Files
cowspent/PRIVACY.md
T
2026-09-19 10:27:15 +02:00

74 lines
2.5 KiB
Markdown

# Privacy Policy for Cowspent
**App:** Cowspent (`net.helcel.cowspent`)
**Developer:** Helcel
**Effective date:** 19 September 2026
## What we collect
Nothing. We operate no servers and receive no data from the app. Cowspent
contains no analytics, advertising, or tracking libraries.
## Data you enter and where it goes
Cowspent stores your projects, members, bills, categories, and app settings on
your device.
If you connect the app to a Cospend or IHateMoney server, this data is
synchronised with **the server you choose**: either your own or one operated by
a third party. That server's operator controls that copy of your data and their
privacy policy applies to it. We are not involved in that transfer and cannot
access it.
Your server address, username, and password or access token are stored on your
device and sent only to the server you configured, over the connection it
provides. If you sign in through the Nextcloud Files app, authentication is
handled by that app's Single Sign-On and we never see your password.
## Sharing projects
Project share links and QR codes are generated by your server. Anyone who
obtains a link or code may be able to access the project, so share them only
with people you trust.
## Permissions
- `INTERNET`, `ACCESS_NETWORK_STATE` — synchronising with your chosen server.
- `CAMERA` — scanning QR codes to import a project. Images are processed on the
device, never stored or transmitted.
- `GET_ACCOUNTS` — used by the Nextcloud Single Sign-On library to list accounts
from the Nextcloud Files app.
## Retention and deletion
Data on your device remains until you delete it. Clearing the app's data in
Android Settings, or uninstalling Cowspent, removes the local copy and the
stored credentials. Data already synchronised to a server must be deleted on
that server, by you or its administrator.
## Children
Cowspent is suitable for all ages and collects no data from any user, including
children.
## Security
Credentials and project data are held in the app's private storage, protected by
the Android sandbox. Use an HTTPS server address so that synchronisation is
encrypted in transit.
## Open source
Cowspent is released under the GNU General Public License v3.0. The full source
is available at https://github.com/helcel-net/cowspent, so these statements can
be independently verified.
## Changes
Any change affecting privacy will be published in this document before or with
the release that introduces it.
## Contact
Email: net-helcel+privacy@gmail.com
Issues: https://github.com/helcel-net/cowspent/issues