Masarify

Public legal documents

View the Project on GitHub Montivagant/masarify-legal

Privacy Policy

Last updated: 2026-09-30

Masarify (“we”, “our”, or “the app”) is a personal finance tracker. This policy describes what data the app collects, how it is used, and your rights over it.

What we collect

What we do NOT collect

Permissions

All permissions are optional. The core finance-tracking features work fully offline.

Crash & error diagnostics (optional, OFF by default)

Crash diagnostics are separate from usage analytics and are off by default. If you enable them — on the consent screen when you set up the app, in the home-screen prompt, or in Settings → Privacy — Masarify sends crash reports to Sentry in the EU so we can fix reliability problems. Turning analytics on does not turn crash diagnostics on, and either choice can be changed independently.

A crash report contains the exception type, the code location and limited app and operating-system context. Performance tracing and profiling are disabled. Before sending, the app removes database statements and their values, masks digit sequences, Arabic text and email addresses in exception messages, and keeps only a limited set of breadcrumbs, with navigation routes normalized. Reports must not contain amounts, merchant or account names, notes, AI chat content, your name, email, advertising identifier, or an analytics installation identifier. This processing is based on your explicit consent.

Usage analytics (optional, OFF by default)

Usage analytics are off by default. Only if you explicitly opt in do we collect pseudonymous product analytics to understand feature adoption, quality and subscription conversion. Events carry a random identifier stored by this installation of Masarify and a keyed account code: a one-way cryptographic code (HMAC) that our server derives from your app’s Firebase account ID. Neither is your advertising ID, name, email or store account, and the raw account ID is never stored with analytics. Because both are stable, events can be grouped into sessions and funnels and linked to the same app account’s subscription record (see Subscriptions); the data is therefore pseudonymous, not anonymous, and it is linked to your app account.

Collected fields are limited by a closed schema. They include canonical feature events and screen names; session and event IDs; app version, platform, locale, OS-major version, broad device/screen classes and timezone offset; coarse counts and bands such as wallet/goal adoption, transaction-count band, budget-health band, AI-usage band, free/Pro tier, broad age/income/spending brackets and a built-in top-category key. Our first-party schema does not collect gender, exact profile values, bracket midpoints, exact financial amounts, balances, individual transaction or recurring-bill details, custom names, notes, AI content, raw error messages, full device model, precise coordinates, advertising IDs, or screen recordings. Purchase-funnel events may contain only a low-cardinality store product key (such as monthly/yearly and a founding-offer band) and a closed outcome such as started, succeeded, restored, failed, or cancelled; they never contain a store receipt, purchase token, order number, price, or payment details. Route query strings and record IDs are removed. Unknown fields and events are rejected on the device and again by our server.

Our server may derive an approximate city, region and country from the request IP using an offline DB-IP database (IP Geolocation by DB-IP). The IP is used in memory for this lookup and is never stored or sent to a geolocation service. We collect no postal code and no precise/GPS location for analytics.

Analytics are sent to our own servers on Google Cloud in the European Union. During a measured migration period, the same allowlisted event names and sanitized app-supplied properties are also sent to PostHog’s EU service so we can compare loss and counts before removing it. Its native SDK may add standard app/device context, including device model and operating-system version. PostHog lifecycle autocapture, feature flags, surveys, error capture and session replay are disabled; no screen frames are collected. PostHog will be removed only after the documented parity and rollback gates pass, so that the privacy migration does not silently destroy operational visibility.

Firebase authentication protects the ingest callable. Our server derives the keyed account code from the authenticated account ID, which is used only in memory and never stored or logged with analytics. We use the code to answer product questions — which features subscribers use before and after subscribing, whether the paywall works, why people cancel — never for advertising, and never combined with data from other companies. The code is not sent to PostHog. We do not add your name, email or store account to analytics. Broad income, spending, savings and budget-health brackets are kept only where the law permits; our server can drop them without an app update.

Raw analytics events are kept for at most 14 months and then deleted automatically. You can stop future collection at any time, clear unsent events, or use Settings → Privacy → Delete analytics history to request deletion for the current installation. Clearing app data also requests deletion of the current installation’s analytics history, gives the installation a new identifier, and resets consent to off. Deleting your account deletes analytics linked to its keyed account code. Deleting analytics does not cancel a store subscription or delete an optional Masarify account because those systems are deliberately separate. After deletion, we retain only a keyed, non-reversible tombstone for at most 14 months—without the raw installation ID or any events—so a restored device backup cannot accidentally reuse an identifier that was deleted. This processing is based on your explicit consent.

Cloud reminders (optional, OFF by default)

Masarify can remind you about your spending using on-device notifications, which work fully offline. If you additionally turn on Cloud reminders (Settings → Reminders), we register your device with Google’s Firebase Cloud Messaging (FCM) so reminders can be delivered even when the app is closed. When enabled, a small amount of non-financial data is sent to and processed by Google (Firebase) on servers outside Egypt: an anonymous device notification token (a pseudonymous identifier for your app installation, not tied to your name or account), your chosen reminder schedule — the daily-reminder time and the dates of any bill or subscription reminders you’ve set — your timezone, and your app language. We never send your financial data — transactions, amounts, wallets, budgets, notes, bill names, and AI content are never included in reminder messages or their metadata; a bill push only says a reminder is due. You can turn Cloud reminders off at any time; doing so deletes the token from your device and removes it from our records the next time your device is online, which stops the transfer. Uninstalling the app, or prolonged inactivity, also invalidates the token. This processing is based on your explicit consent, and this cross-border transfer to Google/Firebase is disclosed here in line with Egypt’s Personal Data Protection Law (Law 151 of 2020).

In-app feedback (optional)

You can send us feedback from inside the app (Settings → Send feedback, or the home-screen invitation). When you choose to submit, the following is sent to and stored on Google’s Firebase (Firestore) on servers outside Egypt: your message text, the category you picked (bug/idea/other), your app version, platform (e.g. android), the app language, and — only if you type it — an optional contact email. We never attach your financial data, and submissions are not linked to your identity unless you include your email. Feedback is used solely to fix issues and improve the app, is never sold or shared, and you can request deletion of any submission at any time via the contact email below. Sending feedback is always your explicit action — nothing is sent automatically.

Account & sign-in (optional, OFF by default)

Masarify works fully without any account — by default you use the app anonymously and all of your data stays on your device. You may optionally sign in (Settings → Account) using either Google or Sign in with Apple.

Sign in with Google: We use Google’s Firebase Authentication to establish a secure identity. The data involved is limited to your Google email address and basic profile (display name), which are processed by Google (Firebase) to authenticate you.

Sign in with Apple: Apple authenticates you and provides a secure token and — if you do not choose to hide your email — your Apple ID email address, which is processed by Apple and then by Firebase Authentication to establish a secure identity. If you choose to hide your email, Apple provides a private relay address instead. No display name is shared unless you provide one.

In both cases a pseudonymous account identifier is created. We do not attach your transactions, amounts, wallets, budgets, notes, or any other financial data to this account — your finances never leave your device because you signed in.

Signing in is purely additive: it gives you a stable identity (for example to support future optional cloud sync) and is required for none of the app’s features. You can sign out at any time, or permanently delete your account (Settings → Account → Delete account), which removes the Firebase identity and any associated cloud-reminder record. The Google sign-in is separate from the optional Google Drive backup sign-in described above. This processing is based on your explicit consent, and the transfer to Google/Firebase (on servers outside Egypt) is disclosed here in line with Egypt’s Personal Data Protection Law (Law 151 of 2020).

Subscriptions

Masarify offers a Pro subscription unlocking advanced features. Billing is handled by Google Play (on Android) or the Apple App Store (on iOS). We do not see your payment-card or bank details. When you subscribe, the app sends the store an opaque, store-specific billing identifier: Google receives a 64-character keyed hash; Apple receives a random UUID. Our billing registry stores the mapping between that identifier and the Firebase account used for the purchase. When you buy or restore, the app also sends the store’s proof of purchase to our server, which verifies it with Google or Apple and records which app account holds the subscription. We also receive the stores’ own subscription notifications (Google Play real-time notifications and Apple App Store Server Notifications). These records hold the product and plan or offer, the purchase token or transaction ID, status, region, and renewal, expiry, cancellation and refund dates — and, where the store provides it, the reason category you chose when cancelling, never any text you typed. We never fill a gap by trusting subscription status the app reports about itself. Subscription records are used for app functionality, fraud prevention, support and account deletion, and — only if you opted into usage analytics — linked through the keyed account code to understand how subscribers use Masarify. Never for advertising.

Data retention and deletion

Your on-device data. Your finances live on your device. To delete everything, uninstall the app or use the in-app Clear all data option (Settings). If you used Drive backup, you can delete that backup from your Google Drive’s “App Data” management page at any time.

Deleting your account. If you signed in — via Google or Sign in with Apple (see “Account & sign-in” above) — you can permanently delete your account and its associated data in either of two ways:

After deletion we keep no account data, aside from copies Google/Firebase may hold transiently in their own backups, which expire on Google’s standard schedule.

Three things are deliberate exceptions, and we would rather name them than let you assume otherwise:

Children’s privacy

Masarify is intended for users aged 18 and older. Because its AI features use Google’s Gemini API — which requires users to be 18+ — the app is not directed at, and must not be used by, anyone under 18. We do not knowingly collect data from minors.

Changes to this policy

We may update this policy. Changes will be reflected here with an updated “Last updated” date.

Contact

For privacy questions: omarwalidghazal@gmail.com