Privacy Policy

Last updated: July 2, 2026

"CashLeakLogger" (the "app", "we", "us") is developed by ROBOBOBR. This Privacy Policy explains what data the app collects, how it is used, where it is stored, and who it may be shared with.

The app is offline-first: the core functionality — recording expenses, categories, history, and statistics — works without an internet connection, and your expense data is stored locally on your device and is not sent to our servers. The internet is used only for a few optional features: checking your subscription status, a one-time download of the model used to suggest expense categories, backing up data to your own Google Drive, and basic analytics/crash diagnostics. Details below.

1. What data we collect

Permissions summary:

PermissionWhy it's neededWhere data is processed
CameraPhotographing receipts for text recognitionLocally on the device (Google ML Kit, on-device)
MicrophoneVoice entry of expensesAndroid system service (SpeechRecognizer) — locally or via Google, depending on the device
Post notificationsShowing a progress notification while downloading the ML category model (subscription feature)Locally on the device — no data leaves the device
InternetDownloading the categorization model (subscription feature), backup, analyticsSee sections 1.2–1.7 below

1.1 Expense data (core functionality)
Amounts, categories, dates, notes, and other information you enter in the app are stored locally on your device in the app's database. The developer does not have access to this data and does not transmit or store it on our own servers.

1.2 Google Drive backup (optional)
If you enable the backup feature, the app creates a backup file with your data in your personal Google Drive, using restricted access to the app's private folder (App Data Folder). This file is not visible in the regular Google Drive interface, is accessible only to this app on your account, and is never transmitted to the developer or any third party. You can delete the backup by revoking the app's access to your Google account.

1.3 Analytics, crash reporting, and performance monitoring
We use Firebase Analytics, Firebase Crashlytics, and Firebase Performance Monitoring (Google services) to understand how the app is used, diagnose errors, and measure app performance. These services may automatically collect:

Expense amounts are never sent to analytics in raw form — they are bucketed into ranges (e.g. "10-50", "200-1000") so individual amounts cannot be reconstructed. This data is processed by Google in accordance with its privacy policy.

1.4 Purchases and subscriptions
Paid subscriptions are processed through Google Play Billing. We do not receive or store your payment card details — all payment information is handled directly by Google. The app only receives the subscription status (active/inactive, expiration date) to unlock features. The subscription is tied to your Google Play account; no separate in-app registration is required.

1.5 Camera (receipt scanning)
The app requests camera access to photograph receipts. Text recognition (OCR) on receipts is performed entirely on-device using the Google ML Kit library (on-device model, com.google.mlkit). Receipt photos are not transmitted to the developer or to any external server — processing happens directly within the app on your device.

1.6 Microphone (voice expense entry)
The app requests microphone access for voice entry of expenses, via the Android system component android.speech.SpeechRecognizer. The actual audio processing is performed not by our app but by the speech recognition service configured on your device (typically a Google service). Depending on your device and whether an offline language pack is installed, recognition may happen locally or audio may be sent to Google's servers for transcription — this is determined by Android system settings, not by our app. We do not record or store audio on our own servers: once the recognized text is returned, the audio is not retained.

1.7 Internet access and category-model download (subscription)
The app requires internet access, among other things, to download a machine learning model file used to suggest an expense category based on the text produced from voice input. This feature is available with a subscription. The model is downloaded once and then runs entirely on-device (offline inference) — the text of your expenses is not sent to a server for this processing.

2. How we use data

We do not sell your data to third parties and do not use it for personalized advertising.

3. Sharing data with third parties

The app uses the following third-party services, each with its own privacy policy:

4. Data storage and security

Expense data is stored locally on your device and is deleted when you uninstall the app. Backups in Google Drive are stored on Google's servers and protected by Google's security infrastructure. The developer does not store user data on its own servers.

5. Deleting your data

You can delete all app data by uninstalling the app from your device. To delete a backup from Google Drive, use the backup management screen within the app (tap Delete on any backup), or revoke the app's access in your Google account settings (Google Account → Security → Apps with account access), which will also remove all backup data.

6. Children

The app is not directed at children under 13, and we do not knowingly collect data from children.

7. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top of this document reflects the most recent revision. We will communicate material changes through an app update or within the app itself.

8. Your rights (EU, UK, and Switzerland users)

If GDPR or similar legislation applies to you, you have the right to:

Since your core expense data is stored locally on your device, most of these requests can be fulfilled simply by deleting the app or specific records within it. For data processed by third-party services (Firebase, Google Drive, Google Play Billing), you may also contact Google directly. Legal bases for processing include: performance of a contract (subscription), legitimate interest (crash diagnostics and analytics), and consent (where applicable, e.g. for voice input handled by a third-party service).

9. California users (CCPA/CPRA)

We do not sell or "share" (as defined under the CCPA) your personal information with third parties for advertising purposes. California residents have the right to request information about the categories of data collected, and to request its deletion or correction. To do so, contact us using the details in section 12.

10. Brazilian users (LGPD)

If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) may apply to you. You have the right to:

Since your core expense data is stored locally on your device, most of these requests are fulfilled simply by deleting the app. For data processed by third-party services (Firebase, Google Drive, Google Play Billing), you may also contact Google directly. To exercise your rights, contact us using the details in section 12.

11. International data transfers

Some data may be processed by third-party services (Google Firebase, Google Drive, Google Play Billing) on servers located outside your country, including in the United States. Such transfers take place under Google's own GDPR compliance mechanisms (including standard contractual clauses). We do not transfer data to any recipients other than the services listed in this policy.

12. Contact and data controller

Controller: Yahor Hryniuk, conducting business as ROBOBOBR
NIP: 1133094472
Country: Poland
Email: yahor.hryniuk.dev@gmail.com

For privacy-related questions or to exercise your rights under GDPR, LGPD, CCPA, or other applicable legislation, please contact us at the email address above.