App Privacy Policy

This Privacy Policy explains how GoldenRatio (Golden Ratio United LLC, "we", "us", or "our") collects, uses, and discloses information about you when you use our mobile application and related services. This policy supplements the website privacy policy and specifically covers the in-app data processing. Last updated: 2 June 2025.


Information We Collect

Information you provide to us:

Account data (email address, password hash, optional display name), profile data (currency preference, language, notification settings), financial records that you enter manually or import (income and expense entries, gold purchases, forecasts, multi-profile setups, network/referral entries), support communications, and feedback you submit through the app.

Information collected automatically:

Technical data such as device type, operating system, app version, IP address, crash reports and diagnostic information, anonymised app usage events (which screens are opened, which features are used) and timestamps. We do not connect to your bank account; all financial data is entered manually or imported via files.

Firebase (Google LLC):

We use Firebase Authentication to manage user accounts, Cloud Firestore to store your encrypted user data, Firebase Cloud Functions to run server-side logic, and Firebase Crashlytics for error reporting. Firebase may process data such as IP address, device identifiers, authentication tokens and crash diagnostics. Firebase Privacy Policy: https://firebase.google.com/support/privacy

Google Fonts:

We use Google Fonts to display typography in our web app. The mobile apps ship fonts locally and do not contact Google servers. For the web app, your browser may connect to fonts.gstatic.com when loading the page; Google may receive your IP address. Google Fonts Privacy: https://developers.google.com/fonts/faq/privacy

RevenueCat:

We use RevenueCat (RevenueCat, Inc., USA) to manage subscriptions and in-app purchases across platforms. RevenueCat receives an anonymous user identifier, the purchased product, transaction status and platform receipt. We do not transmit your email or financial records to RevenueCat. Privacy: https://www.revenuecat.com/privacy

Stripe:

Web subscriptions are processed by Stripe Payments Europe Ltd. Stripe collects card data, billing address, IP address and fraud signals directly. We never store your card data on our servers. Privacy: https://stripe.com/privacy

Google Play Billing:

Subscriptions purchased on Android are processed by Google Play. Google receives your purchase data and receipt. We only receive a confirmation token and the purchased product. Privacy: https://policies.google.com/privacy

Apple In-App Purchases:

Subscriptions purchased on iOS are processed by Apple. Apple receives your purchase data via your Apple ID. We only receive a confirmation token and the purchased product. Privacy: https://www.apple.com/legal/privacy

How We Use Your Information

We use your data to (a) provide the core app functionality (storing and displaying your records, syncing between devices), (b) authenticate access and prevent abuse, (c) process and verify subscription payments, (d) provide customer support, (e) improve the app through aggregated, anonymised usage analytics, and (f) comply with legal obligations such as accounting and tax law. Legal basis under GDPR: Art. 6(1)(b) (contract performance), Art. 6(1)(c) (legal obligation) and Art. 6(1)(f) (legitimate interest in service improvement and security).

How We Share Your Information

We do not sell your data. We share data only with the processors listed above (Firebase/Google, RevenueCat, Stripe, Apple, Google Play) to deliver the requested service. With each processor we have a Data Processing Agreement under Art. 28 GDPR. We may disclose data to authorities if required by applicable law (Art. 6(1)(c) GDPR) or to protect our rights and the safety of users.

Data Retention

Account data is kept as long as your account is active. After account deletion, personal data is removed from active systems within 30 days. Encrypted backups are rotated within 90 days. Billing records are retained for up to 10 years to comply with tax and commercial law in the relevant jurisdiction.

Your Data Protection Rights (GDPR)

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent (Art. 7(3)). You can request account deletion at any time via Settings > Account > Delete Account inside the app or by email to contact@golden-ratio-united.com. You also have the right to lodge a complaint with your data protection authority.

International Data Transfers

Some of our processors are located in the United States (Google/Firebase, RevenueCat, Apple). Transfers are safeguarded by EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and, where applicable, by the EU–US Data Privacy Framework adequacy decision.

Data Security

Data is transmitted exclusively via TLS 1.2 or higher. Authentication tokens are stored in the platform-secure keystore. Server-side data is encrypted at rest by Google Cloud. Access to production systems is restricted to a small number of authorised employees and protected by multi-factor authentication.

Children's Privacy

GoldenRatio is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

Changes to This Privacy Policy

We may update this policy to reflect technical or legal changes. The current version is always available at https://golden-ratio-united.com/app-privacy and inside the app under Settings > Legal. Material changes will be communicated via in-app notice.

Contact Us

Privacy enquiries: contact@golden-ratio-united.com – Golden Ratio United LLC, 23160 Fashion Dr Ste 219, Estero, FL 33928, USA.