Privacy Policy
This Privacy Policy describes how Artho – Your Money, Your Meaning ("we", "us", or "our") collects, uses, stores, and shares information about you when you use our mobile application ("App"). By using Artho, you agree to the practices described in this policy. Please read it carefully.
1. Data We Collect
- Account & Identity Data: Your full name, email address, profile photo, and authentication provider (Google Sign-In or Email/Password) when you create or update your account.
- Financial Data: Income records, expense entries, salary information, overtime logs, pay & due records, asset values, stock journal entries, split-expense group data (Splitwise), remittance transaction details, insurance policies, financial goals, and any other data you voluntarily enter into the app.
- Authentication Tokens: Secure tokens issued by Firebase Authentication used solely to verify your identity and maintain your session. These are never stored in plain text.
- Local Device Storage: Certain features (such as Smart Goals) store data locally on your device using browser localStorage, keyed by your unique user ID. This data does not leave your device unless you are connected and syncing. Clearing your browser/app storage will permanently remove locally stored goals.
- Device & Technical Data: Device model, operating system version, app version, unique device identifiers (Android ID), and crash/diagnostic logs collected automatically to ensure app stability.
- Usage Data: Feature interaction logs, session duration, and navigation patterns collected in anonymized form to improve the user experience.
- Approximate Location (Country/Region): Derived from your IP address or manually selected in Settings, used only for currency formatting, regional tax defaults, and public holiday calculations. We do not collect precise GPS location.
- Communications: Any messages or attachments you send us through support channels for the purpose of responding to your queries.
2. How We Use Your Data
- Service Delivery: To create and manage your account, store your financial records, and provide all features of Artho including reports, charts, and financial summaries.
- Synchronization: To sync your data securely across devices logged in with the same account.
- Personalization: To display currency symbols, regional formats, and local holidays appropriate to your country or region.
- Security & Fraud Prevention: To detect suspicious activity, protect your account, and prevent unauthorized access.
- App Improvement: To analyze anonymized usage patterns, fix bugs, and develop new features based on how users interact with the app.
- Communications: To send critical security alerts, policy update notices, and service-related messages. We do not send marketing emails without your explicit opt-in consent.
- Legal Compliance: To meet our obligations under applicable laws and to respond to lawful requests from public authorities.
- We do NOT use your financial data to serve advertisements, build advertising profiles, or make automated decisions that produce legal effects on you.
3. Data Sharing & Disclosure
- We do NOT sell, rent, lease, or trade your personal or financial data to any third party for commercial or advertising purposes — ever.
- Google Firebase (Alphabet Inc.): We use Firebase Authentication for secure sign-in and Cloud Firestore for encrypted data storage. Google processes your data as a data processor under Google's Cloud Data Processing Addendum. See: firebase.google.com/support/privacy
- Google Play Services: Used for app delivery, update management, and Android device integration on Android devices.
- Analytics & Crash Reporting: We may use Google Analytics for Firebase or a similar tool to collect anonymized, aggregated usage statistics. No personally identifiable financial data is included in these reports.
- Legal Obligations: We may disclose data if required by a valid court order, subpoena, government regulation, or to protect the rights, property, or safety of Artho, its users, or the public.
- Business Transfers: If Artho undergoes a merger, acquisition, or asset sale, your data may be transferred. We will notify affected users via in-app notice or email at least 30 days before any such transfer, and you may delete your account beforehand.
- With Your Explicit Consent: We only share data with additional parties when you have given us your clear and informed consent (e.g., data export to another service you authorize).
- Aggregate & Anonymized Data: We may share statistical, non-identifiable data (e.g., 'X% of users track salary') with partners or for research. Such data cannot identify you.
4. Data Storage & Security
- Storage Location: All personal and financial data is stored on Google Cloud Platform (Firebase Cloud Firestore) servers, which may be located in the United States or other regions where Google operates data centers.
- Encryption in Transit: All data transmitted between your device and our servers uses HTTPS/TLS 1.2+ encryption, preventing interception.
- Encryption at Rest: Firebase encrypts all stored data at rest using AES-256 encryption by default.
- Access Control: Your data is strictly isolated by your unique user ID (UID). Firebase Security Rules enforce that no user can read or write another user's data under any circumstances.
- Authentication Security: Firebase Authentication supports OAuth 2.0, secure token refresh, and brute-force protection. We do not store your passwords in plain text.
- Least Privilege Principle: Our application only requests the minimum permissions necessary. We do not request access to contacts, microphone, camera, or SMS unless a specific feature explicitly requires it and you consent.
- Incident Response: In the event of a data breach that poses a significant risk to your rights, we will notify affected users without undue delay and no later than 72 hours after becoming aware of the breach.
- No security system is 100% impenetrable. We continuously work to protect your data but cannot guarantee absolute security against all threats.
5. Data Retention
- Active Accounts: Your personal and financial data is retained for as long as your account remains active and you continue to use the service.
- Account Deletion: Upon your request to delete your account, all personally identifiable data is permanently purged from our live systems within 30 days.
- Backups: Backup snapshots used for disaster recovery are purged within 90 days of account deletion.
- Anonymized Analytics: Aggregated, non-identifiable usage statistics may be retained indefinitely for service improvement purposes.
- Legal Hold: Where required by applicable law (e.g., tax regulations in your jurisdiction), certain transaction records may be retained for the legally mandated period even after account deletion. You will be notified of any such requirement.
- You may request a summary of retained data by contacting us at the email address listed in the Contact section.
6. Your Rights & Choices
- Right to Access: You can view all personal data stored in your profile at any time via the Profile and Settings screens within the app.
- Right to Correction: You can update or correct inaccurate personal information (name, email, country) through your profile settings at any time.
- Right to Deletion: You can delete individual records within the app or request full account deletion by going to Settings → Delete Account, or by emailing us. Deletion is permanent and irreversible.
- Right to Data Portability: You can export your financial data in PDF or CSV format from the Financial Reports section. This allows you to transfer your data to another service.
- Right to Restrict Processing: You may contact us to request restriction of processing of your personal data in certain circumstances (e.g., while you contest the accuracy of data).
- Right to Withdraw Consent: Your continued use of the app constitutes ongoing consent. You may withdraw consent at any time by deleting your account. Withdrawal does not affect the lawfulness of prior processing.
- Opt-Out of Analytics: You can disable anonymized analytics collection in Settings → Privacy. Opting out will not affect core app functionality.
- GDPR Rights (EU/EEA Users): If you reside in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR) including the right to lodge a complaint with your local data protection authority.
- CCPA Rights (California Users): California residents have the right to know what personal information is collected, to opt out of sale (we do not sell data), and to non-discrimination for exercising their rights under the California Consumer Privacy Act.
- To exercise any right, contact us at: support.artho@gmail.com. We will respond within 30 days.
7. Cookies & Tracking Technologies
- The Artho mobile app does not use browser cookies.
- We use Firebase Authentication session tokens stored securely in the device's local storage to maintain your login session. These are essential for app functionality and cannot be disabled.
- Firebase Analytics may use anonymized device identifiers (e.g., Firebase Instance ID) to associate usage events with a device session without identifying you personally.
- We do not use cross-site tracking, advertising trackers, or third-party marketing pixels.
- You can reset your device's advertising ID at any time through your device settings (Android: Settings → Google → Ads → Reset advertising ID).
8. Third-Party Services
- Firebase Authentication (Google LLC): Handles secure account sign-in via Google OAuth 2.0 and Email/Password. Privacy policy: policies.google.com/privacy
- Firebase Cloud Firestore (Google LLC): Stores your financial data with encryption and strict access controls. Processes data as a data processor under Google's DPA.
- Google Play Services (Google LLC): Provides app update delivery and Android platform integration.
- Google Analytics for Firebase (optional, with consent): Collects anonymized, aggregated usage statistics. No financial data is included. Can be disabled in app Settings.
- Capacitor (Ionic/Capacitor open-source): Provides the native Android/iOS bridge layer. Does not independently collect or transmit any user data.
- All third-party services listed above operate under their own privacy policies. We select partners who maintain appropriate data protection standards consistent with this policy.
9. Children's Privacy (COPPA Compliance)
- Artho is intended for users who are 13 years of age or older. Users in the European Union must be at least 16 years old, or the minimum age required by their country's applicable law.
- We do not knowingly collect personal information from children under the applicable minimum age.
- If we discover we have inadvertently collected data from a child under the minimum age, we will promptly delete that data and terminate the associated account.
- Parents or guardians who believe their child has provided personal information to us should contact us immediately at support.artho@gmail.com.
- By using this app, you represent and warrant that you meet the minimum age requirement applicable in your jurisdiction.
10. International Data Transfers
- Artho is operated from Nepal. Your data may be processed on Google Cloud Platform servers located in the United States and other countries where Google maintains data centers.
- Where data is transferred from the European Economic Area (EEA) to countries not recognized as providing adequate protection under GDPR, such transfers are covered by Google's Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework.
- By using Artho, you acknowledge and consent to the transfer of your data to countries outside your country of residence, subject to the protections described in this policy.
11. How to Delete Your Data
- In-App Deletion: Open the app → go to Profile → scroll to 'Danger Zone' → tap 'Delete Account'. This permanently deletes your account and all associated data.
- Individual Record Deletion: You can delete individual income, expense, salary, overtime, asset, or other records directly within each module by using the delete option on any record.
- Email Request: If you cannot access the app, email us at support.artho@gmail.com with the subject 'Account Deletion Request' and your registered email address. We will process your request within 30 days.
- Data Export Before Deletion: We strongly recommend exporting your data from Financial Reports before deleting your account, as deletion is permanent and cannot be undone.
- After account deletion, your data will be removed from live systems within 30 days and from backup systems within 90 days.
12. Changes to This Privacy Policy
- We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
- We will notify you of material changes by displaying a prominent in-app notice at least 14 days before the changes take effect.
- For significant changes affecting your rights, we will also send an email notification to your registered address.
- Your continued use of Artho after the effective date of the updated policy constitutes your acceptance of the changes.
- If you do not agree with the updated policy, you must stop using the app and may request account deletion.
- The date at the top of this page always shows when this policy was last revised.