1. who we are
wym is an independently developed app. In this policy, "wym," "we," "us," and "our" refer to the independent developer operating the app. For privacy or support questions, contact david@waasg.com.
wym records and organizes financial information that you choose to enter or capture. It is not a bank, payment processor, money transmitter, lender, financial adviser, tax adviser, or debt-collection service. It does not access your bank login or receive your full payment card number.
2. information you provide
Depending on the features you use, you may provide:
- account details such as your name, email address, username, profile information, and authentication identifiers;
- transactions, amounts, merchants, categories, notes, dates, currencies, recurring expenses, budgets, savings goals, and related financial records;
- friends, groups, guest participants, split requests, settlement status, reminders, and social activity;
- support messages, feedback, and other information you choose to send.
When a shortcut helps capture an Apple Pay or other payment moment, wym processes the transaction details made available to the shortcut, such as merchant and amount. wym records the purchase; it does not process the payment itself.
3. information handled automatically
wym and its service providers may handle user and device identifiers, Firebase authentication identifiers, push-notification tokens, subscription product and entitlement information, basic service and security logs, and app interactions required to operate features.
Precise location is handled only when you enable location access and use travel or transaction-context features. iOS controls the permission. Widgets, App Intents, and shortcuts may place limited app data in local or shared device storage so those features can work.
The current public app does not integrate a third-party crash-reporting SDK or a separate in-app analytics sharing control. Apple and platform providers may still provide their own diagnostics subject to your device settings and their policies.
account-linked product measurement
While you use an authenticated account, wym records activity such as starting or saving a transaction, using splits and invitations, returning to the app, viewing a subscription offer, and starting or completing a subscription purchase. These records are linked to your account and include the event time, app version, a session identifier, and limited details such as the entry method, group size, or subscription plan. wym uses this information to understand feature use and improve the app.
These measurement records are stored in Google Firebase. They do not include transaction amounts, merchant names, receipt photos, email contents, or notes. They are not used for advertising or cross-app tracking. Your data export includes these records, and account deletion removes them. The current app does not automatically delete these records after a fixed period or provide a separate measurement opt-out switch.
4. how information is used
Information is used to create and secure accounts; sync transactions and settings; show budgets, goals, histories, groups, splits, and widgets; send requested notifications; provide location-enabled context; manage premium access; prevent abuse; troubleshoot service problems; respond to support; and comply with applicable law.
5. authentication
wym supports email and password, anonymous guest accounts, Sign in with Apple, and Google Sign-In. Apple or Google may provide an authentication identifier and, depending on your choices and provider settings, a name or email address. Their use of information is governed by their own terms and privacy policies. An anonymous account still receives a unique service identifier and may store app data.
6. optional Gmail imports
Gmail access is separate from signing in and is enabled only when you choose Connect Gmail in Email Imports settings. The requested read-only Gmail permission allows wym to read mailbox messages but does not allow wym to send, modify, move, or delete email.
wym first checks message metadata and then processes the content of messages that look like receipts or transaction alerts. Attachments are not accessed. Email subjects and bodies are processed transiently and are not retained. wym retains extracted transaction fields such as merchant, amount, currency, date, sender domain, a short payment description and payment method when available, and review status. Candidates not dismissed by your learned filters are shown for your review, and no transaction is added without your approval.
Choosing Not a transaction saves your review decision and, when a sufficiently specific pattern can be identified, an account-specific fingerprint derived from the sender and message template. The fingerprint does not store the subject or body. Matching future suggestions may be retained as dismissed instead of appearing in the review queue. Ordinary dismissal does not teach a filter. You can restore a dismissed suggestion to review and disable its matching filter, or reset learned filters in Gmail settings. Reset stops using earlier filters; it does not erase existing suggestions or feedback records. Feedback records remain until account deletion.
Google authorization tokens are encrypted and restricted to server-side processing. You can pause importing, disconnect Gmail, revoke access, and delete extracted candidates. Disconnecting erases wym's stored Google refresh token. Account deletion also erases the token and feedback records and attempts to revoke the Google grant.
saved receipt photos (separate from Gmail email attachments)
When you scan or select receipt photos and save them, wym keeps a private copy linked to your account so you can reopen it from transaction details. Receipt text is processed to suggest items and totals. Photos are not automatically shared with split participants. You can explicitly include receipt photos when sharing a split through the system share sheet. Cloud receipt photos are removed after their last linked transaction or your account is deleted. Signing out or erasing transactions clears the corresponding local copies.
7. service providers
wym uses third parties to operate the app:
- Google Firebase for authentication, Firestore database storage, Firebase Storage for receipt photos, cloud functions, remote configuration, and Firebase Cloud Messaging;
- Google for Google Sign-In and optional read-only Gmail imports;
- Apple for Sign in with Apple, iOS services, push delivery, and App Store billing;
- RevenueCat for subscription products, entitlement status, purchase history, and restoration.
These providers process information under their own policies and may process it in countries other than your own.
8. sales, ads, and tracking
The current public configuration is designed without third-party ads and without app tracking. The privacy manifest declares no tracking and no tracking domains. wym does not sell personal information or use it for cross-context behavioral advertising. If this changes, this policy and the App Store disclosures must be updated before the changed feature is released.
9. storage, security, and international processing
Cloud account and app records are stored through Firebase services. Some widget, shortcut, preference, and session data is stored on your device. Subscription records are processed by Apple and RevenueCat.
wym uses reasonable technical and organizational safeguards and the security controls provided by its service providers. No storage or transmission method is completely secure, so absolute security cannot be guaranteed. Providers may process information in the United States and other locations where they operate.
10. retention
Account and app records are kept while your account is active and as needed to provide the features you use. When you delete your account, the app runs its deletion flow against the active Firebase account and associated app collections. Service-provider logs, transaction records held by Apple or RevenueCat, and backup copies may remain for the periods those providers require for security, billing, recovery, or legal compliance.
Information may also be kept when reasonably necessary to comply with law, resolve disputes, prevent abuse, or enforce these terms. Files you export remain wherever you choose to save or share them.
11. account and data deletion
You can delete your account from the app's data-management settings. The implemented deletion flow removes the Firebase Authentication account, profile and public profile, username reservation, personal transaction collections, budgets, recurring transactions, savings goals, categories, friends, guests, social activity, requests, invitations, and local widget account data. It also removes the user from groups. Sign in with Apple accounts are reauthenticated and the Apple authorization token is revoked as part of deletion.
Shared records may affect or remain visible to other participants where needed to preserve their own group or split history. Anonymous accounts can use the same deletion action while signed in. The deletion request runs when you confirm it in the app; if it cannot complete, the app reports an error rather than silently treating the account as deleted.
Deleting a wym account does not cancel an active App Store subscription. Apple and RevenueCat may retain transaction and entitlement records under their legal obligations and policies. Cancel billing in your Apple account separately.
12. your choices
You can edit account and financial information in the app, export transaction history as a CSV where that feature is available, manage notification and location permissions in iOS Settings, restore or manage subscriptions through Apple, withdraw optional permissions, and request access, correction, export, or deletion by contacting david@waasg.com.
13. children's privacy
The current app does not ask for a date of birth and does not include an age-verification flow. wym is intended for people who can manage their own personal-finance records and agree to these terms. If you are a parent or guardian and believe a child has provided information, contact david@waasg.com so the account can be reviewed and, where appropriate, deleted.
14. privacy rights
Depending on where you live, including certain US states, the EEA, or the UK, you may have rights to know or access personal information, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, or appeal a denied request. You may also complain to your local data-protection authority.
wym does not discriminate for exercising applicable privacy rights. We may need to verify your identity before completing a request. Authorized-agent requests may require proof of authority.
15. updates to this policy
This policy may change as the product or law changes. The effective date will be updated, and material changes may also be communicated in the app or through another appropriate channel.
16. contact
For privacy questions, support, corrections, exports, or deletion requests, email david@waasg.com.