Privacy Policy

Last updated: July 30, 2026

This Privacy Policy is designed to provide clarity about the personal information and data collected by Bakiye.io and/or its agents, consultants, employees, officers and directors. It explains how this information is collected, why it is processed, how and where it is used, how long it is retained, and whether it is shared with other parties. By using the Bakiye.io web application, you give your explicit and informed consent to the processing of your personal information in accordance with this Privacy Policy and Terms of Service.

As per definition, "personal data is any information relating to an individual, whether it relates to his or her private, professional or public life. It can be anything from a name, a home address, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer's IP address."

Information We Collect

Bakiye.io collects data from you through your interactions with our application. Bakiye.io uses third-party services, and these services may collect both non-personal and personal data.

Personal Information

  • Registration Information: Email address, password (stored in encrypted form), first name and last name
  • Usage Data: IP address, device information, browser type, operating system, screen resolution, language preference
  • Financial Data: Income and expense transactions, savings information, categories, notes (transaction and savings amounts are stored as numbers)
  • Family Information: Family group information, data sharing between family members

Non-Personal Information

Non-personal information includes technical information, behavioral data, and statistical data. This type of data cannot be used to personally identify you. Non-personal information may include:

  • Operating system type (e.g., Windows, macOS, Linux, iOS, Android)
  • Browser type (e.g., Chrome, Firefox, Safari, Edge)
  • Screen resolution
  • Language preference
  • Device type
  • General location information (at country/city level)

How We Collect Information

We work with third-party services. Below is a concise list of such services, the type of personal information they collect, and links to their Privacy Policies (if available). We may use one or more of these services at different times.

Authentication and Data Storage:

Service ProviderPersonal Information
Firebase AuthenticationEmail address, name, last name, unique user identifier, authentication tokens
Cloud FirestoreUser profile information, transaction data, savings information, family information (transaction and savings data)

Analytics:

Service ProviderPersonal Information
Firebase AnalyticsCookies, unique device identifiers for advertising, and usage data

Infrastructure:

Service ProviderPersonal Information
Upstash RedisTemporary IP address and request data for rate limiting

When you contact us directly (such as to request information, report a bug, or for Customer Support), we may receive additional information about you, such as your contact information and the contents of your communication.

Why We Collect Information

  • Service Provision: To track your financial data, generate reports, and provide the core functions of the application
  • Security: To protect your account with Firebase Authentication and keep data access limited by Firestore security rules; financial amounts are stored as plain numbers and transmitted over HTTPS
  • User Experience: To fix bugs, improve application flow, and shape the application according to user preferences
  • Communication: To respond to inquiries sent to the email address you provide for customer service or technical support purposes
  • Security and Abuse Prevention: To prevent API abuse through rate limiting

Where and How Long We Retain Information

Your data is stored in the following ways:

  • Firebase Firestore: All your user data and financial transactions are stored in Firebase Cloud Firestore. Financial data (including transaction and savings amounts) is stored in Firestore.
  • Firebase Authentication: Your authentication information is securely stored in the Firebase Authentication system.
  • Upstash Redis: Temporary data required for rate limiting is stored. This data is typically automatically deleted within a few minutes.

Retention Period: Your data will continue to be retained as long as you do not delete your account. When you delete your account, all your personal data and financial data will be permanently deleted within 30 days.

Analytical data collected by third-party services is stored by those services themselves. We have limited control over this data, and the retention period of this data is subject to the privacy policies of the relevant services.

Do We Share Information We Collect

Bakiye.io is not a data mining company and we do not share your information with any other third party. However, the third-party services we use in our application may share the personal information they collect with other parties under the conditions set forth in their own Privacy Policies.

We do not disclose any part of your information unless required by law. We may disclose information about you in the following circumstances:

  • If required by law, regulation, or legal process (e.g., court order or subpoena)
  • In response to requests by government agencies (e.g., law enforcement authorities)
  • When we believe disclosure is necessary or appropriate to protect against or respond to physical, financial, or other harm, injury, or loss to property
  • In connection with an investigation of suspected or actual unlawful activity
  • With your explicit consent

Note: If you use the family feature, your data is shared with family members. This sharing is limited only to authorized members within the family group.

Security

To ensure the security of your data, we take the following measures:

  • Data storage: Financial amounts are stored in Firebase Cloud Firestore
  • Secure Authentication: Secure user authentication with Firebase Authentication
  • Firestore Security Rules: Strict security rules for data access control
  • Rate Limiting: Rate limiting to prevent API abuse and DDoS attacks
  • HTTPS: All data transmission is performed encrypted over HTTPS

Your Rights

  • You have the right to access your personal data
  • You have the right to receive information about how your personal data is being processed
  • You have the right to request the erasure of personal data related to you that we retain on our own servers
  • You have the right to request the correction of your personal data
  • You have the right to object to the processing of your personal data (for analytical data)
  • You have the right to delete your account and all your data

You can contact us to exercise these rights (contact information below).

Our application is not designed for children under the age of 13, and we do not knowingly collect personal information from children in this age group. If a child under the age of 13 uses our application and personal information is collected, Bakiye.io cannot be held liable. If we learn of this, we will take reasonable measures to promptly delete such information from our records.

Cookies

Our application uses cookies for authentication and session management. These cookies are necessary for the proper functioning of the application. Additionally, third-party services (such as Firebase Analytics) may use cookies for analytical purposes.

Contact Us

If you have any questions, comments, or concerns regarding our Privacy Policy and/or practices, please contact us by email:chnakbs@gmail.com

Updates to this Privacy Policy

We will post any adjustments to this Privacy Policy on this page, and the revised version will be effective when it is posted. If we materially change the ways in which we use or share Personal Information previously collected from you through our products, we will notify you through our product, by email, or other communication.