Privacy Policy
Last updated: 23 August 2026
This policy covers the data processed by our expense tracking app and the servers it connects to. We do not track users, do not sell or share data, and do not use data for marketing. We do not ask for your name, email address, or any other information that identifies you personally.
1. Controller
SemaDev z o.o.ul. Trylogii 34
01-982 Warszawa
Poland
support@sema-dev.com
2. Data we process
Device identifier
A random identifier is created when the app is first installed. It is used to authenticate the device and associate it with its data. It is not linked to your name, contact details, app store account, or any advertising identifier.
Expense entries and configuration
If backup and sync is used, entries are stored on our servers: amount, currency, category, tag, date, note text, and creation time. Configuration is stored alongside them: categories, tags, currencies, and app settings. This data is associated with the device identifier and nothing else.
Usage and diagnostic events
The app reports technical events: app launches, screens opened, subscription options selected, purchase results, which variant of a screen was shown, and the app language. These are used to operate the app, diagnose faults, and inform development.
Connection data
The IP address and timestamp of each request are processed and recorded in technical server logs, for delivery, security, and fault diagnosis.
Data we do not collect
- Name, email address, postal address, phone number.
- Contacts, calendar, photos, files.
- Precise location.
- Advertising identifiers, or identifiers shared with other apps or advertising networks.
- Bank account, card, or other payment credentials. Purchases are handled by the app store.
- Health, biometric, racial or ethnic, political, religious, sexual orientation, or other special-category data.
The note field on an entry is free text and is stored exactly as entered. Do not enter personal details you do not want stored.
3. Purposes and legal bases
- Operating the app and syncing data, including device authentication. Performance of a contract (Article 6(1)(b) GDPR).
- Service availability and security: debugging, fault diagnosis, abuse and fraud prevention, infrastructure protection. Legitimate interests (Article 6(1)(f) GDPR).
- Product development: measuring feature use and testing screen and pricing variants in aggregate. Legitimate interests (Article 6(1)(f) GDPR), or consent where required (Article 6(1)(a) GDPR).
- Legal obligations: accounting and tax duties relating to purchases, and lawful requests. Article 6(1)(c) GDPR.
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not build advertising or behavioural profiles.
4. What we do not do
- We do not sell data, or share it for cross-context behavioural advertising.
- We do not track users across other apps, websites, or devices.
- We do not use data for marketing, and do not send marketing messages.
- We do not embed third-party advertising or profiling SDKs.
- We do not combine your data with information obtained from data brokers.
5. Recipients
Data is disclosed only to service providers processing it on our instructions, under contract:
- Cloud hosting and database providers, which store and serve the data described above.
- Apple, Google, and our subscription management provider, which process purchases and subscription status. We do not receive payment details; their own privacy policies apply to the purchase.
Data may also be disclosed where legally required, or where necessary to establish, exercise, or defend legal claims.
6. Location and international transfers
Our infrastructure is operated within the European Economic Area. Where a provider processes data outside the EEA, transfers rely on a European Commission adequacy decision or on Standard Contractual Clauses, with appropriate technical safeguards.
7. Retention
- Synced entries and configuration: while the device continues to use the service, and until deletion is requested.
- Usage and diagnostic events: up to 24 months, then deleted or aggregated so they cannot be traced to a device.
- Server and security logs: up to 90 days.
- Records relating to a purchase: for the period required by accounting and tax law.
8. Security
Traffic between the app and our servers is encrypted in transit. Access to production systems is authenticated and limited to personnel who require it. No system is completely secure.
9. Rights in the EU and the UK
Under the GDPR and UK GDPR you have the right to:
- access the data held about your device and obtain a copy;
- have inaccurate data corrected;
- have data erased;
- restrict processing;
- receive the data you provided in a portable, machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing rests on consent, without affecting prior processing.
You may lodge a complaint with a supervisory authority. In Poland: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa.
10. Rights in the United States
Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have the right to know what personal information is collected and why, to obtain a copy, to have it corrected or deleted, and not to be discriminated against for exercising those rights. Requests may be submitted through an authorised agent.
We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA, and have not done so in the preceding twelve months. No "Do Not Sell or Share My Personal Information" mechanism is offered, as there is no such processing to opt out of. We do not collect sensitive personal information, and do not use or disclose personal information for purposes other than those stated in this policy.
11. Exercising your rights
Send requests to support@sema-dev.com. Because no name, email address, or account is held, a request can only be matched to data using the device identifier your app uses; contact us and we will confirm where to find it in your version of the app. Requests are answered within one month, free of charge. A request that cannot be verified as relating to your own device may be declined.
Uninstalling the app removes the data held on the device itself.
12. Children
The app is not directed at children under 16 and we do not knowingly collect their data. If a child has left data with us, contact us and it will be deleted.
13. Changes
Changes to this policy are reflected in the date at the top of this page. Material changes are announced in the app before taking effect. The current version is always published at this address.