RoamSaldo is a travel budgeting and expense tracker. We collect the trip and expense data you enter, your account email, and — only if you choose to link one — read-only transaction data from your card through Plaid. If you buy Pro or a Trip Pass, Apple or Google processes the payment and RevenueCat verifies the purchase; RoamSaldo stores the product and access period, not your payment-card number. We do not sell personal information, show ads, use your financial data for advertising, or track you across other apps or websites. You can export or delete your RoamSaldo data from Settings in the app.
1. Information you provide
- Account: email address and a password (stored only as a salted hash by Supabase, our authentication provider).
- Trip data: trip name, home and local currencies, budget, dates, and the exchange rate snapshot.
- Expenses: amounts, categories, notes, dates, and any category corrections you make.
- Purchases (if you subscribe or buy a Trip Pass): store product identifier, purchase/access status, and expiry used to verify and restore card-sync access. Apple or Google processes your payment details; RoamSaldo does not receive your payment-card number.
- Support: anything you send us by email.
Trip and expense data is cached on your device so RoamSaldo works offline while you travel, and is synced to your account when you are signed in.
Google sign-in
If you choose Sign in with Google, Google shares basic account information with our authentication provider, Supabase, including your email address, Google account identifier, and basic profile information such as your name and profile picture. This information is used to authenticate you and associate your sign-in with your RoamSaldo account. RoamSaldo does not request access to your Gmail messages, Google Drive files, contacts, or calendar. Google account information is handled with your account data under the retention and deletion terms below. We do not sell it or use it for advertising.
2. Connected financial accounts (optional)
If you link a debit or credit card, RoamSaldo uses Plaid to make the connection and to retrieve account balances and transaction details. Plaid handles your bank sign-in directly: RoamSaldo never receives or stores your bank username, password, or card number. RoamSaldo stores only the Plaid access token, encrypted on our server, plus the transaction details needed to show purchases in your trip (merchant name, date, amount, category). You can unlink a card at any time, which revokes the token at Plaid and deletes the imported transactions.
3. Information collected automatically
Analytics (Android only): the Android app includes Firebase Analytics, which can report app-usage events and a device/app identifier. Analytics collection is turned off by default and no data is sent until it is enabled in a future release, at which point we will ask for your consent where required and update this policy. The iOS app contains no analytics SDK.
Technical requests: like any app that talks to a server, RoamSaldo makes network requests that necessarily reveal your IP address to our hosting provider. We do not use this information to build advertising profiles and we do not track you across apps.
4. Third-party services we rely on
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication and account data storage | Email, password hash, trip and expense data, purchase entitlement and expiry |
| Plaid | Bank/card connection and transaction import | Access token, balances, transaction details |
| RevenueCat | Native purchase receipt verification, restore, and subscription lifecycle | RoamSaldo account ID, product and transaction/receipt validation data |
| Apple App Store / Google Play | In-app checkout, billing, and subscription management | Store account, payment details, product and transaction records (handled by the store) |
| Render | Application hosting (API and web app) | Request metadata, IP address, server logs |
| open.er-api.com | Exchange rates | Currency codes requested (no account data) |
| Google Fonts, flagcdn.com | Typefaces and flag images shown in the app | Standard web request data (IP, user agent) |
| Google (Firebase) | App analytics on Android — disabled by default | App-usage events, device/app identifier |
Each provider processes data under its own privacy policy and only to deliver its service to us.
5. How we use information
- Converting expenses between currencies and tracking your remaining budget.
- Importing and categorizing card purchases when you link a card.
- Verifying and restoring in-app purchases, and enabling paid card sync for the purchased period.
- Syncing your trip across your devices, and restoring it when you sign back in.
- Account recovery, support, and keeping the service secure (rate limiting, abuse prevention).
- Improving the app — using aggregated, non-financial usage information only.
6. What we do not do
- We do not sell or rent personal information.
- We do not use connected transaction data for advertising or marketing.
- We do not use or share data for cross-app or cross-site tracking.
- We do not share data with data brokers or credit bureaus.
7. Retention and deletion
We keep your information while your account is open. You can export a readable copy of your data or delete your account at any time from Settings → Data & Account → Export / Delete account, or by requesting deletion on our account deletion page.
Deleting your account removes your RoamSaldo account, trip settings, expenses, imported transactions, and purchase entitlement rows from our live database immediately, and revokes any Plaid access token so the connection stops at the provider. We delete purchase entitlement rows and request deletion of the RevenueCat customer profile. RevenueCat and the app stores may retain transaction records under their own terms and policies. Deleting your RoamSaldo account or uninstalling the app does not cancel an auto-renewing App Store or Google Play subscription — cancel it separately in the store to stop future charges. Residual copies in encrypted backups are purged within 90 days. We may keep minimal records (for example, a record of your deletion request) where we are required to by law or need them for security and fraud-prevention purposes.
8. Security
Traffic is encrypted in transit with HTTPS/TLS. Plaid access tokens are encrypted at rest with AES-256-GCM using a server-side key and are bound to your account so a copied token cannot be replayed elsewhere. Account data is protected with row-level database policies that limit each signed-in user to their own rows. No internet service can guarantee absolute security, so please protect your password and your device.
9. Children
RoamSaldo is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA). If you believe a child has created an account, contact us and we will delete it.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. RoamSaldo provides export and deletion directly in the app; for anything else, email us and we will respond within 30 days. We do not discriminate against anyone for exercising these rights.
11. Changes to this policy
If we materially change this policy we will update the date above and, where appropriate, notify you in the app. Continuing to use RoamSaldo after a change means the updated policy applies.
12. Contact
Privacy questions and data requests: roamsaldo.admin@gmail.com. See also our Terms of Service and Help & Support.