Privacy Policy - Numora

Last Updated: November 15, 2025

Introduction

Welcome to Numora ("we," "our," or "us"). We respect your privacy and are committed to
protecting your personal data. This Privacy Policy explains how we collect, use,
disclose, and safeguard your information when you use our mobile application (the
"App").

Developer Information:

Please read this Privacy Policy carefully. If you do not agree with the terms of this
Privacy Policy, please do not access the App.

This Privacy Policy complies with the EU General Data Protection Regulation (GDPR) and
Romanian data protection laws.

Information We Collect

Personal Data

We may collect personal information that you voluntarily provide to us when you:

  • Create an account (via email, Google Sign-In, or Apple Sign-In)

  • Use features of our App

  • Enable cloud synchronization (free feature available to all users)

  • Share budgets or goals with family members

  • Contact us for support

  • Participate in surveys or promotions

  • Provide feedback or ratings

The personal information we may collect includes:

  • Account Information: Email address, name, user ID

  • Authentication Data: Login credentials, OAuth tokens (Google/Apple Sign-In)

  • Profile Information: Display name, profile photo (encrypted), country, income range

  • Financial Data:

    • Transaction details (amount, date, description, notes, location, payment method)

    • Budget information (name, amount, categories, period)

    • Savings goals (name, target amount, contributions)

    • Debt tracking information

    • Recurring transactions

    • Categories (custom and default)

  • Device Information: Device type, operating system, screen size, app version

  • Usage Data: Features you use, navigation patterns, session duration

  • Location Data: Optional location tagging for transactions (requires your explicit
    permission)

  • User Preferences: Currency, language, date format, theme, notification settings

  • Personalization Data: Personality type (Planner/Budget Master/Impulsive), spending
    patterns

Analytics and Usage Data

With your explicit consent, we collect analytics and usage data to improve our App,
including:

  • Device information (type, model, operating system, screen size)

  • IP address and network information

  • App features you use and how you interact with them

  • Session information (duration, frequency, time of day)

  • Feature usage metrics and navigation patterns

  • Time and date of your use

  • Performance data (load times, memory usage, app responsiveness)

  • Button taps, screen views, and navigation flows

Note: Analytics collection is entirely optional. You can enable or disable this at any
time in Privacy Settings. The app functions fully without analytics enabled.

Financial Behavior Data

With your consent, we may collect and analyze financial behavior data, including:

  • Spending patterns and categories

  • Saving behavior and progress toward goals

  • Budget adherence metrics

  • Transaction frequency and timing

  • Financial health indicators

User Feedback and Surveys

With your consent, we collect feedback data including:

  • Feature ratings and satisfaction scores

  • Survey responses

  • Bug reports and feature requests

  • General feedback and comments

Third-Party Services

We use the following third-party services to provide and improve our App:

  • Firebase Services (Google LLC):

    • Firebase Authentication (account management)

    • Cloud Firestore (database storage)

    • Cloud Storage (file storage for profile photos)

    • Firebase Analytics (usage analytics - with your consent)

    • Cloud Functions (server-side operations)

  • Apple Sign-In (Apple Inc.) - for iOS authentication

  • Google Sign-In (Google LLC) - for Android/iOS authentication

  • Apple App Store / Google Play Store - for payment processing and subscription
    management

  • Expo Push Notifications - for sending notifications

  • Notifee - for local notification management

Data Transfer: Some of these services may store data on servers located outside the
European Economic Area (EEA), including the United States. We ensure appropriate
safeguards are in place for such transfers in accordance with GDPR Article 46.

How We Use Your Information

We use the information we collect for various purposes, including to:

  • Core Functionality:

    • Provide, maintain, and improve our App

    • Store and sync your financial data (locally by default, optionally in cloud)

    • Process and display transactions, budgets, and goals

    • Calculate statistics, trends, and insights

    • Send notifications for budget limits, recurring transactions, and reminders

  • Account Management:

    • Authenticate and manage your account

    • Provide customer support

    • Respond to your comments and questions

  • Premium Features:

    • Process subscriptions and payments (handled by App Store/Google Play)

    • Provide advanced data export (PDF, Excel - CSV and JSON are free)

    • Enable advanced transaction insights and intelligence

    • Provide budget and goal analytics

    • Enable home card management and customization

    • Provide country-specific AI-powered goal recommendations

  • Social Features:

    • Enable shared budgets and goals with family members

    • Manage connections and sharing permissions

  • Improvement & Development (with your consent):

    • Understand how users use our App to improve functionality

    • Personalize your experience based on your preferences

    • Analyze user behavior to improve features

    • Generate insights for product development

    • Monitor app performance and optimize speed

  • Security:

    • Detect, prevent, and address technical issues

    • Protect against harmful, fraudulent, or illegal activity

    • Maintain audit logs for security monitoring (GDPR Article 32)

  • Legal Compliance:

    • Comply with legal obligations

    • Enforce our Terms of Service

    • Protect our rights and property

Your Privacy Controls

We provide you with controls to manage your privacy preferences directly in the App:

Consent Management

You can grant or withdraw consent for:

  • Analytics: Collection of anonymous usage data

  • Data Collection: General data processing

  • Marketing: Communications about our products

  • Personalization: Customized experiences based on your usage

  • Performance Monitoring: App performance metrics

  • User Feedback: Collection of your feedback and ratings

  • Crash Reporting: Technical error information

  • Behavioral Profiling: Analysis of usage patterns for recommendations

Data Retention

You can choose how long we retain your data:

  • 30 days, 90 days, 180 days, 1 year, or indefinitely

Data Export

You can export your data in CSV or JSON format at any time.

Account Deletion

You can request deletion of your account and associated data.

Data Storage and Security

Local and Cloud Storage

  • Local Storage (Default): Your financial data is stored locally on your device using
    encrypted storage

  • Cloud Synchronization (Free Feature): If you enable cloud sync, your data is encrypted
    and stored on Firebase Cloud Firestore servers. Cloud sync is available to all users at
    no additional cost.

Encryption

We take data security seriously and implement industry-standard encryption:

  • AES-256-CBC Encryption: All sensitive data is encrypted using AES-256-CBC encryption
    before storage

  • Encrypted Fields:

    • Transaction descriptions, notes, and locations

    • Budget and goal names and descriptions

    • Category names

    • Debt creditor names and descriptions

    • Recurring transaction details

    • Profile photos

  • Key Derivation: Encryption keys are derived using PBKDF2 with 100,000 iterations

  • Secure Storage: Encryption keys are stored in the device's secure keychain (iOS
    Keychain / Android Keystore)

Security Measures

We implement appropriate technical and organizational measures to protect your personal
data:

  • End-to-end encryption for sensitive data

  • Secure authentication (Firebase Authentication with industry standards)

  • Regular security audits and monitoring

  • Automated security logging (GDPR Article 32 compliance)

  • 2-year audit log retention for security events

  • Protection against unauthorized access, alteration, disclosure, or destruction

  • Secure data transmission using HTTPS/TLS

Note: While we implement strong security measures, no method of electronic storage or
transmission is 100% secure. We cannot guarantee absolute security.

Data Sharing and Disclosure

We do not sell your personal information to third parties.

We may share your information in the following situations:

Shared Budgets and Goals (Social Features)

When you use our social features to share budgets or goals with family members:

  • What You Share: Budget names, amounts, spending data, goal progress, and contributions

  • Who Can See It: Only users you explicitly invite and approve

  • Your Control: You can view all participants, remove access at any time, and delete
    shared items

  • Their Control: Participants can leave shared budgets/goals at any time

  • Data Sharing: Shared data is visible to all participants in real-time

  • Privacy: We do not share your data with anyone you haven't explicitly added as a
    participant

Important: Be mindful about who you share financial information with. We are not
responsible for how other participants use the shared data.

Third-Party Service Providers

We share your information with third-party service providers who perform services on our
behalf:

  • Firebase/Google: Cloud storage, authentication, analytics (with your consent)

  • Apple/Google: Sign-in authentication, payment processing

  • Expo/Notifee: Push notification delivery

These service providers are contractually obligated to protect your data and use it only
for the services they provide to us.

Legal Requirements and Protection

We may disclose your information if required to do so by law or in good faith belief
that such action is necessary to:

  • Comply with legal obligations or valid legal requests

  • Protect and defend our rights or property

  • Prevent or investigate possible wrongdoing

  • Protect the personal safety of users or the public

  • Protect against legal liability

Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be
transferred as part of that transaction. We will notify you via email and/or a prominent
notice in the App before your information is transferred and becomes subject to a
different Privacy Policy.

With Your Consent

We may share your information for any other purpose with your explicit consent.

Your Rights Under GDPR

As a user in the European Union (or EEA), you have the following rights under GDPR:

Right to Access (Article 15)
You can view all your personal data at any time within the App. You can also export your
data in machine-readable JSON format.

Right to Rectification (Article 16)
You can correct any inaccurate personal data directly in the App (edit transactions,
budgets, goals, profile information).

Right to Erasure (Article 17) - "Right to be Forgotten"
You can request deletion of your account and all associated data through the Privacy
Settings screen. This action is permanent and cannot be undone.

Right to Restrict Processing (Article 18)
You can limit how we process your data by withdrawing consent for optional features
(analytics, personalization, etc.) in Privacy Settings.

Right to Data Portability (Article 20)
You can export all your personal data in a structured, machine-readable JSON format at
any time (free of charge). This export includes all your transactions, budgets, goals,
and preferences with all encrypted fields automatically decrypted.

Right to Object (Article 21)
You can object to processing of your data for analytics, personalization, or marketing
purposes by disabling these features in Privacy Settings.

Right to Withdraw Consent (Article 7)
You can withdraw consent for any optional data processing at any time through Privacy
Settings. This will not affect the lawfulness of processing based on consent before its
withdrawal.

Right to Lodge a Complaint
If you believe we have violated your privacy rights, you have the right to lodge a
complaint with your local data protection authority (supervisory authority) in Romania
or your country of residence.

Romania's Data Protection Authority:

  • Name: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
    (ANSPDCP)

  • Website: www.dataprotection.ro

How to Exercise Your Rights

Most rights can be exercised directly in the App through:

  • Privacy Settings screen (consent management, data retention, export, account deletion)

  • Profile screen (edit personal information)

  • Settings screens (manage preferences)

For other requests or questions about your rights, contact us at:
contact@numora-official.com

Children's Privacy (COPPA Compliance)

Age Restriction

Numora is intended for users aged 13 years and older. We do not knowingly collect
personal information from children under 13 years of age without verifiable parental
consent.

Parental Notice

If you are a parent or guardian and believe your child under 13 has created an account
or provided us with personal information, please contact us immediately at
contact@numora-official.com, and we will delete the account and all associated data.

Educational Use

While children under 13 may use the App under parental supervision for educational
purposes (learning about money management, tracking allowances), the account must be
created and managed by a parent or guardian.

Compliance

This policy complies with the U.S. Children's Online Privacy Protection Act (COPPA) and
GDPR provisions regarding children's data.

Data Retention

You can set your data retention period in Privacy Settings:

  • 30 days, 90 days, 180 days, 1 year, or indefinitely

After the retention period expires, your transaction data will be automatically deleted.
However:

  • Account information and current budgets/goals remain until you delete them

  • You can always export your data before it's deleted

  • Security audit logs are retained for 2 years as required by GDPR Article 32

International Data Transfers

As we use Firebase services (Google LLC), your data may be transferred to and stored on
servers located in the United States and other countries outside the European Economic
Area (EEA).

We ensure such transfers comply with GDPR requirements through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission

  • Adequacy decisions where applicable

  • Additional safeguards including encryption and access controls

For more information about Firebase's data protection measures, visit:
https://firebase.google.com/support/privacy

Changes to This Privacy Policy

We may update our Privacy Policy from time to time to reflect changes in:

  • Our practices

  • Legal requirements

  • New features or services

We will notify you of any material changes by:

  • Posting the new Privacy Policy in the App

  • Updating the "Last Updated" date at the top

  • Sending you an in-app notification or email for significant changes

We encourage you to review this Privacy Policy periodically. Your continued use of the
App after changes are posted constitutes your acceptance of the updated Privacy Policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your
personal data, please contact us at:

Email: contact@numora-official.com
Website: https://numora-official.com
App: Use the "Contact Developer" feature in Settings → Help Center

Response Time: We aim to respond to all privacy-related inquiries within 30 days, as
required by GDPR.

Supervisory Authority

For users in the European Union, you have the right to lodge a complaint with your local
data protection authority if you believe we have not adequately addressed your privacy
concerns.

Romania (our jurisdiction):

Your Consent

By creating an account and using Numora, you acknowledge that you have read and
understood this Privacy Policy and agree to its terms.

You can:

  • Manage your consent preferences in Privacy Settings

  • Withdraw consent at any time (this will not affect data processed before withdrawal)

  • Export your data at any time

  • Delete your account and all data

Note: The App requires certain essential data processing to function (account
management, storing your financial data). Optional features like analytics,
personalization, and cloud sync require your explicit consent.