Privacy Policy
is made by Forstra Digital. This page explains, plainly, what the app collects, why, and who else ever touches it. If anything here is unclear, email consult@forstradigital.com.
What we collect, and why
| Data | Where it lives | Why |
|---|---|---|
| Email, display name | Forstra's Supabase project | Account creation and login |
| Wallets, categories, budgets, transactions | Forstra's Supabase project, protected by row-level security so only you can read your own data | The core function of the app — tracking your spending |
| Receipt photos (only if you use Scan Receipt) | Not stored. Sent directly to our backend, forwarded once to a third-party AI provider for extraction, then discarded. Only the image's size in kilobytes, whether the scan succeeded, and a timestamp are logged, for cost tracking. | Auto-filling a receipt's line items and categories |
| GnuCash PostgREST URL & access token (only if you enable GnuCash Sync) | Encrypted on-device storage, plus a backup copy in Forstra's Supabase so reinstalling your phone doesn't lose the connection | Letting your phone talk to your own self-hosted GnuCash setup. We never see or store your actual GnuCash database password. |
| Advertising identifiers | Collected by Google AdMob per its own policies, not by us directly | Shown to free-tier users; ads help offset the real, per-scan cost of the AI used for receipt scanning. Removed entirely on the (planned) paid tier. |
| App usage events (which screens/features get used — e.g. a receipt scan, a GnuCash sync, switching Budget Mode) | PostHog, an EU-hosted analytics service. Events are keyed to an internal account ID, never your email or display name. | Understanding which features are actually used, to guide what we build next |
| Anonymous pageviews and clicks on this website | PostHog, same EU-hosted service. Nothing here is tied to an account — this site never calls identify(), which is why no cookie/consent banner is shown for it. | Understanding which pages and links are actually useful |
Browsing without an account
You can look around the app without signing up. In that mode, nothing is collected or stored — every write requires an authenticated account, enforced at the database level, not just in the app's interface.
Who else sees this data
- Supabase — hosts our database and authentication. Your account and transaction data live there, protected by row-level security.
- A third-party AI provider — processes a receipt photo at the moment you scan one, to extract line items and suggest categories. The photo itself passes through; we don't keep a copy.
- Google AdMob — shows ads to free-tier users and collects the advertising identifiers standard to any AdMob-integrated app, per Google's own policies.
- PostHog — an EU-hosted analytics service. Collects anonymous pageviews/clicks on this website, and app usage events keyed to an internal account ID (never your email or name). Session recording is off everywhere we use it.
- We do not sell your data to anyone, for any reason.
Your GnuCash ledger specifically
If you turn on GnuCash Sync, connects to a PostgREST service that you run, in front of a GnuCash database that you control. We never connect to your database directly, never see your real database password, and the narrow role your phone uses can only insert new expense transactions through one specific function — it cannot read balances, read transaction history, or change anything else in your ledger. Full technical detail is in the setup guide.
How long we keep things
Account and transaction data is kept for as long as your account exists. Deleting your account deletes your wallets, categories, budgets, and transactions. Receipt photos are never retained in the first place, so there's nothing to delete there. To request account deletion, email consult@forstradigital.com.
Changes to this policy
This is a beta and things will change as the app does. We'll update the "last updated" date above when this page changes; check back occasionally if you want to stay current.
Contact
Questions, deletion requests, or anything else: consult@forstradigital.com. You can also use the feedback form for general comments.