Bsync

Privacy Policy

Last updated: 26 August 2026  ·  Effective: 26 August 2026  ·  Version 2.0

The short version. Bsync is a budgeting app for couples and for people tracking money on their own. To do that, it stores the expenses, budgets and income you enter, and — if you link with a partner — shows all of it to that partner in real time.

We do not sell your personal information, we do not share it with advertisers or data brokers, and no financial figures are ever sent to our analytics. When you scan a receipt, the photo is sent to Google's Gemini AI to be read and is not stored afterwards. You can delete your account at any time, from inside the app or from this website.

The rest of this page is the detail behind those sentences. Please read it — particularly section 5, on what your partner can see, and section 9, on what we keep after you delete your account.

Contents

  1. Who we are
  2. Scope of this policy
  3. Information we collect
  4. How and why we use it
  5. What your partner can see
  6. Receipt scanning and AI processing
  7. Third-party services
  8. How we protect your information
  9. How long we keep it
  10. Deleting your account
  11. Your rights and choices
  12. International data transfers
  13. Regional privacy rights
  14. Children's privacy
  15. Changes to this policy
  16. Contact us

1. Who we are

Bsync ("Bsync", "the app", "we", "us", "our") is a mobile application published by [LEGAL ENTITY NAME], operating from Jamaica. For the purposes of the UK and EU General Data Protection Regulation, and Jamaica's Data Protection Act, 2020, [LEGAL ENTITY NAME] is the data controller for the personal information described in this policy.

Our privacy point of contact is [email protected]. We aim to respond to every privacy enquiry within 30 days.

2. Scope of this policy

This policy covers the Bsync mobile application on iOS and Android, and the supporting cloud services that run behind it. It applies whether you use Bsync solo — tracking only your own money — or linked with a partner in a shared workspace.

It does not cover the practices of the third-party services listed in section 7, each of which operates under its own privacy policy, or of the app stores you download Bsync from.

3. Information we collect

3.1 Account and profile information

We never see or store your password. Authentication is handled entirely by Google Firebase Authentication, or by Google or Apple when you use those sign-in methods.

3.2 Financial information you enter

This is the substance of the app, and all of it is information you type in or scan yourself. We do not connect to your bank, and we have no access to your accounts, balances, card numbers or statements.

3.3 Partnership information

3.4 Receipt images

If you use receipt scanning, we access your camera and, if you choose to pick an existing photo, your photo library — only at the moment you tap to scan, and only for the image you select. We do not browse, index or upload your photo library.

What happens to the image is described in full in section 6.

3.5 Device and technical information

3.6 What we do not collect

Bsync does not collect your location, your contacts, your microphone, your calendar, your health data, your browsing history, or any advertising identifier. We do not use advertising SDKs, and there are no ads in the app.

4. How and why we use it

What we doInformation usedLegal basis (UK/EU GDPR)
Run the core app — budgets, expenses, cycles, reportsAccount, financial, partnershipPerformance of a contract
Sync your workspace with your linked partner in real timeFinancial, partnershipPerformance of a contract
Read a receipt you photograph and turn it into an expenseReceipt image, extracted textPerformance of a contract; your consent for camera access
Answer your questions in "Ask Syd"Spending summaries, your questionPerformance of a contract
Send reminders and alerts you have switched onPush token, time zone, financialYour consent, withdrawable at any time
Verify your email address and reset your passwordEmail address, hashed IPPerformance of a contract; legitimate interest in account security
Manage your subscription and unlock Pro featuresAccount identifier, subscription statusPerformance of a contract
Diagnose crashes and fix defectsCrash diagnostics, platform, app versionLegitimate interest in a working, secure product
Understand which features are used, in aggregateAnonymous usage events (see 7.4)Legitimate interest in improving the product
Prevent abuse, fraud and runaway costsAccount identifier, usage counters, hashed IPLegitimate interest in protecting the service

Where our basis is legitimate interest, we have considered whether that interest is overridden by your rights, and limited the processing accordingly — for example, our analytics is structurally incapable of receiving a financial figure. You may object to legitimate-interest processing at any time (see section 11).

We do not use your financial information for advertising, profiling, credit scoring, lending decisions, resale, or any purpose other than operating the features you are using.

5. What your partner can see

Please read this section carefully. Linking with a partner is not a limited or partial share. Once you are linked, everything you put into the shared workspace is visible to your partner in real time — every expense, its amount, the merchant, the category, your notes, your budgets, and the income figures recorded in that workspace. There is no private expense, no hidden category, and no way to enter something the other person cannot see.

This is the entire point of the app, and it is symmetrical: you see everything they add, too. Do not link with someone you are not willing to share your complete spending with.

Linking. One partner generates a six-digit invite code; the other enters it. Linking creates a new shared workspace. If you were previously using Bsync solo, your existing solo history stays saved but does not move into the new shared workspace.

Pausing (unlinking). Either partner can pause the partnership at any time. When that happens, the shared history is frozen, not deleted — both of you keep read-only access to everything already recorded, and neither of you can add anything new to it. The other partner is notified that you paused it.

Resuming. If you later link with the same person again, you will both be offered the choice to restore your shared history or start fresh.

If your partner deletes their account. Their profile and sign-in credentials are permanently deleted. The shared workspace is marked dissolved, and the expenses they recorded remain in your history, still attributed to their nickname, so your past budgets and cycle reports stay accurate and readable. See section 9.

6. Receipt scanning and AI processing

Two features in Bsync use Google's Gemini generative AI models, accessed through the Google AI API. Both are optional and neither runs unless you invoke it.

6.1 Receipt scanning

When you photograph a receipt:

  1. Text is first read on your device using on-device optical character recognition. This step involves no network transmission.
  2. The image is resized and compressed on your device, then sent over an encrypted connection to our cloud service, together with the text recognised in step 1.
  3. Our service forwards the image and text to the Google Gemini API, which returns structured details: merchant name, total, tax, line items, date, currency and receipt number.
  4. The image is not stored. It exists only in memory for the duration of the request and is discarded once extraction completes. We do not keep a copy, and neither our database nor any file storage ever receives it.
  5. The extracted details — not the image — are cached for up to 400 days, so that re-scanning the same receipt does not incur a second AI call. This cache is scoped to your account and your workspace and is unreadable by any other user.

6.2 Ask Syd

When you ask the in-app assistant a question about your spending, we send the Google Gemini API:

We do not send your name, your email, your partner's identity, your notes, or any account identifier. Answers are cached so that a repeated question costs nothing.

What Google does with it. Requests are made through the paid Google AI API, under which Google states that it does not use submitted data to train its models and retains it only briefly for abuse monitoring. Your data is not used to improve Gemini. See Google's Gemini API terms for the current position, which is set by Google and may change.

AI is not perfect. Receipt extraction and assistant answers can be wrong. Always check a scanned amount before saving it, and never treat an assistant answer as financial advice.

7. Third-party services

We use the following processors and services. We have no other data-sharing arrangements, and we do not sell or rent your information to anyone.

ServiceWhat it doesWhat it receives
Google Firebase
(Google LLC)
Authentication, database, cloud functions, hosting of all app data Everything described in section 3, other than the items listed separately below
Google Gemini API
(Google LLC)
Reads receipts; answers Ask Syd questions Receipt images and text; spending summaries and your question (section 6)
Google Analytics for Firebase
(Google LLC)
Aggregate product analytics Your account identifier, plus a fixed list of anonymous events. See 7.4
Google Crashlytics
(Google LLC)
Crash and error reporting Crash diagnostics, device model, OS version, app version
Google Sign-In
(Google LLC)
Optional sign-in method Provides us your name and email, if you use it
Sign in with Apple
(Apple Inc.)
Optional sign-in method on iOS Provides us your email, or a private relay address if you choose to hide it
Expo
(Expo, Inc.)
Push notification delivery, app build infrastructure Push tokens and the content of notifications. See 7.3
Resend
(Resend, Inc.)
Sends verification and password-reset emails Your email address and the one-time code
RevenueCat
(RevenueCat, Inc.)
Manages subscriptions and entitlements Your account identifier and subscription status
Apple / Google Play Process subscription payments Payment details go to the store, never to us. See 7.2

7.1 Where your data is stored

All app data is stored in Google Firebase, in Google Cloud data centres located primarily in the United States. Our cloud functions run in the us-central1 region.

7.2 Payments

Subscriptions are purchased and billed entirely through the Apple App Store or Google Play. We never receive, see or store your card number, bank details or billing address. We receive only a confirmation from RevenueCat that a subscription is active, tied to your account identifier.

7.3 Notification content

Some notifications include financial details in their text — for example, "Netflix · $15.99 is due in 3 days", or "$450.00 is still on your card". To reach you, that text passes through Expo's push service and then through Apple's or Google's push infrastructure, and it may appear on your lock screen where anyone holding your phone can read it.

If that concerns you, you can turn individual notification types off in Settings → Notifications, or hide notification previews in your phone's own system settings.

7.4 What our analytics can and cannot see

Our analytics is deliberately built so that financial information cannot reach it. Only a fixed, predefined list of events may be recorded — such as "an onboarding step was completed" or "the paywall was viewed" — and each event may carry only a short, restricted set of non-personal labels. Free text of any kind, including merchant names, descriptions, nicknames, email addresses and currency amounts, is rejected before transmission rather than trusted not to appear.

Your Firebase account identifier is set as the analytics user identifier, so that one person using two devices is counted once. That identifier is random and specific to Bsync; it does not reveal your name or email.

8. How we protect your information

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please use a strong, unique password, keep your device locked, and sign out of any device you do not control.

Breach notification. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, you directly, without undue delay.

9. How long we keep it

InformationRetention
Account profile and financial recordsFor as long as your account exists
Paused or dissolved partnership historyKept indefinitely, read-only, so both former partners retain their records
Nickname snapshot on a dissolved partnershipKept indefinitely — see the note below
Receipt imagesNot retained. Discarded as soon as extraction completes
Extracted receipt details (cache)Up to 400 days, then automatically expired
Ask Syd spending summaries and cached answersUntil your workspace data changes, or your account is deleted
Email verification and password-reset codes10 minutes
Hashed IP rate-limit recordsShort rolling window, then overwritten
Push notification tokensRemoved when you sign out or delete your account
Crash diagnosticsPer Google Crashlytics' retention, currently up to 90 days
Analytics eventsPer your Google Analytics settings, up to 14 months

What survives account deletion, and why. Bsync is a shared record between two people. If deleting your account erased everything you had ever entered, your former partner's budgets, past cycles and reports would silently change — figures they had already relied on would no longer add up.

So when you delete your account, we permanently delete your profile, your sign-in credentials and your personal records — but the expenses you recorded in a shared workspace remain in that workspace, still labelled with the nickname you used, and the partnership keeps a permanent snapshot of that nickname so the history stays readable.

If you would prefer your entries to be removed or your nickname replaced, email [email protected] and we will assess the request, balancing your rights against your former partner's interest in the integrity of their own financial records. If you were using Bsync solo, no other person has an interest in the data, and we will delete your records outright on request.

10. Deleting your account

You can delete your account in two ways, and neither requires you to contact us:

Deletion is immediate and irreversible. We cannot recover a deleted account. When you delete:

If you have an active subscription, deleting your Bsync account does not cancel it. Subscriptions are managed by the app store and must be cancelled there — see your Apple or Google account's subscription settings.

11. Your rights and choices

Depending on where you live, you may have some or all of the following rights:

To exercise any of these, email [email protected]. We will not discriminate against you for exercising a privacy right. We may need to verify your identity — normally by asking you to write from the email address on the account.

12. International data transfers

We operate from Jamaica, and your information is stored and processed in the United States and other countries where our service providers operate. These countries may not offer the same level of data protection as your own.

Where information is transferred out of the UK, EEA or Switzerland, we rely on our providers' Standard Contractual Clauses and equivalent safeguards — Google, Apple, Expo, Resend and RevenueCat each maintain these as part of their data processing terms. Where information is transferred out of Jamaica, we rely on the transfer conditions permitted by the Data Protection Act, 2020.

13. Regional privacy rights

13.1 Jamaica (Data Protection Act, 2020)

If you are in Jamaica, you have the right to be informed about our processing, to access your personal data, to have inaccurate data rectified, to prevent processing likely to cause damage or distress, to prevent processing for direct marketing (we do not carry out direct marketing), and to complain to the Office of the Information Commissioner. Contact us first at [email protected] and we will try to resolve the matter directly.

13.2 United Kingdom and European Economic Area (UK GDPR / GDPR)

Our legal bases are set out in the table in section 4. You have the rights listed in section 11, and the right to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office. We do not carry out automated decision-making that produces legal or similarly significant effects about you.

13.3 California (CCPA / CPRA)

In the last 12 months we have collected the categories of personal information described in section 3, for the purposes in section 4, from the sources described in section 3, and disclosed them to the service providers listed in section 7.

We have not sold or shared personal information as those terms are defined by the CCPA, and we do not sell or share the personal information of any consumer, including minors under 16. We do not use or disclose sensitive personal information beyond the purposes permitted under the CPRA. You have the rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising them.

13.4 Other jurisdictions

If your local law grants you privacy rights not listed here, contact us and we will honour any right we are legally required to provide.

14. Children's privacy

Bsync is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe someone under 18 has created an account, email [email protected] and we will delete it promptly.

15. Changes to this policy

We may update this policy as the app changes or the law does. When we do, we will revise the "Last updated" date at the top and increment the version number. If the change is significant — for example, a new category of data or a new third party — we will tell you inside the app before it takes effect. Continuing to use Bsync after a change takes effect means you accept the updated policy.

16. Contact us

[LEGAL ENTITY NAME] — publisher of Bsync

Privacy enquiries and data rights requests: [email protected]

General support: [email protected]

Legal notices: [email protected]

Operating from Jamaica.

You can also delete your account at any time, without contacting us, from Settings → Profile → Delete Account in the app or at bsync.bappssupport.com/DeleteAccount.