Privacy Policy
Last updated: 5 August 2026
The controller for Balanzo is Balanzo, Berlin, Germany. Privacy enquiries: privacy@balanzo.de.
1. Privacy-first design
Balanzo stores financial data, local credentials, extracted receipt fields and preferences encrypted on your device by default. The native document scanner creates a cropped and perspective-corrected receipt image in Balanzo’s private storage on your device. The receipt image and recognized text are not sent to our server. Balanzo does not store your complete personal finance database in a cloud finance account or synchronize it with our server. A server account is used only for sign-in and Shared Spaces you explicitly use.
2. Data stored on your device
- display name for the local profile
- salted password and PIN hashes
- income, expenses, goals, bills, loans, subscriptions and tax-planning data
- receipt images and locally recognized receipt items
- language, biometric preference and AI consent choice
3. Online assistant
The online assistant is optional. Before first use, we show a separate consent notice. If you agree, the app sends your question, a random device identifier and only the summarized financial values permitted for that question to the Balanzo API. Names, IBANs, card numbers, receipt images, raw OCR and identity documents are excluded from model context.
For open-ended explanations, the Balanzo API may use Google Gemini as a processor. Exact finance and tax figures are produced by Balanzo calculation logic; the language model may only explain those figures. Consent can be withdrawn at any time in Settings.
4. Server data
For sign-in and Shared Spaces, the server stores an account record containing a display name, hashed email address and identity-provider identifier. When Shared Spaces are used, the server stores membership, shared expenses, selected participants, allocations, confirmations, purchase proposals and settlements. For security and abuse prevention, the server also temporarily processes IP address, session and rate-limit information. Routine application logs do not contain complete financial snapshots or analysis reports.
5. Camera, photos and biometrics
Camera access is requested only when you choose to scan a receipt. On iPhone, Balanzo uses Apple’s VisionKit document camera; on Android, it uses the Google ML Kit document scanner. Edge detection, cropping, perspective correction and the subsequent text recognition happen on device. Balanzo sends neither the receipt image nor raw recognized text to its server. Biometric data is handled only by the operating system; Balanzo does not receive fingerprint or face data.
6. Purposes and legal bases
- performance of the service and delivery of app functions
- consent for optional online AI and optional permissions
- legitimate interests in security, abuse prevention and troubleshooting
7. Retention and deletion
Local data remains on your device until you delete it, remove your local vault in Settings or uninstall the app. “Delete local vault and data” removes the profile, finance database, Balanzo’s private receipt images, local AI session and consent preference. If you use a Balanzo server account or Shared Spaces, you can delete the account in the app. Owned Shared Spaces must be removed and open shared balances settled first. Account deletion removes linked identities and deactivates the account record; shared transaction records needed for other members or legal obligations may remain in anonymized form.
8. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. You may also lodge a complaint with a competent data-protection authority.
9. Children
Balanzo is not directed to children under 16 and does not knowingly collect their personal data.
10. Changes
We update this policy when features, providers or legal requirements change. The date above identifies the current version.