Privacy Policy
This Privacy Policy explains what information the Gedara Budget mobile application ("App") handles, how it is used, and the choices you have. It should be read together with the App's Terms and Conditions. The App is local-first: your financial data stays on your device.
1. Summary
- The App is local-first: your transactions, budgets, accounts, and settings are stored only on your device, in an encrypted database.
- There are no accounts, no sign-in, and no cloud sync. Your data never leaves your device (Section 3).
- Bank statement files you import are processed entirely on your device and are never uploaded (Section 6).
- The free tier shows ads through Google AdMob, which may use advertising and device identifiers (Section 5).
- We do not sell your data or use your financial records for advertising profiles.
2. Data stored on your device
The App stores the following data on your device, in a database encrypted at rest with SQLCipher:
- Transactions (income and expenses): amounts, dates, descriptions, categories, notes, and merchants you enter or import
- Accounts you set up, including account names and balances
- Budgets and budget limits, categories, and categorization rules
- Content of statements you import: text extracted on your device from the CSV, PDF, DOCX, OFX, QIF, or MT940 files you choose, plus import history (file name, file hash, row counts)
- App preferences, including your chosen default currency and language
- An optional App PIN, stored only as a cryptographic hash, and your app-lock/biometric-unlock toggle
- Subscription entitlement status cached from Google Play
All of this stays on your device. When the App is locked, screen content is protected from screenshots and the recents preview (the App sets the Android FLAG_SECURE flag in release builds).
3. Your data never leaves your device
The App has no account system, no sign-in, and no cloud sync. There is no server that receives your transactions, budgets, accounts, statements, or any other financial data. We never see your data, and we cannot recover it for you.
The App contains a dormant server component for verifying Google Play purchases that is not active today. If a future App version activates it, the App would send only your Google Play purchase token and the identifier of the product you purchased — never any of your financial data — and this Privacy Policy will be updated and published before that version is released.
4. Data we (the developer) collect
None. The App contains no analytics SDKs, no crash reporters, no trackers, and no servers receiving your data today. We do not sell your data, share it with third parties for their marketing purposes, or use your financial records to build advertising profiles.
5. Advertising (free tier only)
The free tier of the App is supported by advertising served through Google AdMob. Ads are shown only after you make a choice in Google's consent form (shown in the App); if consent for personalised ads is not given or cannot be determined, only non-personalised ads are shown. Google and its partners may use advertising identifiers and device information as described in Google's Privacy Policy. We do not send your financial records to Google or to any advertiser.
You can review or change your ads personalisation choice at any time in your device's Settings → Google → Ads (or Settings → Privacy → Ads, depending on your device), where you can also reset your advertising ID. Ads are removed when you purchase a subscription. We do not select or endorse advertised products.
6. Third-party services
The App relies on the following third parties, each governed by its own terms and privacy policy:
- Google Play Billing — processes subscription purchases. Purchase data is processed by Google under Google's terms; we receive only entitlement status, never your payment details.
- Google AdMob — serves ads on the free tier (Section 5).
- ML Kit text recognition (Google) — used to read scanned PDF statements. Recognition runs entirely on your device; statement images and text are never uploaded.
- open.er-api.com — an exchange-rate service used for currency conversion. Requests are made over HTTPS and contain only the three-letter code of your display currency in the URL path — no amounts, no account data, no identifiers.
The App contains no analytics SDKs, no crash reporters, and no other trackers.
7. Local backups
The App can export an encrypted backup of your data, protected with a passphrase that you choose (AES-256-GCM encryption, with the key derived from your passphrase using PBKDF2). The backup file is saved wherever you choose on your device (for example, to share to your own cloud storage). We never receive backup files and cannot restore them for you. If you lose your passphrase, the backup cannot be decrypted — by anyone, including us.
8. Permissions the App requests
- Internet: used for advertising (free tier) and exchange-rate lookups. It is not used to upload your financial data.
- Notifications: used only for budget alerts and summaries you opt into.
- Biometric: used only to unlock the App if you enable biometric unlock.
- Billing: required by Google Play for in-app subscriptions.
The App does not request access to your contacts, location, camera, microphone, or files outside the ones you explicitly pick for import or backup.
9. Security
- Encrypted database: all App data is stored in a SQLCipher-encrypted database on your device.
- PIN lock: your PIN is stored locally as a cryptographic hash (PBKDF2 with a random salt) and never leaves your device.
- Biometric unlock: uses your device's built-in fingerprint or face unlock (Android Biometric API). Biometric data never leaves your device and is not accessible to the App.
- Screenshot protection: in release builds, the App blocks screenshots and the recents preview while its screens are showing.
- No OS backups: the App opts out of Android cloud backups (
allowBackup=false), so your local database is not copied to Google's device backup service. - Encrypted settings and entitlement cache: sensitive App settings are stored using Android's EncryptedSharedPreferences; the subscription cache is integrity-protected.
- App-lock (PIN/biometric) is available and recommended.
10. Data retention and deletion
Your data remains on your device until you delete it. You can delete everything by:
- Using Settings → Reset All Data in the App; or
- Uninstalling the App (this removes the App and its data from your device).
Because there are no accounts and no cloud storage, there is nothing to delete on our side.
11. Children
The App is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
12. Changes to this policy
If this policy changes, we will update the "Effective date" above, publish the new version, and note significant changes in the App or its release notes. Continued use after changes take effect constitutes acceptance of the updated policy.
13. Contact
If you have questions about this Privacy Policy, contact the Developer via the support email shown on the App's Google Play listing, or at: