Privacy Policy
Ploutos — Personal Finance Manager
Last Updated: June 2026 · Effective Date: June 2026
David Gómez (“Developer”, “we” or “our”) has created Ploutos (“the Application”) as a mobile application for personal finance management. This Privacy Policy explains how information is collected, used, and disclosed when you use the Application.
By downloading or using Ploutos, you agree to the terms of this Privacy Policy.
1. Information We Collect
1.1 Financial Data Provided by You
Ploutos allows you to manage the following data:
- Account names, balances, and currencies.
- Transaction descriptions, amounts, dates, and notes.
- Category names and preferences.
- Application settings (preferred currency, language, month start day).
For users of the free version, all financial data is stored exclusively on your device. We do not have access to it and it is never transmitted to any server.
On iOS, local data is encrypted at rest using SQLCipher (AES-256 encryption).
1.2 Subscription and Cloud Functionalities (Future)
In the future, the Application may offer a paid subscription plan with cloud-based functionalities, such as data backup, cross-device synchronization, and account management. This functionality will be entirely optional and will only apply to users who:
- Voluntarily create an account by providing their name and email address.
- Subscribe to a paid plan.
If you subscribe, the following additional data will be collected and stored on our servers:
- Your name and email address (for account authentication).
- Your financial data (accounts, transactions, categories and settings), for the purpose of backup and cloud synchronization.
Users who do not create an account or do not subscribe will continue to use the Application with all data stored locally on their device, exactly as it works currently. The free, local-only experience will remain fully functional.
1.3 Automatically Collected Information
When you use the Application — whether as a free or subscribed user — certain information is collected automatically through third-party services:
a) Usage Analytics (Firebase Analytics)
We collect anonymous usage data to understand how features are used and improve the Application. This includes:
- The screens you visit.
- The features you interact with (e.g., creating a transaction, applying a filter, changing a setting).
- Application version, device model and operating system version.
- Session duration and frequency.
No financial data (amounts, account names, descriptions or notes) is included in the analytics events.
b) Crash Reports (Firebase Crashlytics)
If the Application crashes, diagnostic data is automatically collected, including:
- Stack traces and error logs.
- Device model, operating system version and application version.
- Navigation traces (the screens visited before the crash).
c) Device Token (Firebase Cloud Messaging)
If you grant notification permissions, a unique device token is generated to enable push notifications. This token does not identify you personally.
d) Advertising Data (Google AdMob)
The Application displays ads provided by Google AdMob. AdMob may collect:
- Device advertising identifiers (only with your explicit consent on iOS through the App Tracking Transparency prompt).
- General device information for ad delivery.
- Ad interaction data (impressions, clicks).
On iOS, you can deny tracking when prompted, in which case only non-personalized ads will be shown. You can change this at any time in your device Settings > Privacy & Security > Tracking.
e) Remote Configuration (Firebase Remote Config)
The Application retrieves configuration values (such as whether ads are enabled) from Firebase Remote Config. No personal data is sent during this process.
1.4 Information We Do NOT Collect
For free users (without an account):
- Personal identifiers (name, email address, phone number).
- Location data.
- Contacts, photos or camera data.
- Health or biometric data.
- Browsing history.
- Financial account credentials (bank logins, card numbers).
For subscribed users (with an account):
- We only collect name and email for authentication. The above list applies in its entirety.
2. How We Use Information
- Local financial data: Used only within the Application on your device. We do not access, process, or analyze it.
- Analytics and crash data: Used to improve Application functionality, fix bugs, and understand aggregate usage patterns.
- Advertising data: Used to deliver ads that support the free version of the Application.
- Remote configuration data: Used to manage Application functionalities remotely.
3. Third-Party Services
The Application integrates the following third-party services, each with its own privacy policy:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Firebase Analytics | Usage analysis | firebase.google.com |
| Firebase Crashlytics | Crash reporting | firebase.google.com |
| Firebase Remote Config | Feature flags | firebase.google.com |
| Firebase Cloud Messaging | Push notifications | firebase.google.com |
| Google AdMob | Advertising | policies.google.com |
| Open Exchange Rates API | Exchange rates | open.er-api.com |
The Open Exchange Rates API is used exclusively to retrieve daily currency exchange rates. No user data of any kind is transmitted to this service.
When cloud functionalities are introduced, the hosting provider and data jurisdiction will be disclosed in an updated version of this policy.
4. Data Storage and Security
4.1 Free Users (Local Storage)
- All financial data is stored locally on your device using SQLite.
- On iOS, the database is encrypted using SQLCipher (AES-256).
- Data is not synchronized between devices. If you uninstall the Application or lose your device, your data cannot be recovered.
- We do not have access to your financial data.
4.2 Subscribed Users (Cloud Storage — Future)
- Your financial data will be encrypted in transit (TLS) and at rest on our servers.
- Your name and email will be stored securely for account management.
- You will be able to download or delete all server-side data at any time.
- Details of server infrastructure and data jurisdiction will be disclosed when the subscription service launches.
4.3 General
- All network communication uses HTTPS encryption.
- We follow industry-standard security practices to protect data.
5. Data Retention
- Local data: Retained on your device until you delete it within the Application or uninstall the Application.
- Cloud data (subscribers): Retained on our servers as long as your subscription is active. Upon cancellation, your data will be retained for 30 days to allow for reactivation, after which it will be permanently deleted, unless you request early deletion.
- Account information: Your name and email will be deleted upon an account deletion request.
- Analytics and crash data: Retained by Firebase in accordance with Google's data retention policies (typically 14 months for Analytics, 90 days for Crashlytics).
- Advertising data:Retained by Google in accordance with Google's advertising data retention policies.
6. Your Rights and Choices
6.1 Deleting Your Data
- Free users: Delete any data within the Application, or uninstall to remove all data.
- Subscribers: Request deletion of cloud-stored data at any time through the Application or by contacting us. Deleting your account will remove all server-side data.
6.2 Opting Out of Ad Tracking (iOS)
When prompted for the first time, you can deny app tracking. You can also change this at any time via Settings > Privacy & Security > Tracking.
6.3 Opting Out of Analytics
You can limit ad tracking and analytics collection through your device's privacy settings:
- iOS:Settings > Privacy & Security > Analytics & Improvements
- Android: Settings > Google > Ads
6.4 Disabling Notifications
You can disable push notifications at any time through your device settings.
6.5 European Users (GDPR)
If you are in the European Economic Area, you have the right to:
- Access the information collected about you.
- Request the deletion of your data.
- Object to data processing.
- Data portability (export your data).
- Lodge a complaint with your local data protection authority.
- Free users: Your financial data is stored entirely on your device and is under your control. For analytics and crash data held by Firebase, contact us at the address indicated below.
- Subscribers: Contact us to exercise any of these rights regarding your cloud-stored data.
6.6 California Users (CCPA)
If you are a California resident, you have the right to know what data is collected and to request its deletion. We do not sell personal information to third parties.
7. Children's Privacy
Ploutos is not directed to children under 13 years of age. We do not knowingly collect personal information from children. The Application contains ads served by Google AdMob; these are configured to comply with applicable regulations. If you believe a child has provided personal information through the Application, please contact us.
8. Changes to This Privacy Policy
We may update this Privacy Policy occasionally, including when new features such as the subscription service and cloud storage are introduced. Changes will be posted within the Application or on our website with an updated “Last Updated” date.
For substantial changes — such as the introduction of server-side data storage or new categories of data collection — we will provide a prominent notice within the Application.
Your continued use of the Application after changes are posted constitutes acceptance of the revised policy.
9. Contact Us
If you have questions or concerns about this Privacy Policy, please contact: