Last updated: 23 July 2026
1. Information We Collect
FamilySpendr stores the spending and income entries you log, your family’s shared shopping-list items and their comments, the loyalty cards you add to the family wallet (a card name, its barcode or QR value, optional notes, and which members it is shared with), the family group you belong to, and a small set of preferences (currency, date format, week start day, theme, language) in your private Firebase project. Each member also has a private in-app notification board that records recent family activity (for example, a new entry, a shopping comment, or an item marked done) so it can be shown inside the app. We deliberately store no personally identifiable information: only a nickname you choose and a single-glyph emoji avatar represent you. We never store your real name, email address, or phone number in our database.
Your sign-in identity (Google or Apple) is held by Firebase Authentication. Your account email is visible to Firebase only for the purpose of signing you in; it is not copied into the app’s own data.
2. How We Use Your Information
The data you log — amounts, categories, locations, notes, receipt photos — is read and written to your family’s private collection in Firestore so that you and the other members of your family can see it. We use it only to render the app’s screens. No analytics, no marketing, no third-party tracking SDKs.
Currency conversion uses daily exchange rates from the free public Frankfurter API. The conversion request sends only the two ISO currency codes (e.g. EUR → USD). No personal data, no amounts, no account identifiers reach this service.
If you enable AI Insights in Settings, the app sends a short summary to Google Gemini consisting only of: the month label, the names of your spending categories, the per-category totals, and your total income and total spending. Nicknames, member identifiers, individual log notes, receipts, locations, and any dates beyond the month label are never sent.
3. Third-Party Services
- Firebase (Google) — Authentication, Firestore database, Cloud Storage for receipt images, Cloud Functions for membership writes, and Cloud Messaging for the family-entry push notification described in §5. See Google’s Firebase Privacy and Security for how they handle data.
- Frankfurter (frankfurter.dev) — Free public currency-rate API used for cross-currency conversion. We send only currency-code pairs; no personal data.
- Google Gemini (optional, opt-in) — Only when you have provided your own API key and enabled AI Insights. The request payload is restricted to the contents described in §2 above.
4. Data Storage & Security
- All Firestore reads and writes are governed by strict Security Rules — every document is locked down by default and access is granted only to the signed-in user’s own data or to the data of the family they belong to.
- Receipt images are compressed to a maximum of 800 KB before upload and stored under a path that includes your family ID and user ID; Storage Security Rules enforce both size and MIME constraints.
- Your Gemini API key (if you provide one) stays on your device: in the Android and iPhone apps it lives in the secure keychain (Keychain on iOS, Keystore on Android), and in the web app it is kept encrypted in your browser’s storage for familyspendr.com. It is never written to Firestore, never logged, and never transmitted to any server we control.
- In the Android and iPhone apps, your app-lock PIN is hashed with SHA-256 and a per-install random salt; only the hash + salt are stored in the device’s secure keychain. The PIN itself never leaves the device and never appears in plaintext anywhere.
- When App Lock is enabled in the Android or iPhone app, the app hides its own screen from the device’s app-switcher / recents preview, so the last screen you viewed isn’t left visible there. (On Android 13+ this affects only the recents preview; on older Android versions it also disables screenshots while the app is open. On iOS the preview is blurred.)
- Invite codes are server-only — clients cannot read them; only the
joinFamilyCloud Function can look them up via the Admin SDK. - Android device backup is disabled for this app. Android’s Auto Backup would otherwise copy the app’s private storage — including the encrypted app-lock PIN and your Gemini key — to your Google Drive. Nothing from FamilySpendr is included in a device backup, so that data stays on the device it was created on. (A practical consequence: restoring to a new phone starts the app fresh rather than carrying your PIN across.)
5. Permissions
- Photo library / Camera — used to attach a receipt photo to a spending entry, and to scan a loyalty card’s barcode or QR code when you add one. Scanning happens entirely on your device: only the decoded code value is kept, never the camera image. Each photo you attach is yours; we never scan or upload anything you didn’t pick.
- Location — used only to autofill the optional “Location” field on the spending form when you tap the GPS button. We do not record your location in the background.
- Notifications — used to alert family members about activity: a new spending or income entry, and shopping-list events (an item added, a comment, or an item marked done). The same alerts appear in the in-app notification center, which works even when device push is unavailable. The opt-ins live in Settings (“New family entries” and comment notifications) and can be turned off at any time. A separate, optional daily-spending reminder can fire at a time you choose; it is a purely local notification and never leaves your device. You can also ask for a daily reminder before a future-dated spend — it repeats each day at your chosen time until the spend’s date passes, shows that entry’s category, amount, and date in the notification, is visible only to you, and is scheduled locally on your device; nothing is sent to any server.
- Face ID / Fingerprint — used only to unlock the Android or iPhone app when you have enabled biometric unlock in Settings. Your biometric data never leaves the device; the OS confirms the match locally.
All permissions can be revoked at any time through your device’s system settings.
6. Data Deletion & Retention
Your entries, shopping items, and loyalty cards are kept until you delete them or leave the family — we do not expire them.
Notification-board entries are the exception: each one is automatically deleted 90 days after it is created. The board is a record of recent family activity, not an archive, and the underlying entries it points at are unaffected. You can also clear the board yourself at any time from the notifications screen.
You can leave a family at any time from the Family tab. If you are the last member of the family, exiting deletes the entire family record and all its logs — including shopping-list items and every comment on them.
Uninstalling the app removes all local preferences. To delete your account entirely, sign out from Settings, then revoke the app’s access from your Google or Apple account settings; the per-user document and any owned logs can be removed via support request.
7. Children’s Privacy
FamilySpendr is intended for use by adults managing a household. We do not knowingly collect data from anyone under the age of 13. If a parent believes their child has signed in to the app, they may delete the account as described in §6.
8. Contact
For questions about this privacy policy, please use the contact form.