Privacy Policy
Last updated: 26 September 2026
FlowPerch is a money tracker designed to work without an account and without the internet. By default, everything you enter stays on your device. This policy explains what leaves your device, when and why, who processes it, and what you can do about it. It covers the FlowPerch app for iPhone, iPad and Android, and the flowperch.app website.
At a glance
- You can use FlowPerch without an account. Your entries then stay on your device.
- Signing in is optional. It turns on cloud backup and sync, and lets you share an entry, send feedback, buy Premium and redeem promo codes.
- Analytics, crash reports and ads never receive your amounts, notes, people's names or other financial records.
- We do not sell your financial records.
- You can clear your data or delete your account at any time, and Premium subscribers can export their data.
1. Data that stays on your device
Your entries (income, expenses, investments, and money lent and borrowed), categories, budgets, payment modes and the balances you enter for them, savings goals, bills, recurring payments and your app preferences are stored on your device, encrypted by FlowPerch (AES-256) with a key kept in your phone's secure key storage (the iOS Keychain or the Android Keystore). Receipt photos and your profile picture are kept in FlowPerch's private storage, protected by your phone's own encryption. You can also turn on App Lock, which asks for Face ID, a fingerprint or your device passcode through your device's operating system (FlowPerch never receives biometric data) and hides the app's contents in the app switcher.
- When anything leaves your device: only when you are signed in and use a feature that needs our servers — cloud backup and sync (section 3), sharing an entry (section 4), Premium or promo codes (section 5) or feedback (section 6) — or when you export or share something yourself.
- Reminders: reminders about bills, recurring payments, due dates, budgets and your weekly or monthly check-in are created and scheduled on your device. They can show amounts and people's names, including on your lock screen. You can turn them off in More → Notifications.
- Home-screen widget: the widget shows this month's recorded spending only if you choose to show amounts, and never while App Lock is on.
- Device backups: on Android, FlowPerch's data is excluded from Google backups and device-to-device transfers. On iPhone and iPad, your device's own backups (to iCloud or a computer) may include FlowPerch's on-device data, according to your Apple backup settings. Your entries are in them encrypted; the key is restored with iCloud and encrypted computer backups, so an unencrypted computer backup restored onto a different iPhone cannot open entries made without an account.
- Signing out hides your account's data on this device until you sign in again; it does not delete it. To remove it, use Clear all data (section 13) or uninstall the app.
2. Your account and sign-in
An account is optional. It is needed for cloud backup and sync, sharing an entry, sending feedback, buying or restoring Premium, and redeeming promo codes. Sign-in is handled by Google Firebase Authentication, using your Google account, your Apple ID, or an email address and password.
- What we receive: a random account ID, your email address and the name on your account. With Google or Apple, the name comes from that account (Apple shares it only the first time you sign in, and lets you use its "Hide My Email" relay address instead of your own). With an email address, it is the name you enter. You can change your name in the app.
- Your password is handled by Firebase Authentication. FlowPerch never receives or stores it. Firebase sends the email that verifies a new email sign-in, and password-reset emails when you ask for one.
- Profile picture: if you sign in with Google, the app can display your Google profile photo, which is loaded from Google. A picture you choose yourself is stored only on your device.
- Your name is shown to the other person when you share an entry with them (section 4).
3. Cloud backup and sync
While you are signed in, FlowPerch keeps a copy of your data in Google Cloud Firestore, part of Firebase, and keeps it in sync automatically so you can use the same data on another device. In More → Backup & sync you can also back up immediately or restore the latest cloud copy. Entries you recorded before signing in stay on your device until you choose to add them to your account.
- What is included: all of your entries and their details — amounts, dates, categories, payment modes, notes, the names of people you lend to or borrow from, investment names and platforms, due dates, and the file name of any attached receipt — plus your categories and budgets, payment modes and their balances, savings goals, bills, recurring payments, and settings such as currency, language, number format and reminder preferences.
- What is not included: receipt photos, a profile picture you chose yourself, and exported files.
- How changes reach your other devices: each synced entry records when it was last changed, and deleting an entry leaves a marker (its random ID and the time) for 60 days, so your other devices can fetch only what changed and remove what you deleted.
- Who can access it: our database security rules allow only your signed-in account to read or change your synced data. Shared entries are the one exception, described in section 4.
- Our server functions — used for invites, reminders between people who share an entry, promo codes, purchase checks from earlier app versions, and account deletion — run on Google Cloud in the europe-west1 region (Belgium).
4. Shared lent and borrowed entries
A lent or borrowed entry is private to you unless you choose to share it. If you do, that one entry becomes visible to the person you share it with. Sharing needs an account, and the other person needs one to accept. This is the only feature in FlowPerch that shows any of your data to another person, so it is worth being precise about.
- What they can see: the amount and currency, whether it is money lent or borrowed, the date it began, its note and purpose, the name on your account (or, if you have not set a name, the part of your email address before the @), every repayment and correction either of you records with its note, any dispute and its reason, a repayment plan, whether reminders are on or paused, and when either of you sends a reminder or leaves. The record also contains random account IDs so that both apps can keep it in step. Nothing else in your app is shared — no other entries, balances or totals.
- What you can see: exactly the same, from their side. The record is symmetrical by design.
- Invite codes and links: sharing creates a code and a link (flowperch.app/i/…) that you send yourself, through your device's share sheet; FlowPerch never reads your contacts. Anyone signed in to FlowPerch who has the code can see a preview — your name, the amount, the currency and whether it is lent or borrowed — and the invite record also holds the entry's date, note and purpose. A code can be used once and stops working after 30 days, and there are over a trillion possible codes, so guessing one is impractical. We would rather state that here than leave you to discover it. Our website's invite page only displays the code in your browser; it does not store it.
- Neither of you can delete it alone: a record two people agreed on should not be erasable by one of them. Leaving a shared entry closes it for both instead of removing it.
- Reminders between you: either of you can send the other a reminder, delivered as a push notification through Firebase Cloud Messaging (and Apple's push notification service on iPhone). To make this possible, we store a push notification token for each device you are signed in on, with its platform and when it was last updated. Only our server can read these tokens — not even the person you share with. The message names the sender and the amount and says nothing else, and it is limited to one per person, per entry, per day. Signing out removes that device's token, deleting your account removes all of them, and tokens that stop working are removed automatically.
5. Premium, free trials and promo codes
- Purchases: FlowPerch Premium is an auto-renewing subscription sold through Apple's App Store or Google Play. You need to be signed in to buy or restore it, so that it stays with your account. Apple or Google processes the payment; FlowPerch never receives your card, bank account or other payment details.
- RevenueCat: our subscription service provider, RevenueCat, receives your FlowPerch account ID — not your name or email address — and the purchase information from Apple or Google: the product, transaction identifiers, subscription status, any free trial or introductory offer, and renewal, expiry, cancellation and refund details. We use this only to unlock Premium, restore it on your devices and respond to renewals, cancellations and refunds.
- Free trials: any free trial is offered and managed by Apple or Google under their terms. Before showing one, the app asks the store, through RevenueCat, whether a trial is available to you.
- Purchases made with earlier versions: earlier versions of FlowPerch checked purchases with Apple or Google through our server. For those purchases we may keep the verified subscription status, its start and expiry dates, and a one-way hashed purchase identifier that stops one purchase from unlocking several accounts.
- Promo codes: when you redeem a code, it is sent to our server, which checks it and records the code, when you redeemed it, when your access ends and any promotion it belongs to, so that one account cannot redeem the same promotion twice. To stop codes from being guessed, the server also briefly counts redemption attempts for each account.
- Promotional offers: while a promotion is running, the app may show you an offer once; your device remembers that it has been shown for your account.
- Cancelling: you manage and cancel your subscription in your App Store or Google Play settings. Deleting your FlowPerch account does not cancel it (see Delete Account).
6. Feedback and support
If you choose to send feedback inside the app (you need to be signed in), we store your message, its type (feedback, suggestion or bug), your FlowPerch account ID and email address, the app version, platform and submission time in Firestore. This is used only to read, investigate and respond to feedback. Feedback is deleted when you delete your account.
If you write to us at flowperch@zohomail.eu, the content of that email is stored by our email provider (Zoho Mail) for the purpose of replying to you.
7. Analytics
FlowPerch uses Google Analytics for Firebase to understand how the app is used, so we know which parts to improve. Analytics is not linked to your FlowPerch account ID, and it never includes your financial information: no amounts, balances, totals, category or account names, people's names, notes or transaction dates — nothing you have typed into the app. What we send is limited to:
- which entry types and reports are used, whether an entry was new or edited, and whether it was your first;
- whether onboarding was finished or skipped, which export format was used, and when a rating prompt was shown or a reminder was sent to someone you share with (never who or how much);
- whether the upgrade screen was shown or closed, whether a subscription or free trial started or failed, and whether a restore or promo redemption succeeded or failed;
- a rough size band for how many entries you have (for example “50–199”), never the exact number;
- your app language, whether you are signed in, and your Premium status;
- the standard information Firebase collects automatically, such as app opens and sessions, app version, device model, operating system version and approximate country, tied to a random app-instance identifier rather than to your account.
Analytics and crash reporting (section 8) are switched off in development builds and do not run if Firebase cannot start on your device. FlowPerch keeps working fully offline either way.
8. Crash reports
FlowPerch uses Firebase Crashlytics. If the app crashes or hits an unexpected error, a report is sent automatically containing the technical details of the failure: the error, the stack trace, your device model and operating system version, and the same non-financial context described in section 7 (app language, whether you are signed in, Premium status and entry size band). Crash reports are not linked to your FlowPerch account ID, and they do not contain your transactions or anything you have typed.
9. App settings, update notices and ratings
FlowPerch downloads a few settings from Firebase Remote Config: the latest app version, so it can tell you when an update is available; whether a promotion is running; and whether ads are switched on. The update notice compares the latest version with the one installed on your device and can open the App Store or Google Play. Firebase uses an app installation identifier and basic app and device details to deliver these settings.
From time to time the app may ask whether you would like to rate FlowPerch, using Apple's or Google's built-in rating prompt. Your device remembers when you were last asked. Any rating or review you leave goes to Apple or Google under their terms.
10. Advertising
FlowPerch includes Google AdMob and shows ads to free users only when we switch advertising on. Premium users never see ads, and versions released before advertising was added contain no advertising code. There are two placements: a banner at the bottom of the More screen, and an optional rewarded video ad that a free user can choose to watch to open the Income and Expense reports for the rest of that day. A rewarded ad is only shown after you tap “Watch ad”; FlowPerch stores on your device only the date on which you last unlocked reports this way.
FlowPerch asks Google for non-personalised ads only. To deliver and measure ads and help prevent fraud, Google's advertising technology may still receive your IP address (which can indicate an approximate location), device or app identifiers where available and permitted, ad views and interactions, and technical diagnostics such as app performance. Google and participating ad partners may process this information under their own privacy terms. FlowPerch never sends your transaction amounts, balances, categories, receipt photos, notes or other financial records to AdMob, and does not request your precise location.
Where required, FlowPerch asks for your advertising privacy choices through Google's consent tool before requesting any ad, and you can review or change them later in More → Ad privacy choices. Declining does not remove free access to FlowPerch. FlowPerch does not request Apple's advertising identifier or show an App Tracking Transparency prompt, and the Android advertising ID permission is removed from the app. You can read Google's advertising privacy information for more about Google's processing.
11. Device permissions
- Camera and photo library: only when you choose to photograph or pick a receipt or a profile picture. The images stay on your device.
- Notifications: requested only when you turn on reminders or share or join an entry, and used for your reminders and for reminders between people who share an entry.
- Face ID or fingerprint: only for App Lock, and checked by your device's operating system.
- FlowPerch also uses internet access, in-app billing and, on Android, permission to restore scheduled reminders after your phone restarts. It does not request access to your location, contacts or microphone, or Apple's tracking permission.
12. Exporting your data
Premium subscribers can export their entries as a CSV spreadsheet or a PDF report, with the option to embed receipt photos in the PDF. Export files are created on your device and handed to your device's share sheet; you choose where they go, and FlowPerch does not upload them. The temporary copy FlowPerch makes for sharing is deleted once it is an hour old, the next time you export or open the app. Anyone can also ask us for a copy of the data held in their cloud account (section 16).
13. Clearing your data and deleting your account
- Clear all data (More → Manage data → Clear all data) removes your entries, savings goals, bills, budgets, custom categories and payment modes, recurring payments and receipt photos from this device and from your cloud copy, cancels scheduled reminders, and closes any shared entries you are part of. Your account, Premium subscription and promo records are kept.
- Delete account (More → your account at the top of the screen → Delete account) asks you to confirm your identity, then permanently deletes your sign-in account, your cloud profile and entries, feedback, invites you created or accepted, push notification tokens, Premium and promo records, purchase binding and related security records. It also removes your profile picture from this device and cancels its reminders.
- Entries on your device are not deleted with your account. To remove them too, use Clear all data before deleting your account, or uninstall the app.
- Without the app: if you can no longer use the app, you can ask us to delete your account by email. See Delete Account.
- The one limit: a shared entry belongs to two people. When you delete your account, your account ID, name and private transaction link are removed from that record and your events are anonymised, but the other participant keeps the financial facts you both recorded. We think a record of a debt that one side can erase outright would be worth less to both of you, but you should know it before you share one.
- Not covered by account deletion: your subscription itself (cancel it in your store settings); purchase records kept by Apple, Google and RevenueCat under their own policies; and analytics and crash data, which are not linked to your account.
14. Who we share data with
We do not sell your financial records. Data is shared only as described in this policy:
- The other person in a shared entry, as described in section 4.
- Google, which runs Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging, Analytics, Crashlytics, Remote Config, App Check and Hosting, Google Sign-In, AdMob, Google Play (including Play Integrity), and the fonts on our website (Google Privacy Policy, Firebase privacy).
- Apple, for Sign in with Apple, App Store purchases, push notifications and DeviceCheck app verification on iPhone and iPad (Apple Privacy Policy).
- RevenueCat, for subscriptions (RevenueCat Privacy Policy).
- Zoho, for email you send us (Zoho Privacy Policy).
These providers may process data in countries other than the one you live in. FlowPerch's server functions run in Google Cloud's europe-west1 region (Belgium); where each provider processes data is described in its privacy policy.
15. How long we keep data
- On your device: until you delete it, use Clear all data or uninstall the app.
- Cloud copy and account: until you delete the data, use Clear all data or delete your account.
- Shared entries: for as long as either participant still has an account. A shared record is deleted once neither does.
- Invites: a code stops working after 30 days, and the expired invite record is then deleted automatically, usually within a few days. It is deleted sooner if the account that created or accepted it is deleted.
- Feedback: until you delete your account.
- Push notification tokens: until you sign out on that device, delete your account, or the token stops working.
- Premium, promo and earlier purchase-check records: until you delete your account.
- Deletion markers: 60 days, then deleted automatically.
- Anti-abuse counters (for promo code attempts, reminders and purchase checks): short-lived, overwritten as they are used, and deleted with your account or shared entry.
- Server logs: our server functions keep technical logs that can include your account ID and the action taken (for example, a promo code redemption or an account deletion). They are used for security and troubleshooting and kept under Google Cloud's log retention settings.
- Analytics and crash reports: kept by Google according to Firebase's retention settings.
- Purchase records at Apple, Google and RevenueCat follow their own policies.
16. Security and your rights
Data sent between the app and our service providers travels over encrypted connections. Database security rules limit each account's synced data to that account, and each shared entry to its two participants. On your device, FlowPerch encrypts your entries and offers App Lock. To help protect our servers from misuse, the app uses Firebase App Check: when it contacts Firebase, it asks Apple's DeviceCheck (on iPhone and iPad) or Google Play Integrity (on Android) to confirm that the request comes from the genuine FlowPerch app. Apple or Google process information about the app and your device for this check under their own terms; it contains none of your FlowPerch data. No method of storing or sending data is completely secure, so please protect your device with a passcode.
- Access: your data is on your device, so you already have it. If you have a cloud copy, you can view every entry directly in the app.
- Correction: you can edit or delete any entry, and change your name, in the app.
- Export: see section 12.
- Deletion: see section 13.
- Your choices: you can turn reminders off in More → Notifications or in your device settings, change your advertising privacy choices in More → Ad privacy choices where they are offered, and sign out to stop syncing on a device.
- Other rights: depending on where you live, you may have further rights, such as to object to or restrict some processing and to complain to your data protection authority. To exercise any of your rights, or to request a copy of the data held in your cloud account, email flowperch@zohomail.eu.
17. Our website
flowperch.app is hosted on Firebase Hosting, which processes standard request information, such as your IP address, to deliver the pages. The website does not use cookies, analytics or advertising. Its pages load fonts from Google Fonts, so your browser connects to Google when you visit (Google Fonts privacy).
18. Children
FlowPerch is not directed at children under 13, and we do not knowingly collect personal information from children.
19. Changes to this policy
If we change this policy, we will update the "Last updated" date at the top of the page. Substantive changes will also be communicated inside the app.
20. Contact
Questions about this policy or your data? Write to flowperch@zohomail.eu. To delete your account without the app, see Delete Account.
FlowPerch