Flovvy

Privacy Policy

Last updated: September 24, 2026

Note: this policy describes how Flovvy processes personal data, why, with whom and for how long. For any privacy request, write to [email protected].

1. Who we are

Flovvy is a personal expense-management app that lets you record income and expenses, scan receipts, organize budgets, accounts and shopping lists, and share expenses in groups. For the processing described here, the Data Controller — the party that decides the purposes and means of processing — is:

The providers that process data on our behalf (Section 9) act as Processors under a Data Processing Agreement (Art. 28 GDPR). You are the data subject.

2. What data we process

CategoryExamples
Account dataUser ID, email and name (received at sign-in with Google or Apple; with Google, the sign-in service also receives your account's profile picture, which the app does not use), the profile photo you choose to upload yourself, the household type you select (for example single, or couple with children), used only to compare your spending with reference budgets for similar households, and the country you select when you set up the app. The country is used to pre-fill your default currency and to show figures in a format that matches where you are; you can change it at any time in your profile.
Expense & financial dataExpenses and income (amount, date, description, merchant, currency, category/sub-category), accounts and balances, budgets, tags, shopping lists, notes.
Receipt dataPhotos of the receipts you choose to scan and the text/line-items extracted from them (may include a tax code printed on the receipt).
Special-category data (Art. 9)Information that may reveal health or another special category, e.g. the items on a pharmacy receipt. What AI derives from the content you entrust to it is processed only with your explicit consent; what you write or classify yourself stays where you put it and is not analysed, except for the limited cases described in Section 5.
Shared-expense dataGroups, splits, participants and shared items you create or join.
Purchases & subscriptionsSubscription status, in-app purchases, AI credits and related transactions.
AI credit giftsIf you give AI credits with a gift code, or redeem one: the code, the credits, the dates and the names of the sender and of the recipient, so that each of them can see who the gift came from or went to (Section 11).
Consent recordsWhich consents you gave or withdrew, when, and the exact text/version and language you were shown (Section 7).
Technical / diagnostic dataDevice model, operating system, app version, crash and error information, and a technical user identifier. We also read the device identifier provided by the operating system (Android ID, or the iOS "identifier for vendor"): in clear text, to keep your devices in sync.
Website & server logsWhen you visit flovvy.app, or when the app contacts our servers, the infrastructure records the IP address, the time of the request and basic technical details (browser or app version, endpoint called), in order to deliver the page or the response and to protect the Service against attack and abuse. These logs are held by the providers listed in Section 9 for the periods given in Section 11, and are never used to build a profile of you. The sign-in service (Supabase) also keeps, for each open session of your account, the IP address and the type of app or browser, to keep the account secure (for how long, see Section 11).

Data we do NOT collect. We do not collect your location/geolocation (the location permission has been removed from the app), we do not use advertising, analytics or cross-app tracking SDKs — the only third-party SDKs the app embeds are the error monitoring described in Section 15, the purchase management described below and the Google and Apple sign-in libraries, which come into play only if you choose to sign in with them — and we do not sell your personal data.

Sign in with Apple. If you choose to sign in with Apple, we keep on our servers an authentication token issued by Apple, for the sole purpose of revoking the app's access to your Apple ID when you delete your account. This token is not used for anything else and is permanently deleted when the account is deleted.

Cookies, local storage and other tracking technologies

The website. The pages of flovvy.app are static and load fonts and scripts from our own domain. The site uses one technical cookie, which remembers your cookie choice. Only if you choose "Accept" in the banner does it also use Google Analytics 4, to count visits and page views in aggregate: in that case your browser downloads Google's script and receives the cookies listed below. Before you choose, and if you reject, nothing is sent to Google. In the banner "Accept" and "Reject" carry the same weight, and you can change your mind at any time from the "Cookie settings" link at the bottom of the pages (on the home page, from the "Cookie settings" button at the bottom): if you withdraw consent, the Google Analytics cookies are deleted. We have turned off Google signals and any advertising use of the data; Google Analytics uses your IP address only to derive the country and does not store it, and Google keeps the collected data for 2 months. No advertising or social-media script.

CookieSet byPurposeDurationEssential
flovvy_cookie_consentflovvy.appRemembers your cookie choice6 monthsYes
_gaGoogle Analytics, on our behalfTells visitors apart pseudonymously, to count visits6 monthsNo: only with your consent
_ga_<ID>Google Analytics, on our behalfKeeps the state of the current visit6 monthsNo: only with your consent

As with any web server, the infrastructure that serves the site (Cloudflare, see Section 9) processes the IP address and the browser user-agent of each request in order to deliver the page and to protect the site from attack (for how long, see Section 11); that data is not combined with your Flovvy account and is never shared for advertising. Cloudflare sets no cookies on the site today. If an attack made a security check necessary (the "I am not a robot" check), it could set the technical cookie cf_clearance, which remembers for a short time (normally 30 minutes) that you passed the check: it is essential and needs no consent.

The app. The app uses no advertising, no analytics and no cross-app tracking SDK. It does not read the advertising identifier of your device (IDFA / Android advertising ID) and it never shows the App Tracking Transparency prompt, because there is nothing to ask you about. Besides the Google and Apple sign-in libraries, which only handle signing in when you choose them, the app embeds two third-party SDKs, both strictly necessary and neither of them for advertising or measurement. The first is the error-monitoring SDK described in Section 15 (Sentry), which keeps the app working and secure: it records crashes and errors, never your expenses, your receipts or your photos. The second is RevenueCat, which manages subscriptions and in-app purchases (Section 9): it receives the pseudonymous identifier of your account (before you sign in, an anonymous identifier it generates itself), never your email, the purchase confirmation issued by Apple or Google (product, price, dates, transaction identifier) and the technical data it needs to work (platform and system and app versions, language, store country, IP address of the request), so that what you have paid for is unlocked on every device where you sign in. Neither SDK reads the advertising identifier of your device, and neither is used to measure how you use the app or to profile you. The app also stores information on your own device — the local database of your expenses, your settings, and your sign-in token in the operating system's secure storage — which is what lets Flovvy work offline; that information stays on your device except when it syncs to your account.

The device identifier. The only device-level identifier we read is the one described in the table above (Technical / diagnostic data). We use it solely to keep your account in sync across your devices (for example so that a scan started on one phone is collected by only one of them) — never to track or profile you across other apps or websites, never as an anti-abuse fingerprint, and never shared with an advertising network.

If we add anything else. Any other analytics or similar tool — on the website or in the app, for example to understand which screens are used — will be switched on only with your prior, freely given consent, with "reject" as easy as "accept" and a way to change your mind; and we will update this section — with the exact list, provider, purpose, duration and whether it is essential — before it goes live, not after. If the list of website cookies changes, the banner asks you to choose again. The same information, with instructions for managing cookies in your browser, is also on the Cookie Policy page.

3. Why we process it and on what basis

We do not use your data for marketing, profiling or automated decisions with legal or similarly significant effects (Section 12).

4. Receipt scanning and AI processing

When you scan a receipt, the image and/or extracted text is sent to Google Cloud's artificial-intelligence services — Gemini models via Vertex AI for structuring and Cloud Vision for OCR — to recognize items, amounts and categories. This processing takes place within the European Union (EU endpoints of Vertex AI and Cloud Vision), so there is no transfer outside the EU for AI/OCR. The same EU Google Cloud is used for voice entry, the AI assistant and shopping-list comparison. It runs on a paid tier where, under the provider's terms, data is not used to train the models; Google acts as a data processor. To detect abuse of its services, Google runs automated checks on requests: only a request those checks flag may be kept by Google for a limited period, within the EU, and examined by its staff, solely to verify the abuse. We have asked Google to exclude our account from this monitoring; once that is in place, we will update this section. AI credentials are held only on our secure server, never on your device.

A scan does not stop when you close the app: it finishes on our servers, and what it read from the receipt waits there until your app comes to collect it. That waiting copy holds the text read from the receipt and the items and amounts taken from it, never the photo, and it is short-lived — see Section 11.

Sensitive data (special category — Art. 9 GDPR). A receipt cannot be known to be health-free before it is analyzed, and the same goes for a recording, a question or a list, so every AI feature — scanning, voice, assistant and list comparison — requires your prior explicit consent ("AI features"); without it, it does not run at all. You can always record expenses manually (no photo, no AI), which never requires consent. See Section 5.

Receipts you send us by email

If a receipt does not come out right and you choose to send it to [email protected], we use it only to test and fix the reading: we look at it ourselves and have it read again by the same system the app uses (Google Cloud, in the European Union: see this Section and Section 9). We do not use it to train any model.

The legal basis is your consent, given by the act of sending it. You decide whether to send a receipt and you never have to; this section is here so that you know what happens before you do.

What we keep is the photo and the text we read from it, inside the test bench we use to measure the scanner. It stays there for as long as it is useful for that measurement. Write to [email protected] at any time and we will delete it.

Please do not send pharmacy receipts, medical bills or any other receipt that says something about your health or other special-category data (Art. 9 GDPR, see Section 5): for these, the act of sending is not enough as consent, and we do not use them. We look at every receipt before using it: if it contains such data, we delete it at once, without running it through the scanner and without keeping it. More generally, do not send receipts you would rather not share: a receipt says more than a total, namely where you were, when, and what you bought.

5. Health-related information and explicit consent (Art. 9)

Some content you entrust to the AI features may reveal your health (for example a pharmacy receipt) or another special category of data under Art. 9 GDPR (for example religious beliefs). This is why the app asks for two separate consents, optional, never pre-ticked and revocable at any time:

With only "AI features", the photo is used temporarily to read it and is not stored; with photo saving as well, it is stored for backup and multi-device access. The "AI features" consent also covers storing the product detail, including the items you correct or add by hand in the detail, and the shopping-list comparison reports. When the wording of a consent changes substantially, the app asks you to reconfirm it, and until you do, the features that depend on it stay off.

Text you write yourself. In expense descriptions and notes you can write whatever you like, including health information (for example "cardiologist visit"). That text stays where you put it: we store and sync it for you, but we do not read it, analyse it or send it to any AI system, except in the single case, covered by the "AI features" consent, described in the next paragraph. This is why we do not ask for a specific consent: there would be nothing to stop if you refused. We still protect it as sensitive data (Section 15).

What does reach the AI, only if you use the AI features. Under the "AI features" consent, and only to understand your request or to classify what you scan or dictate, the AI also receives the names you gave to categories, sub-categories, accounts and tags, and the names of the shopping lists you compare — never amounts. If you use the assistant, its previous answers, without any amounts, are sent back to the model so that it can understand your next question, and they may include the name of an expense.

Withdrawing consent. You can withdraw either consent at any time from Menu → Privacy & data → Consents. Withdrawing "AI features" turns the AI features off (you can always enter expenses by hand) and the app immediately deletes, on the device and in the cloud, the stored product detail and the shopping-list comparison reports. On the device where you withdraw it, the app also deletes its automatic copies of the database and offers to delete the copies you saved yourself: if you keep them, they still contain the detail. On your other devices the detail disappears at their next sync, but copies of the database saved on those devices stay there until you delete them from those devices. Each expense keeps its amount, date, description, account, category, subcategory, tags and photo, if you allowed it to be saved. Shopping lists stay as they are, including products you added to them from a receipt: they are content you created yourself, with an action of your own. Withdrawing photo saving deletes the photos already stored, on the device and in the cloud. All of this also applies to your own rows in shared groups. You are warned first and can export your data (Section 13). We do not use AI to automatically detect or mask medicines.

6. Aggregate price statistics

From the line items of receipts scanned with product detail, we build aggregate, anonymous price statistics — for example the average price of a product at a given retailer, in a given month and country. The purpose is to be able to tell you whether what you paid is in line with the market, and to power price comparisons.

These statistics live in a physically separate database of their own, hosted in the European Union, which the app never reads and which holds no identifier of any kind: no user ID, no pseudonym, no receipt ID, no photo, and no record of when you scanned. A row describes a purchase, not a person. It holds the country, the month, the retailer, the product and the price (as printed and converted to euro), plus the category, and the quantity and unit of measure where the receipt states them; and two technical markers — how the row was produced, and the date of the nightly batch that wrote it.

The month of purchase is recorded, never the day. The batch date is a different thing: it is shared by every row written the same night and says nothing about when any particular person shopped. Rows are written in randomized order, so the items of a single receipt cannot be put back together, and there is no key that would let us — or anyone else — walk from a statistic back to you or to your basket.

Pharmacy and medicines are excluded — and here is the honest limit of that. Items classified in the Health category as medicines never enter this archive, and neither do Health items whose sub-category could not be determined: in case of doubt the item is left out. But that filter works on the category the AI assigned, so it is a rule, not a guarantee — a pharmacy purchase that the AI happened to file under, say, "Groceries" would not be caught by it. What protects you in that case is everything else about this archive: the rows carry nothing that points back to you, and no figure is ever shown unless it rests on at least 3 separate observations, in a country with at least 100 contributing users. A one-off item never surfaces as a result.

Country spending averages. We may also compute average spending per country and category, so the app can tell you how your own spending compares. If we do, it is calculated on the expense data already in your account — no new archive of personal data is created — and only the aggregate result is kept, never the individual figures behind it. A result is kept only when it rests on at least 20 distinct people.

Legal basis. Producing an anonymous row still means reading a receipt, which is personal data, so that step needs a legal basis: our legitimate interest (Art. 6(1)(f)) in understanding market prices in order to offer this feature, together with Art. 5(1)(b) and Art. 89, which allow further processing for statistical purposes under appropriate safeguards — the safeguards being exactly the measures described above. We do not ask for your consent for this, and we do not rely on the Art. 9 consent described in Section 5, which covers the scanning itself and is unaffected by any of this.

To be precise rather than reassuring: this is a further use of data you have already given us. It is a light one — no new archive of personal data, no new retention period, no transfer, and the anonymous result is no longer personal data — but it is not "nothing", and we would rather say so than claim otherwise.

Your right to object (Art. 21). You can object at any time, without giving a reason and without losing any other feature, from Menu → Privacy & data → Anonymous statistics → "Don't use my data for statistics". From that moment your receipts stop feeding the price archive and your expenses are left out of any spending averages. In a shared group, an objection by any one member takes the whole group's shared expenses out.

What objecting cannot do. Rows already written to the anonymous archive contain nothing that links them to you, so we cannot find them and therefore cannot remove them — that is the very property that makes them anonymous. The same is true if you delete your account. Objecting stops every future contribution.

7. Consent register

For the Art. 9 consents and the 18+ confirmation, we keep a consent register (your identifier, the type of consent, grant/withdraw/confirm, date/time, the exact text version and language shown, and where it was given) solely to demonstrate consent under Art. 7. It is kept for the life of your account.

What happens to it when you delete your account. The register is the only proof of what you agreed to and when. If we deleted it together with your account we would have nothing left to show if that consent were ever questioned — and the person questioning it would be you. So we keep a reduced version of it for 5 years after the account is deleted, on the basis of Art. 17(3)(e) GDPR (establishment, exercise or defence of legal claims), and then delete it automatically. What survives is only: which consent, whether it was given, withdrawn or confirmed, the version and language of the text you were shown, the date and time, and a one-way hash of your email address — computed with a secret key held server-side, so it cannot be reversed — which is what lets us find your records again if you or an authority ask about them. Your user identifier is removed, and for the Terms and this Policy we do not keep a copy of the text either, because the exact wording of every version is archived separately and permanently (Section 17). For every other entry — the Art. 9 consents, the 18+ confirmation and the specific approval described below — the exact text you were shown is kept, because it is not archived anywhere else: without it the entry would show that you agreed to something, but not to what.

The same register also records when you accepted these Terms of Service and when the Privacy Policy was presented to you: the version, the date, the language and where it happened. For these two documents we store a reference to the version — not a copy of the text, which is identical for everyone and is archived once, separately, at a permanent address (Section 17).

Accepting the Terms is a contractual step, not a consent under Art. 6(1)(a); acknowledging this Policy is a record that you were informed, not an approval. Neither of them changes the Art. 9 consents above, which stay separate and can be withdrawn at any time.

If you use Flovvy for purposes relating to your trade, business, craft or profession, you are also offered a separate tick box to specifically approve certain provisions of the Terms, as Art. 1341, second paragraph, of the Italian Civil Code requires. It is optional — it changes nothing for consumers — and it is recorded as an entry of its own, distinct from your acceptance of the Terms, because the law requires the two to be separate acts. For this entry we keep the exact text you were shown, since it is what lists the provisions approved. It is a contractual act, not a consent under the GDPR.

8. Welcome credits, free trial and anti-abuse

New users get a one-time bonus of 10 AI credits, meant to be available once per person. To stop the same person claiming it over and over by deleting and recreating an account, we keep — for up to 6 months from the deletion — only a one-way hash of your email address, never the address itself.

This hash is pseudonymous: it cannot be reversed to your email, it is never used to profile, track or contact you, and it is compared only when a new account claims the welcome credits and in the abuse investigations described below. It is deleted automatically once the 6 months have passed.

If the hash matches, you can still re-register and use the app straight away: only the welcome credits are unavailable during that period. A match on its own is never treated as wrongdoing — if you are affected for a legitimate reason, write to [email protected] and we will enable them for you.

The free trial is granted by the store, not by us. The 30-day trial of the Plus plan is the subscription's introductory offer: it is granted by Apple or Google when you subscribe, and they decide who is eligible under their own rules. For this purpose we process no data about you: no hash of your Apple or Google account, no hash of your device, no check on our side. If the store does not offer you the trial, that decision is theirs — we can neither see nor change its outcome.

Investigating serious abuse. There is one further case in which we consult the email hash: when we are investigating automated, bulk or coordinated abuse — accounts created by a script, a bot or an emulator, or welcome credits and gift codes farmed across several accounts. There we use it to establish how far a single abuse extends, and the accounts we find to be part of it may be suspended or closed under Terms of Service, Section 9. We do not suspend or close an account on the strength of a hash match alone. Legal basis: our legitimate interest in preventing abuse of the Service and in protecting its other users (Art. 6(1)(f)); you may object at any time (Art. 21), and you can contest any measure taken against you by writing to us.

9. Who we share data with

We rely on the following providers acting as data processors on our behalf, each under a Data Processing Agreement (Art. 28 GDPR). The last two rows are the exception: Google and Apple, for sign-in, and the app stores, for payments, act as independent controllers, under their own terms and privacy policies:

ProviderRoleLocation / transfer
SupabaseDatabase and file storage (backend)EU region (eu-central-1)
Google CloudAI/OCR of receipts, voice, AI assistant and list comparison — Vertex AI (Gemini models) + Cloud Vision, via service accountEU — EU endpoints of Vertex AI and Cloud Vision (data residency in the EU)
RevenueCatManaging subscriptions and in-app purchasesOutside the EU; SCC + DPA
CloudflareHosting and protection of the flovvy.app website (static pages); processes request IP addresses in its access and security logsGlobal network; SCC + DPA
Google (Analytics)Website visit statistics, only with your consentOutside the EU (USA); EU-US Data Privacy Framework + SCC
SentryCrash and error monitoringUS provider; EU ingestion; SCC + DPA
ZohoMailbox of [email protected]: the emails you write to us and their attachmentsEU data centre; SCC for any access from outside the EU
Google / Apple"Sign in with Google/Apple"Per the provider's terms
App stores (Google Play / App Store)Payment processing (merchant of record)Per the store's terms

We do not sell your personal data and do not use it for third-party advertising. We disclose data to public authorities only where the law requires it (Art. 6(1)(c) GDPR): for example, on a binding order of a judicial or administrative authority, or where the Digital Services Act requires us to report a suspected serious criminal offence (Terms of Service, Section 12). If in future we add another AI provider, we will update this policy, sign the relevant DPA and assess any transfer outside the EU before it goes live.

Shared groups and people you add to them

When you share a group with the invite code, anyone who joins sees all of the group's expenses, including the items on detailed receipts, which may reveal, for example, the purchase of medicines. The app reminds you of this before you share. The other members receive this data because you chose to share it.

If someone added you to a group by name. In a group, participants can be added just by typing their name, even if they don't use Flovvy. For these people we keep only the name, as it was typed, linked to the group's expenses: no contact details, no contact, no other data. We do this to make expense splitting work (legitimate interest, Art. 6(1)(f)). Since we have no way to reach you, we inform you through this section (Art. 14(5)(b) GDPR), and the app asks whoever adds you to let you know. The name is kept as long as the group exists (Section 11). You can ask us to see, correct or delete it, or object, by writing to [email protected]: tell us the group's name or who added you, so we can find it. On request we replace the name with a neutral label.

10. International transfers

Your account and expense data is stored in the European Union (Supabase), and AI/OCR processing is also carried out in the EU (Google Cloud — EU endpoints of Vertex AI and Cloud Vision), so there is no transfer outside the EU for AI processing. Some other providers — error monitoring (Sentry), purchase management (RevenueCat), the network serving the website (Cloudflare), website visit statistics if you accept them (Google Analytics) and, for any support access, email (Zoho) — may process data outside the EU (typically the USA), on the basis of appropriate safeguards such as the European Commission's Standard Contractual Clauses and each provider's DPA.

11. How long we keep it

Account/ledger data is kept for the life of the account and deleted or anonymized on closure (not purged on a timer); technical logs are kept for a limited period and expire automatically.

DataRetention
Account data (expenses, income, accounts, budgets, categories, tags, lists, profile)Life of the account; deleted or anonymized on closure (cascade).
Receipt photos (cloud)Life of the account, or until you withdraw the "Saving receipt photos" consent — then deleted from cloud and device. We may in future set a maximum storage period for older photos: if we do, the period will be stated here and announced in advance in the app (see Terms of Service, Section 16).
Extracted receipt detail (line items) and shopping-list comparison reportsLife of the account, or until you withdraw the "AI features" consent — then deleted (of a receipt, only the header is kept).
Temporary result of an AI scanA scan keeps running on our servers even if you close the app, so what it read from the receipt — the text it read and the items and amounts taken from it, never the photo — waits in a queue until your app collects it. It is deleted 24 hours after your app has collected it, and in any case within 7 days, collected or not.
AI credit ledgerLife of the account and as long as needed for accounting/tax and disputes; deleted or anonymized on closure.
AI usage log (for each AI request: the feature, the AI model, the amount of text processed, the duration, the outcome and the time — never the content)13 months, to check our costs against the provider's invoices, then deleted automatically. If you delete your account, it is detached from you straight away.
AI credit gift codes12 months after the code is redeemed, taken back by whoever created it, or cancelled, then deleted automatically. A code nobody has used (others can redeem it for 30 days) stays until its creator takes the credits back or deletes the account. If you delete your account, the codes you created are deleted and your name is removed from those you redeemed.
Consent registerLife of the account. After the account is deleted, a reduced version (consent type, action, version and language of the text, date, and a keyed one-way hash of the email — no user ID; the text shown is kept only for the entries that are not archived elsewhere, see Section 7) is kept for 5 years to defend against claims about consent (Art. 17(3)(e) GDPR), then deleted automatically. See Section 7.
Purchases / subscriptionsAs required by accounting/tax law and to handle disputes and refunds (may be several years). The purchase history stays with the store and with RevenueCat, linked to the pseudonymous identifier of your account — never to your email or name. After your account is deleted we no longer keep anything that links that identifier to you, except for the short periods of the technical logs and server backups listed in this table. Our own copy is deleted with the account.
Website visit statistics (Google Analytics)Data kept by Google for 2 months; _ga cookies up to 6 months; your cookie choice for 6 months, then you are asked again.
Technical / diagnostic logs (Sentry)30 days from receipt, then deleted automatically by the provider.
Server and website access logsApp servers (Supabase): up to 7 days, then deleted automatically. Website (Cloudflare): we keep no access logs; in the dashboard we see aggregate statistics and, only for requests stopped by the security filters, the details including the IP address for the last 24 hours. Cloudflare also keeps a small random, pseudonymized sample of traffic, for up to 12 months, to improve the protection of its network.
Sign-in sessions (IP address and type of app or browser)As long as the session is open: deleted when you sign out or when you delete your account. If you uninstall the app without signing out, the session may stay open until your account is deleted: to close it straight away, sign out before uninstalling the app.
Anti-abuse hash of the email address6 months from the account deletion, then deleted automatically. See Section 8.
Orphaned shared groupsPurged 30 days after there are no active linked members, or 90 days without an active subscription covering the group.
Soft-deleted items ("tombstones")When you delete something, a record of the deletion is kept until each of your devices has synchronized it — without that record, a device that had been offline would bring the deleted item back. A device we have not heard from for more than 90 days no longer holds it back, and a nightly job on our servers carries out this cleanup even if you stop opening the app.
Emails to [email protected]Ordinary correspondence: 24 months from the last message. Requests to exercise your rights (Section 13) and reports of illegal content or abuse, with our replies: 5 years, to be able to show how we handled them. Then deleted.
Server backupsData you delete may remain in the encrypted backups of our database for up to 7 days, then it is overwritten. Backups are used only to restore the Service after a fault; if we ever had to restore one, we would re-apply the deletions made in the meantime.
Local data on your deviceKept until you uninstall the app or use the in-app "Delete device database" function.

12. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects on you (Art. 22). The AI features help you record and understand your own expenses; they do not make decisions about you.

13. Your rights

You have the right to access your data, rectify it, erase it, receive a portable copy (a full JSON export is available in the app, Art. 20), restrict or object to processing (including the processing based on our legitimate interest described in Sections 6, 8, 9 and 15), and to withdraw consent at any time without affecting past processing. To exercise these rights, write to [email protected]. You also have the right to lodge a complaint with your competent supervisory authority (in Italy, the Garante per la protezione dei dati personali).

14. Account deletion

You can delete your account and all associated data at any time, directly in the app via Menu → Delete data options → Delete account, or by email. Full instructions are on the Delete account page. Deletion runs through a secure server function that deletes your files in storage, anonymizes your entries in shared groups so other members are unaffected (your name becomes "Deleted user", with no transfer of ownership), and cascades the deletion across all your tables (expenses, accounts, categories, budgets, tags, lists, profile, purchases/subscriptions/credits). Apart from the server backups and technical logs described below, no trace of your user identifier remains on our servers.

Only two items remain, and neither contains your user identifier: the keyed one-way hash of your email used against abuse (Section 8), kept for 6 months, and the reduced version of the consent register (Section 7), kept for 5 years; both are then deleted automatically, and neither allows us to contact you. Deleted data may also remain in the encrypted server backups for up to 7 days; technical logs and error and crash reports, which may contain your user identifier, are deleted automatically within 30 days (Sections 11 and 15); and the emails you sent to support are kept for the periods in Section 11. Members of a shared group can see the group's expense history, including items you add; after you leave or delete your account your entries remain with them in anonymized form. Group invite codes expire and can be revoked.

15. Security

We apply, among others: private storage buckets for receipt images and avatars with per-user access control and expiring signed links; encryption at rest for the database and storage; AI credentials held only server-side; sensitive operations performed only by privileged server functions; error monitoring with EU ingestion (described below); and on-device protections you control (app lock with PIN/biometrics and "hide amounts"). Account data is pseudonymous, not anonymous, and remains fully protected as personal data.

Error monitoring. Crash and error reports are sent to Sentry with EU ingestion (de.sentry.io), and they are linked to your account: we attach the pseudonymous identifier of your account — the internal user ID, not your email, your name or any receipt content — so that a crash can be traced back to the session that produced it and so that an access or erasure request can be honoured for these reports too. The reports contain no receipt content, no expense content and no photos: the SDK runs with sendDefaultPii disabled, console breadcrumbs are discarded before sending, and performance tracing is switched off; in our Sentry account, storage of IP addresses is disabled, automatic removal of sensitive data (such as passwords and card numbers) is mandatory, and reports are deleted automatically after 30 days. Error monitoring is disabled entirely in development builds. Legal basis: our legitimate interest in the security and stability of the service (Art. 6(1)(f)). Our store listings declare the same thing: Google Play Data Safety lists User IDs as shared with Sentry, and the App Store privacy label lists Crash Data as linked to you.

Data breach notification. If a personal-data breach occurs that is likely to affect you, we will notify the competent supervisory authority within the time limit set by Art. 33 GDPR and, where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay — directly, or, in the cases Art. 34(3) GDPR allows, through a public communication of equivalent effectiveness.

16. Children

Flovvy is intended for users aged 18 or over; we ask you to confirm this during onboarding. This is not a limit set by the GDPR, which in Italy lets people consent on their own to online services from the age of 14 (Art. 2-quinquies of the Italian Privacy Code): it is our choice, because the app may process sensitive data, such as pharmacy receipts, and handles purchases. We do not knowingly collect data from anyone below that age: if we find that an account belongs to a minor, we close it and delete its data, and a parent or guardian can ask us to do so by writing to [email protected].

17. Changes

We may update this policy. Each version has a date, and the version in force is published at flovvy.app/privacy — the address in the app always points there, so it always shows you the current text.

Every published version is also kept at its own permanent address, in the form flovvy.app/legal/privacy-YYYY-MM-DD. Those pages are never changed or removed: they are what lets you check later exactly what you were shown on a given day.

When a change is significant, the app asks you to acknowledge the new version before you continue using it. Even if you do not, you can still export all of your data and delete your account — those are your rights and they never depend on accepting anything.

18. Contact

For any privacy-related request: [email protected].


Informativa privacy

Ultimo aggiornamento: 24 settembre 2026

Nota: questa informativa descrive come Flovvy tratta i dati personali, perché, con chi e per quanto tempo. Per qualsiasi richiesta in materia di privacy scrivi a [email protected].

1. Chi siamo

Flovvy è un'app di gestione delle spese personali che ti permette di registrare entrate e uscite, scansionare scontrini, organizzare budget, conti e liste della spesa, e dividere le spese in gruppo. Per i trattamenti descritti qui il Titolare del trattamento — chi decide finalità e mezzi del trattamento — è:

I fornitori che trattano dati per nostro conto (Sezione 9) agiscono come Responsabili del trattamento, sulla base di un accordo ai sensi dell'art. 28 GDPR. Tu sei l'interessato.

2. Quali dati trattiamo

CategoriaEsempi
Dati dell'accountIdentificativo utente, email e nome (ricevuti dall'accesso con Google o Apple; con Google il servizio di accesso riceve anche l'immagine del profilo del tuo account, che l'app non usa), la foto del profilo che scegli di caricare tu, il tipo di nucleo che indichi (per esempio single, o coppia con figli), usato solo per confrontare le tue spese con i budget di riferimento di nuclei simili, e il paese che scegli quando configuri l'app. Il paese serve a precompilare la valuta predefinita e a mostrare gli importi in un formato coerente con dove ti trovi; puoi cambiarlo quando vuoi dal profilo.
Dati di spesa e finanziariSpese ed entrate (importo, data, descrizione, esercente, valuta, categoria e sottocategoria), conti e saldi, budget, etichette, liste della spesa, note.
Dati degli scontriniFotografie degli scontrini che scegli di scansionare e il testo e le singole voci estratti da essi (può comparire un codice fiscale stampato sullo scontrino).
Categorie particolari di dati (art. 9)Informazioni che possono rivelare lo stato di salute o un'altra categoria particolare, per esempio i prodotti di uno scontrino di farmacia. Quelle che l'IA ricava da ciò che le affidi sono trattate solo con il tuo consenso esplicito; quelle che scrivi o classifichi tu restano dove le metti e non vengono analizzate, salvo i casi limitati descritti nella Sezione 5.
Dati delle spese condiviseGruppi, divisioni, partecipanti e voci condivise che crei o a cui aderisci.
Acquisti e abbonamentiStato dell'abbonamento, acquisti in-app, crediti AI e relative transazioni.
Regali di crediti AISe regali crediti AI con un codice, o ne riscatti uno: il codice, i crediti, le date e i nomi di chi regala e di chi riceve, perché ciascuno dei due veda da chi arriva o a chi è andato il regalo (Sezione 11).
Registro dei consensiQuali consensi hai dato o revocato, quando, e la versione e la lingua esatte del testo che ti è stato mostrato (Sezione 7).
Dati tecnici e diagnosticiModello del dispositivo, sistema operativo, versione dell'app, informazioni su crash ed errori, e un identificativo tecnico dell'utente. Leggiamo anche l'identificativo del dispositivo fornito dal sistema operativo (Android ID, oppure l'«identifier for vendor» di iOS): in chiaro, per tenere sincronizzati i tuoi dispositivi.
Log del sito e dei serverQuando visiti flovvy.app, o quando l'app contatta i nostri server, l'infrastruttura registra l'indirizzo IP, l'ora della richiesta e alcuni dati tecnici di base (versione del browser o dell'app, endpoint chiamato), per consegnare la pagina o la risposta e per proteggere il servizio da attacchi e abusi. Questi log restano presso i fornitori elencati nella Sezione 9 per i tempi indicati nella Sezione 11 e non vengono mai usati per costruire un profilo su di te. Il servizio di accesso (Supabase) tiene inoltre, per ogni sessione aperta del tuo account, l'indirizzo IP e il tipo di app o browser, per la sicurezza dell'account (per quanto tempo, vedi la Sezione 11).

Dati che NON raccogliamo. Non raccogliamo la tua posizione o geolocalizzazione (il permesso di localizzazione è stato rimosso dall'app), non usiamo SDK pubblicitari, di analytics o di tracciamento fra app — gli unici SDK di terze parti che l'app incorpora sono il monitoraggio degli errori descritto nella Sezione 15, la gestione degli acquisti descritta qui sotto e le librerie di accesso di Google e Apple, che entrano in gioco solo se scegli di accedere con loro — e non vendiamo i tuoi dati personali.

Accesso con Apple. Se scegli di accedere tramite Apple, conserviamo sui nostri server un token di autenticazione fornito da Apple, al solo scopo di poter revocare l'accesso dell'app al tuo Apple ID quando elimini l'account. Questo token non è usato per altri fini ed è eliminato definitivamente al momento della cancellazione dell'account.

Cookie, memoria locale e altre tecnologie di tracciamento

Il sito. Le pagine di flovvy.app sono statiche e caricano caratteri e script dal nostro dominio. Il sito usa un solo cookie tecnico, che ricorda la tua scelta sui cookie. Solo se nel banner scegli «Accetta» usa anche Google Analytics 4, per contare in forma aggregata le visite e le pagine viste: in quel caso il browser scarica lo script di Google e riceve i cookie elencati qui sotto. Prima della tua scelta, e se rifiuti, verso Google non parte niente. Nel banner «Accetta» e «Rifiuta» hanno lo stesso peso, e puoi cambiare idea quando vuoi dal link «Preferenze cookie» in fondo alle pagine (sulla home, dal pulsante «Preferenze cookie» in basso): se revochi il consenso, i cookie di Google Analytics vengono cancellati. Abbiamo disattivato i segnali di Google e ogni uso pubblicitario dei dati; Google Analytics usa il tuo indirizzo IP solo per ricavare il paese e non lo conserva, e Google conserva i dati raccolti per 2 mesi. Nessuno script pubblicitario o di social network.

CookieDi chiA cosa serveDurataEssenziale
flovvy_cookie_consentflovvy.appRicorda la tua scelta sui cookie6 mesiSì
_gaGoogle Analytics, per nostro contoDistingue i visitatori in forma pseudonima, per contare le visite6 mesiNo: solo con il tuo consenso
_ga_<ID>Google Analytics, per nostro contoTiene lo stato della visita in corso6 mesiNo: solo con il tuo consenso

Come qualunque server web, l'infrastruttura che serve il sito (Cloudflare, vedi Sezione 9) tratta l'indirizzo IP e lo user-agent del browser di ogni richiesta per consegnare la pagina e per proteggere il sito dagli attacchi (per quanto tempo, vedi la Sezione 11); quei dati non vengono associati al tuo account Flovvy e non sono mai condivisi a fini pubblicitari. Oggi Cloudflare non imposta cookie sul sito. Se un attacco rendesse necessario un controllo di sicurezza (la verifica «non sono un robot»), potrebbe impostare il cookie tecnico cf_clearance, che ricorda per un tempo breve (di norma 30 minuti) che la verifica è stata superata: è essenziale e non richiede il consenso.

L'app. L'app non usa alcun SDK pubblicitario, di analytics o di tracciamento fra app. Non legge l'identificativo pubblicitario del dispositivo (IDFA su iOS, ID pubblicitario su Android) e non mostra mai la richiesta di App Tracking Transparency, perché non c'è nulla su cui chiedertelo. Oltre alle librerie di accesso di Google e Apple, che servono solo ad accedere quando le scegli, l'app incorpora due SDK di terze parti, entrambi strettamente necessari e nessuno dei due pubblicitario o di misurazione. Il primo è quello di monitoraggio degli errori descritto nella Sezione 15 (Sentry), necessario a mantenere l'app funzionante e sicura: registra crash ed errori, mai le tue spese, i tuoi scontrini o le tue foto. Il secondo è RevenueCat, che gestisce abbonamenti e acquisti in-app (Sezione 9): riceve l'identificativo pseudonimo del tuo account (prima dell'accesso, un identificativo anonimo che genera lui), mai la tua email, la conferma d'acquisto emessa da Apple o Google (prodotto, prezzo, date, identificativo della transazione) e i dati tecnici che gli servono per funzionare (piattaforma e versioni di sistema e app, lingua, paese dello store, indirizzo IP della richiesta), perché quello che hai pagato si sblocchi su ogni dispositivo dove accedi. Nessuno dei due legge l'identificativo pubblicitario del tuo dispositivo, e nessuno dei due viene usato per misurare come usi l'app o per profilarti. L'app conserva inoltre informazioni sul tuo dispositivo — la banca dati locale delle tue spese, le tue impostazioni e il token di accesso nell'archivio sicuro del sistema operativo — ed è ciò che permette a Flovvy di funzionare offline; quelle informazioni restano sul tuo dispositivo, salvo quando si sincronizzano con il tuo account.

L'identificativo del dispositivo. L'unico identificativo a livello di dispositivo che leggiamo è quello descritto nella tabella qui sopra (dati tecnici e diagnostici). Lo usiamo soltanto per tenere sincronizzato il tuo account fra i tuoi dispositivi (per esempio perché una scansione iniziata su un telefono venga raccolta da uno solo) — mai per tracciarti o profilarti attraverso altre app o altri siti, mai come impronta anti-abuso e mai condiviso con un circuito pubblicitario.

Se aggiungiamo altro. Qualunque altro strumento di analytics o simile — sul sito o nell'app, per esempio per capire quali schermate vengono usate — lo attiveremo solo con il tuo consenso preventivo e libero, con «rifiuta» facile quanto «accetta» e la possibilità di cambiare idea; e aggiorneremo questa sezione — con l'elenco esatto, il fornitore, la finalità, la durata e se è essenziale — prima che entri in funzione, non dopo. Se l'elenco dei cookie del sito cambia, il banner ti chiede di nuovo la scelta. Le stesse informazioni, con le istruzioni per gestire i cookie dal browser, sono anche nella pagina Cookie Policy.

3. Perché li trattiamo e su quale base

Non usiamo i tuoi dati per finalità di marketing, per profilazione o per decisioni automatizzate che producano effetti giuridici o similmente significativi (Sezione 12).

4. Scansione degli scontrini e trattamento con IA

Quando scansioni uno scontrino, l'immagine e/o il testo estratto vengono inviati ai servizi di intelligenza artificiale di Google Cloud — i modelli Gemini tramite Vertex AI per la strutturazione e Cloud Vision per l'OCR — per riconoscere voci, importi e categorie. Questo trattamento avviene all'interno dell'Unione europea (endpoint UE di Vertex AI e di Cloud Vision), quindi non c'è alcun trasferimento fuori dall'Unione per l'IA e l'OCR. Lo stesso Google Cloud europeo è usato per l'inserimento vocale, l'assistente IA e il confronto fra liste della spesa. Gira su un piano a pagamento in cui, secondo le condizioni del fornitore, i dati non vengono usati per addestrare i modelli; Google agisce come responsabile del trattamento. Per individuare gli abusi dei suoi servizi, Google sottopone le richieste a controlli automatici: solo una richiesta segnalata da quei controlli può essere conservata da Google per un periodo limitato, nell'Unione, ed esaminata dal suo personale, al solo scopo di verificare l'abuso. Abbiamo chiesto a Google di escludere il nostro account da questo controllo; quando l'esclusione sarà attiva, aggiorneremo questa sezione. Le credenziali dei servizi di IA sono custodite solo sul nostro server, mai sul tuo dispositivo.

Una scansione non si interrompe quando chiudi l'app: prosegue sui nostri server, e ciò che è stato letto dallo scontrino resta lì in attesa che la tua app venga a raccoglierlo. Quella copia in attesa contiene il testo letto dallo scontrino e le voci e gli importi ricavati, mai la fotografia, e ha vita breve — vedi la Sezione 11.

Dati sensibili (categorie particolari — art. 9 GDPR). Non è possibile sapere che uno scontrino non contiene dati sulla salute prima di averlo analizzato, e lo stesso vale per un audio, una domanda o una lista: per questo ogni funzione di IA — scansione, voce, assistente e confronto delle liste — richiede il tuo consenso esplicito preventivo («Funzioni AI»); senza, non parte affatto. Puoi sempre registrare le spese a mano (nessuna foto, nessuna IA), e in quel caso non serve alcun consenso. Vedi la Sezione 5.

Gli scontrini che ci mandi per email

Se uno scontrino non viene letto bene e scegli di mandarcelo a [email protected], lo usiamo solo per provare e correggere la lettura: lo guardiamo noi e lo facciamo rileggere dallo stesso sistema che usa l'app (Google Cloud, nell'Unione europea: vedi questa Sezione e la Sezione 9). Non lo usiamo per addestrare nessun modello.

La base giuridica è il tuo consenso, prestato con l'atto stesso di mandarlo. Decidi tu se mandare uno scontrino e non sei mai tenuto a farlo: questa sezione sta qui perché tu sappia cosa succede prima di decidere.

Quello che conserviamo è la foto e il testo che ne abbiamo letto, dentro il banco di prova con cui misuriamo lo scanner. Ci resta finché serve a quella misura. Scrivi a [email protected] quando vuoi e lo cancelliamo.

Non mandarci scontrini di farmacia, di visite mediche o altri che dicono qualcosa sulla tua salute o su altri dati particolari (art. 9 GDPR, vedi la Sezione 5): per questi il gesto di mandarceli non basta come consenso, e non li usiamo. Ogni scontrino lo guardiamo prima di usarlo: se ne contiene, lo cancelliamo subito, senza passarlo allo scanner e senza tenerlo. In generale non mandarci scontrini che preferiresti non condividere: uno scontrino dice più di un totale, cioè dove eri, quando e cosa hai comprato.

5. Informazioni sulla salute e consenso esplicito (art. 9)

Alcuni contenuti che affidi alle funzioni di IA possono rivelare il tuo stato di salute (per esempio lo scontrino di una farmacia) o un'altra categoria particolare di dati ai sensi dell'art. 9 GDPR (per esempio le convinzioni religiose). Per questo l'app chiede due consensi distinti, facoltativi, mai preselezionati e revocabili in ogni momento:

Con il solo consenso «Funzioni AI» la foto viene usata temporaneamente per leggerla e non viene conservata; aggiungendo il salvataggio, viene conservata per il backup e per l'accesso da più dispositivi. Il consenso «Funzioni AI» copre anche la conservazione del dettaglio dei prodotti, comprese le voci che correggi o aggiungi a mano nel dettaglio, e dei report dei confronti fra liste. Quando il testo di un consenso cambia in modo sostanziale, l'app ti chiede di riconfermarlo, e finché non lo fai le funzioni che ne dipendono restano ferme.

Il testo che scrivi tu. Nelle descrizioni e nelle note delle spese puoi scrivere quello che vuoi, anche informazioni sulla salute (per esempio «visita dal cardiologo»). Quel testo resta dove l'hai messo: lo conserviamo e lo sincronizziamo per te, ma non lo leggiamo, non lo analizziamo e non lo mandiamo a nessun sistema di IA, salvo l'unico caso, coperto dal consenso «Funzioni AI», descritto nel paragrafo successivo. Per questo non ti chiediamo un consenso apposito: non ci sarebbe niente da fermare se lo negassi. Lo proteggiamo comunque come un dato sensibile (Sezione 15).

Cosa arriva comunque all'IA, solo se usi le funzioni di IA. Con il consenso «Funzioni AI», e solo per capire cosa chiedi o per classificare ciò che scansioni o detti, all'IA arrivano anche i nomi che hai dato a categorie, sottocategorie, conti ed etichette, e il nome delle liste che confronti: mai importi. Se usi l'assistente, le sue risposte precedenti, senza importi, tornano al modello perché capisca la domanda successiva, e possono contenere il nome di una spesa.

Revoca del consenso. Puoi revocare l'uno o l'altro consenso in qualsiasi momento da Menu → Privacy e dati → Consensi. Revocando «Funzioni AI» le funzioni di IA si disattivano (puoi sempre inserire le spese a mano) e l'app cancella subito, sul dispositivo e nel cloud, il dettaglio dei prodotti già archiviato e i report dei confronti fra liste della spesa. Sul dispositivo dove revochi, l'app elimina anche le proprie copie automatiche del database e ti propone di eliminare quelle che hai salvato tu: se le tieni, contengono ancora il dettaglio. Sugli altri tuoi dispositivi il dettaglio sparisce alla sincronizzazione successiva, ma le copie del database salvate su quei dispositivi restano finché non le elimini da lì. Di ogni spesa restano importo, data, descrizione, conto, categoria, sottocategoria, etichette e la foto, se ne hai autorizzato il salvataggio. Le liste della spesa restano come sono, anche i prodotti che ci hai aggiunto da uno scontrino: sono contenuti che hai creato tu, con un tuo gesto. Revocando il salvataggio delle foto, quelle già conservate vengono cancellate dal dispositivo e dal cloud. Tutto questo vale anche per le tue righe nei gruppi condivisi. Vieni avvisato prima e puoi esportare i tuoi dati (Sezione 13). Non usiamo l'IA per individuare o mascherare automaticamente i farmaci.

6. Statistiche aggregate sui prezzi

Dalle singole voci degli scontrini scansionati con il dettaglio dei prodotti costruiamo statistiche aggregate e anonime sui prezzi — per esempio il prezzo medio di un prodotto presso un dato esercente, in un dato mese e in un dato paese. Lo scopo è poterti dire se quello che hai pagato è in linea con il mercato, e alimentare i confronti di prezzo.

Queste statistiche vivono in una banca dati fisicamente separata, ospitata nell'Unione europea, che l'app non legge mai e che non contiene alcun identificativo: nessun identificativo utente, nessuno pseudonimo, nessun identificativo dello scontrino, nessuna foto e nessuna traccia di quando hai scansionato. Una riga descrive un acquisto, non una persona. Contiene il paese, il mese, l'esercente, il prodotto e il prezzo (come stampato e convertito in euro), più la categoria e, dove lo scontrino le riporta, la quantità e l'unità di misura; e due indicatori tecnici: come è stata prodotta la riga e la data del lotto notturno che l'ha scritta.

Del momento dell'acquisto viene registrato il mese, mai il giorno. La data del lotto è un'altra cosa: è condivisa da tutte le righe scritte la stessa notte e non dice nulla su quando una singola persona abbia fatto la spesa. Le righe vengono scritte in ordine casuale, così le voci di uno stesso scontrino non possono essere ricomposte, e non esiste alcuna chiave che permetta a noi — o a chiunque altro — di risalire da una statistica a te o alla tua spesa.

Farmacia e farmaci sono esclusi — ed ecco il limite onesto di questa esclusione. Le voci classificate nella categoria Salute come farmaci non entrano mai in questo archivio, e non ci entrano nemmeno le voci di categoria Salute la cui sottocategoria non è stata determinata: nel dubbio, la voce resta fuori. Ma quel filtro lavora sulla categoria assegnata dall'IA, quindi è una regola, non una garanzia — un acquisto in farmacia che l'IA avesse classificato, poniamo, come «Alimentari» non verrebbe intercettato. In quel caso ciò che ti protegge è tutto il resto di questo archivio: le righe non contengono nulla che riporti a te, e nessun dato viene mostrato se non poggia su almeno 3 osservazioni distinte, in un paese con almeno 100 utenti che vi contribuiscono. Una voce isolata non emerge mai come risultato.

Medie di spesa per paese. Possiamo calcolare anche la spesa media per paese e categoria, così l'app può dirti come si colloca la tua. In quel caso il calcolo avviene sui dati di spesa già presenti nel tuo account — non viene creato alcun nuovo archivio di dati personali — e si conserva solo il risultato aggregato, mai i valori individuali che lo compongono. Un risultato viene conservato solo se poggia su almeno 20 persone distinte.

Base giuridica. Produrre una riga anonima significa comunque leggere uno scontrino, che è un dato personale: quel passaggio ha quindi bisogno di una base giuridica, ed è il nostro legittimo interesse (art. 6(1)(f)) a conoscere i prezzi di mercato per poter offrire questa funzione, insieme all'art. 5(1)(b) e all'art. 89, che consentono l'ulteriore trattamento a fini statistici in presenza di garanzie adeguate — garanzie che sono esattamente le misure descritte qui sopra. Per questo non chiediamo il tuo consenso, e non ci basiamo sul consenso ex art. 9 descritto nella Sezione 5, che riguarda la scansione in sé e non è toccato da nulla di tutto questo.

Per essere precisi anziché rassicuranti: questo è un ulteriore uso di dati che ci hai già dato. È un uso leggero — nessun nuovo archivio di dati personali, nessun nuovo periodo di conservazione, nessun trasferimento, e il risultato anonimo non è più un dato personale — ma non è «niente», e preferiamo dirlo piuttosto che sostenere il contrario.

Il tuo diritto di opposizione (art. 21). Puoi opporti in qualunque momento, senza dover motivare e senza perdere alcuna altra funzione, da Menu → Privacy e dati → Statistiche anonime → «Non usare i miei dati per le statistiche». Da quel momento i tuoi scontrini smettono di alimentare l'archivio dei prezzi e le tue spese restano fuori da qualunque media. In un gruppo condiviso, l'opposizione di un solo membro esclude le spese condivise dell'intero gruppo.

Cosa l'opposizione non può fare. Le righe già scritte nell'archivio anonimo non contengono nulla che le colleghi a te: non possiamo trovarle e quindi non possiamo rimuoverle — è proprio la proprietà che le rende anonime. Lo stesso vale se cancelli il tuo account. L'opposizione ferma ogni contributo futuro.

7. Registro dei consensi

Per i consensi ex art. 9 e per la conferma dei 18 anni teniamo un registro dei consensi (il tuo identificativo, il tipo di consenso, se è stato dato, revocato o confermato, data e ora, la versione e la lingua esatte del testo mostrato e dove è avvenuto) al solo scopo di dimostrare il consenso ai sensi dell'art. 7. È conservato per tutta la vita dell'account.

Cosa succede quando cancelli l'account. Il registro è l'unica prova di che cosa hai accettato e quando. Se lo cancellassimo insieme al tuo account non ci resterebbe nulla da mostrare qualora quel consenso venisse messo in discussione — e chi lo metterebbe in discussione saresti proprio tu. Per questo ne conserviamo una versione ridotta per 5 anni dopo la cancellazione dell'account, sulla base dell'art. 17(3)(e) GDPR (accertamento, esercizio o difesa di un diritto in sede giudiziaria), e poi la cancelliamo automaticamente. Sopravvive soltanto: quale consenso, se sia stato dato, revocato o confermato, la versione e la lingua del testo che ti è stato mostrato, la data e l'ora, e un'impronta unidirezionale del tuo indirizzo email — calcolata con una chiave segreta custodita sul server, quindi non reversibile — che è ciò che ci permette di ritrovare le tue registrazioni se tu o un'autorità ce le chiedete. Il tuo identificativo utente viene rimosso e, per i Termini e per questa informativa, non conserviamo nemmeno una copia del testo, perché il testo esatto di ogni versione è archiviato a parte e in modo permanente (Sezione 17). Per tutte le altre registrazioni — i consensi ex art. 9, la conferma dei 18 anni e l'approvazione specifica descritta qui sotto — il testo esatto che ti è stato mostrato viene invece conservato, perché non è archiviato da nessun'altra parte: senza, la registrazione proverebbe che hai accettato qualcosa, ma non che cosa.

Lo stesso registro annota anche quando hai accettato i Termini di servizio e quando ti è stata presentata questa informativa: la versione, la data, la lingua e dove è avvenuto. Per questi due documenti conserviamo un riferimento alla versione, non una copia del testo, che è identico per tutti ed è archiviato una volta sola, separatamente, a un indirizzo permanente (Sezione 17).

Accettare i Termini è un atto contrattuale, non un consenso ai sensi dell'art. 6(1)(a); prendere atto di questa informativa è la registrazione del fatto che sei stato informato, non un'approvazione. Nessuno dei due incide sui consensi ex art. 9 qui sopra, che restano separati e revocabili in ogni momento.

Se usi Flovvy per scopi riferibili alla tua attività imprenditoriale, commerciale, artigianale o professionale, ti viene proposta anche una casella separata per approvare specificamente alcune clausole dei Termini, come richiede l'art. 1341, comma 2, del codice civile. È facoltativa — per i consumatori non cambia nulla — ed è registrata come annotazione a sé, distinta dall'accettazione dei Termini, perché la norma vuole che siano due atti separati. Per questa annotazione conserviamo il testo esatto che ti è stato mostrato, perché è quello che elenca le clausole approvate. È un atto contrattuale, non un consenso ai sensi del GDPR.

8. Crediti di benvenuto, prova gratuita e anti-abuso

I nuovi iscritti ricevono un bonus una tantum di 10 crediti AI, pensato per essere disponibile una volta per persona. Per impedire che la stessa persona lo richieda più volte cancellando e ricreando un account, conserviamo — per un massimo di 6 mesi dalla cancellazione — soltanto un'impronta unidirezionale del tuo indirizzo email, mai l'indirizzo in chiaro.

Questa impronta è pseudonima: non può essere ricondotta alla tua email, non viene mai usata per profilarti, tracciarti o contattarti, e viene confrontata solo quando un nuovo account richiede i crediti di benvenuto e nelle indagini sugli abusi descritte qui sotto. È cancellata automaticamente allo scadere dei 6 mesi.

Se l'impronta corrisponde, puoi comunque registrarti e usare l'app subito: solo i crediti di benvenuto restano indisponibili per quel periodo. Una corrispondenza, da sola, non viene mai trattata come un illecito — se ne sei toccato per un motivo legittimo, scrivi a [email protected] e te li abilitiamo.

La prova gratuita la concede lo store, non noi. La prova di 30 giorni del piano Plus è l'offerta introduttiva dell'abbonamento: la concedono Apple o Google quando sottoscrivi, e sono loro a stabilire chi ne ha diritto secondo le proprie regole. Per questa finalità non trattiamo nessun dato tuo: nessuna impronta del tuo account Apple o Google, nessuna impronta del tuo dispositivo, nessuna verifica da parte nostra. Se lo store non ti offre la prova, la decisione è sua: noi non possiamo vederne né cambiarne l'esito.

Indagini su abusi seri. C'è un ulteriore caso in cui consultiamo l'impronta dell'email: quando stiamo indagando su un abuso automatizzato, massivo o coordinato — account creati con uno script, un bot o un emulatore, oppure crediti di benvenuto e codici regalo accumulati su più account. Lì la usiamo per stabilire quanto si estende un singolo abuso, e gli account che risultano farne parte possono essere sospesi o chiusi ai sensi della Sezione 9 dei Termini di servizio. Non sospendiamo né chiudiamo un account sulla sola base di una corrispondenza. Base giuridica: il nostro legittimo interesse a prevenire gli abusi del servizio e a proteggerne gli altri utenti (art. 6(1)(f)); puoi opporti in qualunque momento (art. 21) e puoi contestare qualsiasi misura adottata nei tuoi confronti scrivendoci.

9. Con chi condividiamo i dati

Ci avvaliamo dei seguenti fornitori, che agiscono come responsabili del trattamento per nostro conto, ciascuno sulla base di un accordo ai sensi dell'art. 28 GDPR. Fanno eccezione le ultime due righe: Google e Apple, per l'accesso, e gli store, per i pagamenti, agiscono come titolari autonomi, secondo le proprie condizioni e informative:

FornitoreRuoloUbicazione / trasferimento
SupabaseBanca dati e archiviazione dei file (backend)Regione UE (eu-central-1)
Google CloudIA e OCR degli scontrini, voce, assistente IA e confronto delle liste — Vertex AI (modelli Gemini) e Cloud Vision, tramite service accountUE — endpoint UE di Vertex AI e di Cloud Vision (residenza dei dati nell'Unione)
RevenueCatGestione di abbonamenti e acquisti in-appFuori dall'UE; Clausole Contrattuali Standard e accordo sul trattamento
CloudflareHosting e protezione del sito flovvy.app (pagine statiche); tratta gli indirizzi IP delle richieste nei propri log di accesso e sicurezzaRete globale; Clausole Contrattuali Standard e accordo sul trattamento
Google (Analytics)Statistiche di visita del sito, solo con il tuo consensoFuori dall'UE (Stati Uniti); EU-US Data Privacy Framework e Clausole Contrattuali Standard
SentryMonitoraggio di crash ed erroriFornitore statunitense; ingestione nell'UE; Clausole Contrattuali Standard e accordo sul trattamento
ZohoCasella di posta di [email protected]: le email che ci scrivi e i loro allegatiData center nell'UE; Clausole Contrattuali Standard per gli eventuali accessi da fuori UE
Google / AppleAccesso con Google o AppleSecondo le condizioni del fornitore
Store (Google Play / App Store)Gestione dei pagamenti (venditore, merchant of record)Secondo le condizioni dello store

Non vendiamo i tuoi dati personali e non li usiamo per pubblicità di terze parti. Comunichiamo dati alle autorità pubbliche solo quando la legge lo impone (art. 6(1)(c) GDPR): per esempio su ordine vincolante di un'autorità giudiziaria o amministrativa, o quando il Digital Services Act ci obbliga a segnalare il sospetto di un reato grave (Termini di servizio, Sezione 12). Se in futuro aggiungeremo un altro fornitore di IA, aggiorneremo questa informativa, firmeremo il relativo accordo e valuteremo ogni trasferimento fuori dall'Unione prima che entri in funzione.

Gruppi condivisi e persone che vi aggiungi

Quando condividi un gruppo con il codice invito, chi entra vede tutte le spese del gruppo, compresi i prodotti degli scontrini dettagliati, che possono rivelare per esempio l'acquisto di medicinali. L'app te lo ricorda prima della condivisione. Gli altri membri ricevono questi dati per tua scelta.

Se qualcuno ti ha aggiunto a un gruppo con il tuo nome. In un gruppo si possono aggiungere partecipanti scrivendo solo il nome, anche se non usano Flovvy. Di queste persone conserviamo soltanto il nome, così come è stato scritto, collegato alle spese del gruppo: nessun recapito, nessun contatto, nessun altro dato. Lo facciamo per far funzionare la divisione delle spese (legittimo interesse, art. 6(1)(f)). Non avendo modo di raggiungerti, ti informiamo con questa sezione (art. 14(5)(b) GDPR), e l'app invita chi ti aggiunge ad avvisarti. Il nome resta finché esiste il gruppo (Sezione 11). Puoi chiederci di vederlo, correggerlo o cancellarlo, oppure opporti, scrivendo a [email protected]: indicaci il nome del gruppo o chi ti ha aggiunto, così possiamo trovarlo. Su richiesta sostituiamo il nome con una dicitura neutra.

10. Trasferimenti internazionali

I dati del tuo account e delle tue spese sono conservati nell'Unione europea (Supabase), e anche il trattamento di IA e OCR avviene nell'Unione (Google Cloud — endpoint UE di Vertex AI e di Cloud Vision): non c'è quindi alcun trasferimento fuori dall'Unione per il trattamento con IA. Alcuni altri fornitori — il monitoraggio degli errori (Sentry), la gestione degli acquisti (RevenueCat), la rete che serve il sito (Cloudflare), le statistiche di visita del sito se le accetti (Google Analytics) e, per eventuali accessi di assistenza, la posta (Zoho) — possono trattare dati fuori dall'Unione (tipicamente negli Stati Uniti), sulla base di garanzie adeguate come le Clausole Contrattuali Standard della Commissione europea e l'accordo sul trattamento dei dati di ciascun fornitore.

11. Per quanto tempo li conserviamo

I dati dell'account e del registro delle spese sono conservati per tutta la vita dell'account e cancellati o anonimizzati alla chiusura (non eliminati a scadenza); i log tecnici sono conservati per un periodo limitato e scadono automaticamente.

DatoConservazione
Dati dell'account (spese, entrate, conti, budget, categorie, etichette, liste, profilo)Vita dell'account; cancellati o anonimizzati alla chiusura (a cascata).
Fotografie degli scontrini (cloud)Vita dell'account, oppure fino alla revoca del consenso «Salvataggio delle foto degli scontrini» — poi cancellate dal cloud e dal dispositivo. In futuro potremmo introdurre un periodo massimo di conservazione per le foto più vecchie: se lo faremo, il periodo sarà indicato qui e annunciato in anticipo nell'app (vedi Termini di servizio, Sezione 16).
Dettaglio estratto dagli scontrini (singole voci) e report dei confronti fra listeVita dell'account, oppure fino alla revoca del consenso «Funzioni AI» — poi cancellati (dello scontrino resta la sola intestazione).
Risultato temporaneo di una scansione con IAUna scansione prosegue sui nostri server anche se chiudi l'app, quindi ciò che è stato letto dallo scontrino — il testo letto e le voci e gli importi ricavati, mai la fotografia — resta in coda finché la tua app non lo raccoglie. Viene cancellato 24 ore dopo che la tua app l'ha raccolto e comunque entro 7 giorni, raccolto o no.
Registro dei crediti AIVita dell'account e per il tempo necessario a fini contabili, fiscali e di contestazione; cancellato o anonimizzato alla chiusura.
Registro d'uso dell'IA (per ogni richiesta all'IA: la funzione, il modello, la quantità di testo elaborata, la durata, l'esito e l'orario — mai il contenuto)13 mesi, per riscontrare i nostri costi con le fatture del fornitore, poi cancellato automaticamente. Se cancelli l'account, viene subito staccato da te.
Codici regalo di crediti AI12 mesi dopo che il codice è stato riscattato, ripreso da chi l'ha creato o annullato, poi cancellati automaticamente. Un codice che nessuno ha usato (gli altri possono riscattarlo per 30 giorni) resta finché chi l'ha creato non si riprende i crediti o non cancella l'account. Se cancelli l'account, i codici che hai creato vengono cancellati e il tuo nome viene tolto da quelli che hai riscattato.
Registro dei consensiVita dell'account. Dopo la cancellazione dell'account se ne conserva una versione ridotta (tipo di consenso, azione, versione e lingua del testo, data e un'impronta unidirezionale dell'email calcolata con chiave segreta — nessun identificativo utente; il testo mostrato si conserva solo per le annotazioni che non sono archiviate altrove, vedi la Sezione 7) per 5 anni, per difendersi da contestazioni sul consenso (art. 17(3)(e) GDPR), poi cancellata automaticamente. Vedi la Sezione 7.
Acquisti e abbonamentiPer il tempo richiesto dalla normativa contabile e fiscale e per gestire contestazioni e rimborsi (anche diversi anni). Lo storico degli acquisti resta presso lo store e presso RevenueCat, legato all'identificativo pseudonimo del tuo account, mai alla tua email o al tuo nome. Dopo la cancellazione dell'account non conserviamo più nulla che colleghi quell'identificativo a te, salvo per i tempi brevi dei log tecnici e delle copie di sicurezza indicati in questa tabella. La nostra copia viene cancellata con l'account.
Statistiche di visita del sito (Google Analytics)Dati conservati da Google per 2 mesi; cookie _ga fino a 6 mesi; la tua scelta sui cookie per 6 mesi, poi ti viene richiesta.
Log tecnici e diagnostici (Sentry)30 giorni dalla ricezione, poi cancellati automaticamente dal fornitore.
Log di accesso dei server e del sitoServer dell'app (Supabase): fino a 7 giorni, poi cancellati automaticamente. Sito (Cloudflare): noi non teniamo log di accesso; nel pannello vediamo statistiche aggregate e, solo per le richieste fermate dai filtri di sicurezza, i dettagli con l'indirizzo IP delle ultime 24 ore. Cloudflare conserva inoltre un piccolo campione casuale e pseudonimizzato del traffico, fino a 12 mesi, per migliorare la protezione della sua rete.
Sessioni di accesso (indirizzo IP e tipo di app o browser)Finché la sessione è aperta: si cancellano quando esci dall'account o quando cancelli l'account. Se disinstalli l'app senza uscire, la sessione può restare aperta fino alla cancellazione dell'account: per chiuderla subito, esci dall'account prima di disinstallare l'app.
Impronta anti-abuso dell'indirizzo email6 mesi dalla cancellazione dell'account, poi cancellata automaticamente. Vedi la Sezione 8.
Gruppi condivisi rimasti orfaniEliminati 30 giorni dopo che non vi sono più membri collegati attivi, o dopo 90 giorni senza un abbonamento attivo che copra il gruppo.
Elementi cancellati («tombstone»)Quando cancelli qualcosa, resta traccia della cancellazione finché ognuno dei tuoi dispositivi non l'ha sincronizzata: senza quella traccia, un dispositivo rimasto offline farebbe riapparire l'elemento cancellato. Un dispositivo di cui non abbiamo notizie da più di 90 giorni smette di trattenerla, e un processo notturno sui nostri server esegue questa pulizia anche se smetti di aprire l'app.
Email a [email protected]Corrispondenza ordinaria: 24 mesi dall'ultimo messaggio. Richieste di esercizio dei diritti (Sezione 13) e segnalazioni di contenuti illeciti o di abusi, con le nostre risposte: 5 anni, per poter dimostrare come le abbiamo gestite. Poi cancellate.
Copie di sicurezza del serverI dati che cancelli possono restare nelle copie di sicurezza cifrate della nostra banca dati per un massimo di 7 giorni, poi vengono sovrascritti. Le copie servono solo a ripristinare il servizio dopo un guasto; se mai dovessimo ripristinarne una, riapplicheremmo le cancellazioni avvenute nel frattempo.
Dati locali sul tuo dispositivoConservati finché non disinstalli l'app o non usi la funzione «Elimina database del dispositivo» presente nell'app.

12. Decisioni automatizzate

Non adottiamo decisioni automatizzate che producano effetti giuridici o similmente significativi nei tuoi confronti (art. 22). Le funzioni di IA ti aiutano a registrare e a capire le tue spese; non prendono decisioni su di te.

13. I tuoi diritti

Hai il diritto di accedere ai tuoi dati, di rettificarli, di cancellarli, di riceverne una copia portabile (nell'app è disponibile un'esportazione completa in formato JSON, art. 20), di limitare il trattamento o di opporti (compresi i trattamenti fondati sul nostro legittimo interesse descritti nelle Sezioni 6, 8, 9 e 15) e di revocare il consenso in qualunque momento, senza che ciò pregiudichi i trattamenti già svolti. Per esercitare questi diritti scrivi a [email protected]. Hai inoltre il diritto di proporre reclamo all'autorità di controllo competente (in Italia, il Garante per la protezione dei dati personali).

14. Cancellazione dell'account

Puoi cancellare il tuo account e tutti i dati associati in qualunque momento, direttamente dall'app da Menu → Opzioni cancellazione dati → Elimina account, oppure via email. Le istruzioni complete sono nella pagina Cancella account. La cancellazione passa da una funzione server sicura che elimina i tuoi file dall'archivio, anonimizza le tue voci nei gruppi condivisi così che gli altri membri non ne risentano (il tuo nome diventa «Utente cancellato», senza alcun trasferimento di titolarità) e propaga la cancellazione a tutte le tue tabelle (spese, conti, categorie, budget, etichette, liste, profilo, acquisti, abbonamenti e crediti). A parte le copie di sicurezza e i log tecnici descritti qui sotto, sui nostri server non resta alcuna traccia del tuo identificativo utente.

Restano solo due elementi, e nessuno dei due contiene il tuo identificativo utente: l'impronta unidirezionale della tua email calcolata con chiave segreta, usata contro gli abusi (Sezione 8), conservata per 6 mesi, e la versione ridotta del registro dei consensi (Sezione 7), conservata per 5 anni; entrambi vengono poi cancellati automaticamente, e nessuno dei due ci consente di contattarti. I dati cancellati possono inoltre restare nelle copie di sicurezza cifrate del server per un massimo di 7 giorni; i log tecnici e i rapporti su errori e crash, che possono contenere il tuo identificativo utente, si cancellano da soli entro 30 giorni (Sezioni 11 e 15); e le email che hai scritto all'assistenza sono conservate per i tempi indicati nella Sezione 11. I membri di un gruppo condiviso possono vedere lo storico delle spese del gruppo, comprese le voci che aggiungi tu; dopo che avrai lasciato il gruppo o cancellato il tuo account, le tue voci restano a loro in forma anonimizzata. I codici di invito ai gruppi scadono e possono essere revocati.

15. Sicurezza

Applichiamo, fra le altre: archivi privati per le immagini degli scontrini e per gli avatar, con controllo di accesso per singolo utente e collegamenti firmati a scadenza; cifratura a riposo della banca dati e dell'archivio; credenziali dei servizi di IA custodite solo lato server; operazioni sensibili eseguite solo da funzioni server privilegiate; monitoraggio degli errori con ingestione nell'Unione (descritto qui sotto); e protezioni sul dispositivo che controlli tu (blocco dell'app con PIN o biometria e funzione «nascondi importi»). I dati dell'account sono pseudonimi, non anonimi, e restano pienamente tutelati come dati personali.

Monitoraggio degli errori. I rapporti su crash ed errori sono inviati a Sentry con ingestione nell'Unione (de.sentry.io) e sono collegati al tuo account: vi alleghiamo l'identificativo pseudonimo del tuo account — l'ID utente interno, non la tua email, il tuo nome o il contenuto di uno scontrino — così che un crash possa essere ricondotto alla sessione che lo ha prodotto e così che una richiesta di accesso o di cancellazione possa essere soddisfatta anche per questi rapporti. I rapporti non contengono alcun contenuto di scontrini, alcun contenuto di spese e alcuna fotografia: l'SDK gira con sendDefaultPii disattivato, le tracce della console vengono scartate prima dell'invio e il tracciamento delle prestazioni è spento; nel nostro account Sentry la memorizzazione dell'indirizzo IP è disattivata, la rimozione automatica dei dati sensibili (come password e numeri di carta) è obbligatoria e i rapporti si cancellano da soli dopo 30 giorni. Nelle build di sviluppo il monitoraggio degli errori è disattivato del tutto. Base giuridica: il nostro legittimo interesse alla sicurezza e alla stabilità del servizio (art. 6(1)(f)). Le nostre schede negli store dichiarano la stessa cosa: la sezione Sicurezza dei dati di Google Play indica gli ID utente come condivisi con Sentry, e l'etichetta privacy dell'App Store indica i dati sui crash come collegati a te.

Notifica di violazione dei dati. Se si verifica una violazione dei dati personali che probabilmente ti riguarda, notificheremo l'autorità di controllo competente entro il termine stabilito dall'art. 33 GDPR e, qualora la violazione possa comportare un rischio elevato per i tuoi diritti e le tue libertà, informeremo anche te senza ingiustificato ritardo — direttamente oppure, nei casi consentiti dall'art. 34(3) GDPR, mediante una comunicazione pubblica di efficacia equivalente.

16. Minori

Flovvy è destinata a utenti di età pari o superiore a 18 anni; ti chiediamo di confermarlo durante la configurazione iniziale. Non è un limite imposto dal GDPR, che in Italia permette di acconsentire da soli ai servizi online dai 14 anni (art. 2-quinquies del Codice privacy): è una nostra scelta, perché l'app può trattare dati sensibili, come gli scontrini di farmacia, e gestisce acquisti. Non raccogliamo consapevolmente dati di persone al di sotto di quell'età: se scopriamo che un account appartiene a una persona minorenne lo chiudiamo e ne cancelliamo i dati, e un genitore o tutore può chiedercelo scrivendo a [email protected].

17. Modifiche

Possiamo aggiornare questa informativa. Ogni versione ha una data, e la versione in vigore è pubblicata su flovvy.app/privacy — l'indirizzo presente nell'app punta sempre lì, quindi ti mostra sempre il testo corrente.

Ogni versione pubblicata resta inoltre disponibile a un proprio indirizzo permanente, nella forma flovvy.app/legal/privacy-AAAA-MM-GG. Quelle pagine non vengono mai modificate né rimosse: sono ciò che ti permette di verificare in seguito che cosa esattamente ti era stato mostrato in un dato giorno.

Quando una modifica è significativa, l'app ti chiede di prendere atto della nuova versione prima di continuare a usarla. Anche se non lo fai, puoi comunque esportare tutti i tuoi dati e cancellare il tuo account: sono tuoi diritti e non dipendono mai dall'accettazione di alcunché.

18. Contatti

Per qualsiasi richiesta in materia di privacy: [email protected].