Privacy Policy
PiggyLedger ("we", "us") operates the PiggyLedger mobile app ("the App"). This policy explains what data the App and its service providers process, why, and how you can control it.
In short: we do not read, store, or analyze your Google account details or the contents of your receipts. Google sign-in exists only so your phone can talk directly to your Google Drive — that connection never passes through us. If you use the optional AI-enhance feature, extracted receipt text (never the photo itself) is sent directly from your device to Google's Gemini API. If you choose Send Feedback, your email app sends us the email address, message, and any attachment you deliberately include; nothing is sent until you choose to send it.
1. Data we collect
Category A — needed to run a feature you turn on. This data is exchanged directly between your device and Google; we never store a copy or analyze it.
| Service | What it touches | Why |
|---|---|---|
| Google Sign-In | Google's own sign-in handshake identifies your account so the App can be authorized to access your Drive — we do not store your email or profile | Required only if you turn on Drive backup; skip sign-in and this never happens |
| Google Drive & Sheets | Your receipt photos and expense data, written directly from your device to a folder the App creates in your own Google Drive | Cloud backup and optional spreadsheet export — this data belongs to you, stays in your Drive account, and we never see or host a copy |
| Google Gemini API | The text extracted from a scanned receipt via on-device OCR (merchant name, date, amounts) — sent directly from your device to Google's Gemini API. The receipt photo itself is never sent, only this extracted text | Optional AI-assisted field detection, only when you choose to use it — this exchange is between your device and Google directly; we don't see or store a copy |
Category B — limited usage, diagnostic, and advertising data used to run and improve the App. This data may include SDK-generated identifiers and is not described as fully anonymous, but we do not send your email, name, Google account identity, or receipt content to Analytics.
| Service | What it collects | Why |
|---|---|---|
| Google AdMob | Advertising ID where available and permitted, IP address or approximate location, device and app information, consent signals, and ad impressions/interactions | To request, display, measure, protect, and frequency-cap in-app ads. Ads may be personalized where permitted by your settings and consent choices |
| Firebase Crashlytics | Crash and diagnostic logs, stack traces, app state supplied for diagnosis, device model, OS/app version, and SDK-generated installation identifiers | To detect, diagnose, and fix crashes and reliability problems |
| Firebase Analytics | App usage and technical signals only — which screens/features get used, settings choices, default currency, how a receipt was added and whether that succeeded, AI token usage when you use AI-enhance, sync/backup/restore outcomes, app version, and SDK-generated device/technical identifiers. Never your email, Google account details, receipt photos or text, merchant names, financial amounts, notes, or search text | To understand feature use, reliability, and AI capacity usage so we can improve the App |
| Email feedback | Only the email address, message, and attachments you choose to send from your own email app | To answer support requests, investigate problems, and consider feature suggestions |
2. Data storage & sharing
- Your receipt data lives on your device and, if you enable sync, in your own Google Drive — we do not host a copy on our own servers.
- Crash and usage data is processed by Google/Firebase as our service provider; we do not sell any data to third parties.
- Data in transit is encrypted (HTTPS/TLS).
3. Data retention
Firebase Crashlytics generally retains crash stack traces and associated installation identifiers for 90 days before beginning deletion. Firebase Analytics user-level event data is retained according to the retention setting configured for our Google Analytics property; some aggregated reports may remain available for longer. Google and its services may retain other advertising and service data under their applicable policies. Your receipt/backup data in Google Drive is retained until you delete it yourself — we never delete your Drive files on your behalf.
4. Your choices
- Revoke the App's access to your Google account anytime at myaccount.google.com/permissions.
- Turn off Drive sync and Sheets export anytime in the App's Settings.
- Where required, Google may show an AdMob consent or privacy message so you can make advertising choices. You can also reset or delete your advertising ID and manage ad personalization in your device or Google account settings.
- Firebase Analytics is used for product measurement and reliability, not to link Analytics activity to your Google Sign-In identity. Advertising ID collection is disabled for Firebase Analytics; this does not disable AdMob's separate advertising processing.
- Send Feedback is optional and opens your email app with a draft; you can edit or discard it before anything is sent.
- The Google Play review card is operated by Google Play. PiggyLedger does not receive your star rating or review text from the in-app card.
- Uninstalling the App removes all locally stored data (your Drive backup, if enabled, is unaffected).
5. Children's privacy
PiggyLedger is not directed at children under 13, and we do not knowingly collect personal information from children.
6. Changes to this policy
If this policy changes, we'll update the "Last updated" date above. Continued use of the App after a change means you accept the updated policy.
7. Contact us
Questions about this policy, your data, or the App? Email piggyledger@gmail.com. Support emails are retained only as long as reasonably needed to respond, investigate the issue, and meet legal obligations; you may ask us to delete your support correspondence.