Skip to content
SettleVa Features Premium Support RO  ·  EN Get the app

Privacy policy

Version 0.1 (draft) · Effective date: [pending] · Changelog

1. Controller2. What the app is3. Data we process and why4. Data about other people5. Recipients and processors6. International transfers7. Retention8. Your rights9. Security10. Children11. Changes to this policy12. Store-specific appendix

1. Controller

Logic Software SRL, registered office at Calea Floreasca 242, Building F, CUI RO18047367, is the controller for the personal data processed through the SettleVa app and this website. Privacy questions: [email protected]. No data protection officer is appointed for this processing; the contact above handles every request.

2. What the app is

SettleVa is a shared-expense app. It tracks a group’s shared fund and each member’s own spending, calculates who owes whom, and suggests the smallest set of payments that settles everyone up. It is a ledger and a calculator: no money moves through SettleVa.

3. Data we process and why

DataWhere it comes fromPurposeLegal basis (GDPR art. 6)
E-mail address, display name, account identifierYour account (sign-in service)Creating and securing your account, showing your name to the other membersPerformance of a contract, 6(1)(b)
Amounts, contributions, balances, settlement payments, project names and categoriesEntered by you or by other members of your projectsThe service itselfPerformance of a contract, 6(1)(b)
Receipt photographs and the amounts read from themYour camera or photo library, only when you choose to attach oneReading the total for you, keeping the receipt with the expensePerformance of a contract, 6(1)(b)
Push notification tokenYour device, only after you allow notificationsDelivering notifications about your projectsConsent, 6(1)(a) — withdraw it in your device or app settings
E-mail address and name of people you inviteTyped by youSending and tracking the invitationLegitimate interest, 6(1)(f) — yours and the invitee’s, see §4
Technical logs (request identifiers, timestamps, error codes) with personal data redactedOur serversSecurity, abuse prevention, diagnosing failuresLegitimate interest, 6(1)(f)
Biometric unlock (Face ID, fingerprint)Your deviceUnlocking the app fasterProcessed on your device only by the operating system; never transmitted to us

We do not collect your location, your contacts, an advertising identifier, or crash and usage analytics. If a crash reporter is ever added, this policy and the store declarations will be updated first.

4. Data about other people

When you record a cost for another member, or invite someone by e-mail, you are sharing that person’s data with the group. You are responsible for having the right to do so — normally because they are part of the trip, vehicle or event you are tracking. Invitee e-mail addresses are stored by the service in a hashed and masked form; the full address is used only to deliver the invitation.

5. Recipients and processors

  • Hosting — our own servers, operated by us, in data centres in the European Union. No third-party cloud provider holds your data.
  • Sign-in — a self-hosted identity service (Keycloak) operated by us.
  • Receipt reading — a self-hosted service operated by us; no third party ever receives the image. It is processed on our servers and its metadata (EXIF) is stripped before storage.
  • Notifications — Google Firebase Cloud Messaging and Apple Push Notification service deliver notifications to your device. Only the device token and the notification content reach them.
  • Stores — Apple and Google act as merchant of record for Premium purchases; we receive a purchase confirmation, never your payment details.

We do not sell personal data and we do not share it with advertisers or data brokers.

6. International transfers

Push notifications may route through servers in the United States operated by Google and Apple. These transfers rely on the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses. All other processing takes place in the European Union.

7. Retention

  • Account data — until you delete your account.
  • Ledger entries — after you delete your account, the entries you were part of are pseudonymised, not deleted: your name and identifiers are removed, the figures remain, because the other members’ balances are computed from them (art. 17(3)(b) and (e) GDPR).
  • Receipt images — 3 years after the expense is recorded, or until the project is deleted, whichever comes first.
  • Push tokens — deleted when you sign out or disable notifications.
  • Technical logs — 30 days.
  • Data on your device — the local cache is cleared when you sign out or uninstall the app.

8. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time without affecting earlier processing.

  • Access and portability — export everything we hold about you from Settings → Export my data in the app, or see /account/export.
  • Rectification — edit your profile in the app.
  • Erasure — Settings → Delete my account in the app, or see /account/delete. The page explains what is deleted and what is pseudonymised.
  • Notifications — withdraw consent in the app’s notification settings or in your device settings.

For anything else write to [email protected]. We answer within one month. You can also lodge a complaint with the Romanian supervisory authority, ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), B-dul G-ral Gheorghe Magheru 28-30, 010336 Bucharest, dataprotection.ro.

9. Security

All traffic between the app and our servers is encrypted (HTTPS). Sign-in uses OAuth 2.0 with PKCE; your password is never stored on the device. Session tokens are kept in the operating system’s secure keystore or keychain. Access to production data is restricted to the people who operate the service.

10. Children

SettleVa is not directed at people under 16 and we do not knowingly create accounts for them. If you believe a child has an account, write to us and we will delete it.

11. Changes to this policy

We may update this policy. Material changes are announced in the app before they take effect. Every version, with its effective date, remains available in the changelog.

12. Store-specific appendix

This section mirrors the App Privacy label on the App Store and the Data safety section on Google Play, so the three documents can be compared line by line.

Data type (store vocabulary)CollectedLinked to youUsed for trackingShared with third parties
Contact info → Email addressYesYesNoNo
Contact info → NameYesYesNoNo
Identifiers → User IDYesYesNoNo
Financial info → Other financial infoYesYesNoNo
Photos → Photos (receipts, optional)YesYesNoNo
Identifiers → Device ID (push token, optional)YesYesNoNo
Location, Contacts, Advertising data, Crash data, Usage dataNo———

All data is encrypted in transit. You can request deletion from inside the app and from /account/delete.

Privacy Terms Cookies Delete account Support Legal
ANPC SAL © 2026 Logic Software SRL · All rights reserved.