Floosy Privacy Policy
Last updated: June 6, 2026
Contact: proga.egy@gmail.com
Floosy (“we”, “our”) provides a personal finance assistant mobile app. This policy describes what data we collect, how we use it, and your choices.
Data we collect
Account information
- Email address and authentication identifiers when you sign up or sign in (via Supabase Auth).
- OAuth profile data when you use Google or Apple sign-in.
Financial information you provide
- Expenses, income, payment commitments, assets, liabilities, and zakah-related inputs you enter or dictate in the app.
- This data is stored in our backend database linked to your account.
Voice input
- When you use hold-to-talk, a short audio recording is sent to our servers and transcribed using Groq’s Whisper speech-to-text service.
- Audio is processed in memory for that request only (we do not save voice files to our database or disk). Any temporary upload buffer from the web framework is deleted as soon as the audio is read.
- We receive the transcribed text for AI processing; raw audio is not kept after transcription completes. Groq processes the audio under their own terms.
- For English voice turns, we may generate a short spoken summary using Groq text-to-speech. The summary text is sent to Groq for synthesis; the resulting audio is returned to your device for playback and is not stored on our servers.
- Language is detected automatically by the transcription service (you do not need to select a language).
AI processing (text)
- We process text you type or dictate (including transcriptions) to provide AI-assisted features such as insights, summaries, and chat responses.
- This may involve sending relevant text (and limited associated context like category/merchant labels) to our AI providers for processing under their terms.
AI usage and subscription tier
- We track AI usage counters on our servers (for example chat turns, advisor refreshes, voice requests) to enforce free-tier limits and provide remaining-balance information in the App.
- Your subscription tier (free or Floosy Plus) and entitlements (such as ad-free and Pro AI access) are stored on our backend and synced from Google Play / the Apple App Store via RevenueCat when you subscribe.
Device and app data
- App interactions needed to operate the service (e.g. API requests, error diagnostics when enabled).
- Error monitoring & performance: When enabled on our servers, we use Sentry to collect crash reports and performance telemetry (e.g. request timing, stack traces, and device/app metadata) to improve reliability. We do not send LLM prompts or completions to Sentry.
- Advertising (Google AdMob): If you use the free tier (or are not subscribed to Floosy Plus), Google AdMob may collect device identifiers, ad interaction data, and approximate location per Google’s ad partners policy. AdMob serves programmatic third-party ads in designated slots.
- Partner campaigns (first-party): Floosy may show curated partner offers labeled Sponsored in the app. These are sold and served directly by Floosy, not through AdMob. Partner offers may appear for both free users and Floosy Plus subscribers.
- Sponsorship analytics: When a partner offer is shown or you tap its call-to-action, we record an impression or click event (campaign id, placement, event type) on our backend for campaign reporting. We do not send your financial transaction details to partners through these events.
- Purchases: If you subscribe to Floosy Plus, Google Play or the Apple App Store and RevenueCat process subscription status linked to your Floosy user id. Plus removes network (AdMob) ads and unlocks higher AI usage limits; partner campaigns may still appear.
Local-only data
- Biometric unlock preferences are stored on your device and are not sent to our servers.
- Local notification schedules for payment reminders are stored on your device.
- If you enable Morning briefing, we store your FCM device token, timezone, and preferred delivery time on our servers to send personalized push notifications.
Bank SMS detection (Android, optional)
- If you opt in under Settings, the Android app may read purchase and credit SMS from banks and wallets on your device to suggest expenses or income for your review.
- Only messages that look like financial transactions are forwarded to our servers; OTP and promotional SMS are ignored on-device when possible.
- SMS content is used to create a pending draft for you to confirm before anything is saved. Raw SMS text is purged from our servers after you confirm, dismiss, or after a short retention period (typically within 7 days).
- This feature is off by default and requires SMS permission on Android. It is not available on iOS.
How we use data
- Provide core app features (tracking expenses, insights, wealth tools, AI-assisted chat).
- Authenticate you and secure your account.
- Enforce AI usage limits and show remaining credits in the App.
- Show network ads (AdMob) on the free tier, optional partner campaigns, and manage Floosy Plus subscriptions.
- Improve reliability and fix bugs.
We do not sell your personal financial data.
Data retention
We retain your data while your account is active. When you delete your account in Settings, we delete your authentication account and associated app data.
Your choices
- Access and correction: Update financial data in the app.
- Delete account: Settings → Danger zone → Delete account (permanent). See Delete your Floosy account for full steps and what data is removed.
- Floosy Plus: Subscribe via Settings to remove network (AdMob) ads and increase AI limits, or limit ad tracking in your device settings. Partner offers may still appear when enabled by Floosy.
- Notifications: Disable in system settings or do not grant permission in the app.
- Bank SMS detection (Android): Turn off in Settings or revoke SMS permission in Android system settings.
Third-party services
- Supabase (authentication, database hosting)
- Groq (speech-to-text, optional text-to-speech, and AI processing when enabled)
- Google Cloud (API hosting)
- Firebase Cloud Messaging / Google Firebase (push notification delivery)
- Google AdMob (advertising)
- RevenueCat (subscription management)
- Google / Apple (OAuth sign-in and in-app billing)
- Sentry (error monitoring and performance telemetry, when enabled)
- Langfuse (LLM/agent tracing, when enabled)
Each provider has its own privacy policy.
Children
Floosy is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect data from children.
International transfers
Your data may be processed in the United States and other countries where our providers operate.
Changes
We may update this policy. We will post the new version at this URL and update the “Last updated” date.
Contact
Questions or requests: proga.egy@gmail.com