Privacy Policy
Effective date and last updated: August 31, 2026
1. Scope & Overview
This Privacy Policy applies to the Canolia Expense application (the “App”), provided by Kyaw Myo Thant (the “Service Provider”), available across Google Play, direct Android distributions, Desktop (macOS, Windows, Linux), and iOS. The App is provided as-is. This policy explains what information the App processes, how it is stored, why it is processed, and your rights and choices under platform policies including Google Play’s User Data Policy and Data Safety requirements.
2. Financial Data & Local Storage
Local Device Storage: All core financial records you create—including expenses, incomes, budgets, loan records (receivables and payables), books, wallets/accounts, currency allocations, categories, and financial notes—are stored locally on your device within app-private storage.
Your financial data remains strictly on your device unless you explicitly opt in to cloud synchronization or choose to export your reports. Android cloud backup and device-transfer backups are disabled for app data to safeguard your financial privacy.
Note: The loan tracking feature is purely a personal bookkeeping and debt-tracking tool. The App does not offer, issue, broker, or advertise financial loans or banking products.
3. Multiple Currencies, Themes, and App Settings
The App provides multi-currency conversion, customizable UI theme modes (Cyberpunk, Midnight, Neo, Minimal, Classic), custom accent colors, font configurations, and language options.
All theme choices, currency preferences, and exchange-rate caches are stored locally on your device. No personal data, user identity, or device tracking identifiers are collected in connection with these personalization features.
4. Google Play Subscriptions, Billing, & Offline Licenses
- Payment Processing: All subscription purchases and billing transactions are processed directly and securely by Google Play (via Google Play Billing). Canolia Expense never receives, processes, or stores your credit/debit card numbers, PayPal details, or bank account credentials.
- Subscription Status: To unlock Premium features, the App processes the Google Play purchase token, product identifier, purchase state, entitlement status, and any expiry or renewal status made available through Google Play Billing. A purchase token is an account-linked technical identifier.
- Offline License: Active subscription entitlement is cached locally in secure device storage so that Premium features remain functional when temporarily offline. Google Play will automatically re-verify the active license when an internet connection is restored.
5. Optional Cloud Synchronization & Google Sign-In
Google Sign-In and Cloud Firestore synchronization are completely optional. If you choose to enable cloud synchronization:
- Firebase Authentication processes your basic Google profile identifiers (name, email address, and user ID) to securely verify your account.
- Supported financial records, categories, books, and settings are securely stored in your private Cloud Firestore account to provide multi-device sync, backup, and restore capabilities.
- Your synchronized data is protected by Firebase Security Rules and is accessible only under your authenticated account.
Premium Packages & Cloud Access Update
This update describes the Premium packages and cloud access offered by the Play and Direct editions.
- Direct Premium packages: Google sign-in is required to request, receive, restore, and protect a Direct Premium package. For this purpose, we process the Firebase user ID, email address, display name, requested package/plan, request status, Premium entitlement, and expiry/access status. Any payment arrangement for a Direct package is handled outside the App; the App does not collect or store card, bank, PayPal, or other payment-account credentials.
- Premium cloud upgrade: A signed-in Premium account can synchronize every eligible ledger/book. When the account becomes Premium, the App may make a one-time upload of eligible local financial records, accounts, categories, books, and supported settings to the account's private Cloud Firestore area so multi-device sync, backup, and restore can begin.
- Restricted admin access: To review an upgrade request or provide support, the Service Provider's restricted admin tool may process only Firebase user ID, email, display name, account role, recent sign-in information, selected package/plan, request status, and Premium expiry/access status. This tool is not intended to display private financial records.
- No sale of personal data: Selling a Premium package is a sale of app access, not a sale of personal or financial data. We do not sell personal, financial, authentication, or purchase/package-related data, and we do not use it for third-party advertising.
6. Data Export & Sharing
When you generate financial reports in CSV, Microsoft Excel (.xlsx), or PDF formats, the files are compiled 100% locally on your device. Exported files are shared only when you explicitly tap the export or share action and select an external application or destination (such as saving to device files, email, or a messaging app). The receiving app processes the data under its own privacy policy.
7. Third-Party Services
The App integrates with reputable third-party services to support core functionality:
8. Data Retention & Deletion
- Local Data Deletion: You can delete any individual transaction, category, or book at any time within the app. You can also erase all local data by using the Reset Data option in Settings, clearing the app’s data in your device system settings, or uninstalling the app.
- Cloud Account & Data Deletion: If you have an active cloud synchronization account, you can permanently delete your account and all associated cloud data directly inside the App by navigating to Settings > Delete Account, or by submitting a deletion request through our dedicated online portal:
9. Security & Protection
We employ multi-layer security measures to protect your financial records, including Android app-private sandboxed storage, biometric and PIN app lock security, Firebase security rules, App Check verification, and encrypted network communications via TLS/HTTPS.
10. Children’s Privacy
The App is not directed to children under 13 years of age, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately so we can remove it.
11. Your Choices and Rights
You have full control over your data. You may use all core expense tracking features offline without creating an account, toggle cloud sync on or off, edit or delete records at will, export your data at any time, and request complete account deletion.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect app updates, new platform features, or regulatory requirements. Any changes will be posted on this page with an updated effective date.
13. Contact Us
If you have any questions, feedback, or privacy-related requests regarding Canolia Expense, please contact the Service Provider: