Legal
Finance 509 is a notebook for your money. Everything in it is a figure you typed: the app has no link to a bank, a card or a payment provider, so we never see a statement, a card number or a real transaction. What we do hold is the bookkeeping you enter — and that is personal, so this page says exactly where it goes.
Last updated 2 October 2026 · Finance 509 for Android and iOS (com.cikup.finance509)
Finance 509 is published by Shamu ("we"). For any privacy question, or to exercise any right on this page, write to mujiburr741@gmail.com and we will answer within 30 days.
We ask for no other permissions. Finance 509 requests no access to your location, contacts, photos, SMS, call log or health data.
Finance 509 is local-first. Your records are written to a database on the phone itself, which is why the app works in airplane mode, and a copy is then pushed to the cloud if you are signed in. Your preferences stay on the device only; your sign-in session is kept by the Firebase SDK in the platform's own storage. Uninstalling the app removes everything local — but not the cloud copy, which needs the deletion in section 8.
Firebase Authentication holds your email address and password credential. Cloud Firestore holds the cloud copy of your records, under a path reserved for your account. Google Analytics for Firebase receives the usage events in section 2. Google may process this data on servers outside your country.
That is the whole list. There are no ad networks, no data brokers, no analytics resellers, and no exchange-rate or bank-data provider — the app fetches no rates, because you enter them yourself.
Your records are not end-to-end encrypted. They travel over HTTPS and Google encrypts them at rest, but they are stored as readable fields, which means that in principle we — as the owners of the Firebase project — could open them, and so could Google as the operator. We do not read them, and we have no interest in doing so; we are telling you because a finance app that let you assume otherwise would be lying by omission.
Finance 509 needs an account to work — signing in is how your figures reach a second device and survive a reinstall — so while your account exists there is a cloud copy of your records. If you would rather we held nothing, deleting your account (section 8) removes that copy, and we would rather you did that than keep an account you are uneasy about.
If you want to be certain nothing of yours is left behind after a deletion, email us and we will check the database by hand and confirm.
Where the GDPR applies, we rely on contract for your account and your records — without them there is no app — and on legitimate interest for the basic usage and diagnostic data, to keep the app working on the devices people actually use. You can object to the latter by writing to us.
If you are in the EEA or UK you may also complain to your local data protection authority.
Finance 509 is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.
All traffic to Firebase uses HTTPS. Your cloud records sit under a path tied to your account id, and Firestore security rules are what stop one account from reading or changing another's. Passwords are handled by Firebase Authentication and never reach our own storage. Deleting an account requires re-entering your password, so a borrowed unlocked phone cannot wipe your data.
If we change this policy we will update the date at the top of this page, and for a significant change we will say so in the app.