EduWallet

Privacy Policy for EduWallet

Last Updated: 2026-09-06

EduWallet ("the App", "we", "us", or "our") is a student budget and expense
tracker developed by Ikramul Hossain Mondal (LazyByte Labs). This Privacy Policy
explains what information the App collects, how it is used and stored, who it is
shared with, and the choices you have.

By downloading or using EduWallet, you agree to the practices described in this
policy. If you do not agree, please do not use the App.


1. Summary

  • EduWallet is designed to work primarily as a personal finance tool on your
    own device
    . You can use core features without a Google or Apple account.
  • If you sign in, your financial data is synced to your private cloud account
    so you can use it across devices.
  • You can also use the App as a Guest. A guest session is a temporary
    anonymous account; the data synced under it is automatically deleted after
    30 days of inactivity
    , and immediately if you exit Guest mode (see Section 6).
  • We do not sell your data.
  • We use Google Analytics for Firebase to understand how the App is used in
    aggregate. The App does not currently show advertisements, but we intend to
    add advertising in a future version; this policy already describes how that
    will work so you can make an informed choice (see Section 2.7 and Section 3).
  • The data you enter (expenses, loans, notes, budgets) is stored either on your
    device, in your private cloud database, or both.

2. Information We Collect

2.1 Account information (only if you sign in)

EduWallet offers optional sign-in through Google Sign-In and Sign in with
Apple
, handled by Firebase Authentication. When you sign in we receive and
store:

  • Your name (or the name you choose to share)
  • Your email address
  • Your profile photo URL, where provided by the sign-in provider
  • A unique user identifier generated by Firebase Authentication

Sign in with Apple allows you to hide your email address; if you choose this,
we only receive Apple's private relay address.

2.2 Guest mode (anonymous sessions)

Instead of signing in, you can choose "Continue as Guest". This creates an
anonymous account identified only by a randomly generated user identifier from
Firebase Authentication. We do not receive your name, email address, or
profile photo for a guest session.

A guest session is temporary. The anonymous identifier cannot be recovered
after you sign out, exit Guest mode, or remove the App, and inactive guest
accounts — together with any expenses, loans, and settings synced under them —
are automatically deleted after 30 days (see Section 6). To keep this data,
link a Google or Apple account before exiting Guest mode.

2.3 Financial and usage data you provide

The core purpose of the App is to record information you enter yourself. This
may include:

  • Expenses and income: amount, date, category (including custom categories),
    payment mode, notes, whether an item is a personal or college expense,
    semester, recurring status, due dates, paid/unpaid status, and income source.
  • Loans and repayments: loan name, lender name, loan type, principal and
    sanctioned amounts, down payment, processing fees and other charges, interest
    rate and method, tenure, start and repayment dates, moratorium details,
    disbursement records, the payment ledger (dates, amounts, installment numbers,
    notes), loan status, and free-text notes.
  • Personalisation settings: custom income sources, custom payment modes, and
    custom expense categories.
  • Receipt images: if you attach a receipt to an expense, the image is
    selected from your device camera or photo library. For free (non-premium)
    users
    , only the local file path is stored on your device and the image is
    never uploaded. For EduWallet Pro (premium) subscribers, the receipt
    image is uploaded to and stored in Google Firebase Cloud Storage, linked
    to your account, so it is available across your devices as part of cloud
    sync. Uploaded receipt images are stored under a path keyed to your user
    account and are accessible only to you.

Notes and lender names are free-text fields. Please avoid entering sensitive
personal information you do not want stored.

2.4 Data stored locally on your device

To allow offline use and use without a Google or Apple account, EduWallet
stores expense and loan records on your device using local app storage
(shared_preferences). This data stays on the device unless it is synced to a
signed-in or guest account.

2.5 Subscription information

EduWallet offers an optional paid subscription ("EduWallet Pro"). Purchases and
subscription status are processed by RevenueCat together with the Apple
App Store
or Google Play. We receive a subscription status and an
anonymous purchase identifier from RevenueCat. We do not receive or store
your full payment card details; those are handled by Apple or Google.

2.6 Information collected automatically

  • Analytics: the App uses Google Analytics for Firebase, which collects
    aggregated and pseudonymous usage information such as app opens, screens
    viewed, feature interactions, session length, a randomly generated app
    instance identifier, approximate location derived from IP address (the IP
    address itself is not retained by Google Analytics), device model, operating
    system version, language, and country. This is used to understand how the App
    is used and to improve it. It is not used to identify you personally, and we
    do not link it to the financial data you enter.
  • Google-hosted fonts: the App loads fonts through the google_fonts
    package, which may request font files from Google's servers. Such requests
    expose your device's IP address to Google as part of normal internet
    communication.
  • Cloud service logs: Google Firebase, as our backend provider, may log
    technical information such as IP address, device type, operating system
    version, and timestamps when your device communicates with its servers, for
    security and reliability purposes.

2.7 Advertising (planned, not yet active)

The current version of EduWallet does not contain advertising SDKs and does
not display ads. We plan to introduce advertising, likely through Google
AdMob
, in a future release. When that happens:

  • Ad providers may collect a mobile advertising identifier, IP address, device
    and usage information, and coarse location in order to serve and measure ads.
  • Where required by law, the App will ask for your consent before any
    personalised advertising identifiers are used, and will offer a non-personalised
    ads option.
  • This Privacy Policy will be updated, and the "Last updated" date changed,
    before ads are enabled. Continued use after that update will be subject to the
    revised policy.

3. How We Use Information

We use the information described above to:

  • Provide the App's core features: recording, categorising, and reporting on
    your expenses, income, and loans.
  • Authenticate you and keep your account secure.
  • Sync your data across your devices when you are signed in.
  • Provide and manage the optional EduWallet Pro subscription.
  • Maintain, troubleshoot, and improve the App's reliability and security.
  • Understand aggregate usage patterns through Google Analytics for Firebase so we
    can prioritise improvements.
  • In a future version, serve and measure advertising (see Section 2.7).
  • Comply with legal obligations.

We do not use the financial data you enter for advertising or profiling, we do
not sell or rent your personal information, and we do not combine your analytics
data with your financial records.


4. Legal Bases for Processing (EEA/UK users)

Where the GDPR or UK GDPR applies, we process your data on the following bases:

  • Performance of a contract: to provide the App and its features you request.
  • Consent: for optional sign-in and cloud sync, for analytics where consent
    is required in your jurisdiction, and for any future personalised advertising.
    You may withdraw consent at any time.
  • Legitimate interests: to keep the App and its infrastructure secure and
    functioning, and to understand aggregate usage where analytics does not
    require consent.
  • Legal obligation: where we must retain or disclose information to comply
    with the law.

5. How Information Is Stored and Shared

5.1 Storage

  • On your device: local expense and loan records and, for free users, any
    receipt image file references.
  • In the cloud (if you sign in, or while using Guest mode): your expenses,
    loans, and personalisation settings are stored in Google Cloud Firestore
    in a database record keyed to your account (users/{your user id}, or
    users/{anonymous id} for a guest session). Access is restricted to that
    authenticated account. Guest records are deleted as described in Section 6.
  • Receipt images (EduWallet Pro subscribers only): uploaded to Google
    Firebase Cloud Storage
    under a path keyed to your user account
    (receipts/{your user id}/...). Access is restricted to your authenticated
    account. If you cancel your subscription or delete your account, please
    delete your receipt images within the App first; contact us if you need
    assistance removing any residual files.

5.2 Service providers

We share information only with providers that help us run the App:

| Provider | Purpose | Privacy policy |
|----------|---------|----------------|
| Google Firebase (Authentication, Cloud Firestore) | Sign-in and cloud data storage/sync | https://firebase.google.com/support/privacy |
| Google Analytics for Firebase | Aggregated, pseudonymous usage analytics | https://firebase.google.com/policies/analytics |
| Google Sign-In | Optional authentication | https://policies.google.com/privacy |
| Apple (Sign in with Apple) | Optional authentication | https://www.apple.com/legal/privacy/ |
| RevenueCat | Subscription management | https://www.revenuecat.com/privacy |
| Apple App Store / Google Play | Payment processing for subscriptions | https://www.apple.com/legal/privacy/ · https://policies.google.com/privacy |
| Google Fonts (google_fonts) | Font delivery | https://policies.google.com/privacy |
| Google AdMob (planned, not yet active) | Advertising in a future version | https://support.google.com/admob/answer/6128543 |

We do not share your personal information with third parties for their own
marketing purposes.

5.3 Legal disclosures

We may disclose information if required to do so by law, or if we believe in
good faith that disclosure is necessary to comply with legal process, protect
our rights, or protect the safety of users or the public.

5.4 International transfers

Our service providers, including Google and RevenueCat, may process and store
data on servers located outside your country, including in the United States.
These providers rely on recognised transfer mechanisms such as Standard
Contractual Clauses.


6. Data Retention

  • Local data remains on your device until you delete the relevant records,
    clear the App's data, or uninstall the App.
  • Cloud data is retained for as long as your account exists. When you delete
    your account (see Section 7), your authentication record is removed. You
    should also delete your financial records within the App before deleting your
    account; contact us if you need help removing residual data.
  • Guest (anonymous) accounts and the data synced under them are
    automatically deleted after 30 days of inactivity. They are also deleted
    immediately if you choose "Exit guest mode" in Settings. Because a guest
    identifier cannot be recovered, this data cannot be restored once removed —
    link a Google or Apple account beforehand to keep it.
  • Subscription records held by RevenueCat and the app stores are retained
    according to their own policies and applicable financial-record requirements.
  • Analytics data is retained by Google Analytics for Firebase according to
    the retention period configured for the project (by default, between 2 and 14
    months for event-level data), after which it is aggregated or deleted.

7. Your Rights and Choices

  • Use without signing in: you can use the App as a Guest without a Google
    or Apple account. Guest data is stored on your device and synced to a
    temporary anonymous account that is deleted after 30 days of inactivity (see
    Section 6). Analytics may still be collected as described in Section 2.6.
  • Limit analytics: you can reduce or reset the identifiers used for
    analytics through your device's operating-system privacy controls (for
    example, "Allow Apps to Request to Track" on iOS, or resetting/deleting your
    advertising ID on Android). If we add an in-app analytics toggle, it will
    appear in Settings.
  • Access and portability: your data is visible in the App at all times; the
    App also provides a share/export function for reports.
  • Correction and deletion: you can edit or delete individual expenses,
    loans, and settings directly in the App.
  • Account deletion: you can delete your account from within the App
    (Settings → delete account). This removes your Firebase Authentication record.
  • Guest data: choosing "Exit guest mode" in Settings permanently deletes
    the guest session and its data. If you do nothing, the guest account and its
    data are deleted automatically after 30 days of inactivity.
  • Withdraw consent: sign out at any time to stop cloud sync.
  • Sign in with Apple: you can manage or revoke the App's access in your
    Apple ID settings.

Depending on your location, you may also have the right to object to or restrict
processing, or to lodge a complaint with your local data protection authority.
To exercise any right, contact us using the details in Section 10.


8. Security

We use commercially reasonable measures to protect your information, including
transport encryption (HTTPS/TLS) for data in transit and access controls on
cloud data restricting each record to its authenticated owner. However, no
method of transmission over the internet or method of electronic storage is
completely secure, and we cannot guarantee absolute security.


9. Children's Privacy

EduWallet is intended for students and general users and is not directed to
children under 13 (or the minimum age of digital consent in your country). We do
not knowingly collect personal information from children under this age. If you
believe a child has provided us with personal information, contact us and we
will delete it.


Contact Us

If you have any questions about this Privacy Policy, please contact the developer directly:

Ikramul Hossain Mondal

support@lazybyte.in
Built by One, Used by Many.

© 2026 LazyByte Labs. All rights reserved.