Privacy Policy
Last updated: 24 July 2026
The controller for Balanzo is Balanzo, Berlin, Germany. Privacy enquiries: privacy@balanzo.de.
1. Privacy-first design
Balanzo stores financial data, local credentials, extracted receipt fields and preferences encrypted on your device by default. The native document scanner creates a cropped and perspective-corrected receipt image in Balanzo’s private storage on your device. The receipt image and recognized text are not sent to our server. We currently do not operate a persistent cloud finance account and do not synchronize your complete financial database to our server.
2. Data stored on your device
- display name for the local profile
- salted password and PIN hashes
- income, expenses, goals, bills, loans, subscriptions and tax-planning data
- receipt images and locally recognized receipt items
- language, biometric preference and AI consent choice
3. Online assistant
The online assistant is optional. Before first use, we show a separate consent notice. If you agree, the app sends your question, a random device identifier and only the summarized financial values permitted for that question to the Balanzo API. Names, IBANs, card numbers, receipt images, raw OCR and identity documents are excluded from model context.
For open-ended explanations, the Balanzo API may use Google Gemini as a processor. Exact finance and tax figures are produced by Balanzo calculation logic; the language model may only explain those figures. Consent can be withdrawn at any time in Settings.
4. Server data
For security and abuse prevention, the server temporarily processes IP address, random device identifier, session and rate-limit information. Routine application logs are designed not to contain complete questions, financial summaries or model answers. The current rate-limiting data is not intended as a long-term user profile.
5. Camera, photos and biometrics
Camera access is requested only when you choose to scan a receipt. On iPhone, Balanzo uses Apple’s VisionKit document camera; on Android, it uses the Google ML Kit document scanner. Edge detection, cropping, perspective correction and the subsequent text recognition happen on device. Balanzo sends neither the receipt image nor raw recognized text to its server. Biometric data is handled only by the operating system; Balanzo does not receive fingerprint or face data.
6. Purposes and legal bases
- performance of the service and delivery of app functions
- consent for optional online AI and optional permissions
- legitimate interests in security, abuse prevention and troubleshooting
7. Retention and deletion
Local data remains on your device until you delete it, remove your local vault in Settings or uninstall the app. “Delete local vault and data” removes the profile, finance database, Balanzo’s private receipt images, local AI session and consent preference. Because Balanzo currently has no persistent cloud account, there is normally no server-side account record to delete.
8. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. You may also lodge a complaint with a competent data-protection authority.
9. Children
Balanzo is not directed to children under 16 and does not knowingly collect their personal data.
10. Changes
We update this policy when features, providers or legal requirements change. The date above identifies the current version.