Last updated: July 13, 2026
Flovvy is a personal expense-management app that lets you record income and expenses, scan receipts, organize budgets, accounts and shopping lists, and share expenses in groups. For the processing described here, the Data Controller — the party that decides the purposes and means of processing — is:
The providers that process data on our behalf (Section 9) act as Processors under a Data Processing Agreement (Art. 28 GDPR). You are the data subject.
| Category | Examples |
|---|---|
| Account data | User ID, email, name, profile image (received at sign-in with Google or Apple). |
| Expense & financial data | Expenses and income (amount, date, description, category/sub-category), accounts and balances, budgets, tags, shopping lists, notes. |
| Receipt data | Photos of the receipts you choose to scan and the text/line-items extracted from them (may include a tax code printed on the receipt). |
| Special-category data (Art. 9) | Information that may reveal health, e.g. pharmacy items or a "Health/Medical" category, whether extracted from a receipt or entered manually. Processed only with your explicit consent (Section 5). |
| Shared-expense data | Groups, splits, participants and shared items you create or join. |
| Purchases & subscriptions | Subscription status, in-app purchases, AI credits and related transactions. |
| Consent records | Which consents you gave or withdrew, when, and the exact text/version and language you were shown (Section 6). |
| Technical / diagnostic data | Device model, operating system, app version, crash and error information, and a technical user identifier. |
Data we do NOT collect. We do not collect your location/geolocation (the location permission has been removed from the app), we do not use advertising, analytics or third-party tracking SDKs, and we do not sell your personal data.
We do not use your data for marketing, profiling or automated decisions with legal or similarly significant effects (Section 12).
When you scan a receipt, the image and/or extracted text is sent to Google Cloud's artificial-intelligence services — Gemini 2.5 via Vertex AI for structuring and Cloud Vision for OCR — to recognize items, amounts and categories. This processing takes place within the European Union (Vertex AI region europe-west1 for Gemini and the EU endpoint for Cloud Vision), so there is no transfer outside the EU for AI/OCR. The same EU Google Cloud is used for voice entry, the AI assistant and shopping-list comparison. It runs on a paid tier where, under the provider's terms, data is not used to train the models and is not subject to human review; Google acts as a data processor. AI credentials are held only on our secure server, never on your device.
Some receipts (e.g. from a pharmacy) and some manual entries (e.g. "psychiatrist visit") may reveal your health, a special category under Art. 9 GDPR. Before you can use AI receipt scanning, the app asks for up to two separate, optional and freely revocable consents (never pre-ticked):
With only "AI capture", the image is used temporarily to read it and the photo is not stored; with "cloud photo saving" as well, the photo is stored for backup and multi-device access. The consent also covers the structured storage of health-revealing entries (e.g. medicine names), whether created by AI or entered manually.
Withdrawing consent. You can withdraw either consent at any time in your profile. On withdrawal the app immediately deletes all stored receipt photos and all extracted product detail (cloud and device), keeping only the expense header — amount, date, merchant, category — which does not reveal health. This also applies to your own rows in shared groups. You are warned first and can export your data (Section 11) before proceeding. We do not use AI to automatically detect or mask medicines.
For the Art. 9 consents and the 18+ confirmation, we keep a consent register (your identifier, the type of consent, grant/withdraw/confirm, date/time, the exact text version and language shown, and where it was given) solely to demonstrate consent under Art. 7. It is kept for the life of your account and deleted together with the account.
New users get a one-time bonus of 10 AI credits. To stop the same person repeatedly claiming it by deleting and recreating an account, on deletion we keep — for up to 30 days — only a one-way hash of the email (not the email itself), plus the date, then it is deleted automatically. The hash is pseudonymous, cannot be reversed to your email, and is never used to profile or contact you. You can re-register immediately; only the welcome credits are suspended for 30 days. Legal basis: legitimate interest; you may object (Art. 21).
To offer price trends and averages we keep a physically separate statistics database, fed from detailed scans, storing per product only: country, year (not the full date), shop name, product name, price and (where available) quantity — no user identifier, receipt identifier, photos, full date/time, location or device identifiers. Averages are shown only above a minimum count (at least three occurrences). Designed this way the data is anonymous and falls outside the GDPR. A separate technical de-duplication table holds only a keyed hash of a receipt, used solely to detect duplicates. You may object to this processing (Art. 21).
We rely on the following providers acting as data processors on our behalf, each under a Data Processing Agreement (Art. 28 GDPR):
| Provider | Role | Location / transfer |
|---|---|---|
| Supabase | Database and file storage (backend) | EU region (eu-central-1) |
| Google Cloud | AI/OCR of receipts, voice, AI assistant — Vertex AI (Gemini 2.5) + Cloud Vision, via service account | EU — Vertex AI europe-west1 + Cloud Vision EU endpoint (data residency in the EU) |
| RevenueCat | Managing subscriptions and in-app purchases | Outside the EU; SCC + DPA |
| Sentry | Crash and error monitoring | US provider; EU ingestion; SCC + DPA |
| Google / Apple | "Sign in with Google/Apple" | Per the provider's terms |
| App stores (Google Play / App Store) | Payment processing (merchant of record) | Per the store's terms |
We do not sell your personal data and do not use it for third-party advertising. If in future we add another AI provider, we will update this policy, sign the relevant DPA and assess any transfer outside the EU before it goes live.
Your account and expense data is stored in the European Union (Supabase), and AI/OCR processing is also carried out in the EU (Google Cloud — Vertex AI europe-west1 and the EU Cloud Vision endpoint), so there is no transfer outside the EU for AI processing. Some other providers — currently error monitoring (Sentry) and purchase management (RevenueCat) — may process data outside the EU (typically the USA), on the basis of appropriate safeguards such as the European Commission's Standard Contractual Clauses and each provider's DPA.
Account/ledger data is kept for the life of the account and deleted or anonymized on closure (not purged on a timer); technical logs are kept for a limited period and expire automatically.
| Data | Retention |
|---|---|
| Account data (expenses, income, accounts, budgets, categories, tags, lists, profile) | Life of the account; deleted or anonymized on closure (cascade). |
| Receipt photos (cloud) | Life of the account, or until you withdraw the "cloud photo saving" consent — then deleted from cloud and device. |
| Extracted receipt detail (line items) | Life of the account, or until you withdraw the "AI capture" consent — then deleted (only the header is kept). |
| AI credit ledger | Life of the account and as long as needed for accounting/tax and disputes; deleted or anonymized on closure. |
| Consent register | Life of the account; deleted together with the account. |
| Purchases / subscriptions | As required by accounting/tax law (may be several years). Source of truth is the store / RevenueCat; our copy is deleted with the account. |
| Technical / diagnostic logs (Sentry) | A limited period set automatically by the provider (about 30–90 days). |
| Hashed-email anti-abuse list | 30 days from the last account deletion, then deleted automatically. |
| Orphaned shared groups | Purged 30 days after there are no active linked members, or 90 days without an active subscription covering the group. |
| Soft-deleted items ("tombstones") | Kept until the deletion has synchronized across your devices, then purged. |
| Aggregate price statistics | Anonymous — retained as anonymized data (outside the GDPR). The de-duplication hash is kept only for the de-duplication window, then deleted. |
| Local data on your device | Kept until you uninstall the app or use the in-app "reset database" function. |
We do not carry out automated decision-making that produces legal or similarly significant effects on you (Art. 22). The AI features help you record and understand your own expenses; they do not make decisions about you.
You have the right to access your data, rectify it, erase it, receive a portable copy (a full JSON export is available in the app, Art. 20), restrict or object to processing (including the legitimate-interest processing in Sections 7 and 8), and to withdraw consent at any time without affecting past processing. To exercise these rights, write to [email protected]. You also have the right to lodge a complaint with your competent supervisory authority (in Italy, the Garante per la protezione dei dati personali).
You can delete your account and all associated data at any time, directly in the app via Profile → Privacy & data → Delete account, or by email. Full instructions are on the Delete account page. Deletion runs through a secure server function that deletes your files in storage, anonymizes your entries in shared groups so other members are unaffected (your name becomes "Deleted user", with no transfer of ownership), and cascades the deletion across all your tables (expenses, accounts, categories, budgets, tags, lists, profile, the consent register, purchases/subscriptions/credits). After deletion, no trace of your user identifier remains on our servers.
The only residual item is the pseudonymous email hash described in Section 7, kept for up to 30 days and then deleted automatically; it does not allow us to identify or contact you. Members of a shared group can see the group's expense history, including items you add; after you leave or delete your account your entries remain with them in anonymized form. Group invite codes expire and can be revoked.
We apply, among others: private storage buckets for receipt images and avatars with per-user access control and expiring signed links; encryption at rest for the database and storage; AI credentials held only server-side; sensitive operations performed only by privileged server functions; error monitoring configured for EU ingestion without personal identifiers; and on-device protections you control (app lock with PIN/biometrics and "hide amounts"). Account data is pseudonymous, not anonymous, and remains fully protected as personal data.
Flovvy is intended for users aged 18 or over; we ask you to confirm this during onboarding. We do not knowingly collect data from anyone below that age.
We may update this policy. In case of significant changes we will provide notice through the app or this site, updating the date at the top.
For any privacy-related request: [email protected].