Nomad Budget

Data Protection Notice (KVKK)

Version 2.1 · Effective: 2026-10-01

This notice is issued under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and the related Communiqué on the Procedures and Principles for Fulfilling the Disclosure Obligation.

For a fuller account of everything the App does with data, see the "Privacy Policy".

1. Identity of the Data Controller

Data controller: Rubeeks (rubeeks.co)

Contact address: nomadbudget@rubeeks.co

2. Categories of Personal Data Processed

  • Identity and contact data: email address; the display name and avatar you choose. Where the account was created with Sign in with Apple or Sign in with Google, this also covers the identifier the provider issues and the address it passes on, which with Apple may be a private relay alias. A guest account has no email address and carries only the display name and avatar, if you set them.
  • Customer transaction data: the wallets, transactions, categories, budgets, goals and recurring rules you enter — whether typed in or imported from a file you chose — including their amounts, currencies, dates and free-text note fields.
  • Travel data: the visits and crossings you confirm or enter (country, first and last day, where from and where to, means of travel, the transaction that was the ticket) and the countries you mark as visited.
  • Transaction security data: the hash of your password (an account created with Sign in with Apple or Sign in with Google has none, because the provider confirms the identity instead), session information, account creation date, and the version and date of your consent.
  • Device data: where you have allowed notifications, your device's push token and whether it is an iOS or an Android device.
  • Usage data: the random installation ID the App makes on first launch; the screens and steps seen, how sign-in and purchase attempts ended, the answers to the permissions the App asks for and unexpected errors (an error message with personal details stripped out); the App version, operating system, interface language and time; your account, when you are signed in. It contains no amount, note, category, location or contact detail.
  • Customer request data: the messages you send us through the App's feedback form or by email, the reply address you give, and the device context attached to them (App version, operating system and version, device model, language).
  • Purchase data: the identifier your account is registered under with our subscription provider and, if you subscribe to Pro, the plan, the store, the dates of purchase, renewal and expiry, renewal and refund status, the store's transaction identifiers, and the price and currency charged. Card and bank details are never received.
  • Sharing data: which of your wallets you have shared with whom and in what role, which wallets you have been invited into and by whom, the requests to join you have sent or received through a link, and which member entered a given record.

When you turn on payment capture, the notification and message texts read, the drafts made from them and the message patterns learned are processed only on your device and are not transferred to us; when you confirm a draft, the transaction you save is processed as customer transaction data.

No special categories of personal data are processed. We recommend that you do not write special-category information (health, beliefs and similar) into free-text note fields.

3. Purposes of Processing

  • Creating your membership record and securing your account.
  • Providing the budgeting service: storing and syncing your records, converting currencies, producing summaries and charts, drawing your map and route, and comparing countries on the basis of your own spending.
  • At your request, preparing draft entries on your device from your payment notifications or your Shortcuts automation.
  • Running the sharing feature: creating and redeeming invitations, delivering and answering requests to join, keeping wallet memberships, and showing members who entered a record.
  • Selling and managing the Pro subscription: verifying purchases, renewals, cancellations, refunds and restored purchases.
  • Delivering mandatory service messages (email confirmation, password reset) and, where you have permitted them, push notifications about activity in a shared wallet, requests to join and your budgets, and showing reminders.
  • Running information security processes, debugging and preventing abuse.
  • Measuring how the App is used, finding the steps where people get stuck, and improving the App.
  • Handling requests and complaints, and complying with legal obligations.

4. Legal Grounds

Your personal data is processed on the following grounds under KVKK Art. 5:

  • Art. 5/2-c — directly related to the conclusion or performance of a contract: creating the account and providing the service, including the Pro subscription.
  • Art. 5/2-ç — compliance with the controller's legal obligations: responding to requests from competent authorities.
  • Art. 5/2-f — legitimate interests, provided this does not harm your fundamental rights and freedoms: security, abuse prevention and debugging; improving the App with usage data that holds no content; answering the messages you send us.
  • Art. 5/1 — explicit consent: deriving your country from your device's location, sending push notifications, and preparing draft entries from your payment notifications. Each is given through a device permission (for payment capture, also through the switches in the App or a Shortcuts automation you set up) and can be withdrawn at any time in the same places.

5. Method of Collection

Your personal data is collected electronically, by automated means, as you enter it into the App yourself, from a CSV or Excel file you choose to import (read on your device), and — for location, the camera, notifications and payment capture — through the device permissions you grant and the Shortcuts automations you set up. Usage data is generated automatically by the App while you use it.

Data about you is obtained from third parties in two cases, each only if you choose it. Signing in with Apple or Google: the identifier, the email address and your name reach us from that provider — from Apple on the first sign-in only, from Google on every sign-in, though it is read only the first time. Subscribing to Pro: Apple or Google reports the purchase, and its later renewals, cancellations and refunds, to us through RevenueCat. Otherwise the one record that originates with somebody else is your membership of a wallet you were invited into, which names the person who invited you.

6. Transfers, Including Abroad

Your personal data is transferred to Supabase Inc., our hosting and authentication provider, acting as a data processor, so that the service can be provided. Its servers are servers operated by Supabase Inc. (AWS ap-northeast-2 — Seoul, South Korea); your data is therefore transferred abroad within the meaning of KVKK Art. 9.

The transfer is necessary for the performance of the contract and is protected by our agreement with the processor and by technical and administrative measures.

Where you choose Sign in with Apple or Sign in with Google, the sign-in request is transferred to Apple Inc. or Google LLC in the United States so that the provider can confirm your identity; for that step it acts as an independent controller and receives nothing about your records.

Where you have allowed notifications, your push token and the text of the notification are transferred to Expo, Apple (APNs) and Google (FCM) in the United States, solely so that the message can be delivered.

Where you have allowed location, your device's operating system transfers your approximate coordinates to Apple Inc. (iOS) or Google LLC (Android) in the United States, solely so that the country you are in can be looked up; for that lookup the provider acts as an independent controller and receives nothing about your records.

Your account identifier and, if you subscribe, your purchase data are transferred to RevenueCat, Inc. in the United States, acting as a data processor, so that Pro purchases can be verified and managed. Where you subscribe, the payment itself is processed by Apple Inc. or Google LLC as an independent controller.

Where you share a wallet, its records together with your display name and avatar become visible to the people you invited. That disclosure happens only on your own instruction and you can end it at any time by removing the member. When you send a request to join through a sharing link, your display name and avatar are shown to the link's owner; none of your records are.

Beyond this, your data may be transferred only to legally authorised public authorities, to the extent required by law.

7. Retention Period

Your personal data is retained for as long as your account exists. If you delete your account, the data is permanently deleted; copies in system backups are purged as the backup cycle rolls over, within 30 days at the latest. A guest account is deleted when you sign out of it, since nothing else can reach it. Purchase data is deleted together with the account, and the customer record held by RevenueCat is deleted at our request at the same time; Apple and Google keep their own purchase records under their policies.

Messages sent through the feedback form are kept for up to two years and then deleted, whether or not the account still exists; once an account is deleted they are no longer linked to it.

Usage data is kept for 90 days and then deleted; once an account is deleted it is no longer linked to it. A sharing invitation is deleted at the latest 14 days after it expires, together with the requests to join sent through it. Payment-capture drafts on your device are kept for 14 days at most.

Where a statutory retention obligation applies, the relevant data is kept only for the period and to the extent that obligation requires.

8. Your Rights as a Data Subject (KVKK Art. 11)

By applying to the data controller, you have the right to:

  • Learn whether your personal data is processed;
  • Request information if it has been processed;
  • Learn the purpose of processing and whether the data is used accordingly;
  • Know the third parties, in Türkiye or abroad, to whom the data is transferred;
  • Request correction if the data is incomplete or inaccurate;
  • Request erasure or destruction under the conditions in KVKK Art. 7;
  • Request that corrections and erasures be notified to third parties to whom the data was transferred;
  • Object to a result reached against you through analysis carried out solely by automated systems;
  • Claim compensation for damage arising from unlawful processing.

9. How to Apply

In line with the Communiqué on the Procedures and Principles of Application to the Data Controller, send your request together with information identifying you to nomadbudget@rubeeks.co. Writing from the email address registered in our system speeds up identity verification.

State the subject of your request clearly. Requests are answered free of charge as soon as possible and within 30 days at the latest. If responding involves an additional cost, the fee set by the Personal Data Protection Board may be charged.

If your application is rejected, you find the answer insufficient, or no answer is given in time, you may complain to the Personal Data Protection Board within 30 days of learning the answer and in any case within 60 days of the application date.