This Privacy Policy explains how Devang Shah ("we", "us", "our") collects, uses, stores, and shares information when you use the Farewallet mobile application ("the App"). Please read it carefully. By creating an account or using the App, you agree to the practices described here.
Devang Shah is the data controller for the personal information collected through the App.
Contact:
Email: dontknowtechnologies@gmail.com
If you are in the European Economic Area (EEA) or United Kingdom, we are the controller of your personal data as defined under the General Data Protection Regulation (GDPR) and UK GDPR respectively.
Given the limited scale of our processing, we are not required to appoint a Data Protection Officer under Article 37 GDPR. You can still reach us for any data protection matter using the contact details above.
When you create an account, we collect: email address; password (not stored by us — handled by Firebase Authentication, a Google service); display name (the name you choose).
You may use the App without an account in offline-only mode. In that case, no account information is collected.
All trip content you create is stored locally on your device in an encrypted SQLite database. If you enable cloud sync or create/join a shared trip, the following is also stored in Google Firestore: trip names, destinations, dates, and budget; day-by-day itinerary items (activity titles, location names, GPS coordinates you pin, times, notes); free-text trip and day notes; pre-departure checklist items; emergency medical notes, if you add them (see Section 2M).
For shared trips, this data is visible to all members you invite.
Hospital and embassy directory entries you add on the SOS screen are not included in this list — see Section 2M for how that data is handled.
Expense records (amounts, currencies, categories, descriptions) are stored locally and, if you enable cloud sync, in Google Firestore.
Receipt photos you attach to expenses are stored as files on your device only. They are never uploaded to our servers or any cloud storage.
The App maintains two tiers of document storage:
Personal documents (passport, travel insurance, etc.): encrypted on your device using AES-256-GCM. The encryption key is stored in your device's secure hardware enclave (iOS Keychain / Android Keystore). Personal documents are NEVER transmitted to our servers, Firebase, or any other external service.
Shared trip documents (flight tickets, hotel confirmations, etc.): when you explicitly upload a document to a shared trip, it is stored in Google Firebase Storage and is accessible to all members of that shared trip.
Location access is optional and always requires your explicit permission.
Your real-time GPS position is used on-device to display your location on the map, to rank nearby points of interest, and to show you the nearest itinerary stop. This position is NOT stored in the App's database or sent to our servers.
When you request walking directions, your start coordinates are sent to Project OSRM (router.project-osrm.org) to compute a route. See Section 5 for details.
When you download an offline map pack, a geographic bounding box is sent to the Overpass API (overpass-api.de) to retrieve nearby place data (cafés, ATMs, hospitals, etc.). This does not identify you personally.
You can revoke location permission at any time in your device's Settings.
The Claude Haiku model processes your text and returns structured JSON. We do not store the raw document text after the import is complete.
The App requests access to your camera and photo library for two purposes: to let you attach receipt images to expenses, and to let you photograph or import travel documents such as passports, IDs, and tickets (see Section 2D for how document images are stored and encrypted). Receipt images are stored locally on your device and are never uploaded. Personal travel documents are encrypted locally and never uploaded, except the shared-trip-document case described in Section 2D.
The App includes an optional peer-to-peer sync feature. When enabled, your device broadcasts a service on your local Wi-Fi network using mDNS (Bonjour/Avahi). Another device running the App on the same network can discover and connect to it via TCP to exchange trip data.
Data transferred includes: trips, trip days, expenses, and itinerary items. This transfer occurs entirely on your local network and no data passes through our servers. You must initiate the sync deliberately.
The App fetches current exchange rates from Frankfurter (api.frankfurter.app) to convert expense amounts. This request contains no personal information — only a request for currency data.
Map tiles are served by Maptiler (maptiler.com). When you use the map screen, encrypted (HTTPS) requests for map tiles are sent to Maptiler servers. These requests include tile coordinates and your device's IP address. Maptiler's Privacy Policy applies to this data.
When you search for a place by name, the search query is sent to the Nominatim geocoding service (nominatim.openstreetmap.org), operated by the OpenStreetMap Foundation. The request includes your search text and your device's IP address. The OpenStreetMap Foundation Privacy Policy applies.
We do not use any analytics SDK, crash reporting service, or advertising network. We do not automatically collect device identifiers, advertising IDs, or browsing behaviour. If you contact us by email for support, we collect your email address and the contents of your message solely to respond to you.
This data is handled differently depending on the feature: emergency medical notes are stored locally by default — if the trip is a shared trip, these notes are also stored in Google Firestore and are visible to every member you invite to that trip, the same as other shared trip data described in Section 2B. Hospital and embassy directory entries (name, phone, address of local medical/consular facilities you look up or add) are stored locally on your device only — never uploaded to Firestore or any server, even for shared trips.
Because medical information is treated as a special category of data under GDPR Article 9, we only store it in the cloud with your explicit action (adding a note on a trip you have chosen to share) — see Section 4.
We do not store or have access to the raw audio at any point. Only the transcribed text is kept, and only if you leave it in your note — the same as any other note content described in Section 2B.
We use the information we collect to: provide and operate the App (creating/syncing your trips, displaying maps, calculating expenses, enabling shared trips); authenticate your account and maintain its security; sync your data across your devices via Firebase (if you choose cloud sync); enable sharing of trip data with people you explicitly invite; send you a verification email upon registration; respond to your support requests; improve the App (based on direct feedback only — we have no analytics).
We do not use your personal information for advertising, profiling, or sale to third parties.
If you are in the EEA or United Kingdom, we process your personal data under the following legal bases: performance of a contract (account information, trip data, and cloud sync); legitimate interests (security, fraud prevention, technical functionality); consent (precise location, AI import — withdrawable at any time); explicit consent for special category data (emergency medical notes under Section 2M are "special category" data under Article 9 GDPR — your act of typing this optional field on a shared trip constitutes explicit consent under Article 9(2)(a), and you may delete this data at any time to withdraw that consent).
You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
We do not sell your personal information. We share data only as described below.
We use Firebase Authentication, Cloud Firestore, and Firebase Storage, all operated by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Data processed: account credentials, trip data, expenses, itinerary items, notes, checklists, emergency medical notes (Section 2M), and shared trip documents. Transfers: data is stored on Google's servers, primarily in the United States. For EEA/UK users, Google relies on Standard Contractual Clauses (SCCs). See Google's Privacy Policy.
Used only when you explicitly invoke the AI import feature. Data processed: the full text of your uploaded travel document. See Anthropic's Privacy Policy.
Used only when you request walking directions in the App. Data processed: GPS coordinates of your start point and destination. OSRM is a free, open-source routing service. Requests are made to router.project-osrm.org.
Used when you search for a location by name or when importing an itinerary with location names that need geocoding. Data processed: your search query, your IP address. Operated by the OpenStreetMap Foundation. See their Privacy Policy.
Used when you download an offline map pack to fetch local points of interest. Data processed: the geographic bounding box of your chosen region. No personal data is transmitted. Operated by overpass-api.de.
Used to render the map screen when connected to the internet. Data processed: tile coordinates, your IP address. See Maptiler's Privacy Policy.
Used to fetch current exchange rates for expense conversion. No personal data is transmitted — the request is a simple HTTP GET for currency data.
Used only when you tap the microphone icon to dictate a trip or day note. Data processed: a short audio recording of your speech, sent directly from your device to Apple's or Google's speech-recognition service — not through our servers. See Apple's Privacy Policy or Google's Privacy Policy, depending on your device.
When you create or join a shared trip, trip data (itinerary, expenses, notes, checklists, and any emergency medical notes you've added — see Section 2M) is visible to all members of that shared trip. Shared documents you upload to the "Shared with group" area are accessible to all members; the app will prompt you to confirm a shared upload does not contain a passport, ID, or other personal identification before it uploads. Hospital/embassy directory entries are never shared — they stay on your device only. Only invite people you trust.
Account data and cloud-synced trip data are retained for as long as your account is active. If you delete your account (Account → Delete Account), your Firebase Auth account and all Firestore documents under your user ID are permanently deleted within a commercially reasonable time.
Shared trip data: if you created the shared trip, deleting the trip removes the data from Firestore. Data added by other members persists until those members delete it.
Local device data: deleting or uninstalling the App removes the local SQLite database and encrypted documents. Encrypted document keys in the device Keychain/Keystore are also removed on uninstall on most platforms.
Receipt photos: removing a receipt within the App deletes the local file. They are not in cloud storage.
Emails to us: retained for as long as needed to resolve your inquiry, then deleted.
We implement: local document encryption (AES-256-GCM with per-device keys in the device's secure hardware enclave); transport security (all network communication uses HTTPS/TLS); Firebase security rules (each user can only access their own data, shared trip data only accessible to verified members); account security (passwords hashed by Firebase, never stored by us in plain text).
No security measure is 100% foolproof. We encourage you to use a strong, unique password and to protect your device with a lock screen.
Data breach notification: if a security incident occurs that creates a material risk to your personal data, we will notify affected users and any competent supervisory authority without undue delay, and in any event within the timeframe required by applicable law (for example, 72 hours under Article 33 GDPR where feasible).
Access your data: all your trip data is viewable within the App. Delete individual data: expenses, itinerary items, documents, checklist items, and entire trips can each be deleted at any time without deleting your account. Delete your account: Account → Delete Account permanently removes your cloud data and Firebase account. No app access? If you can no longer sign in, email dontknowtechnologies@gmail.com with your account email and we will delete your account and data within 30 days. Export your expenses: Budget screen → Download icon exports a CSV of all trip expenses. Revoke location permission: Settings → Farewallet → Location. Disable cloud sync: use the App in offline-only mode without signing in.
You have the right to: access a copy of the personal data we hold about you; rectification of inaccurate data; erasure ("right to be forgotten"); restriction of processing; data portability in a structured, machine-readable format; object to processing based on legitimate interests; withdraw consent where processing is based on consent; lodge a complaint with your local supervisory authority — a list of EEA supervisory authorities is available here.
To exercise any of these rights, contact us at dontknowtechnologies@gmail.com. We will respond within 30 days.
California residents have the right to: know the categories and specific pieces of personal information we collect, use, disclose, and sell; delete personal information we have collected; correct inaccurate personal information; opt-out of sale or sharing — we do not sell or share your personal information with third parties for cross-context behavioural advertising, so there is nothing to opt out of, and we honor Global Privacy Control (GPC) signals as a valid opt-out request regardless; limit use of sensitive personal information — we collect two categories of Sensitive Personal Information under the CPRA (precise geolocation, Section 2E, and health information / emergency medical notes, Section 2M), used solely to provide the specific features you request, never to infer characteristics about you; non-discrimination for exercising your CCPA rights.
Categories of personal information collected: identifiers (email, display name), geolocation data (when location is enabled), travel itinerary and financial information (expenses), health information (emergency medical notes, if you add them), and the contents of documents you choose to process with AI import.
To submit a request, contact us at dontknowtechnologies@gmail.com.
The App uses Firebase services hosted on Google's infrastructure, which may include servers in the United States and other countries.
If you are located in the EEA, UK, or Switzerland, transfers of your data to Firebase's US infrastructure are made under Standard Contractual Clauses (SCCs) as approved by the European Commission, and under the UK Addendum to the SCCs for UK transfers. Google's Data Processing Terms are available here.
Anthropic is based in San Francisco, CA, USA. If you use AI import from outside the USA, your document text is transferred internationally. Anthropic's transfer mechanisms are described in their Privacy Policy.
The App is not directed to children under 13 years of age (or under 16 in the EEA/UK). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at dontknowtechnologies@gmail.com and we will delete it promptly.
If you are under 13 (or under 16 in the EEA/UK), do not use the App or provide any personal information to us.
The App may display links or content from third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any external services you access through the App.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the "Last Updated" date at the top of this page and, where appropriate, by showing an in-app notice or sending an email to your registered address.
Continued use of the App after a policy change constitutes your acceptance of the updated policy. If you do not agree, you should stop using the App and delete your account.
For any questions, concerns, or rights requests regarding this Privacy Policy:
Email: dontknowtechnologies@gmail.com
Subject: Privacy Policy — Farewallet
We aim to respond to all requests within 30 days. For complex GDPR requests, we may extend this by a further two months and will notify you.