Σ

Privacy Policy

CroSum — Personal finance, simply.
Last updated: 26 July 2026
Plain-language summary CroSum is built around the principle that your financial data stays on your device. We never receive it. There are no analytics, no tracking pixels and no advertising partners on any platform.

On iPhone and iPad, CroSum collects nothing at all. There is no account and no sign-in: subscriptions run through the App Store, and optional sync uses your own private iCloud, which we cannot read. That is why CroSum for iPhone collects no data at all.

On Android, you can also use CroSum without an account. You only need one if you subscribe to Premium or turn on Google Drive sync — and then we collect the bare minimum needed to sign you in and bill you, described below.

1. Who we are

CroSum (the "app", "we", "us") is operated by Cronicium, a sole proprietorship registered with the Dutch Chamber of Commerce (Kamer van Koophandel).

We act as the data controller for the personal data described below.

2. What data we collect

iPhone and iPad (CroSum for iOS): nothing The iOS version of CroSum is account-free. There is no sign-in, no password, and no CroSum account — so none of the account data in section 2.1 exists on iOS, and the third-party services listed in section 5 (Supabase, Resend) are not involved at all. Subscriptions are handled entirely by Apple, and optional sync writes to your own private iCloud, which we have no access to. Sections 2.1 and 2.4 below describe Android only.

2.1 Account data (Android only — not iOS)

Using CroSum does not require an account — you can start right away as a guest, with your data kept only on your device. On Android you can choose to sign in (with Google or with an email address and password) to subscribe to Premium or to back up and sync to your own Google Drive. If you sign in, depending on the method, we collect:

  • Email address — required to identify your account and send transactional emails (sign-up confirmation, password reset).
  • Display name — only if you sign in with Google, and only as the provider returns it. You can edit or remove it later.
  • Provider user ID — an opaque identifier from your sign-in provider (e.g. the Google "sub" claim). Used to match you to your account on subsequent sign-ins.
  • Encrypted password hash — only if you sign up with email + password. We never see the plaintext password; it's hashed by Supabase Auth.

On iOS none of the above applies. There is no way to create or sign in to a CroSum account from the iPhone or iPad app, so we hold no email address, no name and no identifier for you.

2.2 Financial data — stored on your device

The transactions, budgets, savings goals, and loans you enter are stored locally on your device in the app's private storage. We do not transmit or store this data on our servers.

Android's automatic system backup is disabled in our app manifest, so this data is not copied to your Google Drive by the operating system. If you want to move the data to another device manually, the in-app Backup & Restore feature produces a file you control and transfer yourself.

2.3 Cloud Sync — your own cloud storage (optional)

CroSum offers an optional Cloud Sync feature. It is off by default and only runs if you turn it on. When enabled, CroSum backs up your data to your own cloud storage so you can restore it on a new device or after reinstalling — your own Google Drive on Android, and your own private iCloud (Apple CloudKit) on iPhone and iPad.

In both cases the data goes from your device to storage that belongs to you, under your own Google or Apple account. It does not pass through our servers and we cannot read it. On iOS this uses your app's private CloudKit database; you can remove it at any time from the app, or through iOS Settings › your name › iCloud › Manage Storage.

The Google-Drive specifics below apply to Android and the web app:

  • Your data is written to a single file in Google Drive's hidden, per-app application data folder (the drive.appdata scope). This folder is created and managed by CroSum and does not appear in your normal Drive view.
  • We request only the drive.appdata scope — the narrowest access possible. CroSum cannot see, read, or modify any of your other Google Drive files.
  • Your data travels directly between your device and your own Google Drive. It never passes through, and is never stored on, CroSum's or any third party's servers.
  • You can delete the cloud backup at any time from within the app ("Delete Drive backup"), or remove CroSum's access from your Google account's "Manage apps" settings. Turning Cloud Sync off stops syncing and leaves your existing backup in your Drive until you delete it.

Google API Services User Data Policy / Limited Use. CroSum's access to and use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Drive access solely to provide the backup-and-restore feature you choose to enable; we do not use this data for advertising, we do not sell or transfer it, and no humans read it.

2.4 Subscription data (only if you subscribe)

Android. When you purchase a subscription through the Google Play Store, we receive an opaque receipt token from Google Play. We use this to determine whether your account has paid features unlocked. We do not see your payment-card details — those are handled by Google Play, which acts as the seller of record.

iPhone and iPad. Subscriptions are purchased and managed entirely through Apple's App Store, which is the seller of record. Your subscription status is verified on your device against the App Store; it is not sent to us and is not tied to any CroSum account, because there is none. We receive no receipt, no identifier and no payment details.

2.5 Diagnostic data

We currently do not collect crash reports, analytics, telemetry, or any usage statistics from the app.

3. Why we collect it

We use the data above only to:

  • Sign you in and keep you signed in
  • Send transactional emails (account confirmation, password reset, subscription receipts)
  • Validate your subscription so paid features are unlocked on your account
  • Honour your right to delete your account and the data we hold about it

We do not use your data for advertising, profiling, or algorithmic decision-making. We do not sell your data.

Under GDPR Article 6, our legal bases are:

  • Contract performance (Art. 6(1)(b)): processing your email + auth credentials, and your subscription receipt, is necessary to provide the service you signed up for.
  • Legitimate interest (Art. 6(1)(f)): security logs (sign-in attempts, suspicious activity) are processed to keep accounts safe. We balance this against your privacy interests by retaining only what's needed.
  • Consent (Art. 6(1)(a)): optional features that involve additional processing — such as Cloud Sync to your own Google Drive — are off by default and run only when you explicitly turn them on. You can withdraw consent at any time by turning the feature off.

5. Who we share it with

We share the limited data above with the following sub-processors, each of which is bound by a Data Processing Agreement (DPA) and may only process the data on our instructions:

Not applicable on iPhone or iPad Because the iOS app has no account and no sign-in, we hold no data about you to share. None of the sub-processors in this table receive anything from CroSum for iOS users. They apply to Android users who have chosen to create an account.
Sub-processorRoleData sharedRegion
Supabase Authentication and database Email, display name, password hash, provider user ID, subscription state EU (Frankfurt) — verified per project
Resend Transactional email delivery Email address + email content (confirmation links, reset links) EU / global; data passes through US infra in transit
Google (OAuth) Optional sign-in provider OAuth handshake; we receive your IdP user ID + email Global
Google Play Billing Subscription processing (seller of record) Subscription purchase receipts Global
Netlify Marketing site + password-reset page hosting Standard web access logs (IP address, user agent) — not associated with your CroSum account Global CDN

Apple. CroSum for iPhone and iPad does not use Apple Sign-In, because the iOS app has no accounts at all. Apple acts as the seller of record for iOS subscriptions (App Store / StoreKit) and, if you switch Cloud Sync on, your data is stored in your own private iCloud. In both roles Apple is your counterparty, not our sub-processor: we receive nothing from them about you.

6. Where it's stored

Your account data lives in our Supabase project, hosted in the EU (Frankfurt) data centre. Where a sub-processor routes data outside the EU (e.g. Resend's or Google's global infrastructure), the transfer is protected by Standard Contractual Clauses approved by the European Commission.

Your financial data (transactions, budgets, etc.) lives on your device only and is never transferred to us. If you turn on Cloud Sync, a copy is stored in your own Google Drive on Android, or your own private iCloud on iPhone and iPad (see section 2.3); if you use the manual Backup feature, you transfer the exported file yourself. In both cases the data goes to storage you control — not to us.

7. How long we keep it

  • Account data: kept for as long as your account exists. When you delete your account, we remove all associated rows from our database within 30 days. Backup snapshots (taken nightly by Supabase) are rotated out within 7 days, after which the data is irrecoverable.
  • Transactional emails: Resend retains email logs (sender, recipient, timestamp, status) for up to 30 days. Email body content is not retained beyond delivery.
  • Subscription records: retained as long as legally required for accounting purposes (7 years under Dutch tax law), even after account deletion. Stored as anonymous receipt tokens not linked to a personal identifier after account deletion.
  • Financial data on your device: retained until you uninstall the app or use the in-app delete features.

8. Your rights under GDPR

You have the right to:

  • Access a copy of the personal data we hold about you
  • Rectification — correct inaccurate data
  • Erasure — delete your account and the data we hold about it (use the in-app "Delete Account" button in Settings > Account, the account deletion page, or email privacy@crosum.app)
  • Portability — receive a machine-readable export of your data (use the in-app "Backup" feature)
  • Objection — object to processing based on legitimate interest
  • Restriction — ask us to limit how we process your data
  • Lodge a complaint with the Dutch supervisory authority, Autoriteit Persoonsgegevens

We respond to rights requests within one month, free of charge.

9. Children

CroSum is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has signed up, contact us at privacy@crosum.app and we will delete the account.

10. Cookies and tracking

The marketing site (crosum.app) does not use cookies, analytics, or tracking pixels. We don't run Google Analytics, Meta Pixel, or any equivalent. Standard server access logs (IP, user agent, timestamp) are kept by Netlify per their own privacy policy and are not linked to your CroSum account.

The mobile app uses the WebView's local storage (localStorage) on your device to keep your settings and your financial data. This is not a "cookie" in the ePrivacy sense — it's first-party app storage, comparable to a document a desktop application would save to disk.

11. Changes to this policy

If we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Email everyone with an active CroSum account, at least 30 days before the change takes effect
  • Show an in-app banner on the next session after the change

Previous versions are kept available on request.

12. Contact

Questions about this policy? Want to exercise one of your rights? Email privacy@crosum.app and we'll respond within 30 days.