Privacy Policy — FinanControl
Version: 3.0
Effective date: 09/02/2026
Last updated: 09/02/2026
1. Introduction and Data Controller
This Privacy Policy governs the use of the FinanControl mobile application ("App"), in compliance with the California Consumer Privacy Act (CPRA), the California Online Privacy Protection Act (CalOPPA), the Children's Online Privacy Protection Act (COPPA), the Personal Information Protection and Electronic Documents Act (PIPEDA — Canada), the UK Data Protection Act 2018, and Google AdMob Publisher Policies.
Data Controller:
- Trade Name: ECPDIGITAL
- Company: ERNESTO CAPALBO POLI SERVIÇOS DIGITAIS LTDA.
- Registration: 68.019.620/0001-06
- Email: ecpdigital@ecpservicosdigitais.com
2. Privacy Contact
- Email: ecpdigital@ecpservicosdigitais.com
- Response time: within 15 business days.
3. Available Plans and Data Processing by Plan
FinanControl offers three plans with different levels of data collection:
3.1 Free Plan
- Displays ads via Google AdMob (banner and/or interstitial, depending on region)
- Collects cookies and advertising identifiers (GAID) for ad display
- When opening the App for the first time, users are presented with Google's consent form (UMP — User Messaging Platform), where they can choose between personalized (interest-based) or non-personalized (generic) ads. The free plan remains accessible regardless of the choice
3.2 Ad-Free Plan
- Monthly subscription processed via Google Play Billing
- No ads of any kind
- No cookies or advertising identifiers collected
- No data shared with Google AdMob
- Cookie consent is not required
- Data import (CSV/OFX) included at no extra cost
3.3 Premium Plan
- Monthly subscription processed via Google Play Billing
- All Ad-Free benefits
- Includes automatic receipt reading via Artificial Intelligence
- Receipt images are sent to a proprietary server function (Google Cloud Functions), which forwards the image to the Google Gemini API for processing — this keeps the AI access key from ever being exposed inside the app
- Images are processed in real-time and not stored at any stage (neither by the server function nor by Google Gemini) after processing
- Extracted data (amount, category, date) is saved locally on the user's device
- Limit of 75 reads per month; an additional +25 reads pack is available as a one-time consumable purchase via Google Play Billing
- Includes the Financial Planner Friend: a monthly PDF report generated locally on the device (see Section 6.1)
4. What Data We Collect and Why
| Data | Purpose | Plans | Legal Basis |
| Email, name and profile photo | Account authentication (Firebase Authentication) | All | Consent / Contract |
| Unique account identifier (UID) | Technical account identification, data isolation between accounts | All | Contract |
| Subscription status (active/inactive, expiry date) | Access control for plan features | Ad-Free and Premium | Contract |
| Google Play purchase token | Subscription verification and renewal with Google Play | Ad-Free and Premium | Contract |
| Financial data (amounts, categories, dates) | App functionality | All | Contract |
| Advertising ID (GAID) | Ad personalization | Free only | Consent |
| AdMob cookies | Ad targeting | Free only | Consent |
| Receipt images | AI auto-reading | Premium only | Consent |
| Imported CSV/OFX files | Financial history import | All plans, free of charge | Contract |
Important: financial data (transactions, categories, amounts, receipt images) is never sent to Firebase/Firestore. It remains exclusively on the user's device and, for Google accounts, in the user's own personal, hidden Google Drive folder. Firebase only stores identity data (email, name, UID) and subscription status — never financial content.
We do NOT collect: location, contacts, microphone, browsing history, biometric or health data.
Permissions used:
- Camera/Gallery (Premium Plan): temporary access to capture receipt photos. Images are resized, sent for API processing, and immediately discarded. No images are stored on the device or servers.
4.1 User Region Detection
To determine the user's country and configure language, currency, and ad display, the App reads the following information locally from the device:
1. Carrier country code (MCC): read directly from the device's SIM card. Does not require user permission, does not access GPS, and does not transmit data to external servers.
2. Operating system region settings: language and region configured by the user on the device.
This information:
- Is read locally and is not transmitted to any third party
- Does not constitute geolocation data
- Does not require any special user permission
- Is used exclusively to configure language, currency, and ad type displayed in the App
5. Cookies and Tracking Technologies
Free Plan
Google AdMob uses cookies and device identifiers (GAID) to serve personalized ads, measure performance, limit frequency, and prevent fraud.
You may opt out: Android Settings > Google > Ads > Opt out of Ads Personalization
Ad-Free and Premium Plans
No cookies or advertising tracking technologies are used. These plans are designed for maximum privacy. Your finances stay private.
6. AI Image Processing (Premium Plan)
The Premium plan uses the Google Gemini API for automatic receipt reading:
- Images are resized (800px, 50% compression) before sending
- Sent, via encrypted connection (SSL/TLS), to a proprietary server function (Google Cloud Functions), which forwards the image to the Google Gemini API. This intermediate step protects the API access key, which is never exposed inside the app
- Not stored at any stage — neither by the server function nor by Google Gemini — after processing
- No financial data is used to train AI models
- Processing governed by Google Gemini API Terms
6.1 Financial Planner Friend (Premium Plan)
A feature that generates a monthly financial report in PDF, based exclusively on the income and expense transactions the user has already recorded in the App.
- The report is generated locally on the user's own device — no financial data is sent to any server for this purpose
- Users may opt in to receive the report automatically every 2nd day of the month (covering the previous month), or generate a manual report at any time, using data up to the current date
- Once generated, the App may display a local notification on the device (not sent by a server) letting the user know the report is ready
- Sharing the generated PDF (by email, message, cloud, etc.) is done through the device's native sharing mechanism — the user chooses the destination; ECPDIGITAL never receives or stores a copy of the report
- Should the App also offer, in the future, category-based budget alerts based on a user-declared income figure, that income is used only for the on-screen alert calculation and is never included in the PDF report or transmitted to any third party
7. Data Storage
Local Storage (Email account, without Google)
- Financial data is stored locally on the user's device
- If the app is uninstalled or the phone is changed, data will be lost
Google Drive Storage (Google account)
- Data is automatically synced via a hidden app folder (appDataFolder) in the user's personal Google Drive
- The developer will have no access to user data stored in their Drive
Firebase Storage (all accounts, Ad-Free and Premium)
- Firebase Authentication (Google) stores email, name, profile photo, and the account's unique identifier (UID) — used for login and password recovery
- Cloud Firestore (Google) stores only the subscription status (active/inactive, expiry date, extra-reads balance) — never financial data
- This data is held on Google servers (United States), with security rules that prevent any user from reading another account's data
7.1 Notifications
The App may display local notifications on the device (e.g., letting you know your Financial Planner Friend monthly report is ready). These notifications are scheduled and triggered by the device itself, without relying on an external push server, and do not involve sending data to any third party.
8. Data Sharing
| Recipient | Purpose | Affected Plans |
| Google LLC (AdMob) | Ad display | Free only |
| Google LLC (Gemini API) | Receipt AI reading | Premium only |
| Google LLC (Firebase Authentication) | Account login and identity | All |
| Google LLC (Cloud Firestore) | Subscription status | Ad-Free and Premium |
| Google LLC (Cloud Functions) | Purchase verification and receipt-reading intermediary | Ad-Free and Premium |
Your data is NEVER: sold to third parties, shared with marketing partners, used for financial data-based ad targeting, or transferred to other applications.
8.1 International Data Transfers
Your data may be processed on servers located outside your country of residence, including in the United States, as part of the services provided by Google LLC (AdMob for the Free plan, Gemini API for the Premium plan). These transfers are conducted in accordance with appropriate safeguards, including Google's Standard Contractual Clauses (SCCs) approved by the European Commission, as required by the UK Data Protection Act 2018 (UK GDPR) and the Personal Information Protection and Electronic Documents Act (PIPEDA — Canada).
9. Your Rights
California residents (CPRA/CalOPPA): Right to know, delete, and opt out. We do not sell personal information.
Canadian users (PIPEDA): Right to access, correct, and withdraw consent.
UK users (UK DPA 2018): Rights of access, rectification, erasure, restriction, portability, and objection.
The app provides data export in CSV format for all plans, ensuring the right to data portability under UK DPA 2018, PIPEDA, and CPRA.
The app provides a "Delete Account" feature in Settings that:
1. Deletes data synced to Google Drive (Google accounts)
2. Permanently deletes the account in Firebase Authentication — email, password, and unique identifier cease to exist, irreversibly
3. Erases all data stored locally on the device
For security, Firebase may require the user to re-confirm their password (email accounts) or sign in again (Google accounts) before completing deletion, if the session is not recent.
If you have uninstalled the App and wish to request account deletion or instructions on removing synced data from your personal Google Drive, please contact us at ecpdigital@ecpservicosdigitais.com. As your data is stored exclusively on your device and in your personal cloud, we will provide guidance on revoking access and removing files.
Contact: ecpdigital@ecpservicosdigitais.com
10. Security
- SSL/TLS encrypted communications
- Data stored locally (not on external servers)
- Receipt images compressed before transmission
- No system is 100% secure; we will notify affected users promptly in case of a security incident
11. Age Restriction
This App is for users 13 years or older. Users under 18 must have parental or legal guardian consent. We do not knowingly collect data from minors. If discovered, such data will be immediately deleted.
12. COPPA Compliance
This App is not directed at children under 13. No data is knowingly collected from children.
13. Changes to This Policy
Significant changes will be communicated via in-app notification at least 10 days before taking effect.
14. Contact
Email: ecpdigital@ecpservicosdigitais.com
Response time: within 15 business days