Account data: email address, password hash (bcrypt), display name, optional avatar, locale, timezone. If you sign in via Google OAuth, we receive your email and Google account ID — we do not receive or store your Google password.
Financial data: accounts, transactions, categories, budgets, goals, debts, subscriptions and currency preferences that you create inside the app. This data lives on our servers in the EU.
Device data: an FCM (Firebase Cloud Messaging) push token bound to your device, the device platform (iOS/Android/Web), locale and user-agent — used solely to deliver notifications you opted into.
Usage data: minimal, aggregated server logs (IP address, request path, status code) retained briefly for security and debugging. We do not run third-party analytics SDKs.
Optional bank-sync data: when you connect a bank via PSD2 (GoCardless EU) or Monobank (UA), we receive read-only account and transaction data from those providers on your behalf.