1. Who we are
Financial is developed by What a Nice Idea ("we", "us", "our"), an independent software studio. This policy explains what information the app handles and the choices you have. For privacy questions, contact privacy@whataniceidea.com.
For the EU GDPR and Greek data-protection law, What a Nice Idea is the data controller for the limited processing described here. Where you enable self-hosted sync, you control that backend and act as the controller for the data you send to it.
2. Local-first design
Financial is local-first. Your accounts, transactions, categories, and subscriptions are stored in a database on your device. The app works fully offline and does not require an account with us.
3. What data we process
| Category | Examples | Where it lives |
|---|---|---|
| Ledger data | Accounts, double-entry transactions, categories, amounts, notes, dates | On your device |
| Subscriptions | Subscription names, amounts, billing dates you track | On your device |
| Profile fields (optional) | A display name / email you may enter for your own records | On your device |
| Receipt scans (premium) | Receipt photos and recognised text | On your device |
| Scanned QR URL (premium) | A receipt's QR URL, sent for enrichment if you scan one | Sent to the receipt-enrichment server (see §4) |
| Synced data (optional) | Your ledger, if you enable self-hosted sync | On the backend you configure — not ours |
Any profile display-name or email you enter is stored locally for your own use; it is not an account with us. We do not build advertising profiles or track you across apps.
5. Optional self-hosted sync
Financial can optionally sync your data to a backend that you host and control. This is off by default. If you enable it and point the app at your own server:
- Your ledger data is sent to your backend, not to What a Nice Idea. We do not operate that server and do not receive your synced data.
- You are responsible for the security and privacy of the backend you choose to run.
- If you never configure sync, none of your financial data leaves your device (aside from the optional premium QR lookup described in §4).
6. App lock / biometrics
You can protect the app with a biometric or device lock. Biometric matching is performed by your operating system; we never receive or store your fingerprint or face data.
7. Device permissions
| Permission | Why |
|---|---|
| Camera (premium) | To scan receipt QR codes and read receipt text. |
| Biometrics (optional) | To unlock the app, if you enable the app lock. |
| Photos / storage (optional) | Only if you import/attach a receipt image or export your data. |
8. Third-party services
- Google ML Kit — on-device receipt text recognition (OCR); runs locally.
- Our receipt-enrichment service (Cloudflare) — contacted only for premium QR/myDATA lookups, and only with the receipt's QR URL.
- Greek AADE / e-invoicing providers — queried through our service to retrieve the details of the receipt you scanned.
- A backend you host (only if you enable self-hosted sync) — under your control.
- Your app store — distributes the app and handles any premium purchase billing under its own privacy policy; we do not receive your payment-card details.
No advertising SDKs and no profiling analytics are integrated.
9. Legal basis
- Contract / performing the feature you invoked: enriching a receipt you chose to scan.
- Consent: camera and biometric permissions, revocable at any time.
- Ledger data stays on your device (or on your own backend), so most processing does not involve us as a controller.
10. Retention & deletion
On-device data stays until you delete it or uninstall the app. Data on a self-hosted backend is retained according to how you run that backend. Enrichment requests to our service are transient and are not used to profile you.
11. Your rights
Under the GDPR you have rights to access, correct, delete, export, restrict, and object. Because your data is held locally (or on your own backend), you exercise these directly. For any request involving our enrichment service, contact us. You may also complain to your supervisory authority — in Greece, the Hellenic Data Protection Authority (HDPA).
12. Security
Your data is protected by your device's own security and the optional app lock. Requests to our enrichment service use HTTPS/TLS. If you enable self-hosted sync, transport and storage security depend on the backend you run.
13. Children
Financial is a general-audience finance tool and is not directed at children. We do not knowingly collect data from children.
14. Changes to this policy
We'll update this policy as the app evolves, revising the "last updated" date and, where appropriate, notifying you in the app.
15. Contact
Reach us at privacy@whataniceidea.com.