optional notes and flags), categories with their default ratios and their subcategories, fixed costs, prepayments, monthly settlement records, the insight boards you set up, and the category you choose for a store after scanning its receipt (the store name and category only).
- Notification data — if you allow notifications, a push token identifying your device, together with your device's language and time zone, so that reminders reach you at the right local time.
- Receipt scanning (on your device) — if you choose to scan a receipt, the App uses your camera or photo library only for that action. The image is processed on your device with iOS's built-in text recognition; neither the image nor the recognised text is uploaded to our servers or to any third party, and the App does not keep the image. Only the store name and a category hint derived from it are sent to our backend to suggest a category for the expense.
This information is used solely to provide the App's features — recording expenses, sharing them within your household, and calculating monthly settlements. We do not sell your personal information, and we do not use your budgeting data for advertising.
2. Sharing Within Your Household
Our Wallet is designed to be shared by a two-person household. When you join a household, the other member can see the household's data, including expenses recorded by either of you, categories and ratios, fixed costs, prepayments, settlement records, insight boards, the categories chosen for scanned stores, and your display name and profile photo. Your partner is also notified of activity such as an expense you record or a month you mark as settled. Please only share a household invite code with someone you trust.
3. Third-Party Services
Supabase (database and sign-in)
Your account and household data are stored in a hosted PostgreSQL database provided by Supabase (Supabase, Inc.), which also handles signing in with Apple and Google. Access is protected by authentication and per-household access rules, so your data is only available to you and your household partner. For details, see:
Cloudflare (application backend and photo storage)
The App talks to our own backend, which runs on Cloudflare Workers (provided by Cloudflare, Inc.). Every request the App makes passes through it, so Cloudflare processes connection information such as your IP address in the course of delivering and protecting the service. If you set a profile photo, the image file itself is stored in Cloudflare R2 and served from there. For details, see:
Google AdMob (advertising)
The App displays advertisements through Google AdMob (provided by Google LLC): banners in several places, including the expense list, the settlement, insights, settings, category and fixed-cost screens, and some entry forms, as well as an occasional full-screen ad when you return to the App after being away. To serve and measure ads, AdMob may collect or process information such as:
- Device identifiers (including the Identifier for Advertisers / IDFA, when permitted)
- IP address and approximate (coarse) location derived from it
- Device and OS information, ad interaction events, and crash diagnostics
Your budgeting data (amounts, notes, categories) is never shared with AdMob. Where required, the App also shows a consent form (Google User Messaging Platform) before ads are served. For details on Google AdMob's data practices, see:
Google Analytics for Firebase (usage analytics)
The App uses Google Analytics for Firebase (provided by Google LLC) to understand in aggregate how the App is used — for example how often expenses are added or settlements are completed — so that we can improve it. Analytics may collect or process information such as:
- An app-instance ID, a random identifier assigned to your installation of the App
- Device model, operating system version, app version, language, and approximate (country-level) location derived from IP address
- In-app events such as app opens, screen views, and feature usage (for example adding an expense, scanning a receipt, opening the insights tab, or completing a settlement)
Because household finances are sensitive, analytics events never include the content of your data — no amounts, notes, category names, display names, or email addresses are sent to Analytics. We use this information only in aggregated, statistical form and do not sell it. For details, see:
Firebase App Check and Apple App Attest (abuse prevention)
To keep our backend from being used by anything other than the App, each request carries a token from Firebase App Check (provided by Google LLC), which is in turn issued by Apple's App Attest service. The token confirms that a request comes from a genuine, unmodified installation of the App on a genuine Apple device. It identifies the installation rather than you, and none of your household data is involved.
Expo and Apple (push notifications)
If you allow notifications, the App sends them through the Expo push notification service (provided by Expo, Inc.) and Apple's Apple Push Notification service. A push token identifying your device, along with the text of each notification, passes through these services. Because notifications are written for you and your partner, that text can include amounts and category names — for example, a settlement amount or the expense your partner just recorded. If you would rather not have this appear on your Lock Screen, you can hide notification previews in iOS Settings, turn individual notification types off in the App's settings, or decline notifications entirely. For details, see:
4. App Tracking Transparency (ATT)
The App may present Apple's standard App Tracking Transparency prompt asking whether to allow tracking across apps and websites owned by other companies. Your response determines whether the Identifier for Advertisers (IDFA) is available to AdMob and to Google's advertising features in Analytics:
- Allow: AdMob and Analytics may use the IDFA to personalize ads and measure performance.
- Ask App Not to Track: Neither AdMob nor Analytics will access the IDFA. Non-personalized ads are still shown, and analytics continues without the IDFA.
You can change this choice at any time in iOS Settings → Privacy & Security → Tracking.
5. SKAdNetwork
The App participates in Apple's SKAdNetwork, a privacy-preserving framework that attributes ad installs without revealing user-level data. SKAdNetwork postbacks do not contain personal information about you.
6. Children's Privacy
The App is a general-audience budgeting tool and is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal information through the App, please contact us and we will take appropriate steps to remove it.
7. Data Retention and Account Deletion
We retain your account and household data for as long as your account exists, so that your records and settlement history remain available to you and your household partner.
You can delete your account at any time from the App's settings screen. Account deletion removes the personal data linked to you, including your profile photo and any push tokens registered for your devices. If your partner remains in the household, the shared records are kept so that their history stays intact — expenses you recorded remain, attributed to your display name only. Data collected by AdMob and by Google Analytics for Firebase is retained by Google according to its own policies.
8. Your Choices
- Limit ad tracking: Use the ATT prompt or iOS Settings → Privacy & Security → Tracking to prevent the App from accessing the IDFA.
- Manage notifications: Turn individual notification types off in the App's settings screen, or disable notifications entirely in iOS Settings.
- Camera and photos: Receipt scanning and profile photos are optional. You can revoke the App's access at any time in iOS Settings → Privacy & Security → Camera or Photos.
- Leave a household: You can leave your household from the App's settings screen at any time.
- Delete your account: Use the account deletion option in the App's settings screen to remove the personal data linked to you.
- Manage sign-in: You can review or revoke the App's access in your Apple ID or Google account settings at any time.
9. Security
Your data is transmitted over encrypted connections (HTTPS) and protected by authentication and per-household access rules on our backend. No method of transmission or storage is completely secure, but we take reasonable measures to protect your information.
Profile photos are an exception to the per-household rules above: each one is stored at a web address containing a random, unguessable identifier, and anyone who knows that address can open the image. The address itself is only ever shared within your household. If you would rather not store a photo at all, simply leave your profile photo unset — the App works exactly the same without one.
10. International Users
The App is available worldwide. By using the App, you understand that your information may be transferred to, stored, and processed in countries other than your own — including by the hosting, advertising, and analytics providers described above — in accordance with their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be reflected in an updated version available at this URL.
12. Contact
If you have any questions about this Privacy Policy or the App's privacy practices, contact us at [email protected].