Privacy Policy
This policy explains what NomadSpend processes in the iOS and Android apps and on the web, why it is needed, who receives it, and what choices and rights you have.
1. Controller and scope
NomadSpend is operated by Marek Jánošík. This policy applies to the iOS app, the Android app, the web app, and public pages at nomadspend.eu. The operator's contact for privacy questions and data requests is nomadspend@gmail.com.
2. Data we process
The exact data depends on the features you use. NomadSpend does not access your bank account and does not store bank credentials or full payment-card numbers.
- Account data: user ID, email address including an Apple Private Relay address, display name, selected sign-in provider, optional avatar, and account settings.
- Trips and user content: title, country, destination, dates, budgets, notes, members, invitations, custom categories, and change history.
- Expenses: title, amount, currency, exchange rate, category, payer, shares, payment status, payment method, dates, notes, and optional place information.
- Technical and security data: sessions, request time and result, IP address, and limited server or client error details such as app version, operating system version, endpoint, HTTP status, and error type.
- Platform activity: for an account we keep only one rolling timestamp (date and time) of the last confirmed use of iOS, Android, and web. We do not keep screen or click history, usage duration, an advertising identifier, or location for this purpose.
- Communications: your email and message content when you contact support or exercise a privacy right.
3. Receipt scanning and photos
Receipt scanning runs on your device — Apple Vision on iOS, and Google ML Kit with a model bundled in the app on Android. A camera or library image is not uploaded to NomadSpend servers or an external AI model, and NomadSpend does not save it. The image is discarded after recognition. Text and amounts you choose to add to an expense or its notes are then processed as ordinary expense content and may be synchronized.
4. Location
The mobile app requests location only while you use it and add or edit an expense. It can suggest a currency and fill a place name, city, country, or coordinates. NomadSpend does not track location in the background. If you save a location on an expense, it is synchronized and visible to that trip's members. You can deny or revoke permission in your device settings and edit or omit the place before saving.
5. Purposes and legal bases
We use data only to operate the service: create and secure accounts, authenticate users, synchronize data, calculate budgets and settlements, support trip collaboration and exports, answer support requests, prevent abuse, diagnose errors, and evaluate aggregate platform use and support.
- Performance of a contract or steps at your request: accounts, sign-in, sync, trips, expenses, sharing, and exports.
- Legitimate interests: security, abuse prevention, diagnostics, service reliability, aggregate platform-support planning, and protecting the rights of users and the operator.
- Optional features at your request: camera, photo, and location access can be denied or later disabled in device settings.
- Legal obligation or legal claims where applicable law requires retention or disclosure.
6. Shared trips
A trip is a collaboration space. Depending on their permissions, its members can see trip details, participant names, expenses, shares, payments, notes, and saved places. The owner can invite and remove members, so invite only people you trust. A virtual participant does not need an account, but their display name and assigned expenses remain part of the shared trip.
7. Providers and international transfers
We do not sell, rent, or provide data for advertising. Data is processed as necessary by providers of hosting and databases, sign-in email delivery, identity verification, and exchange rates. It may also be disclosed to public authorities where legally required.
- A sign-in provider receives information needed to verify identity only when you use that sign-in method. Apple may provide a Private Relay address instead of your real email.
- The exchange-rate service receives the requested base currency and ordinary network metadata, not trip or expense content.
- Map tiles in the Android app are provided by OpenStreetMap. When a map is displayed, its servers receive ordinary network metadata including your IP address and the coordinates of the map area being viewed, but not trip or expense content.
- Some providers may process data outside the EEA. Such transfers are governed by safeguards required by applicable law and the relevant provider's terms.
8. Retention and deletion
We retain accounts, user content, and the three timestamps of last confirmed platform use while you use the service or while needed for a shared trip to function. Activity timestamps are cleared when the account is deleted. Authentication, audit, and diagnostic records are retained only while valid or for a limited period needed for security, error resolution, and abuse prevention, after which they are removed automatically.
- You can delete your account in the mobile app's Settings. Trips only you can see are deleted outright, together with their expenses, splits, and notes. Your sessions, sign-in identifiers, email, and profile are removed, and that account's local data is erased from the device.
- In a shared trip the expenses, amounts, and splits remain, because they are equally the other members' financial record. Your name is replaced with an anonymous placeholder such as “Unknown_1”, and notes you wrote on those expenses are cleared. Expense titles and the names of any participants you added by hand stay part of the shared record.
- Before deletion you can export your data and edit or remove content where your permissions allow it. If you need a specific detail removed that remains after anonymization, contact us.
- We may retain specific records longer when required by law, a security incident, or the establishment and defense of legal claims; they are deleted or anonymized afterwards.
9. Local storage, cookies, and security
The mobile apps use a local database and encrypted system credential storage. The web uses necessary cookies for sign-in and remembering the language choice; it uses local storage for language, basic displayed profile data, a pseudonymous session identifier, and the next activity-report attempt deadline. These local identifiers are pseudonymous, not anonymous, and are used only to separate accounts on that device or browser. The deadline normally prevents repeated reports; failures, configuration changes, or multiple tabs or devices can still produce more HTTP attempts. The server overwrites the timestamp at most once per allowed interval, which is typically 24 hours. We do not use advertising or behavioral-analytics cookies. Traffic between the app, website, and API uses HTTPS.
10. Diagnostics, tracking, and automated decisions
When a technical error occurs, the mobile app may automatically send an authenticated diagnostic record containing app and system versions, error type, endpoint, and a technical description. The record may include a truncated excerpt of the server's error response, used to identify the cause. A receipt image is never sent. After an ordinary authenticated request succeeds, an active platform may overwrite its last-use timestamp about once a day; this does not record individual actions. NomadSpend does not use advertising identifiers, track you across apps or websites, or make decisions with legal or similarly significant effects. Suggestions such as “Who should pay next?” are local interface calculations only.
11. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You can export trip data in a machine-readable format. Email nomadspend@gmail.com from the address linked to your account; we may reasonably verify your identity first. You may also lodge a complaint with the Office for Personal Data Protection of the Slovak Republic or your local supervisory authority.
12. Changes and contact
This policy may be updated when features or legal requirements change. The current version and its revision date are published at nomadspend.eu/privacy. Privacy contact: nomadspend@gmail.com. Last updated: 25 August 2026.
Last updated: August 2026