This privacy policy explains how the Tortlo mobile application (“the app”, “we”, “us”) handles user data. Tortlo was designed with privacy in mind — all financial data entered by the user (budgets, transactions, categories, balances) is stored exclusively on the local device and is never transmitted to any servers, including the developer’s servers.
1. Data Controller
The data controller within the meaning of the GDPR is the developer of the Tortlo app. The controller's contact details are available in the app description on Google Play and on the app's support page.
2. Data Stored Locally on the Device
The Tortlo app does not require account registration and does not use any login system. All data entered by the user, including:
- budgets and spending categories,
- transactions, amounts, and balances,
- notes and app settings,
— is stored exclusively on the local storage of the user's device. This data is never transmitted to the developer, to Firebase, or to any third-party servers. Uninstalling the app or clearing its data through Android system settings permanently deletes this information, and it cannot be recovered by the developer.
3. Text and Image Recognition (ML Kit)
The app uses the Google ML Kit library in its on-device variant, meaning all processing happens locally. This feature may be used, for example, to recognize text on photos of receipts or documents provided by the user.
Image processing takes place entirely on the user's device. Photos, scans, and recognition results are never sent to Google, to the developer, or to any third-party servers. This data remains local and is subject to the same principles described in Section 2.
4. Firebase Analytics and Crashlytics
The app uses Firebase Analytics and Firebase Crashlytics, services provided by Google Ireland Limited. These services help us understand how users interact with the app and help us detect and fix technical issues (app crashes).
Data collected by Firebase Analytics may include:
- an anonymous app installation identifier and the device's advertising identifier (Advertising ID),
- device model, operating system version, language, and regional settings,
- app usage statistics (e.g. screens visited, frequency of use, session duration),
- general location data based on IP address (country/region), without precise GPS location.
Data collected by Firebase Crashlytics may include:
- crash and error reports, including stack traces, app version, OS version, and device model,
- an anonymous installation identifier linked to a specific crash.
This data is processed by Google on servers that may be located outside the European Economic Area (e.g. in the USA). Google provides appropriate data protection safeguards in line with the GDPR, including Standard Contractual Clauses. More information: firebase.google.com/support/privacy
5. In-App Purchases
The app offers in-app purchases processed exclusively through Google Play Billing (Google LLC). Available purchase options include:
- subscriptions (e.g. monthly or annual access to premium features),
- a one-time lifetime purchase granting permanent access to premium features.
All payments are handled entirely by Google. The developer does not have access to the user's payment card details or other sensitive financial data entered during the purchase process.
In connection with a purchase, Google may process data such as the user's Google account identifier, country, currency, and transaction history, in accordance with Google's Privacy Policy: policies.google.com/privacy.
6. Legal Basis for Processing
Technical and statistical data collected by Firebase Analytics and Crashlytics is processed on the basis of Article 6(1)(f) GDPR, i.e. the controller's legitimate interest in ensuring the proper functioning, stability, and development of the app. Users can limit this data collection at any time by changing their Android device's privacy settings (e.g. disabling the advertising identifier or restricting app permissions).
Data processed in connection with in-app purchases is handled by Google as an independent data controller, on the basis of the contract concluded between the user and Google when making a purchase via Google Play.
7. User Rights
Under the GDPR, users have the following rights regarding data processed by Firebase:
- the right to access their data and information about how it is processed,
- the right to object to processing for analytics purposes,
- the right to lodge a complaint with a supervisory authority (in Poland: the President of the Personal Data Protection Office).
For financial data stored locally — the user has full and exclusive control over this data at all times, by deleting it within the app, clearing the app's data through Android system settings, or uninstalling the app.
For data processed by Google in connection with purchases — users may exercise their rights directly with Google via myaccount.google.com.
8. Data Security
Since financial data never leaves the user's device, its security largely depends on the security measures of the device itself (e.g. screen lock, system-level storage encryption on Android). We recommend using these mechanisms to protect data from unauthorized access by third parties in case the device is lost or stolen.
9. Children's Privacy
The app is not intended for children under the age of 13 and is not knowingly directed at this age group. We do not knowingly collect personal data from children. In accordance with the US Children's Online Privacy Protection Act (COPPA), if we become aware that personal data from a child under 13 has been collected without verifiable parental consent, we will take steps to delete such data.
10. Information for US Users (CCPA/CPRA and Other State Laws)
This section provides additional information for residents of US states with consumer privacy laws, such as the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), as well as similar laws in states including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comparable regulations.
10.1. Categories of Data Collected
Under CCPA/CPRA definitions, the app may collect the following categories of information via Firebase Analytics and Crashlytics: identifiers (e.g. the device's advertising identifier, app installation identifier), internet or other electronic network activity information (e.g. app interactions), and device information (model, operating system, crash diagnostics). The app does not collect financial data, biometric data, precise geolocation data, or other “sensitive personal information” under the CPRA — the user's financial data remains exclusively on the local device, as described in Section 2.
10.2. Sale and Sharing of Data
We do not sell users' personal information as defined by the CCPA/CPRA, and we receive no compensation for any such activity. To the extent that the use of Firebase Analytics could be considered “sharing” data for advertising purposes under the CPRA, users can opt out of such processing by limiting the advertising identifier in their Android device settings or by disabling analytics data collection, if such an option is available in the app's settings.
10.3. Consumer Rights (California and Other States)
To the extent provided by applicable state law, users have the right to:
- request information about the categories and specific pieces of personal information collected about them over the past 12 months,
- request deletion of collected personal information,
- request correction of inaccurate personal information,
- opt out of the “sale” or “sharing” of personal information (“Do Not Sell or Share My Personal Information”),
- limit the use and disclosure of “sensitive personal information”,
- not be discriminated against for exercising the above rights — exercising these rights does not affect the app's functionality.
To exercise the above rights, users may contact us via the email address listed in the app's contact section on Google Play. For financial data stored locally — users exercise these rights themselves by deleting the data within the app or uninstalling the app, since the developer does not hold a copy of this data.
10.4. Global Privacy Control (GPC) Signal
If advertising mechanisms are introduced in the app that respect the browser-based Global Privacy Control (GPC) signal, we will treat such a signal as equivalent to a request to opt out of the “sale” or “sharing” of data under the CCPA/CPRA, to the extent technically feasible for a mobile application.
11. Changes to This Privacy Policy
This privacy policy may be updated to reflect changes to the app, in particular the introduction of new features (e.g. ads, in-app purchases, cloud synchronization). We will inform users of material changes by updating the date at the top of this document and, if the changes are significant, through a notification within the app.
12. Contact
If you have any questions about this privacy policy or how your data is processed, please contact us via the email address listed in the app's contact section on Google Play.