Amais: Money Manager is a personal finance tracker built around a simple idea: your financial records live on your device, and anything that leaves it is either something you explicitly asked for or the minimum needed to run the optional services described below.
This summary is provided for convenience only. It is not a substitute for the full policy below, which governs.
This Privacy Policy explains how personal data is handled in connection with the mobile application Amais: Money Manager (the "App"), including any updates, and the related web pages we publish at https://sheikhamais.github.io/moneymanager/privacy/ and https://sheikhamais.github.io/moneymanager/terms/ (together, the "Service").
The party responsible for the App — the "data controller" for the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR, and the "business" for the purposes of the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") — is:
Amais Sheikh, an individual developer
Pakistan
Email: sheikhamais@gmail.com
References to "we", "us" and "our" mean that party. References to "you" and "your" mean the person using the App.
Contacting us about privacy. For any question, request, or complaint about privacy or personal data, including to exercise any of the rights described in Section 14, write to sheikhamais@gmail.com. This is our designated contact address for all privacy matters worldwide, and it is monitored.
We have not appointed a Data Protection Officer, because our processing does not meet the thresholds in Article 37 GDPR. Privacy enquiries go to the address above.
This policy applies to the App and to the legal pages we publish for it at https://sheikhamais.github.io/moneymanager/privacy/ and https://sheikhamais.github.io/moneymanager/terms/.
This policy does not apply to:
Because several external services are involved, here is a plain map of who does what and in what capacity, before the detailed sections below:
| Service | What it's used for | Its role |
|---|---|---|
| Firebase Authentication (Google) | Optional Google/Apple sign-in — Section 6 | Our processor: acts on our instructions to run the identity system we chose to use |
| Cloud Firestore (Google/Firebase) | Premium encrypted cloud sync — Section 8 | Our processor: stores only the encrypted, opaque data our App sends it |
| RevenueCat | Subscription/entitlement management — Section 7 | Our processor: verifies and tracks what you've purchased on our behalf |
| Apple (App Store, StoreKit, Sign in with Apple) | Distribution, payment, Apple sign-in — Sections 2, 6, 7 | Independent controller: Apple decides how it uses this data under its own policy |
| Google (Sign-In, AdMob) | Google sign-in identity, advertising — Sections 2, 6, 9 | Independent controller: Google decides how it uses this data under its own policy |
| GitHub Pages | Hosts this policy and our Terms | Independent controller: for the technical logs of visiting these web pages only |
Amais: Money Manager is a general-purpose personal finance utility. It contains no chat, no messaging, no social features, no user-generated content shared with others, and no way for one user to contact another. You must be at least 13 years old to use the App — see Section 3 of the Terms and Conditions.
Parents and guardians. If you believe a child has provided personal data to us, contact sheikhamais@gmail.com and we will investigate and delete anything found. Parents should also be aware that a subscription purchase is charged to the Apple Account signed in on the device; Apple provides Ask to Buy and Screen Time controls to manage this.
The App does not:
Every account and transaction you create — title, balance, amounts payable/receivable, investment values, transaction details, tags, dates — is stored in a SQLite database inside the App's private, sandboxed storage on your device. This is true whether or not you sign in, and whether or not you subscribe. Signing in does not upload this data anywhere by itself — only the separate, opt-in cloud sync feature in Section 8 does that, and only if you turn it on.
Free-text fields. The description you type on a transaction, and the title you give an account, are free text. Be mindful of what you type there — see Section 8.1 for how that text is handled if you enable cloud sync.
You can sign in with your Google account, or (on iOS) with Sign in with Apple. Signing in is entirely optional and does not gate any part of the App — every screen works fully whether you're signed in or not.
When you sign in, we receive, via Firebase Authentication:
| Data | Source |
|---|---|
| A unique account identifier (Firebase UID) | Generated by Firebase when your account is first created |
| Display name | From your Google or Apple account, if shared |
| Email address | From your Google or Apple account, if shared (Apple lets you use a private relay address instead of your real one — that relay address is what we then see) |
| Profile photo URL | From your Google account, if available (Apple does not provide one) |
| Which provider you used | Google or Apple |
This identity information is used only to: (a) show your name in the App, (b) let your $5/year subscription (Section 7) and, if you're premium, your encrypted cloud backup (Section 8) follow you across devices, and (c) let you sign out and back in. We do not use it for marketing, and we do not share it with anyone except the processors described in Section 3 that are necessarily involved in running these features.
You can sign out at any time from the account menu on the Home screen.
Because the App's local database is not automatically split per signed-in user (it's one shared store on the device), when you sign out we ask you a real question, not a formality:
"Do you want to delete the accounts and transactions stored on this device, or keep them for the next person who signs in?"
This choice only affects the local copy on this device. If you had premium cloud sync (Section 8) turned on, your encrypted backup in the cloud is not touched by this local deletion either way — it stays exactly as it was until you separately manage or delete it.
The App offers one subscription: $5.00 USD per year (or the equivalent shown by the App Store in your local currency), unlocking an ad-free experience and encrypted cloud sync (Section 8). It's currently purchasable through the Apple App Store only; Android/Google Play purchasing is not yet available.
If you're a signed-in, premium subscriber, you can turn on an optional backup of your accounts and transactions to Google's Cloud Firestore database (part of the same Firebase platform used for sign-in). This is off by default and only reachable behind the premium paywall.
The first time you turn sync on, the App asks you to create a separate encryption password — not your sign-in password, and something we never see or store:
If you forget this password and lose access to every device that has it saved, your encrypted cloud backup cannot be recovered — by us, by Google, or by anyone. This is a direct consequence of how the encryption is designed: there is no "reset password" option that works, because resetting it would require someone other than you to be able to derive your key, which would defeat the point of end-to-end encryption. If you find yourself in this situation, the only option the App offers is to permanently delete the old encrypted backup and start a fresh one — see the next paragraph.
If you can't remember your password, the App offers an "I don't have this password" option, which permanently deletes your entire existing encrypted backup from our systems and lets you set up a new password with a clean slate. This does not touch your local data on the device you're using at the time.
Firestore, and anyone with server-side access to it, can see: your Firebase UID (which record belongs to which account), the ciphertext blobs themselves (unreadable without your password), the non-secret encryption metadata described above, and the plaintext timestamp of when each record was last changed. At no point does plaintext of your account names, balances, transaction amounts, or transaction descriptions reach our servers or Google's.
Access to your own namespace in Firestore is restricted to your signed-in Firebase account only (enforced server-side).
Turning the sync toggle off in Settings stops any further pushing/pulling — it does not delete your existing encrypted backup. To permanently delete it, use the "I don't have this password" flow described above, or contact us at sheikhamais@gmail.com and we will delete your entire Firestore namespace (the ciphertext, since we cannot read it, but we can still delete it) on request.
Non-premium (free) users may see a rewarded video ad, via Google's AdMob (Google Mobile Ads SDK), at exactly two points: saving a new account, and saving a new transaction. Premium subscribers never see ads. This is currently iOS only — Android does not yet show ads.
A note on the EEA, the UK, and Switzerland. We have not yet integrated a dedicated regional consent tool (such as Google's User Messaging Platform) for these regions, beyond the App Tracking Transparency prompt on iOS described above. Google's own advertising policies independently require a valid consent signal before serving personalised ads to users in these regions, and its systems may serve only limited or no ads there until such a tool is added. We intend to add a proper consent flow for these regions before actively promoting the App there; if you are in the EEA, the UK, or Switzerland and have questions about what, if anything, was shown to you, contact sheikhamais@gmail.com.
| Processing activity | Personal data involved | Purpose | Legal basis |
|---|---|---|---|
| Local storage and use of the App (accounts, transactions, settings) | None received by us; stays on your device unless you enable sync (below) | To provide the App you asked for | Article 6(1)(b) — performance of a contract with you |
| Optional sign-in (Section 6.2) | Name, email, photo URL, provider, Firebase UID | To identify you across devices for subscription/sync | Article 6(1)(b) — performance of a contract, entered into by your choice to sign in |
| Subscription and entitlement management (Section 7) | Firebase UID, purchase/transaction data from Apple | To deliver the premium features you paid for | Article 6(1)(b); Article 6(1)(c) for related tax/accounting obligations |
| Premium cloud sync (Section 8) | Encrypted ciphertext, non-secret KDF metadata, last-modified timestamps, Firebase UID | To provide the opt-in backup feature you turned on | Article 6(1)(a) — your explicit consent, given when you turn the feature on and set a password; Article 6(1)(b) for premium subscribers, as part of that contract |
| Rewarded advertising (Section 9) | Device/usage information processed by Google; advertising identifier only if you grant ATT permission on iOS | To show the optional ad and let Google measure/cap it | Article 6(1)(a) — your consent via the App Tracking Transparency prompt (iOS), together with consent under national ePrivacy rules for accessing information on your device |
| Responding to correspondence you send us | Your email address and message content | To answer you and keep a record | Article 6(1)(b), Article 6(1)(c) for statutory requests, and Article 6(1)(f) — legitimate interest in handling correspondence |
We do not process any special category data under Article 9 GDPR, and we do not process criminal-offence data under Article 10. Where we rely on legitimate interests, you have the right to object under Article 21 GDPR — see Section 14.
If you email sheikhamais@gmail.com, we hold your email address and message content for as long as needed to deal with it, and normally 24 months afterwards for record-keeping, or longer where a legal claim, dispute, or statutory obligation requires it. We do not add you to a mailing list or use your address for marketing.
We do not sell personal information and do not disclose it for money or other valuable consideration. We may disclose information in these circumstances:
We do not disclose information to data brokers, and we do not share personal information for cross-context behavioural advertising.
Using the sign-in, subscription, cloud sync, or advertising features described above means data is processed on servers operated by Firebase/Google Cloud, RevenueCat, Apple, and Google, which may be located outside your country, including in the United States. Where personal data is transferred out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on the safeguard each processor itself provides — typically the European Commission's Standard Contractual Clauses and/or the recipient's certification under the EU-US Data Privacy Framework and its UK/Swiss extensions — as documented in each processor's own privacy policy linked in Section 2. Firestore's ciphertext-only design (Section 8) means that even where your encrypted backup is processed abroad, no plaintext financial data is what's actually transferred. You may request details of the relevant safeguard by writing to sheikhamais@gmail.com.
The rights available to you depend on where you live. We honour the rights below for everyone, wherever you are, so far as it is technically possible.
Unlike a purely local app, we do hold some data about you if you've signed in, subscribed, or turned on cloud sync: your identity fields (Section 6.2), your subscription status (via RevenueCat), and — if sync is on — an encrypted (unreadable to us) backup plus its metadata (Section 8). We can delete all of the above on request. We cannot read, recover, or hand back the plaintext contents of an encrypted cloud backup, because we never had it — only you, via your password, can decrypt it.
Your local accounts and transactions (Section 6.1) remain entirely under your control on your device — visible and editable in the App, and erasable via the sign-out "Delete Data" option (Section 6.3) or by deleting the App.
Under the GDPR and UK GDPR you have the right to:
Representative. We have not designated an Article 27 representative in the EEA or UK, relying on the Article 27(2) exemption: our processing is occasional, does not include large-scale special category data, and is unlikely to result in a risk to individuals' rights.
Depending on your state, you may have rights under the CCPA/CPRA and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states, typically including the right to know/access, delete, correct, opt out of sale/sharing and targeted advertising (we do not sell or share personal information, so there's currently nothing to opt out of in that specific sense — see Section 9 for how our AdMob integration is treated), opt out of profiling, limit use of sensitive personal information (we collect none), non-discrimination, and, in states that provide one, an appeal right — email sheikhamais@gmail.com with "Appeal" in the subject.
CCPA/CPRA statutory disclosures (preceding 12 months): categories collected — identifiers (email, name, Firebase UID), commercial information (purchase/subscription status), and internet/network activity via the AdMob SDK on iOS; sold — no; shared for cross-context behavioural advertising — no; disclosed for a business purpose — to the processors named in Section 12; sensitive personal information collected — no; retention — see Section 15.
Verification. We generally verify a request by corresponding with you at the email address it was sent from, or, for identity-linked data, by confirming you control the signed-in account in question.
We will honour valid requests under Canada's PIPEDA/Law 25, Brazil's LGPD, Australia's Privacy Act 1988, and other applicable data protection laws (Japan, South Korea, India, South Africa, and elsewhere) to the extent they apply to us. Write to us and we will do our best under whichever law applies to you.
Email sheikhamais@gmail.com with the right you want to exercise, your country (and state/province if relevant), and enough detail to identify your account or correspondence. Requests are free. We respond within one month (GDPR/UK GDPR, extendable by two further months for complex requests), 45 days (most US state laws, extendable once by 45 more days), or the period your local law requires, whichever is shorter.
| Data | Where it lives | How long |
|---|---|---|
| Local accounts, transactions, and settings | Your device only | Until you delete the App, use the sign-out "Delete Data" option, or reset the device |
| Sign-in identity (name, email, photo, Firebase UID) | Firebase Authentication | Until you delete your account (contact us, or we can add an in-app option) or it's inactive long enough to be removed under our standard housekeeping |
| Subscription/entitlement records | RevenueCat, per its own retention practice | For as long as needed to manage your subscription and for statutory tax/accounting purposes, typically several years after expiry |
| Encrypted cloud sync backup | Firestore, under your Firebase UID | Until you delete it (Section 8.3) or your account |
| Advertising interaction data | Google, per AdMob's own retention practice | Not controlled by us — see Google's privacy policy |
| Support correspondence | Our email account | Normally 24 months from the last message, longer where a claim or statutory obligation requires it |
We take appropriate technical and organisational measures required by Article 32 GDPR and comparable laws:
flutter_secure_storage), not in plain app storage.No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We encourage you to protect your device with a passcode or biometric lock, keep your OS up to date, and choose a strong, memorable encryption password if you enable cloud sync — see the irreversibility warning in Section 8.1.
Breach notification. In the unlikely event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (Article 33 GDPR) and affected individuals without undue delay where required.
We may update this policy to reflect changes to the App, our practices, or the law — in particular before adding Android advertising/purchases, a formal EEA/UK/Switzerland ad-consent tool, or any new third-party SDK.
When we do, we revise the "Last updated" date and version above, publish the update at https://sheikhamais.github.io/moneymanager/privacy/, and — for material changes (expanding data categories collected, a new incompatible purpose, a new recipient category, or a change to your rights) — give prominent advance notice, which may include an in-app notice, and obtain your consent first where the law requires it. Continuing to use the App after a change takes effect indicates acceptance, except where consent is separately required.
Because the App now includes Firebase Authentication, Cloud Firestore, RevenueCat, and (iOS) Google Mobile Ads, our declarations on the App Privacy section of the App Store and the Data safety section of Google Play reflect real data collection — not "Data Not Collected." In summary, data linked to your identity may include: contact info (email, name), identifiers (Firebase UID, and an advertising identifier on iOS if you grant App Tracking Transparency permission), and purchase history; financial information you enter is stored locally and, if you enable cloud sync, only ever leaves your device as end-to-end encrypted ciphertext we cannot read. We keep these store declarations in step with this policy and update both together whenever either changes.
Email: sheikhamais@gmail.com
Amais Sheikh, Pakistan
We aim to acknowledge every message within 5 business days and resolve it within the statutory period in Section 14.5. If you are in the EEA, the UK, or Switzerland and unsatisfied with our response, you may complain to your supervisory authority (Section 14.2). If you are in the United States, you may contact your state Attorney General. Nothing here limits your right to do so.
Related document: Terms and Conditions