Finance 509

Legal

Privacy policy

Finance 509 is a notebook for your money. Everything in it is a figure you typed: the app has no link to a bank, a card or a payment provider, so we never see a statement, a card number or a real transaction. What we do hold is the bookkeeping you enter — and that is personal, so this page says exactly where it goes.

Last updated 2 October 2026 · Finance 509 for Android and iOS (com.cikup.finance509)

1 Who we are

Finance 509 is published by Shamu ("we"). For any privacy question, or to exercise any right on this page, write to mujiburr741@gmail.com and we will answer within 30 days.

2 What we collect, and why

Email address and passwordat sign-up
To create your account and sign you back in, and to send a reset link if you forget your password. Authentication is handled by Google Firebase; your password is never stored by us in a readable form, and it is never written into your records.
Your nameoptional, editable in Profile
To greet you in the app. Leave it blank and nothing breaks.
The financial records you enteraccounts and balances, income and expenses with category, note and date, budgets, debts, investments, your category list, and any exchange rates you set
This is the app. It is what gets shown on your dashboard and kept in sync so your figures survive a reinstall or a second device. None of it is imported from a bank — every value is one you typed.
App preferencesdisplay currency, light or dark theme, whether balances are hidden
To open the app the way you left it. These stay on the device.
Basic usage and diagnosticsapp opens, screens, app version, device model and OS, and a random app-instance identifier
Collected automatically by the Google Analytics for Firebase SDK that ships inside the app, so we can see that the app launches and runs on real devices. We add no events of our own, and none of your amounts, notes, account names or category names are sent to analytics.

We ask for no other permissions. Finance 509 requests no access to your location, contacts, photos, SMS, call log or health data.

3 What stays on your device

Finance 509 is local-first. Your records are written to a database on the phone itself, which is why the app works in airplane mode, and a copy is then pushed to the cloud if you are signed in. Your preferences stay on the device only; your sign-in session is kept by the Firebase SDK in the platform's own storage. Uninstalling the app removes everything local — but not the cloud copy, which needs the deletion in section 8.

4 Who else processes your data

That is the whole list. There are no ad networks, no data brokers, no analytics resellers, and no exchange-rate or bank-data provider — the app fetches no rates, because you enter them yourself.

5 What we can and cannot see

Your records are not end-to-end encrypted. They travel over HTTPS and Google encrypts them at rest, but they are stored as readable fields, which means that in principle we — as the owners of the Firebase project — could open them, and so could Google as the operator. We do not read them, and we have no interest in doing so; we are telling you because a finance app that let you assume otherwise would be lying by omission.

Finance 509 needs an account to work — signing in is how your figures reach a second device and survive a reinstall — so while your account exists there is a cloud copy of your records. If you would rather we held nothing, deleting your account (section 8) removes that copy, and we would rather you did that than keep an account you are uneasy about.

6 How long we keep it

If you want to be certain nothing of yours is left behind after a deletion, email us and we will check the database by hand and confirm.

7 Legal basis

Where the GDPR applies, we rely on contract for your account and your records — without them there is no app — and on legitimate interest for the basic usage and diagnostic data, to keep the app working on the devices people actually use. You can object to the latter by writing to us.

8 Your choices and rights

If you are in the EEA or UK you may also complain to your local data protection authority.

9 Children

Finance 509 is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.

10 Security

All traffic to Firebase uses HTTPS. Your cloud records sit under a path tied to your account id, and Firestore security rules are what stop one account from reading or changing another's. Passwords are handled by Firebase Authentication and never reach our own storage. Deleting an account requires re-entering your password, so a borrowed unlocked phone cannot wipe your data.

11 Changes

If we change this policy we will update the date at the top of this page, and for a significant change we will say so in the app.

Want your data gone? The fastest route is Profile → Delete account in the app. If you have lost access to it, email mujiburr741@gmail.com from the address you signed up with.