Privacy Policy — MyFinances

Last updated: 3 September 2026

This Privacy Policy explains how MyFinances ("the App", "we", "us") collects, uses, and protects your personal data. MyFinances is developed and operated by Javier Jimenez, an individual acting as data controller, contactable at javierjimhez@gmail.com.

1. What data we collect

MyFinances is a personal finance tracker. We only collect data you enter yourself or that is strictly necessary to run your account:

DataPurpose
Email addressAccount creation and authentication
Transactions (amount, category, description, date, currency)Core app functionality — tracking your income and expenses
Recurring rulesAutomatically generating recurring transactions you've configured
CategoriesOrganizing your transactions (shared, non-identifying reference data)
Receipt photographs (optional, premium) If you choose to scan a till receipt, the photograph is sent to our own server to read the total, the date and the shop name. It is held in memory only for as long as that single request takes, is never written to disk and never stored — not on your phone, not on our server, and not in our database — and is discarded as soon as the text has been read. Nothing is saved to your account until you review the result and confirm it yourself.

To scan a receipt the App asks for access to your camera or your photo library, whichever you choose. Both are requested only at the moment you tap to scan, are optional, and can be withdrawn at any time in your device settings — the rest of the App works exactly the same without them.

We do not link bank accounts, do not use advertising SDKs or trackers, and do not sell or share your personal information with third parties for advertising or any other purpose.

MyFinances does not use cookies, tracking pixels, web beacons, or any similar tracking technologies—neither first-party nor third-party. As a mobile app, we do not employ web-based analytics or session tracking.

2. Legal basis for processing (GDPR)

We process your data under Article 6(1)(b) GDPR — processing necessary for the performance of a contract with you (providing the App's functionality you've signed up for).

Receipt scanning is the one exception. Because it is optional and not needed to run your account, we process receipt photographs under Article 6(1)(a) GDPR — your consent. You give it on a screen shown before the first scan, and you can withdraw it at any time from the App or by removing the camera and photo permissions in your device settings. Withdrawing it stops future scans and leaves everything else untouched; there is nothing to erase afterwards, because no photograph was ever kept.

Reading a receipt produces a suggestion that you review and confirm before anything is saved. No decision is made about you automatically, and nothing legally or similarly significantly affects you as a result, so Article 22 GDPR (automated individual decision-making) does not apply.

3. Who processes your data on our behalf

We use Supabase for two things: authentication and identity management, and hosting the database in which your account's data is stored. That database holds everything you record in the App — your transactions, your budgets, your recurring rules, your categories and your preferences. Supabase acts as our processor and does not use any of it for its own purposes.

Supabase's infrastructure for our project is hosted on AWS in the eu-west-2 (London, UK) region, so the data described above is stored in the United Kingdom. Transfers of personal data from the EU to the UK are covered by the European Commission's UK adequacy decision (renewed 19 December 2025, valid until 27 December 2031), so no additional safeguards are required for this transfer.

We use RevenueCat, Inc. (United States) to process in-app purchases and to tell the App whether your account has premium access. It receives your account identifier and the purchase receipt issued by Apple or Google. It never receives your transactions, your balances, or any receipt photograph. Transfers outside the EEA are governed by the data processing agreement we have entered into with RevenueCat.

If you choose to sign in with Google, Google LLC handles that sign-in and necessarily learns that you signed in to MyFinances, together with the email address and basic profile information you agree to share. Google acts as an independent controller for what it does with that data, under its own privacy policy. You are not required to use it — signing in with an email address and password avoids Google entirely.

Receipt scanning adds no one to this list. The photograph is read on our own server, which we operate ourselves. There is no third-party OCR service and no artificial-intelligence provider. The photograph is never written to disk and is never sent to the database described above — it does not reach Supabase, or any other third party, at any point.

Apart from the processors named above, we do not share your data with any third party, and we do not use any analytics or advertising service that would receive your personal data.

4. Data retention

Your data is retained for as long as your account remains active. If you delete your account (see below), your transactions, recurring rules, and account credentials are permanently and immediately removed from our systems — this is not a "soft delete" or deactivation.

If you have entered transactions into a shared ledger (a "group" ledger with other members), deleting your account removes your login and personal settings, but the transactions you entered remain visible to the other members — they are part of that ledger's shared financial record. Only a ledger where you are the sole member is erased along with your account.

5. Your rights

Under GDPR (and equivalent UK GDPR provisions), you have the right to:

To exercise any of these rights, email javierjimhez@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with a data protection supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD); in other EU countries, your local data protection authority; in the UK, the Information Commissioner's Office (ICO).

Deleting your account

You can permanently delete your account and all associated data at any time from within the App (Settings → Delete Account). If you no longer have access to the App, you can request deletion by emailing javierjimhez@gmail.com from your registered email address with the subject "Delete my account" — we will process the request within 30 days and confirm by email once complete.

6. Children's privacy

MyFinances is not directed at, and we do not knowingly collect data from, children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

7. California / US residents

We do not sell or share your personal information, and do not use it for cross-context behavioral advertising. California residents have the same access, deletion, and correction rights described in Section 5 above, which you can exercise through the same contact channel.

8. Security

All data is transmitted over encrypted connections (HTTPS/TLS), including the connection between our server and the database. Data is encrypted at rest on the database's storage. Authentication credentials (passwords) are never stored or seen by us directly — they are managed entirely by Supabase's authentication service.

Access to the database is restricted to our own application server. It is not reachable from the App or from the public internet, and it is protected by a second layer of database-level access rules so that a mistake in one of those controls does not, on its own, expose anything. We also take our own backups, stored separately from the database provider on a server we control, and delete them automatically after 14 days.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above, and, where appropriate, notified in-app.

10. Contact

Javier Jimenez — javierjimhez@gmail.com