privacy-policy

Privacy Policy — USN Finance

Effective date: 07/11/2026
Last updated: 09/09/2026

1. Who we are

Operator of the USN Finance mobile application (the “App”, “we”, “us”). Legal details and contact information are in section 13 “Contact”.

The App is available on Google Play (package ID com.usn.finance).

The current version of this Policy is always available at: https://usnfinance.github.io/privacy-policy/en.html

Other languages: Українська · Русский

2. Overview

This Policy explains what personal and account-related data we collect, how we use it, who we share it with, and what rights you have.

By using the App, you agree to this Policy. If you do not agree, please do not use the App.

The App is intended for adults (18+) for personal and family financial tracking. We do not knowingly collect data from children under 13.

3. Data we process

3.1. Account and profile

3.2. Financial and accounting data

3.3. Cryptographic data

The secret phrase you create when setting up a group is not sent to our server. It is used only on your device to derive encryption keys.

3.4. Expense recognition (only when you request it)

At your request, the App may process:

This data is sent to our server (Supabase Edge Function) and then to OpenAI for automated recognition. Processing happens within a single request; the result is returned to the App.

Document content (image or text) is not stored in our database. We do not keep a recognition log. Processing by OpenAI is governed by their privacy policy.

When AI Tokens are charged for using a feature (if enabled), we may store operational data only in the database: AI Tokens charged, OpenAI API request token count (a technical metric, not your AI Tokens balance), profile and group identifiers — not document content.

3.5. Shared groups

If you invite a member to a group, we process the invitee’s email address to find a registered account and send an invitation.

3.6. Roles, access, and shared data

The App uses accounting groups — shared spaces where multiple users can maintain one set of financial records.

Access levels

Account — tied to your email. On first registration we create one user profile; your nickname is set once at registration and shown in every group you join. One email may belong to multiple accounting groups under the same profile.

Group owner — the user who created the group. The owner may:

Group member — an invited user. They may accept or decline an invitation (Pending status). After accepting, they gain access to that group’s data like other active members (subject to encryption key availability, see below).

There is no separate “admin” role — only owner and member.

Member statuses

Only active members use group data in the normal way. Members with Deleted status remain visible in the list for transparency of entry authorship but cannot access the group. Access to a specific group’s data is provided in the context of your current session (the group selected in the App).

What other members can see

If you belong to a group, other members of that group with access to its data or member list can see nicknames of all group members (including invited, access-revoked, and deleted accounts) and membership status.

Active members can additionally see:

Other members’ emails are not shown in the group UI. Email is processed only when inviting someone — when the owner enters an address to find a registered user.

After a member deletes their account, their nickname may remain visible to other group members (in the list with Deleted status and when viewing entry authorship). Their email is no longer available.

Encryption key and read-only mode

Editing sensitive fields (notes, object names, currency fields, etc.) requires the group encryption key on your device, obtained via your secret phrase or recovered from secure device storage.

If the key is unavailable (for example, you signed in on a new device without entering your secret phrase), encrypted fields are shown undecrypted (as stored on the server), including account and category names in the object tree, transaction notes, and currency reference fields (name, code, symbol). Amounts, dates, and operation types (by category code) remain readable; in the transaction feed, the currency symbol may show as “#” without the key.

You cannot add, edit, or delete transactions until the key is restored (by entering your secret phrase or recovering from secure device storage, if available).

When inviting a member, the owner shares an encrypted group key tied to the invitee’s public key.

Deletion and retention within groups

3.7. Purchases and AI Tokens

In-app tokens (AI Tokens)

We store on the server your current AI Tokens balance and history of grants and charges. AI Tokens are spent on paid AI-powered features in the App (currently expense recognition; the list may expand). This data is used for limits and balance display. Content you send to AI is handled under the relevant feature’s rules (see § 3.4).

AI Tokens balance may also be granted as a promo or administratively (for example, a signup bonus), without a store payment.

Subscription and AI Tokens purchases

When you purchase a subscription or AI Tokens:

Payment card data is processed by the app store (Google or Apple), not by us.

3.8. Exchange rates

Exchange rates are stored per accounting group and used to convert amounts in reports into a currency you choose (using the rate on the transaction date). Transactions and account balances remain recorded in their original currencies.

To import reference rates, the App calls the public Frankfurter API (api.frankfurter.dev) with currency codes and dates. No personal data is sent in these requests. You may also enter and edit rates manually.

3.9. Data export

At your request, the App builds a JSON file with group data and offers to save it via the system share sheet. Where the file is saved is up to you.

The export’s users block includes only profile identifier (user_id) and nickname (nikname). Email is not included in the export.

3.10. Technical data

We do not use third-party advertising or analytics SDKs (Firebase Analytics, Crashlytics, etc.) to track your behavior.

4. Why we process data

Legal bases (GDPR): contract performance (providing the service); consent (camera, gallery, expense recognition); legitimate interest (account security).

5. Who we share data with

Recipient Purpose Policy
Supabase database hosting, authentication, server functions supabase.com/privacy
OpenAI expense recognition (your action) openai.com/policies/privacy-policy
Google Play payments and subscriptions policies.google.com/privacy
App Store payments and subscriptions apple.com/legal/privacy
RevenueCat subscription and purchase management revenuecat.com/privacy
Frankfurter reference exchange rates frankfurter.dev

We do not sell your personal data to third parties.

6. Where data is stored

Server data is hosted on Supabase (region: Central Europe — Zurich, Switzerland, eu-central-2).

Encryption keys and session data are stored locally on your device in the OS secure storage (Android Keystore / iOS Keychain).

7. Security

No system is 100% secure, but we apply reasonable technical and organizational safeguards.

8. Retention

Data is kept while your account is active.

After account deletion (via “Delete account” in the App):

When access is revoked for an active member, they lose access to group data; their past entries may remain in the shared ledger.

9. Your rights

You may:

For access, correction, deletion, or restriction requests, contact: [usnfinance@gmail.com].

Residents of the EU and other jurisdictions with applicable law may lodge a complaint with their supervisory authority.

10. Device permissions

Permission Purpose
Internet sync, authentication, services
Camera document photos, QR/barcode scan for document URL
Gallery / photos pick a document image (only when you choose to)

Permissions are requested when you use the related feature.

For documents by URL, the App may open a web page (WebView) or fetch its text. You enter or scan the link yourself. We do not control third-party website content.

12. Changes to this Policy

We may update this Policy. The last updated date is at the top. We may notify you of material changes in the App.

13. Contact

FOP Nynko Serhii Fedorovych
Registered address: 17d Chervonoi Kalyny St., apt. 60, Kyiv, 02225, Ukraine
Email: usnfinance@gmail.com