Privacy Policy

Last updated: 26 September 2026

Who is responsible for your data

The data controller for VotaWallet — the votawallet.app website, the my.votawallet.app web application, the VotaWallet apps for Android and iOS, and the VotaWallet Telegram bot and Mini App — is Denis Lipatov, a private individual residing in the Republic of Serbia.

For anything related to your personal data, write to legal@votawallet.app. We have not appointed a data protection officer; your email reaches the controller directly.

What we collect

  • Account data: name (optional), email address and password (stored only as a secure hash), and the date and version of the Terms you accepted.
  • Sign-in through Google, Apple or Telegram: the account identifier the provider gives us, and the email address and name it shares. Apple may give us a private relay address instead of your real email. For Telegram we also receive your username. If you sign in with Apple, we keep a token that lets us revoke VotaWallet's access at Apple when you delete your account. If you skip email during Telegram sign-up, a technical placeholder address is created for your account.
  • Settings: language, timezone, currencies, interface and notification preferences.
  • Financial records you create: accounts, transactions and their notes, itemized purchases, categories, budgets, tags, debts (including the names you give to the other party), companies you track (name, tax ID, address), custom store names and payment habits.
  • Fiscal receipt data: when you scan a receipt QR code, share an e-receipt into the app or send a receipt photo to the bot, we retrieve the official receipt record from the Serbian Tax Administration portal (suf.purs.gov.rs): store, items, prices, VAT, payment method, cashier label and, if the receipt has one, the buyer identifier (PIB, or JMBG if you gave it at the checkout — we only ever show it masked). Receipt photos and files you upload, share or send to the bot are stored with your account.
  • Family sharing data: your family's name, member names or labels you add, and email addresses you invite. An invited address is stored even if that person never registers.
  • Progress data: points, level, league and a random anonymous pseudonym for the leaderboard, plus which steps of the in-app tutorial you have reached — we use the latter to improve onboarding.
  • Support data: if you send a bug report from the app, we receive your message, the page you were on, browser or device information, recent technical console entries and a screenshot of the screen, plus any replies you exchange with us.
  • Mobile device data: to deliver push notifications, the Android app registers a push token together with the platform, language and app version.
  • Technical data: IP addresses and browser or device details in server, session and error logs. An error record may include the content of the request that failed.

What we do not do

  • No advertising, no advertising identifier and no third-party analytics that follow you — neither on the website nor in the apps.
  • No selling or sharing of your data for marketing. Ever.
  • No card or payment processing and no in-app purchases — donations run through external platforms (Boosty or direct crypto transfers).
  • No location tracking, and no access to your contacts.
  • No decisions with legal or similarly significant effects made about you by automated means. Category suggestions are only suggestions — you decide.
  • We do not send your data to third-party AI services.

Why we process it

  • To provide the service you signed up for: storing and displaying your finances, parsing receipts, suggesting categories, family sharing, the leaderboard, sign-in and account security emails (performance of a contract).
  • To keep the service secure, fix errors and answer your bug reports: sessions, technical logs, error monitoring (legitimate interest).
  • To improve the product: anonymous website visit counts and tutorial progress (legitimate interest — you can object at any time by writing to us).
  • To send push, Telegram and email notifications you have enabled (consent — you can switch them off in the app settings or in your phone's settings at any time).
  • To honor donor perks and promo codes you redeem (performance of a contract).

Providing an email address or a sign-in account (Google, Apple or Telegram) is a contractual requirement — without one we cannot create or maintain your account. Everything else (name, receipts, notes, family data) you provide voluntarily; the related features simply will not work without it.

If you enter other people's data — an invited email address, the name of someone in a debt — make sure they are fine with it. We use it only to run that feature.

Where your data lives

Production data — the database, uploaded files and backups — is stored on Google Cloud in Frankfurt, Germany (EU). Under the Serbian Personal Data Protection Act (Article 64) and the Government's list of countries with an adequate level of protection (Official Gazette of RS 55/2019), EU member states provide adequate protection, so this transfer needs no additional safeguards.

Some of the services listed below — Google (push notifications, sign-in), Apple, Cloudflare and Capgo — may process data outside the EU, including in the United States. For those transfers we rely on the recipient's adequate level of protection under Article 64 of the Serbian Personal Data Protection Act (for US companies, certification under the EU–US Data Privacy Framework); where that does not apply, on safeguards under Article 65 or, for services you ask us to provide, on Article 69 of the Act. You can ask us for details of these safeguards.

If you sign in with Telegram or use the bot or Mini App, your messages are processed on Telegram's servers, which may be located in countries without an adequacy decision. That transfer happens at your request and is necessary to provide the Telegram features you use.

Who receives data

  • Google Cloud — hosting, database, file storage, backups and technical logs.
  • Google Firebase Cloud Messaging — delivers push notifications to the Android app: it receives the device's push token and the notification text (for example, that a receipt could not be retrieved).
  • Google, Apple and Telegram as sign-in providers — only if you choose to sign in with them. The provider learns that you are signing in to VotaWallet and sends us the data described above; each processes it under its own privacy policy.
  • Brevo (email delivery) — your email address and the content of service emails: password links, sign-in and security notices, notifications you have enabled.
  • Cloudflare — content delivery for the marketing website.
  • Capgo — the update component inside the Android and iOS apps: when the app starts, it reports a technical event with a random installation identifier created by the component, the app and system version and the install source. No account data is sent.
  • Telegram — the bot and Mini App, conversations with the bot (including receipt photos you choose to send in chat) and service notifications you have enabled, such as password-reset links.
  • Serbian Tax Administration portal (suf.purs.gov.rs) — we fetch the official receipt record using the link from the QR code; no personal identifiers are attached to that request.
  • Product databases (Open Food Facts, UPCitemdb, the open price catalogs on data.gov.rs and retailers' public catalogs) — only product names and barcodes from receipts are used as search queries; your identity is never attached.
  • Exchange-rate services — currency codes only, no personal data.
  • Google Play and the App Store distribute the apps and send us aggregated statistics and crash reports under their own privacy policies.

We disclose data to public authorities only when Serbian law requires it.

Service providers that process data on our behalf (Google Cloud, Firebase, Brevo, Cloudflare, Capgo) do so only on our instructions and under terms that protect your data at least as well as this policy.

Family sharing and the leaderboard — what others can see

Records you share with a family — shared accounts, categories and transactions — are visible to and editable by every member of that family. If shared analytics is enabled, aggregate statistics include family data too. Only join a family with people you are comfortable sharing your finances with.

If the leaderboard is on (it is by default; you can turn it off in settings), other users see your anonymous pseudonym, league and points for the month — never your name, email or finances.

Mobile apps and device permissions

  • Camera — to scan receipt QR codes and take receipt photos. The QR code is read on your device; a photo leaves the device only when you save or send it.
  • Photos (iOS) and sharing into the app — only the images and files you pick or share are uploaded.
  • Notifications — only if you allow them; you can turn them off in settings at any time.

The apps do not use your location, contacts or advertising identifier. The sign-in token is kept in the app's private storage and is excluded from Android device backups.

Cookies and local storage

We use only what is strictly necessary to run the service — which is why there is no cookie banner:

  • Session cookies in the app (laravel-session, XSRF-TOKEN) — sign-in and security; they expire after about two hours of inactivity.
  • Browser localStorage and the mobile apps' private storage: your theme choice on the website, your sign-in token, app preferences, and a copy of your accounts, transactions and categories with a queue of changes made offline, so the app opens quickly and works without a connection.
  • No tracking, advertising or analytics cookies of any kind. If that ever changes, we will ask for your consent first.

How long we keep data and how to delete it

Your data stays in your account until you remove it or delete the account. In the app you can wipe your financial records (accounts, transactions, receipts) yourself.

To delete your account, open Settings → “Delete account” in the app or the web app. Deletion is immediate: your account, financial records, receipt photos, sign-in links and push tokens are erased, your Apple sign-in access is revoked, and you leave your family. If you cannot open the app, follow votawallet.app/delete-account or write to legal@votawallet.app from your account's email — we will delete it within 30 days.

Copies in database backups disappear within 14 days of deletion.

Bug reports you sent stay after account deletion without a link to your account, so we can finish fixing the problem; ask us and we will delete them. Photos and corrections you add to products in the shared product catalogue are visible to all users and also stay, without a link to your account.

Server logs are kept for 30 days; error records and failed background tasks for up to 90 days. If you sign in with Apple, the name Apple shares only on the first sign-in is kept in a temporary cache for up to 90 days, so it is not lost if sign-up is interrupted.

Your rights

Under the Serbian Personal Data Protection Act (ZZPL) — and the GDPR, where it applies to you — you have the right to:

  • access your data and receive a copy of it;
  • receive the data you provided in a structured, machine-readable format (portability);
  • correct inaccurate data;
  • have your data deleted;
  • restrict processing, or object to processing based on legitimate interest;
  • withdraw consent at any time, without affecting prior processing.

Much of this you can do yourself: edit data in the app, unlink a sign-in provider in settings, delete your account. For everything else, email legal@votawallet.app — we reply within 30 days.

You also have the right to lodge a complaint with the Serbian supervisory authority: Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti, Bulevar kralja Aleksandra 15, Belgrade — poverenik.rs. If you live in the EU, you can also contact your local data protection authority.

Security

All traffic is encrypted (TLS), and data is encrypted at rest by Google Cloud. Passwords are stored only as bcrypt hashes. The database has no public address, receipt photos and screenshots are served only through signed links that expire within 48 hours, and secrets are kept in a managed vault. The operator looks at your records only when needed to answer your request, fix an error or protect the service.

Children

VotaWallet is not directed at children under 15, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.

Changes to this policy

We will post any changes on this page and update the date above. Significant changes will be announced in the app or the Telegram channel.