MoneyWatch Privacy Policy
YUNYUNSOFTWARE (the “Developer”) processes only the information needed to provide and protect MoneyWatch.
1. Controller and contact
Controller: YUNYUNSOFTWARE
Privacy contact: suhansz1120@gmail.com
2. Information processed
- Account and authentication: Google account email and basic profile information returned by Google sign-in, Supabase user ID, authentication session, and sign-in timestamps.
- Age verification: a date of birth entered for an age check is transmitted over HTTPS and used by the server only to calculate an age band. The exact date is not stored. The derived band, the month-end date when minor family access ends, verification/correction timestamps and counts, and non-DOB security audit metadata are retained.
- Family access: guardian account ID, member type and display name, hashed/masked invite email, device reference, membership status, family-access end date, seat/cooldown information, and security audit events.
- Plans and billing verification: Free/Plus/Premium tier, access and expiry status, lifetime status, promotion-code redemption, Google Play product/base-plan/offer IDs, purchase token, order/status/renewal information, and verification records.
- Advertising and diagnostics: the Google Mobile Ads SDK may process IP address, approximate location inferred from IP, app interactions, app/SDK diagnostic data, and device or app identifiers for advertising, analytics, and fraud prevention. The app requests non-personalized ads and removes the Android AD_ID permission.
- Support: email address and information voluntarily included in a support or deletion request.
Stored on the device: budgets, income, installments, spending, memos, tags, goals, charts, and settings stay locally on the device and are not uploaded to the Developer server unless a future sync feature is separately introduced and disclosed.
3. Purposes
- Google sign-in, account management, age-appropriate access, and account recovery
- Family invitations, child-device activation, seat limits, expiry, and abuse prevention
- Plan entitlement, purchase restoration, promotion-code control, and Google Play purchase verification
- Non-personalized advertising for eligible free users, consent management, diagnostics, security, support, and legal compliance
4. Children, teens, and family access
- Users under 14 use a guardian-activated child-device flow and do not sign in with a child Google account in the app.
- Users ages 14–18 may use free features or family access granted by an adult guardian. Direct paid purchase access is restricted.
- Family access ends on the last day of the month in which the member turns 19.
- A guardian must provide and manage a minor’s information and consent where required. Age input must be accurate.
- Ads requested in a minor mode are configured as child-directed, general-audience rated, and non-personalized.
5. Service providers and international processing
| Provider | Purpose and data | Location and method |
|---|---|---|
| Supabase, Inc. | Authentication, database, and Edge Functions; account, derived-age, family, entitlement, and verification data described above | Encrypted transmission when used. The current database project region is Singapore. Retention follows Section 6 and Supabase’s terms. |
| Google LLC / Google Play | Google sign-in, purchases, subscriptions, and purchase verification | Encrypted transmission when signing in or purchasing; processing may occur in the United States and other countries where Google operates. |
| Google AdMob | Advertising, consent, analytics, diagnostics, and fraud prevention | Encrypted transmission when an ad is requested; processing may occur in the United States and other countries where Google operates. |
You may decline related processing by not signing in or not using the relevant feature, but account, purchase, family, restoration, or ad-supported functionality may then be unavailable. See Supabase Privacy and Google Privacy.
6. Retention and deletion
- Account, age-band, family, entitlement, and verification data is retained while the account or relevant service relationship remains active.
- The exact date of birth is discarded after the server derives the age band and access end date.
- A canceled pending invitation is deleted. When an active family member is removed, identifying information is cleared and only an anonymous seat-cooldown record may remain for up to 30 days.
- Security, fraud-prevention, dispute, payment-verification, or legally required records may be retained only as necessary and then deleted or de-identified.
- Deleting the app account does not cancel Google Play subscriptions or delete transaction records controlled by Google.
7. Account and data deletion
Delete an account in Settings → Premium and ads → Delete account, or use the external account deletion page. Locally stored data can be cleared with the app’s reset options, Android app-data deletion, or uninstalling the app.
8. Permissions and security
The app may request notification, boot-completed, foreground-service, Internet, and Google Play Billing permissions. It does not request location, contacts, SMS, call-log, microphone, or camera permission. Server traffic uses HTTPS, with Supabase authorization and server-side validation.
9. Choices and rights
You may correct age information through the app’s recheck flow, manage ad privacy choices where available, sign out, delete the account, clear local data, or contact the Developer to request access, correction, deletion, or restriction. Identity verification may be required.
10. Changes
Material changes will be announced by updating this page’s date and, where appropriate, through the app or store listing.