1) Introduction and scope
ExMoney is a digital service for managing personal expenses and shared debt ledgers (groups and 1:1 friends). This policy applies to the mobile app, the API, and related websites, including these policy pages.
By using the service you acknowledge this policy. If you do not agree with the processing described here, please do not create an account, or stop using the service and request deletion of your data.
2) Data controller
The entity responsible for processing your personal data is ExMoney. You can contact us at abdoshokrey4@gmail.com. The service is intended for users in multiple countries and is delivered via an internet app and API.
3) Categories of data we collect
A. Identity and account data
- Display name on your profile.
- Phone number in a normalized international format (E.164) and the related country code.
- Password stored hashed — we do not store it in clear text.
- Profile photo if you upload one (from gallery or camera), and its storage path.
- Preferred currency and budget limits if you set them.
- UI preferences saved on the account (such as light/dark theme and app language) so they can be restored after reinstalling the app.
B. Financial data entered by the user
- Personal transactions (income/expense): amount, category, title, note, date, attachments (images or files — from gallery or camera).
- Group and friend bills: amounts, splits, payer, shares, notes, bill photos (from gallery or camera).
- Settlements, suggested payment methods, and confirm/reject states.
- Monthly budgets and spending alerts.
C. In-product social data
- In-app contacts, add requests, and accept/reject states (numbers/names chosen by the user inside the product).
- Group membership, join invites, and debt balances between members.
- When adding a number in the app, the device contact picker may be used to choose a single number only — without syncing the full device address book to our servers.
D. Technical and operational data
- Push notification device tokens (FCM / Push tokens) and device platform if you enable notifications and register a device.
- Offline sync identifiers (
client_uuid) and sync timestamps. - Technical logs for security and diagnostics (such as IP address in server logs when needed).
3‑B) Data practices summary (aligned with store disclosures)
The following summary reflects what the app discloses to Google Play / the App Store and must stay consistent with this policy. Any material change in collection will be updated here and communicated to the mobile team so store declarations can be updated.
- Account data: Yes (name, phone, profile settings).
- Financial data entered by the user: Yes (transactions, bills, settlements, budgets).
- In-app contacts: Yes (friendship / ledger relationships inside the product).
- Device contact picker: Yes — to pick a single number when needed only, without syncing the address book.
- Location: No.
- Uploaded photos / receipts: Yes (transaction attachments, bill photos, profile photo, support attachments).
- Direct camera: Yes — the app may request camera permission to capture an image (such as a receipt, profile photo, or support attachment) and upload it with your consent; you may instead choose an image from the gallery.
- Advertising ID: No.
- Cross-app tracking for advertising: No.
- Sale of personal data: No.
4) Sources of data
- Directly from you: when registering, updating your profile, entering transactions, uploading attachments, or contacting support.
- From other users in your shared ledgers: when a friend adds a bill that includes you or proposes a settlement.
- Automatically from device/server: technical data needed to run the API, sync, and notifications.
5) Purposes and legal bases
We process data for the following purposes under commonly recognized bases (contract performance, balanced legitimate interests, legal obligation where applicable, and consent where required):
- Providing the service: creating accounts, storing transactions, calculating balances, settlements, budgets, and sync.
- Security and abuse prevention: protecting accounts, limiting fraud, and investigating security incidents.
- Operational communications: in-app and/or push notifications about ledger events that concern you (such as a bill or settlement) and reminders — according to feature and device settings; we do not send an external push for an action you performed yourself when the other party is the one who should be notified.
- Product improvement: understanding performance issues in aggregated/limited form without selling your personal data and without cross-app advertising tracking.
- Compliance: responding to valid legal requests from competent authorities when required by law.
7) Cross-border transfers and storage
Data may be stored or processed on servers in one or more countries depending on the hosting provider and where the service runs. When transferring across borders, we seek appropriate contractual and technical safeguards to the extent practical and as required by laws applicable in your country.
8) Retention periods
- Account and transaction data are kept while the account is active and for as long as needed to provide the service.
- When you delete your account in the app, the account is deactivated (it will not appear in search and you cannot sign in), while data is retained so you can restore the same account by registering again with the same phone number, and to preserve shared-ledger integrity for other users.
- Backups may retain traces for a limited period before full rotation.
- Security logs may be kept for shorter or longer periods depending on security needs.
9) Account deletion
You can delete your account from inside the app: Settings → Delete account, then confirm with your password
(DELETE /api/v1/auth/account).
You may also email
abdoshokrey4@gmail.com
for verification and help.
- After confirmation the account becomes inactive: sign-in is blocked, and your phone number is not shown to people who search for or try to add you.
- Your data (transactions, memberships, etc.) is kept and not permanently erased; registering again with the same phone number restores the same account.
- Historical traces in shared ledgers may remain visible to other members to preserve the group’s financial record.
- If you are the sole owner of a group, transfer ownership or delete the group before completing in-app deletion.
10) Security
We apply appropriate technical and organizational measures, including for example:
- Transport encryption (TLS) for standard communications with the server.
- Password hashing and access controls based on API tokens.
- Logical isolation of user data through authorization controls in the API.
- File upload restrictions by type and size.
No protection on the internet is absolute; we encourage you to protect your device and not share login credentials or verification codes.
11) Your rights
Depending on the law that applies to you, you may have rights including:
- Access to your personal data or obtaining a copy of it.
- Correction of inaccurate data.
- Requesting account deletion / deactivation from inside the app (see Account deletion) or via support.
- Restricting or objecting to processing where the law allows.
- Withdrawing consent where processing is based on consent (such as some optional notifications).
To exercise a right, email us at abdoshokrey4@gmail.com from the email/number linked to the account when possible so we can verify identity.
12) Children
The service is intended for people who have reached the legal age to contract in their country (usually not under 18). We do not knowingly collect data from children under that age. If you learn of a child’s account, contact us to delete it.
13) Policy updates
We may update this policy to reflect product changes or legal requirements. We publish the updated version on this page with the effective date. Continued use after an update constitutes acceptance of material changes to the extent permitted by law; for material changes we may also notify you in-app or by another appropriate notice.
14) Contact
For privacy inquiries: abdoshokrey4@gmail.com — ExMoney.