Skip to content
Back to Walletee

Privacy Policy

Effective 2026-06-07

This privacy policy applies to the Walletee: Expense Tracker app (hereby referred to as “Application”) for mobile devices that was created by Serhii Hryn (hereby referred to as “Service Provider”) as a Free service with optional paid premium features. This service is intended for use “AS IS”.

Walletee is local-first. Your financial data lives in a database on your device, and the Application is fully functional without an account. Creating an account is optional and exists only to back up and sync your data across your own devices. This policy describes what is collected in each case.

Local-First & Guest Mode

You can use Walletee entirely as a guest, without signing in. In guest mode:

  • Your wallets, transactions, budgets, categories, subscriptions, savings goals, notes, and attachments are stored only in an on-device database.
  • None of that financial data is transmitted to the Service Provider's servers or any third party.
  • Only the limited analytics and subscription data described in the Analytics and Purchases sections below is processed.

Cloud backup and cross-device sync (described next) apply only if you choose to create an account and sign in.

Accounts & Authentication

If you choose to create an account, you sign in with Sign in with Apple or Google Sign-In. These providers return a secure identity token to authenticate you. As part of sign-in, the Application receives and stores:

  • Your email address (with Sign in with Apple you may use Apple's private email relay, in which case we never see your real address)
  • Your name, only the first time you sign in with Apple, and only if you choose to share it
  • A unique account identifier used to associate your synced data with your account

This information is used solely to operate your account and sync your data. It is not used for advertising and is not sold. You can delete your account and associated data at any time (see Account & Data Deletion below).

Cloud Sync & Backup (signed-in users)

When you are signed in, the Application backs up your data and syncs it across your devices using Supabase, a hosting platform that provides the database and file storage on the Service Provider's behalf as a data processor. The following data leaves your device, encrypted in transit, and is stored in your account:

  • Wallets: names, types, currencies, and starting balances
  • Transactions and split line items: amounts, original/foreign-currency amounts, dates, types, and the names, notes and descriptions you enter (which may include payee or merchant names)
  • Categories and category groups, budgets, subscriptions (including amounts and billing cycles), savings goals, and transfers
  • App settings such as base currency and language

Your data is isolated to your account and protected by row-level security so that only you can access it. If you only ever use guest mode, none of this data is uploaded.

Attachments (premium, signed-in users)

Adding receipt or document attachments to transactions is a premium feature. When you add an attachment as a signed-in premium user, the file (for example a photo or PDF) and its metadata (file name, type, and size) are uploaded to encrypted cloud file storage (Supabase Storage) so they are backed up and available on your other devices.

When you delete an attachment, the file is removed from your devices and deleted from cloud storage. A background process periodically reconciles storage to clean up any file left behind by a device that happened to be offline at the time of deletion.

Analytics (PostHog)

The Application uses PostHog, a product analytics service, to understand how users interact with the Application and to improve the product. PostHog processes data on behalf of the Service Provider as a data processor under GDPR.

  • What is sent: product-interaction events (screen views, feature usage, button taps), subscription lifecycle events, and app/device metadata such as app version, platform, OS version, language, theme, base currency, and premium status.
  • How it is identified: for guests, events are tagged with a pseudonymous, app-generated random identifier; if you sign in, events are associated with your account identifier so usage can be understood across your devices.
  • What is NOT sent: your transaction amounts, balances, the text of your notes/descriptions, your category or wallet labels, and your attachments are never sent to PostHog. Only counts and structural flags (for example, how many wallets you have, or whether you have a budget) are included.
  • Settings: autocapture, session replay, and IP-based geolocation are all disabled.
  • Where data is stored: PostHog Cloud EU (eu.i.posthog.com), on servers located in the European Union.
  • Tracking: this data is used only for first-party product analytics. It is NOT used for cross-app or cross-site advertising, is not shared with advertising networks, and is not combined with third-party data for tracking purposes.

Purchases and Subscriptions (RevenueCat)

Premium features are provided via in-app subscription, processed by Apple (App Store) or Google (Google Play). The Application uses RevenueCat to manage subscription entitlements. RevenueCat receives:

  • An identifier for you (a pseudonymous app-generated identifier, or, if you are signed in, your account identifier) so subscription status can be associated with you
  • Subscription lifecycle events (purchase, renewal, cancellation, trial start/end) provided by the app store

RevenueCat acts as a data processor on behalf of the Service Provider. The Service Provider never receives your full payment card details; payment is handled entirely by Apple or Google. Subscription events are forwarded to PostHog for revenue analytics.

Information We Do NOT Collect

Regardless of whether you use guest mode or an account, the Application does NOT collect:

  • Your precise location
  • Apple's Advertising Identifier (IDFA) or Google's Advertising ID. The Application does not use advertising identifiers and does not present an App Tracking Transparency (ATT) prompt
  • Your contacts, or your browsing or search history from outside the Application
  • Your full payment card or bank-account numbers (in-app purchases are handled by Apple and Google)
  • Any data used for cross-app or cross-site advertising, and we never sell your data to data brokers

In guest mode, your financial data (wallets, transactions, budgets, categories, savings goals, attachments, etc.) is stored only on your device and is not transmitted to the Service Provider or any third party.

Where Your Data Is Stored

For signed-in users, account and synced data is hosted on Supabase infrastructure located in the European Union. Analytics data is stored by PostHog in the European Union. Data is encrypted in transit (HTTPS/TLS) and at rest. Guest data never leaves your device.

Third Party Access

The Application uses the following third-party services, each of which has its own privacy policy describing how they handle data:

  • Supabase — authentication, database, and file storage for account backup and sync (EU region)
  • PostHog — product analytics (EU region)
  • RevenueCat — subscription management
  • Apple — Sign in with Apple and in-app purchases
  • Google — Google Sign-In and in-app purchases (Google Play)
  • Expo — app development and update delivery platform

Data processed by these services is limited to what is described in this policy. These providers work on our behalf, do not have independent use of the information we disclose to them, and have agreed to adhere to the rules set forth in this privacy statement.

The Service Provider may disclose information:

  • as required by law, such as to comply with a subpoena, or similar legal process;
  • when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
  • with their trusted services providers who work on their behalf, do not have an independent use of the information we disclose to them, and have agreed to adhere to the rules set forth in this privacy statement.

Opt-Out Rights

You can stop all collection of information by the Application by uninstalling it, using the standard uninstall process for your device or app marketplace. You can also choose to use the Application in guest mode without an account, or sign out of your account at any time. To remove data already synced to your account, delete your account as described below.

Your Rights (GDPR / Data Subject Rights)

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that grants data-subject rights, you have the right to:

  • Access: request a copy of the personal data associated with your account or installation
  • Rectification: request correction of inaccurate data
  • Erasure: request deletion of your data (the right to be forgotten)
  • Portability: receive your data in a machine-readable format
  • Restriction / Objection: object to, or restrict, processing of your data

You can exercise erasure directly in the app by deleting your account (see below). To exercise any other right, contact the Service Provider at serhii.hryn.dev@gmail.com. Requests will be processed within 30 days.

Account & Data Deletion

You can permanently delete your account and all associated data at any time, directly in the Application: open More → Profile → Delete Account and confirm. This:

  • Removes your synced data (transactions, wallets, budgets, attachments, and all other records) and your account from the cloud servers;
  • Wipes the data stored locally on the device;
  • Includes a short reversible grace period (currently 30 days) during which you can cancel by signing back in, after which deletion is permanent.

If you cannot access the app, you can also request account and data deletion at walletee.app/delete-account or by emailing serhii.hryn.dev@gmail.com. Requests are processed within 30 days. Deleting your account also removes the associated analytics profile from PostHog and the customer record from RevenueCat.

Data Retention Policy

  • Data stored on your device: retained until you delete it in-app or uninstall the Application.
  • Synced account data (Supabase): retained while your account is active; permanently deleted after you delete your account (subject to the short grace period described above).
  • Deleted attachments: the file is removed from cloud storage when you delete it.
  • Analytics data (PostHog): retained in accordance with PostHog's standard retention settings; aggregated indefinitely, raw events for a limited period.
  • Subscription data (RevenueCat): retained for the duration of your subscription and thereafter as required for accounting, tax, and legal compliance.

If you'd like the Service Provider to delete any data associated with your use of the Application, delete your account in-app or contact serhii.hryn.dev@gmail.com and they will respond within 30 days.

Children

The Application is not directed to children. The Service Provider does not knowingly collect personal data from children under the age of 16 (or the minimum age required in your jurisdiction). If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact the Service Provider (serhii.hryn.dev@gmail.com) so that the necessary actions can be taken, including deleting the information.

Security

The Service Provider is concerned about safeguarding the confidentiality of your information and provides electronic and procedural safeguards to protect the information it processes and maintains. Data transmitted between the Application and third-party services is encrypted in transit using HTTPS/TLS, synced data is encrypted at rest, account data is access-controlled so only you can read it, and authentication tokens are stored in your device's secure keychain/keystore. No method of transmission or storage is 100% secure, however, and absolute security cannot be guaranteed.

Changes

This Privacy Policy may be updated from time to time for any reason. The Service Provider will notify you of any changes to the Privacy Policy by updating this page with the new Privacy Policy. You are advised to consult this Privacy Policy regularly for any changes, as continued use is deemed approval of all changes.

This privacy policy is effective as of 2026-06-07.

Your Consent

By using the Application, you are consenting to the processing of your information as set forth in this Privacy Policy now and as amended by us.

Contact Us

If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at serhii.hryn.dev@gmail.com.