CashBro Privacy Policy

Effective September 30, 2026 · Published August 30, 2026

This version takes effect on September 30, 2026. The previous version, dated August 20, 2026, continues to apply until then.

CashBro ("the app") is a personal budgeting app developed and operated by Luxsoft ("we", "us"). This Privacy Policy explains what information we collect, why, how we use it, who else touches it, and the choices and rights you have. We designed CashBro to collect as little data as possible and to keep your financial information private.

The short version. Your budget data is yours. We do not sell it, we do not share it for advertising, we do not use it to train AI models, we show no ads, and we run no tracking or analytics SDKs. We collect the minimum we need to run the app for you, and you can export it or delete all of it at any time from inside the app.

1. Who is responsible for your data

Luxsoft is the controller of the personal information described in this policy (in Canadian terms, the organisation accountable for it). We are located in British Columbia, Canada.

Our designated privacy contact, who is responsible for our compliance with this policy and with applicable privacy law, can be reached at support@luxsoft.dev (subject line: "Privacy Officer"). A postal address is available on request to the same address. We aim to respond to any privacy request within 30 days.

2. Information we collect

3. What we do not collect

4. Why we use your data, and our legal bases

We use your data solely to provide the app's functionality: to display your budgets and transactions, sync your data across sessions and devices, keep you signed in, send the notifications you have enabled, determine whether your access is active, fix crashes, answer your support requests, and, when you choose to use them, generate the optional AI-powered features described in section 6. We do not use your financial data for any purpose other than operating the app for you.

If the General Data Protection Regulation (EU or UK GDPR) applies to you, our legal bases are:

WhatWhyLegal basis
Account, financial data, preferences, sync, purchase status To provide the app you asked for Performance of a contract (Art. 6(1)(b))
Crash and error reports, security and abuse prevention To keep the app working and secure Legitimate interests (Art. 6(1)(f))
AI category suggestions, email bill scan Optional features you switch on Consent (Art. 6(1)(a)), withdrawable at any time
Purchase, billing-failure and cancellation emails To tell you about your own transaction Performance of a contract (Art. 6(1)(b))
Keeping records of purchases and requests Tax, accounting and legal obligations Legal obligation (Art. 6(1)(c))

Where we rely on consent, you can withdraw it at any time (for example, by turning off the smart category suggestions toggle in Settings, or by revoking Gmail access), without affecting anything done before you withdrew it.

5. How your data is stored, and where

Your account and financial data are stored on our backend provider, Supabase, in a Postgres database protected by row-level security so that each user can only access their own records. A copy of your most recent data is also cached locally on your device so the app works quickly and offline; on your device, your sign-in tokens are stored in the operating system's secure keychain.

International transfers. Supabase and the other service providers named in this policy may process data on servers located in the United States or other countries whose privacy laws differ from those where you live. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or IDTA where applicable) in our agreements with those providers, or on an applicable adequacy decision. You can request more detail about these safeguards using the contact details in section 21.

6. AI features

CashBro may include optional AI-powered features, where available in your version of the app: category suggestions when you log an expense, the email bill scan, and a monthly spending report. When these features are available and you choose to use them, limited data is sent through our own secure server to an AI provider (Google or Anthropic):

This data is used solely to generate the response shown to you in the app. We access these providers through their API services under terms that do not permit your data to be used to train their models. AI output is labelled in the app, is generated automatically, may be wrong, and is applied only after you confirm it. If no AI features are used, nothing is ever sent to an AI provider.

7. Email bill scan (Google user data)

The email bill scan is optional and runs only when you start it from the Bills screen. It connects to your Gmail account using Google's read-only permission (gmail.readonly), which means CashBro can never send, modify, or delete your mail.

When you run a scan, the app searches for bill-related emails from the last 90 days (at most 50) and reads only each message's sender, subject, date, and the first portion of its text. These excerpts are sent to our AI provider (section 6) for the sole purpose of suggesting bills you may want to track. Nothing from your email is saved unless you explicitly approve a suggested bill, and an approved bill stores only the biller name, amount, due date, and category. Your Gmail access token is held in memory only for the duration of the scan and is discarded when the scan ends. We do not store your emails, we do not use email data for advertising, and no human reads your email data. You can revoke CashBro's access at any time at myaccount.google.com/permissions.

CashBro's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Crash and error reporting

To find and fix bugs, the app reports crashes and errors to Sentry, a crash-reporting service. Reports contain technical details only: device model, operating system version, app version, the error itself, and a short trail of recent screens and actions. Reports are associated with a random account identifier so we can tell how many users an issue affects. They never include your name, email address, transaction amounts, notes, or email content, and we have configured Sentry not to store IP addresses or other personal information with reports.

9. Purchases and purchase emails

CashBro includes a free trial and, after it, paid access. Purchases are processed by Apple through the App Store (and, on Android, by Google Play). We never receive or store your payment card details; Apple or Google is the seller and handles billing and refunds.

Whether your access is active is managed for us by our purchases provider, RevenueCat. So that a purchase follows your account rather than a single device, we send RevenueCat your CashBro account identifier (a random UUID). It receives no name, email address, or financial data you have entered into the app.

When a purchase, a failed renewal, or a cancellation happens, we send you a short email about it. Those messages are delivered by Resend, which receives your email address and the text of the message for that purpose only. We do not use it for marketing, and renewals do not generate email.

10. Who else touches your data

We do not sell or rent your personal information, and we do not disclose it except as described here. The service providers we use, and what each one receives:

ProviderWhat it doesWhat it receives
Supabase Database, authentication, hosting Account details and all data you enter
Apple / Google App distribution, sign-in, billing Purchase and sign-in data, handled under their own policies
RevenueCat Purchase and entitlement status Your random account identifier and purchase status only
Sentry Crash and error reporting Technical crash data and a random identifier
Resend Transactional email delivery Your email address and the message text
Google or Anthropic Optional AI features only Only the limited data described in sections 6 and 7

These providers act on our instructions and are bound by contract to protect your data and to use it only to provide their service to us. We may also disclose personal information where we are legally required to (for example, to comply with a valid court order, subpoena or lawful request), to establish or defend a legal claim, or to protect the rights, safety or property of our users, the public or us. We will resist requests that we believe to be overbroad or unlawful, and will tell you about a request affecting you unless we are prohibited from doing so.

11. Security

We take reasonable technical and organisational measures to protect your data. These include encryption in transit (HTTPS/TLS) for everything the app sends, encryption at rest at our database provider, per-user row-level security so one account cannot read another's records, server-side enforcement of trial and access status, storage of sign-in tokens in your device's secure keychain, and minimising what we collect and what we send to any third party in the first place.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your device and your sign-in credentials secure. If a breach of security affecting your personal information occurs and creates a real risk of significant harm, we will notify you and the relevant regulators as required by applicable law, including the Office of the Privacy Commissioner of Canada and, where applicable, the Commission d'accès à l'information du Québec and EU or UK supervisory authorities.

12. Deleting your account and data

You can permanently delete your account at any time from within the app: open Profile then Delete Account. This immediately and permanently deletes your account and all associated financial data from our systems, and revokes the token we hold if you signed in with Apple. This action cannot be undone, so export first if you want a copy: Settings › Export my data writes every transaction, bill, goal and income record to a CSV file you can keep.

13. Data retention

14. Children's privacy

CashBro is not directed to children. It is intended for people aged 13 and over, and 16 and over in the European Economic Area and the United Kingdom. We do not knowingly collect personal information from a child below those ages. If you believe a child has given us personal information, contact us and we will delete it.

15. Your rights and choices

Wherever you live, you can: edit your profile and your records in the app; export everything to a CSV file; turn off notifications, AI category suggestions, and the email bill scan; revoke Gmail access; and permanently delete your account and data.

Depending on where you live, you may also have the right to:

To make a request, email us at support@luxsoft.dev from the address on your account, or tell us enough for us to locate your account. We may need to verify your identity before acting. We do not charge for a request unless it is manifestly unfounded or excessive, and we will tell you first if that applies. An authorised agent may make a request on your behalf with written proof of authority.

16. Regional information

Canada

We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, British Columbia's Personal Information Protection Act. You may complain to the Office of the Privacy Commissioner of Canada or to the Office of the Information and Privacy Commissioner for British Columbia.

Quebec

Our designated person in charge of the protection of personal information is reachable at support@luxsoft.dev (subject line: "Privacy Officer"), as required by Quebec's Law 25. As described above, we use no profiling, tracking or identification technology, and no such function is enabled by default. Personal information may be communicated outside Quebec, as described in sections 5 to 10; we have assessed that it receives adequate protection through the contractual safeguards named there. You may complain to the Commission d'accès à l'information du Québec.

European Economic Area, United Kingdom and Switzerland

Luxsoft is the controller. Our legal bases are in section 4 and our transfer safeguards in section 5. You have the rights listed in section 15, and you may lodge a complaint with your local data protection supervisory authority or, in the United Kingdom, the Information Commissioner's Office. We do not process special categories of personal data as defined in Article 9 of the GDPR.

United States (California and other states)

In the twelve months before the date of this policy, and at all times before it, we have not sold personal information and have not shared it for cross-context behavioural advertising, including the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.

The categories of personal information we collect are identifiers (name, email address, account identifier), commercial information (purchase status), internet or device activity (crash diagnostics), and, because you enter it yourself, financial information. We collect it from you and from your sign-in provider, for the business purposes in section 4, and we disclose it only to the service providers listed in section 10. California, Colorado, Connecticut, Virginia and other state residents may exercise the rights in section 15, including the right to know, delete, correct, and opt out, and to appeal a refused request by replying to our response.

17. Automated decision-making

We do not make decisions about you that produce legal effects or similarly significantly affect you based solely on automated processing. The app's AI category suggestions are proposals shown to you, which take effect only when you confirm them, and they have no consequence outside your own records.

18. Business transfers

If Luxsoft is involved in a merger, acquisition, financing, reorganisation, or a sale of all or part of its business or assets, your personal information may be transferred as part of that transaction. We will require the recipient to continue to protect it in a manner consistent with this policy, and we will notify you in the app or by email before your information becomes subject to a materially different privacy policy, so that you can export your data and delete your account first.

19. This website

The pages at this address are plain static documents. They set no cookies, run no analytics, and embed no trackers. Our web host records standard server logs for security and reliability.

20. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" above and post the updated version at this address. For a change that materially affects how we handle your personal information, we will give you at least 30 days' notice in the app or by email before it takes effect, and, where the law requires your consent, we will ask for it.

21. Contact and complaints

If you have questions about this Privacy Policy, want to exercise a right, or want to complain about how we have handled your information, contact us first at support@luxsoft.dev. We take complaints seriously and will investigate and respond, normally within 30 days.

If you are not satisfied with our response, you may complain to your local privacy regulator: the Office of the Privacy Commissioner of Canada, the Information and Privacy Commissioner for British Columbia, the Commission d'accès à l'information du Québec, your EEA supervisory authority, or the UK Information Commissioner's Office, as applicable.