Privacy Policy
This Privacy Policy explains what information FAK collects, why it is used, how it is stored and protected, and the choices available to users.
Information FAK Collects
Account Information
New users must create a FAK account to use FAK, including when using the Free tier. Existing account restoration remains available for users returning to an existing FAK account.
Creating and using an account may involve an email address, a unique account identifier, account status information, sign-in and security information, and information needed for password recovery.
For eligible new accounts, FAK also processes information needed to issue and administer the 30-day Pro Trial, including Trial eligibility or enrolment status, the Trial start time, Trial expiry time and resulting Pro-access status.
Supabase provides the account, authentication and password-recovery infrastructure used by FAK.
FAK does not ask for a profile name, postal address, telephone number or date of birth when creating a normal account.
2Factor Authentication
Users may choose to protect their account with 2Factor Authentication.
When enabled, the authentication service processes the information needed to set up and verify 2Factor Authentication. FAK uses the resulting security status to help protect the account.
FAK does not gain access to the user's authenticator app.
Budgeting Information
Users manually enter information such as budgets, spending, income, recurring expenses, categories, dates and budget settings.
FAK does not connect to bank accounts, request banking login details or receive raw payment-card information.
Budgeting information is stored on the user's device. When a signed-in account uses cloud backup, applicable budgeting information may also be stored securely in FAK's backend and linked to that FAK account.
Cloud Backup and Account Restore
Cloud backup allows compatible account data to be restored if a user changes, loses or replaces a device.
A backup may include budgets, transactions, income, recurring expenses, categories, settings, preferences and information needed to recreate reports and budgeting history.
Backup data is linked to the user's FAK account so that it can be restored to the correct account.
Subscription and Purchase Information
RevenueCat provides subscription-management infrastructure for FAK's Paid Subscription Plans.
Subscription information may include the FAK account identifier, app store and platform, subscription product, subscription status, purchase and renewal information, expiration information and other technical information needed to verify and manage subscription access.
The FAK account identifier used for this purpose does not contain the user's email address.
Apple or Google processes payments made through the applicable app store. FAK does not receive the user's raw payment-card details.
Support and Bug Reports
When a user sends a Support or Bug report through FAK, the submission may include the user's message and, if provided, a reply email address.
To help diagnose technical problems, Support and Bug reports may also include the device model, operating system and version, application version, build version and platform.
These technical details are not included with submissions categorised as Feedback, Feature Idea or Other.
Support and Bug reports do not include financial or budget data, passwords, authentication tokens, 2Factor Authentication codes or setup keys, precise location, telephone numbers, device serial numbers, MAC addresses, contact lists or the user's FAK account identifier.
Product Analytics
FAK uses PostHog to understand how the app is used and to improve its features and usability.
Analytics is limited to selected categories of activity. FAK does not automatically record screens, taps or touches, and analytics is not linked by FAK to a user's FAK account.
Analytics may record general actions such as completing onboarding, selecting a type of budget or whether it is a Free or paid feature, creating or switching budgets, using spending and income logging, viewing areas such as Home, History, Stats or Reports, general account and Account Restore outcomes, completing 2Factor Authentication, selecting a feedback category, or viewing the Upgrade Banner.
PostHog may also process technical information such as a pseudonymous installation or device identifier, session identifier, app version and build, device type and model, operating system, locale, time zone, screen dimensions, analytics software information, source IP address and an approximate country or region derived from that information.
FAK does not request precise GPS location for Product Analytics.
Analytics does not include manually entered financial amounts, budget names, transaction details, backup contents, FAK account identifiers, email addresses, passwords, 2Factor Authentication codes or setup keys, Contact messages, account-deletion content or raw application and server errors.
FAK does not use Product Analytics for advertising, cross-app tracking, selling user profiles or linking a person's financial activity to a known account identity.
Security and Contact Abuse Prevention
When a Contact form is submitted, the hosting and security infrastructure temporarily processes the source IP address to help prevent spam, repeated submissions and abuse.
FAK creates a pseudonymous security identifier from this information rather than storing the raw IP address in its rate-limiting records.
These security identifiers change daily and are kept for no longer than approximately 48 hours, with some records kept for shorter periods.
This information is not used for advertising, user tracking or profiling.
Infrastructure providers may separately process IP addresses in operational or security logs under their own applicable practices.
How Information Is Used
Information may be used to:
- Provide budgeting features, accounts, cloud backup and Account Restore.
- Authenticate users, recover passwords and protect accounts with 2Factor Authentication where enabled.
- Determine eligibility for, issue and administer the 30-day Pro Trial, and verify and manage access to Paid Subscription Plans.
- Receive, protect and respond to Contact submissions.
- Understand general product use and improve FAK.
- Protect users and the security and integrity of the service.
- Meet applicable legal obligations.
Service Providers
FAK uses a limited number of service providers to operate the app:
- Supabase — account authentication, account data, cloud backup and restore, feedback functions, subscription-access verification and other backend services.
- RevenueCat — subscription, purchase-status and subscription-access infrastructure.
- PostHog — privacy-minimised Product Analytics.
- Resend — sends a generic internal notification when a feedback submission is received. The feedback message, reply email address and technical details remain in the FAK backend and are not included in that notification email.
- Apple — iOS app distribution, store payments and subscription processing.
- Google Play — Android app distribution, store payments and subscription processing.
Information FAK Does Not Collect
FAK does not intentionally ask users to provide bank-account details, payment-card details, banking login credentials, government identification numbers, precise location, contact lists, photographs, camera recordings or microphone recordings.
FAK does not hold, move, transfer or invest users' money and does not provide lending, insurance, credit or payment services.
FAK is a manual budgeting and spending-habit app. It is not a financial-advice, investment-advice, tax, accounting or bookkeeping service.
FAK does not provide financial, investment or tax advice and does not guarantee savings, financial improvement or any particular financial outcome.
FAK provides tools for budget planning and financial tracking based on information entered by the user. The accuracy and usefulness of the app therefore depend on the accuracy and completeness of that information. Users remain responsible for their financial decisions and use FAK at their own discretion.
Legal Bases
Where EU data-protection law applies, information needed for account authentication, account ownership, Trial administration, cloud backup, Account Restore and subscription administration is processed as necessary to provide the service requested by the user or to perform the applicable contract.
Support information is processed to provide assistance requested by the user and, where appropriate, for the legitimate interest of maintaining and improving FAK.
Security, abuse prevention, rate limiting and service-integrity information is processed for the legitimate interest of protecting users and the service.
Information that must be processed to comply with the law is processed on the basis of the applicable legal obligation.
Product Analytics is processed for the legitimate interest of understanding how FAK is used and improving the app. This is balanced by limiting analytics to selected categories of activity, using pseudonymous identifiers, not linking analytics to FAK account identities, and excluding financial amounts and sensitive content.
Where applicable law requires another legal basis or an additional user choice, that requirement will be applied before the relevant processing is used.
Data Retention
Budgeting information stored on a device remains there until it is removed through FAK or normal device operations.
Account information, including information used to determine and administer Trial eligibility, issuance and expiry, and cloud backup data are kept for as long as reasonably necessary to operate the account, administer access, provide backup and Account Restore, deal with security or support matters, prevent repeated Trial issuance, or meet applicable legal obligations.
When a FAK account is deleted, applicable FAK account and cloud backup data is removed through the account-deletion process, subject to information that must be retained for legal or security reasons.
Contact submissions and related technical information are kept only for as long as reasonably necessary to respond to the user, diagnose problems, maintain appropriate communication records, protect the service or meet legal obligations.
Security rate-limiting information is retained for the periods described above.
Pseudonymous Product Analytics is kept only for as long as reasonably necessary for the purposes described in this Policy and may later be deleted or anonymised, subject to provider configuration and legal obligations.
Apple, Google and RevenueCat may keep purchase and subscription records under their own legal, accounting, fraud-prevention and service requirements. Deleting a FAK account does not control those independent records and does not cancel an app-store subscription.
International Processing
Service providers may process information in countries other than the user's own where necessary to provide their services.
Such processing is subject to applicable data-protection laws and contractual requirements.
Data Security
Reasonable technical and organisational safeguards are used to protect information handled by FAK.
Access to information is limited to what is reasonably necessary to operate, support and protect the service.
No method of electronic storage or transmission over the internet can be guaranteed to be completely secure.
User Rights and Choices
Depending on the law that applies, users may have rights to request access to, correction of, deletion of, restriction of, or portability of eligible personal information.
Users may also have the right to object to certain processing based on legitimate interests, withdraw consent where processing is based on consent, or complain to the relevant data-protection authority.
Product Analytics is pseudonymous and is not linked by FAK to an account email address or FAK account identifier. This may limit the ability to identify a particular analytics profile in response to an individual request without information that identifies the relevant app installation.
Account Deletion
Users can delete their account directly through the FAK app or request account deletion at fakbudgets.com/delete-account/.
Account deletion removes the FAK account, applicable account-owned cloud backup and applicable local budgeting data linked to that account through the implemented deletion process, subject to information that must be retained for legal or security reasons.
Deleting a FAK account does not automatically cancel an Apple App Store or Google Play subscription.
Any active subscription must be managed separately through the app store where it was purchased to prevent future renewals or charges where applicable.
Children's Privacy
FAK is not intended for children below the minimum age required by applicable law to use the service without parental consent.
If information is found to have been collected contrary to applicable law, reasonable steps will be taken to remove it.
Changes to This Privacy Policy
FAK may update this Privacy Policy from time to time.
The version number and Last updated date identify the current document.
Where appropriate, including when a material change is made, users may be required to acknowledge an updated Privacy Policy before continuing to use FAK.
Contact
FAK is operated from Portugal. Privacy enquiries can be addressed to Guillaume de Villiers and sent to [email protected].