Account data: email address, password hash (bcrypt), display name, optional avatar, locale, timezone. If you sign in via Google OAuth, we receive your email and Google account ID — we do not receive or store your Google password.
Financial data: accounts, transactions, categories, budgets, goals, debts, subscriptions and currency preferences that you create inside the app. This data lives on our servers in the EU.
Device data: an FCM (Firebase Cloud Messaging) push token bound to your device, the device platform (iOS/Android/Web), locale and user-agent — used solely to deliver notifications you opted into.
Usage data: minimal, aggregated server logs (IP address, request path, status code) retained briefly for security and debugging. In the mobile apps we also collect anonymous usage statistics via Google Analytics for Firebase: which screens are opened and which features are used. These statistics never include your email, name, account identifier, or any financial data. Statistics collection is on by default — you can turn it off at any time in the app’s Settings; when turned off, collection stops and the device’s analytics identifier is reset. Separately — only with your explicit consent — we additionally allow anonymous ad conversion measurement (for example, a one-time sign-up event so we can tell a registration came from an ad). No ad personalization is ever performed on this data.
Optional bank-sync data: when you connect a bank via PSD2 (GoCardless EU) or Monobank (UA), we receive read-only account and transaction data from those providers on your behalf.