Privacy Policy
The short version. Bsync is a budgeting app for couples and for people tracking money on their own. To do that, it stores the expenses, budgets and income you enter, and — if you link with a partner — shows all of it to that partner in real time.
We do not sell your personal information, we do not share it with advertisers or data brokers, and no financial figures are ever sent to our analytics. When you scan a receipt, the photo is sent to Google's Gemini AI to be read and is not stored afterwards. You can delete your account at any time, from inside the app or from this website.
The rest of this page is the detail behind those sentences. Please read it — particularly section 5, on what your partner can see, and section 9, on what we keep after you delete your account.
Contents
- Who we are
- Scope of this policy
- Information we collect
- How and why we use it
- What your partner can see
- Receipt scanning and AI processing
- Third-party services
- How we protect your information
- How long we keep it
- Deleting your account
- Your rights and choices
- International data transfers
- Regional privacy rights
- Children's privacy
- Changes to this policy
- Contact us
1. Who we are
Bsync ("Bsync", "the app", "we", "us", "our") is a mobile application published by [LEGAL ENTITY NAME], operating from Jamaica. For the purposes of the UK and EU General Data Protection Regulation, and Jamaica's Data Protection Act, 2020, [LEGAL ENTITY NAME] is the data controller for the personal information described in this policy.
Our privacy point of contact is [email protected]. We aim to respond to every privacy enquiry within 30 days.
2. Scope of this policy
This policy covers the Bsync mobile application on iOS and Android, and the supporting cloud services that run behind it. It applies whether you use Bsync solo — tracking only your own money — or linked with a partner in a shared workspace.
It does not cover the practices of the third-party services listed in section 7, each of which operates under its own privacy policy, or of the app stores you download Bsync from.
3. Information we collect
3.1 Account and profile information
- Email address — from you when you register with an email and password, or from Google or Apple when you use those sign-in options.
- Display name and nickname — a name you choose in the app. If you sign in with Google, we pre-fill this from your Google display name; you can change it. If you sign in with Apple, Apple provides your name only on the first sign-in and never again.
- An accent colour you pick (or that we assign at random) to identify you in shared views.
- A Firebase account identifier — an opaque, random string that identifies your account across our systems.
- Account timestamps — when the account was created, and whether you have finished setup.
We never see or store your password. Authentication is handled entirely by Google Firebase Authentication, or by Google or Apple when you use those sign-in methods.
3.2 Financial information you enter
This is the substance of the app, and all of it is information you type in or scan yourself. We do not connect to your bank, and we have no access to your accounts, balances, card numbers or statements.
- Expenses and income — description or merchant name, amount, category, date, notes, payment method, and whether the item has been settled.
- Budgets — budget names, spending categories, category limits and line items.
- Income figures — the monthly income you record for yourself and, in a shared workspace, for your partner, plus any additional income sources.
- Recurring bill templates — the name, amount, category, frequency and due date of bills you ask the app to add automatically.
- Pay-cycle settings — the day of the month or fortnightly rhythm your budget runs on.
- Credit-card settings — whether the card tracker is on, the credit limit you enter, and the day of the month your statement falls due. We do not collect card numbers, expiry dates or CVVs, and the app has no field to enter them.
- Split arrangements — how a shared expense is divided between partners, and who has paid their share.
3.3 Partnership information
- Your linked partner's account identifier, nickname and email address.
- Whether the partnership is a solo workspace or a shared one, and whether it is active or paused.
- Invite codes you generate, which expire after 10 minutes.
- The dates a partnership was created, paused or resumed.
- A permanent snapshot of both partners' nicknames taken at the moment a partnership is paused or a member deletes their account. This is kept indefinitely so that shared financial history stays readable to the remaining partner. See section 9.
- A list of your previous partnership identifiers, so you can still browse frozen history from an earlier partnership.
3.4 Receipt images
If you use receipt scanning, we access your camera and, if you choose to pick an existing photo, your photo library — only at the moment you tap to scan, and only for the image you select. We do not browse, index or upload your photo library.
What happens to the image is described in full in section 6.
3.5 Device and technical information
- Push notification tokens — an identifier for each device you have signed in on, used only to deliver notifications. Removed when you sign out on that device.
- Your device's time zone — so that reminders arrive at a sensible local hour rather than in the middle of your night.
- Platform and app version — whether you are on iOS or Android, and which release you are running.
- Crash and error diagnostics — technical reports when the app fails, collected through Google Crashlytics.
- IP address — processed transiently when you request a password-reset code, and stored only as an irreversible cryptographic hash, purely to rate-limit abuse. We do not keep readable IP logs.
3.6 What we do not collect
Bsync does not collect your location, your contacts, your microphone, your calendar, your health data, your browsing history, or any advertising identifier. We do not use advertising SDKs, and there are no ads in the app.
4. How and why we use it
| What we do | Information used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Run the core app — budgets, expenses, cycles, reports | Account, financial, partnership | Performance of a contract |
| Sync your workspace with your linked partner in real time | Financial, partnership | Performance of a contract |
| Read a receipt you photograph and turn it into an expense | Receipt image, extracted text | Performance of a contract; your consent for camera access |
| Answer your questions in "Ask Syd" | Spending summaries, your question | Performance of a contract |
| Send reminders and alerts you have switched on | Push token, time zone, financial | Your consent, withdrawable at any time |
| Verify your email address and reset your password | Email address, hashed IP | Performance of a contract; legitimate interest in account security |
| Manage your subscription and unlock Pro features | Account identifier, subscription status | Performance of a contract |
| Diagnose crashes and fix defects | Crash diagnostics, platform, app version | Legitimate interest in a working, secure product |
| Understand which features are used, in aggregate | Anonymous usage events (see 7.4) | Legitimate interest in improving the product |
| Prevent abuse, fraud and runaway costs | Account identifier, usage counters, hashed IP | Legitimate interest in protecting the service |
Where our basis is legitimate interest, we have considered whether that interest is overridden by your rights, and limited the processing accordingly — for example, our analytics is structurally incapable of receiving a financial figure. You may object to legitimate-interest processing at any time (see section 11).
We do not use your financial information for advertising, profiling, credit scoring, lending decisions, resale, or any purpose other than operating the features you are using.
5. What your partner can see
Please read this section carefully. Linking with a partner is not a limited or partial share. Once you are linked, everything you put into the shared workspace is visible to your partner in real time — every expense, its amount, the merchant, the category, your notes, your budgets, and the income figures recorded in that workspace. There is no private expense, no hidden category, and no way to enter something the other person cannot see.
This is the entire point of the app, and it is symmetrical: you see everything they add, too. Do not link with someone you are not willing to share your complete spending with.
Linking. One partner generates a six-digit invite code; the other enters it. Linking creates a new shared workspace. If you were previously using Bsync solo, your existing solo history stays saved but does not move into the new shared workspace.
Pausing (unlinking). Either partner can pause the partnership at any time. When that happens, the shared history is frozen, not deleted — both of you keep read-only access to everything already recorded, and neither of you can add anything new to it. The other partner is notified that you paused it.
Resuming. If you later link with the same person again, you will both be offered the choice to restore your shared history or start fresh.
If your partner deletes their account. Their profile and sign-in credentials are permanently deleted. The shared workspace is marked dissolved, and the expenses they recorded remain in your history, still attributed to their nickname, so your past budgets and cycle reports stay accurate and readable. See section 9.
6. Receipt scanning and AI processing
Two features in Bsync use Google's Gemini generative AI models, accessed through the Google AI API. Both are optional and neither runs unless you invoke it.
6.1 Receipt scanning
When you photograph a receipt:
- Text is first read on your device using on-device optical character recognition. This step involves no network transmission.
- The image is resized and compressed on your device, then sent over an encrypted connection to our cloud service, together with the text recognised in step 1.
- Our service forwards the image and text to the Google Gemini API, which returns structured details: merchant name, total, tax, line items, date, currency and receipt number.
- The image is not stored. It exists only in memory for the duration of the request and is discarded once extraction completes. We do not keep a copy, and neither our database nor any file storage ever receives it.
- The extracted details — not the image — are cached for up to 400 days, so that re-scanning the same receipt does not incur a second AI call. This cache is scoped to your account and your workspace and is unreadable by any other user.
6.2 Ask Syd
When you ask the in-app assistant a question about your spending, we send the Google Gemini API:
- Your question, capped at 300 characters.
- A summary of your workspace's spending covering up to the last 24 pay cycles — category totals, cycle totals, budget figures, and a list of your most-used merchants by name and amount.
We do not send your name, your email, your partner's identity, your notes, or any account identifier. Answers are cached so that a repeated question costs nothing.
What Google does with it. Requests are made through the paid Google AI API, under which Google states that it does not use submitted data to train its models and retains it only briefly for abuse monitoring. Your data is not used to improve Gemini. See Google's Gemini API terms for the current position, which is set by Google and may change.
AI is not perfect. Receipt extraction and assistant answers can be wrong. Always check a scanned amount before saving it, and never treat an assistant answer as financial advice.
7. Third-party services
We use the following processors and services. We have no other data-sharing arrangements, and we do not sell or rent your information to anyone.
| Service | What it does | What it receives |
|---|---|---|
| Google Firebase (Google LLC) |
Authentication, database, cloud functions, hosting of all app data | Everything described in section 3, other than the items listed separately below |
| Google Gemini API (Google LLC) |
Reads receipts; answers Ask Syd questions | Receipt images and text; spending summaries and your question (section 6) |
| Google Analytics for Firebase (Google LLC) |
Aggregate product analytics | Your account identifier, plus a fixed list of anonymous events. See 7.4 |
| Google Crashlytics (Google LLC) |
Crash and error reporting | Crash diagnostics, device model, OS version, app version |
| Google Sign-In (Google LLC) |
Optional sign-in method | Provides us your name and email, if you use it |
| Sign in with Apple (Apple Inc.) |
Optional sign-in method on iOS | Provides us your email, or a private relay address if you choose to hide it |
| Expo (Expo, Inc.) |
Push notification delivery, app build infrastructure | Push tokens and the content of notifications. See 7.3 |
| Resend (Resend, Inc.) |
Sends verification and password-reset emails | Your email address and the one-time code |
| RevenueCat (RevenueCat, Inc.) |
Manages subscriptions and entitlements | Your account identifier and subscription status |
| Apple / Google Play | Process subscription payments | Payment details go to the store, never to us. See 7.2 |
7.1 Where your data is stored
All app data is stored in Google Firebase, in Google Cloud data centres located primarily in the United States. Our cloud functions run in the us-central1 region.
7.2 Payments
Subscriptions are purchased and billed entirely through the Apple App Store or Google Play. We never receive, see or store your card number, bank details or billing address. We receive only a confirmation from RevenueCat that a subscription is active, tied to your account identifier.
7.3 Notification content
Some notifications include financial details in their text — for example, "Netflix · $15.99 is due in 3 days", or "$450.00 is still on your card". To reach you, that text passes through Expo's push service and then through Apple's or Google's push infrastructure, and it may appear on your lock screen where anyone holding your phone can read it.
If that concerns you, you can turn individual notification types off in Settings → Notifications, or hide notification previews in your phone's own system settings.
7.4 What our analytics can and cannot see
Our analytics is deliberately built so that financial information cannot reach it. Only a fixed, predefined list of events may be recorded — such as "an onboarding step was completed" or "the paywall was viewed" — and each event may carry only a short, restricted set of non-personal labels. Free text of any kind, including merchant names, descriptions, nicknames, email addresses and currency amounts, is rejected before transmission rather than trusted not to appear.
Your Firebase account identifier is set as the analytics user identifier, so that one person using two devices is counted once. That identifier is random and specific to Bsync; it does not reveal your name or email.
8. How we protect your information
- Encryption. All data is encrypted in transit using TLS, and encrypted at rest by Google Cloud using AES-256.
- Database access rules. Server-side security rules enforce that you can only read and write data belonging to your own workspace. Membership is verified against the partnership record itself, which you cannot modify, rather than against any claim your device makes.
- Passwords. Never stored by us. Authentication is delegated to Firebase, Google or Apple.
- One-time codes. Email verification and password-reset codes are stored only as salted cryptographic hashes, expire after 10 minutes, and are limited in the number of attempts allowed.
- Sensitive collections are sealed. Verification codes, reset codes, AI caches, usage counters and spending summaries are readable and writable only by our server code — no app build, modified or otherwise, can reach them.
- Subscription integrity. Paid status can only be set by our server after confirmation from the store; it cannot be granted by a device.
- Rate limiting. AI features are capped per account and globally to prevent abuse.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please use a strong, unique password, keep your device locked, and sign out of any device you do not control.
Breach notification. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, you directly, without undue delay.
9. How long we keep it
| Information | Retention |
|---|---|
| Account profile and financial records | For as long as your account exists |
| Paused or dissolved partnership history | Kept indefinitely, read-only, so both former partners retain their records |
| Nickname snapshot on a dissolved partnership | Kept indefinitely — see the note below |
| Receipt images | Not retained. Discarded as soon as extraction completes |
| Extracted receipt details (cache) | Up to 400 days, then automatically expired |
| Ask Syd spending summaries and cached answers | Until your workspace data changes, or your account is deleted |
| Email verification and password-reset codes | 10 minutes |
| Hashed IP rate-limit records | Short rolling window, then overwritten |
| Push notification tokens | Removed when you sign out or delete your account |
| Crash diagnostics | Per Google Crashlytics' retention, currently up to 90 days |
| Analytics events | Per your Google Analytics settings, up to 14 months |
What survives account deletion, and why. Bsync is a shared record between two people. If deleting your account erased everything you had ever entered, your former partner's budgets, past cycles and reports would silently change — figures they had already relied on would no longer add up.
So when you delete your account, we permanently delete your profile, your sign-in credentials and your personal records — but the expenses you recorded in a shared workspace remain in that workspace, still labelled with the nickname you used, and the partnership keeps a permanent snapshot of that nickname so the history stays readable.
If you would prefer your entries to be removed or your nickname replaced, email [email protected] and we will assess the request, balancing your rights against your former partner's interest in the integrity of their own financial records. If you were using Bsync solo, no other person has an interest in the data, and we will delete your records outright on request.
10. Deleting your account
You can delete your account in two ways, and neither requires you to contact us:
- In the app: Settings → Profile → Delete Account.
- On the web: bsync.bappssupport.com/DeleteAccount
Deletion is immediate and irreversible. We cannot recover a deleted account. When you delete:
- Your profile, nickname, email and account settings are permanently deleted.
- Your Firebase authentication account is permanently deleted — you can no longer sign in.
- Your notification inbox, push tokens and AI usage counters are permanently deleted.
- Any shared partnership is dissolved, and your partner is notified.
- Financial records in a shared workspace are retained as described in section 9.
If you have an active subscription, deleting your Bsync account does not cancel it. Subscriptions are managed by the app store and must be cancelled there — see your Apple or Google account's subscription settings.
11. Your rights and choices
Depending on where you live, you may have some or all of the following rights:
- Access — obtain a copy of the personal information we hold about you.
- Correction — have inaccurate information corrected. Your nickname, colour and financial entries are all editable in the app.
- Deletion — have your personal information erased, subject to section 9.
- Portability — receive your data in a structured, machine-readable format. Pro subscribers can export expenses and budgets as a spreadsheet or PDF from within the app; anyone can request an export by email.
- Restriction — ask us to limit how we process your information.
- Objection — object to processing carried out on the basis of legitimate interests.
- Withdraw consent — turn off notifications in Settings, revoke camera access in your device settings, or pause a partnership to stop sharing with your partner. Withdrawing consent does not affect processing already carried out.
- Complain — lodge a complaint with your local data protection authority.
To exercise any of these, email [email protected]. We will not discriminate against you for exercising a privacy right. We may need to verify your identity — normally by asking you to write from the email address on the account.
12. International data transfers
We operate from Jamaica, and your information is stored and processed in the United States and other countries where our service providers operate. These countries may not offer the same level of data protection as your own.
Where information is transferred out of the UK, EEA or Switzerland, we rely on our providers' Standard Contractual Clauses and equivalent safeguards — Google, Apple, Expo, Resend and RevenueCat each maintain these as part of their data processing terms. Where information is transferred out of Jamaica, we rely on the transfer conditions permitted by the Data Protection Act, 2020.
13. Regional privacy rights
13.1 Jamaica (Data Protection Act, 2020)
If you are in Jamaica, you have the right to be informed about our processing, to access your personal data, to have inaccurate data rectified, to prevent processing likely to cause damage or distress, to prevent processing for direct marketing (we do not carry out direct marketing), and to complain to the Office of the Information Commissioner. Contact us first at [email protected] and we will try to resolve the matter directly.
13.2 United Kingdom and European Economic Area (UK GDPR / GDPR)
Our legal bases are set out in the table in section 4. You have the rights listed in section 11, and the right to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office. We do not carry out automated decision-making that produces legal or similarly significant effects about you.
13.3 California (CCPA / CPRA)
In the last 12 months we have collected the categories of personal information described in section 3, for the purposes in section 4, from the sources described in section 3, and disclosed them to the service providers listed in section 7.
We have not sold or shared personal information as those terms are defined by the CCPA, and we do not sell or share the personal information of any consumer, including minors under 16. We do not use or disclose sensitive personal information beyond the purposes permitted under the CPRA. You have the rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising them.
13.4 Other jurisdictions
If your local law grants you privacy rights not listed here, contact us and we will honour any right we are legally required to provide.
14. Children's privacy
Bsync is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe someone under 18 has created an account, email [email protected] and we will delete it promptly.
15. Changes to this policy
We may update this policy as the app changes or the law does. When we do, we will revise the "Last updated" date at the top and increment the version number. If the change is significant — for example, a new category of data or a new third party — we will tell you inside the app before it takes effect. Continuing to use Bsync after a change takes effect means you accept the updated policy.
16. Contact us
[LEGAL ENTITY NAME] — publisher of Bsync
Privacy enquiries and data rights requests: [email protected]
General support: [email protected]
Legal notices: [email protected]
Operating from Jamaica.
You can also delete your account at any time, without contacting us, from Settings → Profile → Delete Account in the app or at bsync.bappssupport.com/DeleteAccount.