Privacy Policy
This policy describes how Saldofy (the personal finance management app available for Android, hereinafter "the App") collects, uses, and protects your personal data, in accordance with Regulation (EU) 2016/679 ("GDPR").
1. Data Controller
The data controller is:
Stefano Onotri (individual developer)
Contact email: privacy@saldofy.click
2. What data we collect
Account data
- Email address and name — provided upon registration (email and password or Google login).
- Profile photo — if you choose to upload one, it is saved on our cloud systems.
- Preferred language — used to display the App and send you communications in your language.
Financial data
- Wallets and transactions — amounts, dates, the wallet they belong to, and other data you enter to track your finances.
- Transaction notes and categories — these fields are protected with AES-256-GCM encryption to keep their content secure.
- Calculator history — if you use the integrated calculator, operations can be synced with your account.
Collaboration data
- Sharing invitations — if you share a wallet, we process the email address of the invited person and the assigned role (e.g., editor, viewer), for the sole purpose of managing the invitation and shared access.
Biometric data
If you activate biometric unlock, recognition (fingerprint or face) happens exclusively on your device via Android security systems (Keystore). No biometric data is collected, stored, or transmitted to our servers.
Usage data
The App uses Google Firebase Analytics to collect aggregate usage statistics (e.g., screens visited, app events, device model, Android version, installation identifiers). This data helps us improve the App and is not used for advertising.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Account creation and management, data sync across devices, wallet sharing | Performance of a contract (Art. 6.1.b GDPR) |
| Sending service emails (e.g., wallet sharing invitations) | Performance of a contract (Art. 6.1.b GDPR) |
| Statistical analysis of App usage to improve it | Legitimate interest (Art. 6.1.f GDPR) |
| Compliance with legal obligations | Legal obligation (Art. 6.1.c GDPR) |
4. Where data is stored
App data is stored on Google Firebase services (Google Ireland Ltd.). A copy of your data is also stored locally on your device to allow you to use the App without a connection.
5. Recipients and service providers
We use the following providers, who process data on our behalf as data processors:
| Provider | Service | Data processed |
|---|---|---|
| Google Firebase (Google Ireland Ltd.) | Authentication, database, file storage, cloud functions, statistics | Account data, financial data (with encrypted sensitive fields), usage data |
| Resend, Inc. (USA) | Sending service emails from the saldofy.click domain | Recipient email address and invitation email content |
| Frankfurter (api.frankfurter.dev) | Currency exchange rates | No personal data: requests do not contain information about your account |
We do not sell or lease your personal data to third parties for marketing purposes.
6. Extra-EU transfers
Some providers (e.g., Resend, some Google infrastructure) may process data in the United States. In such cases, the transfer takes place on the basis of adequate safeguards under the GDPR, such as the EU-U.S. Data Privacy Framework and/or the Standard Contractual Clauses approved by the European Commission.
7. How long we keep the data
Data is kept as long as your account is active. If you delete your account, associated personal data is deleted or anonymized within a reasonable time, subject to legal retention obligations.
You can request account and data deletion from the Account Deletion page or by writing to the contact address indicated in point 1.
8. Security
- Transaction notes and categories are protected with AES-256-GCM encryption to keep sensitive content secure.
- All communications with servers take place over encrypted connections (TLS/HTTPS).
- On the device, keys are protected by the Android Keystore and, if enabled, by biometric unlock.
- Access to shared wallets is governed by roles and server-side security rules.
9. Your rights
Under Articles 15–22 of the GDPR, you have the right to:
- access your personal data and receive a copy;
- request rectification or deletion;
- limit or object to processing;
- receive data in a structured format (portability);
- withdraw consent at any time, where processing is based on consent.
To exercise your rights, write to privacy@saldofy.click. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or your country's supervisory authority.
10. Minors
The App is not intended for children under 16 and we do not knowingly collect data from minors. If you believe a minor has provided us with personal data, contact us for its removal.
11. Changes to this policy
We may update this policy over time. Substantial changes will be communicated via the App or by email. The last update date is indicated at the top of the page.
12. Contacts
For any questions about this policy or the processing of your data:
privacy@saldofy.click
