PRIVACY & TRUST
Privacy Policy
This policy explains how information is handled in "Coteka", a shared expense and settlement app for couples.
1. Scope
This policy applies to the mobile app "Coteka" (the "App") and the web page on which this policy is published.
2. Information Collected and Stored
The App creates and stores a user identifier and session information through anonymous authentication so that users can use the App without a sign-in screen.
The App stores the following information to provide its features:
- Group information, invitation tokens, member roles, display names, net income amounts, rounding settings, default split method, and display currency
- Payment descriptions, amounts, dates, payers, split methods, and each member's share
- Settlement amounts, dates, payers, and recipients
- Recurring payment descriptions, amounts, payers, split methods, due dates, start months, and end months
- App settings stored on the device, such as onboarding completion state, display settings, authentication sessions, and notification preferences
- When notifications are allowed, an Expo Push Token, the recipient device platform, display language, and token update time
- Limited performance information needed to improve service reliability, such as app startup and time-to-interactive measurements
The App does not require users to enter their legal name, email address, phone number, or postal address. However, if users enter personal information in display names, payment descriptions, or similar fields, that content is stored as App data.
3. Purposes of Use
Collected and stored information is used for the following purposes:
- Providing App functionality, group creation, invitations, synchronization, and shared expense and settlement calculations
- Saving and displaying payments, settlements, recurring payments, member settings, and currency settings
- Sending notifications about payments, settlements, and recurring payments, and scheduling notifications on the device
- Displaying non-personalized ads, managing advertising consent, controlling ad frequency, and preventing misuse
- Responding to bugs, handling inquiries, and improving the service
- Preventing misuse, maintaining security, and complying with laws and store policies
4. Sharing and Third-Party Services
Members who participate in the same group may be able to view and update shared group data, including display names, net income amounts, payments, settlements, and recurring payments. Please share invitation links only with people you trust.
The App uses Supabase for authentication, database, and realtime synchronization. Supabase may process app data, authentication information, and technical information about devices and communications for service provision, security, fraud prevention, operations, and legal compliance.
The App uses Expo services to deliver app updates and push notifications, and to measure app-start performance. If notifications are enabled, the App sends an Expo Push Token and notification content to Expo's push notification service. Notification content may include shared group data such as payment, settlement, or recurring-payment descriptions, amounts, dates, and display names. Expo delivers notifications to Apple or Google notification services. Expo and those notification services may process technical information about devices, communications, and performance.
The App uses the Google Mobile Ads SDK and Google User Messaging Platform and may display ads on the record screen and after a successful entry is added. Ad requests are configured for non-personalized ads. On iOS, the App does not request App Tracking Transparency permission and does not obtain or use the IDFA. The App does not send shared group data, such as payments or settlements, to Google for advertising.
Even for non-personalized ads, Google and advertising providers may process cookies, mobile advertising identifiers, or similar identifiers, as well as technical device and connection information, for ad delivery, frequency capping, aggregated reporting, and fraud prevention. Where required by law, Google presents consent choices. If a "Privacy settings" item is shown in the App's Settings screen, you can use it to change your advertising consent.
We do not sell user information to third parties, except as required by law.
5. On-Device Storage
The App stores authentication sessions, settings, notification preferences, and scheduled on-device notifications for recurring payments on the user's device. Authentication sessions are protected using secure device storage and encrypted local storage.
When the App is deleted, local data stored by the App on the device is generally deleted. However, group data stored on the server may not be deleted solely by deleting the App.
6. Access, Correction, and Deletion
Users may be able to view, edit, and delete display names, net income amounts, payments, settlements, recurring payments, and similar data within the App.
Notifications can be turned off in the App's Settings screen or in the device notification settings. When an entry for changing advertising consent is shown in the App's Settings screen, consent can be changed there.
Users can leave a group using the leave feature. If no other real member has joined the group, the group data is deleted. If another member remains in the group, past shared data such as payments and settlements may remain so that the remaining member can continue using the shared history.
For other requests to access, correct, or delete information, please contact us using the contact information below. We may not be able to fulfill every request due to identity verification requirements or technical or legal restrictions.
7. Children and Minors
If a minor uses the App, the minor should do so with the consent and supervision of a parent or guardian. We will respond within a reasonable scope to inquiries from parents or guardians regarding information handling.
8. Security
We strive to take reasonable security measures to help prevent loss, leakage, alteration, unauthorized access, and similar risks regarding information handled by the App.
9. This Web Page
This web page is hosted by GitHub Pages. We do not place our own analytics tools, advertising tags, or cookies on this page. For details about GitHub's handling of information, please review GitHub's privacy statement.
10. Changes
We may update this policy as needed. If there are material changes, we will announce them on this page. The updated policy becomes effective when posted on this page.
11. Contact
If you have any questions about this policy, please contact us at:
Email: contact@cabine.io