Privacy Policy
Last updated: August 25, 2026
This policy explains what personal data Pinyola (the "Application") collects, how it is used, where it is retained, when it is deleted, and what rights you have over it.
1. Data Controller
Pinyola is an independently developed and managed application. For any privacy-related inquiry or to exercise your rights, you can write to: leguaipinyol@gmail.com.
2. Data We Collect
Pinyola only collects the data necessary for its operation:
- Account and identity data: email address and a unique user identifier (UID) when you create an account. Stored in Firebase Authentication. You can sign in with an email and password, with your Google account, with your Apple account, or as a guest/anonymous user (in which case no email is stored).
- Application data: wallet names, expenses, participants (including their names), categories, budgets, settlements, comments associated with expenses, and activity history. Stored in Firebase Firestore and shared only with the participants of the wallet they belong to.
- Photos and documents: cover photos for your trips, ticket images and documents digitized through OCR, and the structured data extracted from the ticket (merchant, amounts, line items). These may be stored in Firebase Storage and, temporarily, on your device. We may also generate a readable copy (for example, a PDF) of a ticket document.
- Location (optional): if you allow it, the Application may use your device's location to associate it with an expense when you choose to do so. The location is stored with that expense and is not used for tracking or advertising. You may decline this permission and still use the Application.
- Voice (optional): if you allow it, the Application may use the microphone to dictate expense details via speech recognition. The audio is not retained as a file on our servers.
- Google Drive (optional): if you connect Google Drive, the Application may store ticket documents you choose in your own Google Drive account. To do so, OAuth access tokens are stored locally on your device. These tokens are never included in data exports and are never uploaded to Pinyola's servers.
- Application preferences: theme (light/dark), language, currency, and notification preferences. Stored locally on your device.
Pinyola does not collect sensitive financial data, bank account numbers, credit card details, device contacts, or biometric data.
3. How We Use Your Data
- To authenticate you and manage your account (Firebase Authentication).
- To sync your wallets and expenses across your devices (Firebase Firestore).
- To share data with wallet participants you invite (they only see information for that wallet).
- To store cover photos, ticket images and documents, and to generate the structured OCR data.
- To optionally associate a location with an expense if you grant the permission.
- To remind you to log expenses if you enable notifications.
- To store in your Google Drive, if connected, the documents you choose.
- To measure Application usage through analytics (see section 6).
Pinyola does not use your data for advertising, profiling for advertising purposes, sale to third parties, or any purpose other than the Application's own operation.
4. Legal Basis for Processing
The processing of your data is based on the performance of the Application usage agreement (Article 6.1.b of the GDPR) and, where applicable, your explicit consent (Article 6.1.a of the GDPR) for optional features such as voice recognition, location, connecting Google Drive, or analytics. Processing for account security is based on legitimate interest (Article 6.1.f of the GDPR).
5. Third-Party Service Providers
Pinyola uses the following third-party services, which act as processors:
- Firebase / Google LLC: Firebase Authentication (identity), Firestore (database), Firebase Storage (files and images) and Firebase Hosting. Google processes data on Pinyola's instructions. More information at Firebase Privacy & Security.
- Google Analytics / Firebase Analytics: measures Application usage through aggregated events and a user identifier (UID). See section 6.
- Google Drive: if you connect your account, ticket documents you choose are stored in your own Google Drive.
- Apple: if you sign in with Apple, Apple manages authentication and shares with you an identifier and, if you consent, your email.
We do not share your personal data with any other third party.
6. Analytics
The Application uses Firebase Analytics / Google Analytics to understand how it is used and to improve it. Usage events are recorded (for example, creating a wallet or logging an expense) together with a user identifier (UID). The events do not include your name, your email address, or your expense amounts.
When you delete your account, the Application deletes your account and the data that belongs to you, but analytics data already collected by Google Analytics is not automatically deleted and is retained according to Google's retention policy. If you wish to request the deletion of this analytics data, please contact us at the address at the end of this policy.
7. International Data Transfers
Data is stored on Google Cloud servers, which may be located outside the European Union. Google ensures an adequate level of protection through the Standard Contractual Clauses (SCC) approved by the European Commission and compliance with the EU-US Data Privacy Framework.
8. Data Retention and Deletion
- We retain your account data while your account is active.
- You can delete your account and the data that belongs to you at any time from Settings > Account > Delete account. This action is irreversible.
- When you delete your account: the Firebase Authentication account is deleted; the wallets you own are deleted; your local device data is deleted; ticket images in Firebase Storage that unambiguously belong to you are deleted; OAuth access tokens (for example, Google Drive) stored on the device are deleted; and your user document in Firestore is deleted.
- Shared wallets: when you participate in a wallet with other people, that wallet survives the deletion of your account. Your personal references within those wallets are anonymized (your name and identifier are replaced with an anonymous reference) and the economic data (amounts, dates, splits) is retained, because it also belongs to the other participants. Other participants' data is not deleted.
- Ticket images and documents associated with shared expenses may remain if they do not belong exclusively to you.
- Analytics data already collected is not automatically deleted (see section 6).
You can also request account deletion through the web page https://app.pinyola.app/delete-account.
9. Your Rights
Under the GDPR, you have the right to:
- Access your data, including by exporting it from the Application.
- Rectify your data by editing your profile and wallets.
- Erase your data by deleting your account.
- Object to processing where provided by law.
- Restrict processing where applicable.
- Port your data using the export feature available in the Application.
- Withdraw consent at any time for the optional features that require it.
To exercise these rights, write to leguaipinyol@gmail.com. You also have the right to lodge a complaint with the competent supervisory authority.
10. Security
We implement technical and organizational measures to protect your data:
- Encryption in transit (HTTPS/TLS) for all communications with Firebase.
- Encryption at rest by Google Cloud.
- Firestore security rules that restrict access based on user role.
11. Changes to This Policy
If we make material changes, we will notify you within the Application and update the "Last updated" date at the top of this document.
12. Contact
For any privacy-related question or to exercise your rights, you can contact us at: leguaipinyol@gmail.com
Pinyola - Version 1.1