Nomad Budget

Privacy Policy

Version 2.1 · Effective: 2026-10-01

Nomad Budget holds your financial records, so privacy is not an afterthought here. This policy explains what data we process, why, and what rights you have over it.

In short: we do not sell your data, we show no advertising, the App runs no third-party analytics or tracking, and you can delete your account and everything in it from inside the App at any time. We do measure how the App is used, on our own server and without content such as amounts or notes (see "Usage data").

1. Who Is Responsible

The party responsible for processing your data (the data controller) is Rubeeks (rubeeks.co).

Contact: nomadbudget@rubeeks.co

2. Data We Process

Account data: your email address, a cryptographic hash of your password (never the password itself), your account creation date, session information, and the version and date of the consent you gave at sign-up. An account created with Sign in with Apple or Sign in with Google has no password hash at all: what is held instead is the identifier the provider issues for you in this App, together with the address it passed on — with Apple, a private relay alias if you chose to hide your own; with Google, always the address of your Google account. Your name is written to your profile as a starting display name you are free to change. Apple offers it once, on the very first sign-in and never again; Google offers it on every sign-in, but it is read only the first time, so a display name you changed later is never overwritten.

The financial records you enter: wallets (name, country, currency, opening balance), transactions (amount, currency, date, type, category, note, event tag), categories, budgets, goals and recurring rules.

Your travel records: the visits and crossings you confirm or enter for the map — which country, the first and last day there, where you arrived from and left for, how you travelled, and which of your transactions was the ticket — and the countries you mark as visited from memory. The App suggests these from the dates and countries of your transactions; nothing is recorded until you confirm or enter it.

Files you import (optional): when you choose to import a CSV or Excel file, it is opened through your device's file picker and read on the device. Only the rows you confirm are written to your records, as ordinary transactions. The file is neither uploaded nor retained, and the App can reach no file you did not pick.

Captured payments (optional): if you turn on payment capture (see the Terms of Use, "Capturing Payments"), on Android the App uses the device's notification access to read, on the device, the notifications of the sources you switched on — the SMS apps, for bank text messages, and the bank and wallet apps you pick. A notification with no amount of money in it is let go the moment it is read and written nowhere; one with an amount waits on the device until the App is opened, and is deleted there and then if it turns out not to be a payment. Of an app you have not picked, only its name and how many notifications with an amount it has sent are kept on the device, to be listed for you. On iOS the App cannot read other apps' notifications; it receives only the amount, merchant or message text that a Shortcuts automation you set up passes to it. Either way, the message text, the draft made from it and the patterns the App learns from your bank's message format stay on your device and are never sent to our servers. When you confirm a draft, only the transaction you save (amount, currency, date, category, note and wallet) is stored, like any other record.

Profile: the display name and the avatar you pick. These are the only things another person sees about you when you share a wallet — or, when you send a request to join through a sharing link, the person who receives it — and your email address is never shown to another user. If you have no display name yet, you are asked for one when sending a request, and it is written to your profile.

Guest sessions: you can use the App without creating an account. A guest account holds the same records, and the same record of the consent you gave, as a full one, but it has no email address and no password: the session stored on that single device is the only thing that reaches it. Signing out therefore deletes the account and everything in it, irreversibly. Adding an email and a password later turns the very same account into a full one, with nothing moved and nothing lost.

Preferences: interface language, theme and base currency.

Subscriptions (Pro): so that the App can tell whether you have Pro, it registers your account's identifier — a random ID, never your email address — with RevenueCat, our subscription provider, whenever you are signed in. If you subscribe, the store (Apple or Google) takes the payment and reports the purchase to RevenueCat and, through it, to us: the plan, the store, the dates of purchase, renewal and expiry, whether it will renew, billing problems and refunds, the store's transaction identifiers, and the price and currency charged. RevenueCat also receives the technical data such a request carries: the App and operating-system version, the store country and the device's IP address. We never receive your card or bank details or the name on your store account.

Technical data kept on your device: your session token, the local cache that makes offline use possible, records queued while you have no connection, a random installation ID, usage data not yet sent, payment drafts waiting for your confirmation, and the code of a sharing link you opened before you had an account. These stay on your device; what belongs to your account is removed when you sign out, and everything when you uninstall the App.

Usage data: to understand how the App is used and to find and fix errors, the App records on our own server which steps were seen and how they ended: for example how far into the welcome screens someone got, how a sign-up or sign-in attempt ended (including the error code), the setup steps, what opened the entry form and whether it was saved, the answers to the permissions the App itself asks for (notifications, location), which feature opened the Pro screen and how a purchase ended, whether a sharing invitation was opened and used, and unexpected errors (an error message with email addresses, long numbers and identifiers stripped out, and a short technical trace). Each record carries the App version, whether the device runs iOS or Android, the interface language, the time, the random installation ID and — when you are signed in — your account. Amounts, notes, category and wallet names, location and contact details never go into it. The installation ID is a random value the App makes on first launch; it is not a device or advertising identifier and is deleted when you uninstall the App.

Notifications (optional): if you allow them, your device registers a push token with us, together with whether it is an iOS or an Android device, so that we can tell you when someone acts in a wallet you share, when one of your monthly budgets reaches 80% of its limit or goes over it, when someone asks to join through one of your sharing links, and when a request you sent is approved (you can turn budget alerts and sharing notifications off in the App's notification settings). The App's reminders — when you have not logged anything for a while, once if you have logged nothing since setup, and when a recurring transaction is due — and the notifications asking you to confirm a captured payment are created by your device itself; they need neither a token nor a server, and can be turned off in the notification settings. On iOS, when setup ends, the App asks — without showing you a permission prompt — for notifications to be delivered quietly (without sound or banner) to Notification Center; iOS offers you to keep or turn this off with the first quiet notification. You can withdraw the permission at any time in your device settings.

Messages you send us (optional): when you use "Send feedback" in the App, we receive what you write, the kind you picked (problem, idea or other), the email address you give for a reply if you give one, and the device context the form shows you before sending: the App version, whether the device runs iOS or Android and which version, the device model and the interface language — together with your account and whether it is a guest or a Pro account. Only we read it, and only to answer you and to improve the App. The same applies if you write to nomadbudget@rubeeks.co instead.

Camera (optional, QR codes only): the camera opens only when you choose to scan a sharing invitation, and only to read the code in front of it. No photo or video is taken, stored or transmitted.

Location (optional, country only): if you grant permission, your device's approximate location (coarse, city-level accuracy at most) is used to determine which country you are in, and the transactions you record and the countries you visit are marked with that two-letter country code. To turn the location into a country, the App uses the geocoding service built into your device's operating system, provided by Apple (iOS) or Google (Android): your approximate coordinates are sent to that service for the lookup, and only the country comes back. Your coordinates are never stored and never sent to our servers. You can decline the permission, or withdraw it at any time in your device settings — the country is then inferred from your wallets and the rest of the App works exactly as before.

What we do not collect:

  • Bank or card details — the App connects to no financial institution, and payment for Pro is handled entirely by Apple or Google.
  • Location history or coordinate logs — beyond the country described above, nothing about your location is retained.
  • Contacts, photos or any file on your device other than one you explicitly pick to import.
  • Your text messages and other apps' notifications — the App has no permission to read SMS; notifications are read only if you turn on payment capture, on the device as described above, and are not sent to our servers.
  • Advertising identifiers or cross-app tracking data.
  • Third-party analytics, crash-reporting or marketing SDK data — the App contains none of these.

3. Purposes and Legal Bases

  • Creating and securing your account — performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)).
  • Storing, syncing and displaying your records — performance of a contract.
  • Currency conversion, budget and goal tracking, summaries and charts — performance of a contract.
  • Drawing your map and route from your records, and pricing your own spending pattern against other countries — performance of a contract.
  • Deriving the country from your location, to mark your spending and fill the map and the country comparisons — explicit consent (KVKK Art. 5/1; GDPR Art. 6(1)(a)). This consent is given only through the device permission and can be withdrawn at any time in your device settings.
  • Preparing draft entries on your device from your bank's and wallet app's payment notifications, or from a Shortcuts automation you set up — explicit consent (KVKK Art. 5/1; GDPR Art. 6(1)(a)), given on Android through the device's notification access and the sources you switch on in the App, and on iOS by your setting up the automation, and withdrawable at any time in the same places.
  • Preventing abuse, debugging and keeping the service secure — legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)).
  • Measuring how the App is used, finding the steps where people get stuck and the errors they meet, and improving the App (usage data) — legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)). You can object to this processing (see "Your Rights").
  • Answering the messages you send us and fixing the problems you report — legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)).
  • Letting you share a wallet with someone you invite, answer requests to join that come through a link, and join a wallet you are invited to — performance of a contract.
  • Selling Pro, checking whether you have it, and handling renewals, cancellations, refunds and restored purchases — performance of a contract.
  • Sending push notifications about activity in a wallet you share, requests to join and your budgets, and showing reminders — explicit consent (KVKK Art. 5/1; GDPR Art. 6(1)(a)), given through your device's notification permission and withdrawable at any time in your device settings.
  • Sending service messages you cannot opt out of (email confirmation, password reset) — performance of a contract.
  • Complying with legal obligations and responding to lawful requests — legal obligation (KVKK Art. 5/2-ç; GDPR Art. 6(1)(c)).

We do not use your data for profiling, automated decision-making or marketing.

4. Where Your Data Is Stored and International Transfers

Your account and records, usage data and the messages you send us are hosted on servers operated by Supabase Inc. (AWS ap-northeast-2 — Seoul, South Korea). Your data is therefore transferred outside Türkiye (KVKK Art. 9).

South Korea is covered by an adequacy decision of the European Commission. The transfer is necessary to provide the service and is protected by our contract with the hosting provider and by technical safeguards.

When fetching exchange rates, only currency codes are sent to the rate service; no personal data and no transaction details ever leave the App for that purpose. The country illustrations on the map are fetched from our hosting provider's storage by country code alone.

Push notifications are handed to Expo's push service and from there to Apple (APNs) or Google (FCM) for delivery. Those providers receive your push token and the text of the message, which for an event in a shared wallet names the person who acted, the wallet, and the amount of the record, for a budget alert names the budget (its category, or your monthly budget), how much has been spent and its limit, and for a request to join or its approval names the other person's display name and the wallet. That is a transfer to the United States, made only for as long as delivering the message takes, and it stops the moment you turn notifications off in your device settings. Reminders and the confirmation notifications for captured payments are created on your device and are not sent to any of these services.

Subscription data is processed by RevenueCat, Inc. in the United States, as our data processor and under its data processing terms, which is also a transfer abroad. It covers only your account identifier and your purchases: none of your financial records, travel records or profile is sent to RevenueCat.

5. Sharing

We do not sell, rent or share your data for advertising. Data is disclosed to third parties only in the following cases:

  • Hosting and authentication provider (Supabase Inc.): as a data processor, solely to run the service.
  • Sign in with Apple (Apple Inc.): if you choose it, Apple confirms to us that the Apple ID is yours, and in doing so learns that you use the App. For that step Apple is an independent controller under its own privacy policy. Nothing about your records is sent to it.
  • Sign in with Google (Google LLC): if you choose it, Google confirms to us that the Google account is yours, and in doing so learns that you use the App. For that step Google is an independent controller under its own privacy policy. Nothing about your records is sent to it.
  • Subscription provider (RevenueCat, Inc.): as a data processor, your account identifier and your purchase data, solely to verify and manage Pro.
  • App Store (Apple) and Google Play (Google): if you subscribe, the store processes the payment as an independent controller under its own terms and privacy policy. Nothing about your records is sent to it.
  • Email delivery: your email address only, to deliver confirmation and password-reset messages.
  • Notification delivery (Expo, Apple, Google): your push token and the text of the notification, solely so that the message can be delivered.
  • Country lookup (Apple, Google): if you allow location, your device's operating system sends your approximate coordinates to Apple's (iOS) or Google's (Android) geocoding service, solely to name the country you are in. For that lookup the provider is an independent controller under its own privacy policy. Nothing about your records is sent to it.
  • Other people you share a wallet with: only what the next section describes, and only because you chose to invite them or to accept an invitation.
  • Lawful requests: where properly requested by a competent authority, to the extent the law requires.

6. When You Share a Wallet

Sharing is off until you turn it on: no wallet of yours is visible to anybody else unless you create an invitation for it yourself.

Someone who joins sees that wallet's records in full — amounts, dates, categories, notes and the country each record was entered in — and, for each record, which member entered it. An editor can also add and change records; a viewer cannot.

What they see about you as a person is your display name and your avatar, and nothing else. Your email address is never disclosed to another user.

A QR code shown face to face lasts 15 minutes and can be used once; a link sent in a message lasts 7 days and only creates a request to join. When a request comes in you see the requester's display name and avatar; until you approve, they cannot see any of your records — while waiting they see only your display name, your avatar and the names of the wallets their request covers. You can revoke either kind of invitation before it is used. You can remove a member at any time, which ends their access immediately, and a member can leave on their own.

Both sides of a share need a full account. A guest session can neither invite nor join: a guest account can vanish with its device, and the other person would be left trusting something unreachable.

7. Retention and Deletion

Your data is retained for as long as your account exists.

When you delete your account via Settings → Delete Account, your identity record, wallets, transactions, categories, budgets, goals, recurring rules, visits, crossings and marked countries are permanently deleted. This cannot be undone.

Deleting your account also ends the shares you had given: the wallets you shared disappear for their members at the same moment, along with your profile and your push token. Records you entered in a wallet belonging to somebody else stay where they are, because they are that person's records; they simply stop being attributed to you.

A guest session is deleted by signing out of it. That is not a sign-out in the ordinary sense — it is the deletion of the account, because nothing else reaches it — and it cannot be undone.

Your subscription record with us is deleted together with your account, and we have RevenueCat delete the customer record it holds for you at the same time. Apple and Google keep their own records of a purchase under their policies. Deleting your account does not cancel a subscription — see the Terms of Use.

Copies remaining in system backups are purged as the backup cycle rolls over, within 30 days at the latest. The local cache on your device is removed when you uninstall the App.

Messages you send us through "Send feedback" are kept for up to two years and then deleted. Deleting your account does not delete them, so that a report can still be answered, but they are no longer linked to any account. You can ask us to delete one sooner by writing to nomadbudget@rubeeks.co.

Usage data is kept for 90 days and then deleted automatically. When you delete your account, what remains of it until then is no longer linked to any account.

A sharing invitation is deleted at the latest 14 days after it expires, together with the requests to join sent through it; of an approved request, only the wallet membership remains.

Payment drafts exist only on your device: they are deleted when you confirm or dismiss them, when you sign out, or when 14 days pass without your confirming them.

You can also request deletion by writing to nomadbudget@rubeeks.co.

8. Security

All traffic between your device and the server is encrypted with TLS. Data is stored on encrypted disks.

Every table is protected by row-level security rules: at the database level, a user can only reach their own records.

Your password is never stored in plain text — only an irreversible hash of it is kept.

No system can be absolutely secure; please protect your account with a strong, unique password.

9. Cookies and Similar Technologies

The mobile app uses no cookies. Keeping you signed in and working offline rely on your device's own secure storage and local database. The local database also holds a random installation ID, made on first launch to group usage data from the same installation; it is not shared with other apps or advertising networks, is never used to track you across apps or websites, and is deleted when you uninstall the App.

10. Children's Privacy

The App is not directed at people under 18 and we do not knowingly collect their data. If we find that we have, we delete the account and its data.

11. Your Rights

Under KVKK Art. 11 and — where it applies to you — the GDPR, you have the right to:

  • Learn whether your personal data is processed, and request access to it.
  • Have incomplete or inaccurate data corrected.
  • Request erasure or destruction of your data.
  • Request restriction of processing and object to processing.
  • Receive your data in a structured, commonly used format (data portability).
  • Claim compensation if you suffer damage from unlawful processing.

You can exercise most of your access and correction rights directly in the App: every record you have is visible, editable and deletable there.

With Pro, the App can also export your transactions as a CSV file. Data portability is a right on every plan: without Pro, write to nomadbudget@rubeeks.co and we will send your data in the same format.

You can object to the processing of usage data: write to nomadbudget@rubeeks.co and we will delete the usage data linked to your account and stop keeping any that arrives for it from then on.

For anything else, write to nomadbudget@rubeeks.co; requests are answered within 30 days at the latest. See the "Data Protection Notice (KVKK)" for the detailed application procedure.

12. Changes to This Policy

We may update this policy. Material changes are announced in the App or by email before they take effect. The effective date and version are always shown at the top of this document.

13. Contact

For any privacy question, request or complaint: nomadbudget@rubeeks.co