1. Introduction
This Privacy Policy ("Policy") describes how Where's my money? (abbreviated as "wimm," and referred to herein as "we," "us," or "our") collects, uses, stores, and protects your personal information when you use the Where's my money? mobile application ("App") and our associated website at wimm.cash ("Website"), collectively referred to as the "Services."
We are committed to protecting your privacy and ensuring the security of your personal and financial data. This Policy is designed to comply with the Swiss Federal Act on Data Protection ("FADP" / "nDSG"), the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the California Consumer Privacy Act ("CCPA"), and other applicable data protection laws.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any provision of this Policy, you must discontinue use of the Services immediately.
2. Data Controller
The data controller responsible for the processing of your personal data is:
Sascha Jonas
Kantonsstrasse 71
8864 Reichenburg
Switzerland
privacy@wimm.cash
If you have any questions or concerns about this Privacy Policy or our data processing practices, please contact us at the address above.
3. Information We Collect
3.1 Information You Provide Directly
- Account Information: When you create an account, we collect your email address, display name, and profile picture through our authentication provider (Firebase Authentication, provided by Google LLC).
- Financial Transaction Data: Receipt information you scan or manually enter, including merchant names, transaction amounts, dates, tax amounts, tip amounts, currency information, payment methods, and individual receipt line items.
- Budget and Planning Data: Budget definitions, spending limits, savings goals, and alert preferences you configure within the App.
- Business Expense Data: Business expense classifications, tax deductibility flags, project codes, department information, and client names if you use our business expense features.
- Tags and Notes: Any custom tags, notes, or annotations you attach to transactions.
- Receipt Images: Photographs of receipts you capture using your device camera or select from your photo library for AI-powered data extraction.
3.2 Information Collected Automatically
- Device Information: Device type, operating system version, and app version for compatibility and debugging purposes.
- Authentication Tokens: Securely stored JSON Web Tokens (JWT) for maintaining your authenticated session.
- Subscription Information: Your subscription tier (Free, Standard, or Pro) and associated entitlement data, processed through RevenueCat.
- Error and Crash Data: When enabled, application crash reports and error logs are collected via Sentry for the purpose of improving app stability. This can be disabled.
- Usage Quota Data: API usage counts and quota consumption metrics associated with your account, stored on Cloudflare infrastructure for rate limiting and service management.
3.3 Information We Do Not Collect
- We do not collect or store bank account numbers, credit card numbers, or other direct financial account credentials.
- We do not employ behavioral tracking, advertising identifiers, or third-party analytics cookies.
- We do not collect GPS location data or precise geolocation information.
- We do not access your contacts, call logs, or other unrelated device data.
4. How We Use Your Information
We process your personal data for the following purposes and legal bases:
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Providing core App functionality (receipt scanning, expense tracking, budgeting) | Performance of a contract (Art. 6(1)(b)) |
| AI-powered receipt data extraction via Google Gemini | Performance of a contract (Art. 6(1)(b)) |
| User authentication and account management | Performance of a contract (Art. 6(1)(b)) |
| Processing subscription payments and managing entitlements | Performance of a contract (Art. 6(1)(b)) |
| Generating spending analytics, insights, and budget alerts | Performance of a contract (Art. 6(1)(b)) |
| Error tracking and app stability improvement | Legitimate interest (Art. 6(1)(f)) |
| Enforcing usage quotas and preventing abuse | Legitimate interest (Art. 6(1)(f)) |
| Compliance with legal obligations (e.g., tax reporting) | Legal obligation (Art. 6(1)(c)) |
5. Local-First Architecture
Our App employs a local-first architecture. This means:
- On-Device Storage: All financial transaction data, budgets, categories, merchants, payment methods, and analytics are stored locally on your device in an encrypted SQLite database. This data does not leave your device unless you explicitly initiate an action that requires cloud processing (such as AI receipt scanning).
- No Cloud Sync of Financial Data: We do not synchronize your financial records to cloud servers. Your transaction history, budget configurations, and spending analytics remain exclusively on your device.
- Local Backup: Backup functionality creates encrypted archives stored on your device. You maintain full control over these backups.
- Temporary Image Processing: When you scan a receipt, the image is temporarily transmitted to our cloud infrastructure for AI processing. The image is not persistently stored on our servers and is deleted after processing is complete.
6. Third-Party Service Providers
We engage the following third-party service providers to deliver and support our Services. Each provider processes data only as necessary to perform their designated function:
6.1 Firebase Authentication (Google LLC)
- Purpose: User authentication, identity management, and session handling.
- Data Processed: Email address, display name, profile picture, user identifier.
- Privacy Policy: https://firebase.google.com/support/privacy
6.2 Google Gemini AI (Google LLC)
- Purpose: AI-powered features, including receipt data extraction, bank statement parsing, transaction categorization, rule suggestions, budget suggestions, generation of financial insights, and mobile/internet plan comparison.
- Data Processed: Transmitted only when you initiate the corresponding AI-powered action: (i) receipt images and bank statement documents; (ii) transaction metadata, such as merchant names, amounts, dates, descriptions, and categories; (iii) aggregated monthly spending and budget snapshots, including per-category totals, income and expense totals, and up to six months of historical spending patterns; (iv) your category names, currency, and language preferences; (v) when you initiate a mobile or internet plan comparison: the technical specifications of your current plan, namely provider name, plan name, monthly cost, data allowance, voice minutes, download/upload speed, connection type, and contract length where available — but no name, address, customer number, phone number, IBAN, or other personally identifying field from the bill. Processing occurs on Google infrastructure, which may be located outside your country of residence (including the United States) under the safeguards described in Section 10 (International Data Transfers). Our project operates under the paid tier of the Gemini API: per Google's applicable terms, your prompts and responses are not used to train Google's models and are not persistently stored by Google in connection with this processing.
- Privacy Policy: https://policies.google.com/privacy
6.3 RevenueCat, Inc.
- Purpose: In-app purchase management, subscription processing, and entitlement verification.
- Data Processed: Anonymous user identifier, subscription events, tier changes, and purchase receipts from the Apple App Store.
- Privacy Policy: https://www.revenuecat.com/privacy
6.4 Cloudflare, Inc.
- Purpose: API gateway, request routing, quota enforcement, and content delivery.
- Data Processed: User identifier, authentication tokens (for validation), API request metadata, and quota usage counters stored in Cloudflare D1.
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
6.5 Sentry (Functional Software, Inc.)
- Purpose: Error tracking, crash reporting, and application performance monitoring.
- Data Processed: Application error logs, crash stack traces, device information, and diagnostic breadcrumbs. No financial transaction data is transmitted to Sentry.
- Note: Sentry integration is optional and can be disabled by the user.
- Privacy Policy: https://sentry.io/privacy/
7. Data Retention
- Financial Transaction Data: Stored locally on your device indefinitely or until you delete it. We recommend retaining tax-related records for the period required by your applicable tax jurisdiction (typically 7 years).
- Receipt Images: Stored locally on your device until you delete them or the associated receipt. Intermediate scan images that are not saved as a receipt are automatically cleaned up after 24 hours. Images sent to our cloud infrastructure for AI processing are not retained on our servers.
- Account Information: Retained for the duration of your account. Upon account deletion, your Firebase Authentication profile data will be removed in accordance with our deletion procedures.
- Subscription Data: Retained by RevenueCat for the duration of your subscription and as required for financial record-keeping purposes.
- Error Logs: Retained by Sentry for a maximum of 90 days, after which they are automatically purged.
- Quota and Entitlement Data: Retained on Cloudflare D1 for the duration of your active account and reset on a monthly basis.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption at Rest: Local database and sensitive credentials are stored using platform-native secure storage mechanisms (iOS Keychain).
- Encryption in Transit: All communications between the App and our cloud services are encrypted using TLS 1.2 or higher.
- JWT Authentication: API requests are authenticated using JSON Web Tokens validated against Firebase Authentication JWKS endpoints.
- Input Validation: All data submitted to our APIs undergoes validation and sanitization to prevent injection attacks.
- Access Controls: Cloud infrastructure access is restricted to authorized personnel and secured with multi-factor authentication.
- Quota Enforcement: Rate limiting and quota management prevent unauthorized or excessive use of our Services.
While we take all reasonable precautions, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
9.1 Rights Under Swiss Law (FADP/nDSG)
- Right of Access (Art. 25 nDSG): You have the right to request information about whether we process your personal data and to receive a copy.
- Right to Rectification: You have the right to request correction of inaccurate personal data.
- Right to Deletion: You have the right to request deletion of your personal data.
- Right to Data Portability (Art. 28 nDSG): You have the right to receive your personal data in a commonly used electronic format.
- Right to Object: You have the right to object to the processing of your personal data.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch
9.2 Rights Under the GDPR (EEA/UK Residents)
- Right of Access (Art. 15): You have the right to request confirmation of whether we process your personal data and to obtain a copy of such data.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate personal data.
- Right to Erasure (Art. 17): You have the right to request deletion of your personal data, subject to applicable legal retention obligations.
- Right to Restriction (Art. 18): You have the right to request restriction of processing in certain circumstances.
- Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, machine-readable format. The App's export functionality facilitates this right.
- Right to Object (Art. 21): You have the right to object to processing based on legitimate interests.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority.
9.3 Rights Under the CCPA (California Residents)
- Right to Know: You have the right to know what personal information we collect, use, and disclose.
- Right to Delete: You have the right to request deletion of your personal information.
- Right to Opt-Out of Sale: We do not sell your personal information. There is no need to opt out.
- Right to Non-Discrimination: You will not be discriminated against for exercising your CCPA rights.
To exercise any of these rights, please contact us at . We will respond to all legitimate requests within 30 days (or within the timeframe required by applicable law). privacy@wimm.cash
10. International Data Transfers
Your personal data may be transferred to and processed in countries outside your country of residence, including the United States, where our third-party service providers operate. When such transfers occur, we ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission;
- Data Processing Agreements with all third-party processors;
- Adequacy decisions by the European Commission, where available.
11. Children's Privacy
Our Services are not directed at individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take immediate steps to delete such data. If you believe a child has provided us with personal data, please contact us at privacy@wimm.cash.
12. Cookies and Tracking Technologies
Our Website uses minimal cookies and tracking technologies:
- Local Storage: We store your theme preference (light or dark mode) and your selected language in your browser's local storage. Both are strictly necessary functional preferences, never leave your device, and do not constitute tracking.
- No Advertising or Behavioural Cookies: We do not use Google Analytics, Facebook Pixel, or any other third-party advertising or behavioural cookies on our Website.
- Privacy-Friendly Analytics (Cloudflare Web Analytics): We use Cloudflare Web Analytics for aggregated insights into page views, referrers, devices, and regions. No cookies are set, no IP addresses are stored, and no cross-site or cross-device tracking takes place. The beacon script is delivered by Cloudflare, Inc. (USA). Cloudflare privacy notice: https://www.cloudflare.com/privacypolicy/
- Third-Party Content: Fonts are served from our own server; no connection to Google Fonts is established and your IP address is not transmitted to any third party in this context. The Cloudflare Analytics beacon mentioned above is therefore the only third-party service loaded on our Website.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this Policy;
- Provide notice through the App or via email for significant changes;
- Where required by law, obtain your consent before implementing material changes to data processing.
We encourage you to review this Policy periodically to stay informed about how we protect your data.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Email: privacy@wimm.cash
Website: https://wimm.cash
For complaints related to data protection, you also have the right to contact your local data protection authority.