About this pageThis page is a public explanation of Appayo’s current data model. Google Play’s Data Safety form uses specific definitions and the final Play Console declaration must match the exact Android release and SDKs distributed on Google Play.
What stays on your device
Appayo can be used with a local-first workflow. Information that is accessed and processed only on your device is not transmitted to Appayo merely because it exists in the app. This can include local financial records and, depending on the feature, locally handled photos, receipt images, exports, or backups.
What may be transmitted when you use account or cloud features
Personal information
Email address, display name when provided, user/account identifiers, profile identifiers, workspace membership and role information.
Used for authentication, account management, cloud access, shared workspaces, security, and support.
Financial information
Supported finance records you choose to synchronize, such as transactions, categories, credits or debts, payments, reminders, and related records.
Used to provide cloud sync, shared finance features, reports, and app functionality.
Purchase history
Purchase or subscription identifiers, product information, state, and tokens needed to validate or restore Appayo Premium.
Used for paid functionality, entitlement management, security, and fraud prevention. Payment card details are handled by Google Play, not entered into Appayo for subscription validation.
Support requests
Email address, deletion/support request references, and information you choose to provide to resolve a request.
Used for support, developer communications, account verification, and security.
Optional versus required
Because Appayo supports local-first use, account and cloud collection can be optional for users who choose to remain local. When you choose an account, cloud synchronization, shared workspace, support, or Premium feature, the information needed for that selected feature may be required to perform it.
Service providers versus sale of data
Supabase, Google, Google Play, website hosting, and email infrastructure may process information to provide services to Appayo. Appayo does not sell personal financial information and does not describe its finance data as being used for third-party advertising in this release disclosure.
Encryption and security
Supported account and cloud connections are designed to use encrypted transport such as HTTPS/TLS. Sensitive destructive account actions are handled through authenticated server-side operations rather than exposing administrative credentials in the browser.
Deletion
Appayo provides an in-app account deletion path and a public web deletion resource. You can start the external process at Delete account. Shared workspace information is handled so that deleting one user does not improperly destroy records belonging to other legitimate participants.
Items that must be checked for every Android release
Permissions or SDK capabilities do not automatically mean a data type is collected. Before a Google Play submission, Appayo should re-audit the final AAB and all bundled SDKs for any actual off-device transmission of crash logs, diagnostics, app interactions, device identifiers, photos, files/documents, or other data not listed above. If the shipped behavior changes, both the Play Console Data Safety form and this privacy documentation should be updated.