Your information in the TestFlight beta.
This notice covers the invited adult TestFlight and the CrispBudget website. It explains the information we handle, why we use it, who helps process it, and how to request deletion.
Operator and contact
CrispBudget is an individually operated service, not a separate legal entity. Contact CrispBudget Support at support@crispbudget.app. Operator information that must be made available to the individual under Japan’s Act on the Protection of Personal Information, including the operator’s name and address, will be provided without delay upon a request to this contact.
Account, security, and age
We handle Firebase Authentication identifiers and sign-in information, internal account identifiers, App Check verification information, and account/deletion status to sign you in and protect access. Technical requests can include IP addresses and device or request metadata.
You must be at least 18. We record your adult confirmation time and policy version, not your date of birth. This is self-declaration. If we learn that an ineligible person is using the service, we restrict access and address deletion of their information.
Budgeting and sharing
Wallets, currency and time zone, transactions, categories, budgets, savings, memberships, permissions, synchronization records, and entitlement state support the features you request. A local database keeps your work available offline and synchronizes with our server.
PostgreSQL is authoritative for business data and authorization. Neon hosts the current database in Singapore; Google Cloud Run runs the API in Singapore. Other authentication, security, support, and AI processing can take place in other countries.
Shared-wallet information is available to the members you choose, according to their permissions. Information already received by another member or exported outside the app cannot necessarily be withdrawn by us.
Optional photo and voice assistance
Only when you submit a photo or recording for assistance do we send that media and bounded relevant wallet/history context to Google’s paid Gemini API. This produces editable drafts; there is no on-device OCR or automatic ledger write. You review the result before saving.
Google states that paid-service inputs and outputs are not used to improve its products. Google’s abuse-monitoring policy describes retention of prompts, context, and outputs for 55 days for safety, policy enforcement, and required disclosures. Processing may occur where Google or its providers operate. We do not promise zero provider retention.
Do not submit passwords, payment-card credentials, identity documents, or health and other sensitive information that is unnecessary for a budgeting draft. You can use manual entry without submitting media.
- A completed or terminally failed processing job deletes its original media from the application’s active media store. Interrupted or pending processing can require retries or operator cleanup.
- Editable drafts, processing results, and account-linked usage/cost records are separate from the original media. They remain account data until removed through the account lifecycle; saving a transaction does not by itself erase every processing record.
Service providers and support
Google provides Firebase authentication and app verification, Cloud infrastructure, and optional Gemini processing. Neon provides the database. The app also integrates Firebase Cloud Messaging device registration; this is not a promise that background notification delivery is available in every beta build.
Messages sent to support@crispbudget.app pass through Namecheap forwarding to our business Gmail mailbox. We use the sender address, message, and necessary correspondence to answer support and privacy requests. Do not include secrets or detailed financial records in ordinary email.
Apple separately processes Apple sign-in and TestFlight information under its terms, including beta usage, device, and crash information. Crashlytics collection and upload are disabled in the beta configuration. Local diagnostic material may still exist.
The website has no advertising or analytics integration. It stores a local theme preference; hosting providers can process technical connection and security logs.
Purposes and legal grounds
We use information to provide the budgeting, synchronization, sharing, and optional assistance you request; protect the service and prevent abuse; enforce usage limits; respond to requests; and meet applicable legal duties. We do not sell your personal information or use your financial records for advertising.
Where GDPR or UK GDPR applies, providing requested account and app functions relies on performance of our agreement; proportionate security, abuse prevention, and service administration rely on legitimate interests; legally required processing relies on legal obligations. Where consent is required, we request it before the relevant processing and you may withdraw it.
Providers may process information outside your country. The Singapore locations above describe the database and API, not every processing location. Contact us for applicable provider and transfer information. This household beta does not announce a general commercial release in all regions.
Retention and deletion
- Account and budgeting records, drafts, and account-linked processing records are retained while your account and the relevant features need them. You can request account deletion in the app. Pending processing or shared-wallet ownership transfer can need resolution first.
- The completed server account-deletion workflow removes the user and associated private records. Other members’ valid shared records can remain with attribution minimized. A minimal deletion receipt is retained to prevent replay and allow deletion retries; it is separate from your budgeting records.
- Neon’s current history restoration window is six hours. Copies within that window can temporarily contain records deleted from the active database; this is not a promise that all provider copies disappear in six hours.
- Google Cloud’s configured ordinary log retention is 30 days. Its required audit-log bucket retains records for 400 days.
- Firebase describes authentication IP-address retention of a few weeks and removal of other authentication information from live and backup systems within 180 days after customer-initiated user deletion. Google’s separate Gemini abuse-monitoring retention is described above.
- Support correspondence is retained for the request and related follow-up, dispute, or legal obligations, and removed when it is no longer needed. Records required for security or legal obligations can outlast account deletion. We do not represent a database expiry field or a disabled maintenance job as an automatic deletion guarantee.
Requests, choices, and changes
Contact support@crispbudget.app for access, correction, deletion, a copy of your information, restrictions, objections, or questions about processing. Depending on applicable law, you may also withdraw consent or complain to a supervisory authority. We may request proportionate verification of your identity, but will not ask for your password or secret key.
A self-service data export is not currently promised. We handle requests through support and respond within applicable legal time limits. Important changes to this notice will be announced on this page, in the app, or through TestFlight information.