CountaBill
Privacy Policy
Last updated: 27 August 2026
This Privacy Policy explains how CountaBill ("we", "our", or "us") collects, uses, stores, and protects your personal information when you use our mobile application ("the App"). By using the App you agree to the practices described here.
1. Who We Are
CountaBill is an independent mobile application developed by Logical Solutions Innovations (Pty) Ltd for personal financial management. Our launch scope includes South Africa, the United Kingdom, the United States, and the Netherlands. We are not a financial institution, not a registered Financial Services Provider (FSP) under FAIS, not a registered Credit Provider under the NCA, and we do not provide financial advice.
2. Information We Collect
2.1 Information you provide
- Account information: email address and password (Firebase Authentication), or Sign in with Apple (which may provide your email and/or display name as you choose). We store your email address, display name, and Firebase user ID.
- Transaction data: merchant names, amounts, dates, categories, and notes you enter manually or via receipt scanning.
- Budget and financial data: income amounts, budget limits, debit orders, bill splits, debts, fuel logs, meals, and events you record in the App.
- Receipt images: photos you take or upload for AI extraction. See section 2.3 for how these are handled.
- Split and debt data: names of people you split bills with and amounts owed. These names are typed manually by you — we do not access your device contacts.
- Store locations from scans: when you scan a receipt with location permission granted, we use your device location only in the moment of scanning to help identify the store. We do NOT store the precise GPS coordinates of the location where you scanned a receipt; location is used only in the moment of scanning to help identify the store, and is then discarded. Merchant coordinates may be retained separately as anonymised store pins on the spending map.
2.2 Information collected automatically
- Crash reports and diagnostics: via Firebase Crashlytics. These reports include device model, OS version, app version, and a stack trace of the error. They do not include your financial data.
- Anonymised usage analytics: via Firebase Analytics. We track which features are used, session duration, and general navigation flows. This data is aggregated and cannot be linked back to you personally. Analytics can be disabled in Settings > Data & Privacy.
- Push notifications: via Firebase Cloud Messaging when you opt in to notifications (e.g. price-change alerts for stores you follow).
- Anti-abuse protection: via Firebase App Check to help prevent unauthorised access to our backend.
- Feature configuration: via Firebase Remote Config to deliver app settings and feature flags.
- Device location: only when you have granted the "When in use" location permission. Location is captured only at the moment you scan a receipt — it is used to identify the store on the in-app map (map tiles via OpenStreetMap). We do NOT store the precise GPS coordinates of the location where you scanned a receipt. Location is used only in the moment of scanning to help identify the store, and is then discarded. The app does not track your location at any other time.
2.3 Receipt images and AI processing
- When you scan a receipt, the photo is uploaded to Firebase Storage and sent securely to Google Gemini via our Firebase Cloud Functions. We use the paid Gemini API tier, which contractually prohibits Google from training models on your data. The image is processed in real time to extract line items and amounts and is not retained by Google beyond transient processing. No other AI providers are used.
- If you opt in to data collection in Settings > Data & Privacy, receipt images are first analysed for personally identifiable information (PII) by our AI processor (Google Gemini, paid tier). Detected PII regions — including faces, addresses, loyalty numbers, phone numbers, names, and other personal identifiers — are then irreversibly blurred using Gaussian blur before the image is stored in our training dataset. EXIF metadata is stripped; precise location is reduced to ~1 km accuracy; and your user ID is replaced with a salted one-way hash. You can opt out at any time and previously anonymised data cannot be re-linked to you.
2.4 Split names and payment requests
The App does not access your device contacts and does not request contacts permission. When you split a bill, you type names manually. These names are stored in your device's secure storage (iOS Keychain / Android Keystore) only — they are never uploaded to our servers. When you send a payment request, the app uses the system share sheet (e.g. WhatsApp, Messages, or email) to deliver a plain message such as "Please pay R X for [item]" — no banking or payment account details are included or stored.
2.5 Aggregated price data
When you scan receipts, anonymised store/item/price observations (with your user ID replaced by a one-way hash) may be shared to power price-trend and specials features visible to other signed-in users. No personal identity is attached to these observations.
3. How We Use Your Information
- To provide, maintain, and improve the App and its features.
- To sync your data across devices when you are signed in with an account.
- To process receipt images using AI to extract transaction data.
- To detect price changes and send push notifications when you have opted in to follow a store.
- To improve AI receipt extraction accuracy through aggregated, anonymised training data (only if you have opted in).
- To detect crashes and fix bugs via diagnostic reports.
- To respond to support queries you send us directly.
4. Data Sharing, Sale, and Third-Party Processors
4.1 Sale or licensing of anonymised data
We do not sell your personal information. However, if you have opted in to data collection in Settings > Data & Privacy, we may license or sell aggregated, fully-anonymised receipt data to third parties (such as AI research labs, market-research firms, and retailers) to improve receipt-understanding systems and price-tracking products.
This anonymised dataset contains no personal identifiers, faces, addresses, account numbers, signatures, or location information finer than ~1 km. Each record has had its EXIF metadata stripped and its submitter user ID replaced with a salted one-way hash before storage. You can opt out at any time in Settings > Data & Privacy or via our Do Not Sell or Share page.
4.2 Operational processors
We share operational data only with the service providers listed on our Subprocessors page, strictly to operate the App. Each provider acts as a data processor on our behalf and is contractually bound to protect your data.
Where relevant, data is transferred to and processed on Google Cloud infrastructure that may be located outside your country. International transfer mechanisms are described in sections 6, 7, and 8 below.
- Google LLC (Firebase, Google Cloud, Gemini): authentication, database, storage, server-side processing, analytics, crash reporting, push messaging, anti-abuse, feature configuration, and receipt extraction.
- Apple Inc. (Sign in with Apple): authentication when you choose to sign in with your Apple ID.
- OpenStreetMap Foundation: map tiles and Nominatim geocoding. Only store names are sent — no personal data.
- Cloudflare Inc.: website hosting and CDN for this marketing site.
- Buyers / licensees of the anonymised dataset (section 4.1): third parties who purchase or license the anonymised receipt dataset. Because the data is anonymised before transfer, no personal information about you is shared with these recipients.
- Law enforcement or regulators: we will disclose information when required by applicable law or a valid court order.
Retention windows
- Transaction and budget data: retained until you delete your account or the specific record.
- Crash and analytics data: retained for up to 90 days by Google per Firebase default policies.
- Anonymised training examples and aggregated price observations: retained indefinitely after your personal information has been irreversibly stripped.
Data controller
The data controller is Logical Solutions Innovations (Pty) Ltd. POPIA Information Officer details are in section 6 below. Contact: support-budget.app@logicalsolutionsinnovations.com
5. Data Storage and Security
Your data is stored in two places:
- On your device: a local SQLite database (Drift) holds transactions, budgets, income, settings, split names, and other records regardless of whether you have an account. Local data is encrypted at rest using SQLCipher (AES-256) with a key stored in the device secure element (iOS Keychain / Android Keystore).
- Google Firebase (cloud): when you are signed in, your data — including transactions, budgets, income, debit orders, categories, receipts (photos and extracted line items), bill splits, fuel logs, meals, events, debts, and merchant store pins — is mirrored to your private Firebase Firestore and Firebase Storage. Firebase complies with SOC 2 and ISO 27001 standards.
Data in transit is encrypted via TLS. Firebase security rules and Firebase App Check ensure your cloud data is accessible only to your authenticated account. Guest mode users have no cloud storage — data exists only on device.
6. Your Rights Under POPIA (South Africa)
This app is governed by the Protection of Personal Information Act, 2013 (POPIA).
- Responsible Party: Logical Solutions Innovations (Pty) Ltd.
- Information Officer: Guy Church, contactable at support-budget.app@logicalsolutionsinnovations.com.
- Processing principles: we process your personal information lawfully and only for the purposes described in this policy (processing limitation, purpose specification, and further-processing limitation).
- Lawful basis: your consent (given at sign-up and via the in-app consent screen) and our legitimate interest in providing and securing the service.
- Your rights: you may request access to the personal information we hold about you; request correction or deletion; object to processing; and withdraw consent at any time. You can delete all your data yourself via Profile > Delete account, or by emailing us. Access requests under PAIA are handled via our PAIA Manual.
- Security safeguards: data is encrypted in transit (TLS) and protected by per-user access rules, Firebase App Check, and authentication. See section 5.
- Cross-border transfer: your information is processed on Google Cloud infrastructure that may be located outside South Africa. Where this occurs, the recipient is subject to laws or agreements providing an adequate level of protection comparable to POPIA.
- Children: the app is not intended for persons under 18.
- Complaints: you may lodge a complaint with the Information Regulator (South Africa): Website inforegulator.org.za, email POPIAComplaints@inforegulator.org.za / enquiries@inforegulator.org.za, JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001.
7. GDPR — European Union / European Economic Area
If you are located in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) applies to our processing of your personal data.
7.1 Lawful bases (Article 6)
- Article 6(1)(b) — Contract: processing necessary to provide the App and its core features (account, sync, receipt extraction, budgets).
- Article 6(1)(a) — Consent: optional processing including anonymised training data collection, analytics, push notifications, and price-observation sharing. You may withdraw consent at any time in Settings > Data & Privacy.
- Article 6(1)(f) — Legitimate interests: fraud prevention, security (App Check), and service improvement where not overridden by your rights.
Special category data (Article 9): we do not currently collect special category personal data (e.g. race, ethnicity, health, biometric data). If such data were introduced in future, we would rely on Article 9(2)(a) explicit consent before processing.
7.2 Your rights
- Access (Art. 15): request a copy of your personal data.
- Rectification (Art. 16): correct inaccurate data.
- Erasure (Art. 17): request deletion of your data.
- Restriction (Art. 18): request limited processing in certain circumstances.
- Portability (Art. 20): receive your data in a structured, machine-readable format via Settings > Export my data.
- Objection (Art. 21): object to processing based on legitimate interests.
- Automated decisions (Art. 22): we do not make decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise any GDPR right, email support-budget.app@logicalsolutionsinnovations.com with the subject line "GDPR Request". We respond within 30 days.
7.3 International transfers
Transfers of personal data to the United States (Google Cloud / Firebase / Gemini) rely on the European Commission's Standard Contractual Clauses (SCCs) 2021, Module 2 (Controller to Processor), as incorporated in the Google Cloud Data Processing Addendum and the Google Cloud SCCs. Supplementary measures are documented in our Transfer Impact Assessment.
7.4 EU representative
To be appointed prior to launch — details will be published here. An Article 27 EU representative will be designated before the App is made available to users in the Netherlands and other EU/EEA countries.
7.5 Supervisory authority
You have the right to lodge a complaint with your local supervisory authority. For users in the Netherlands, the competent authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). Users in other EU/EEA countries may contact their local data protection authority.
8. UK GDPR — United Kingdom
If you are located in the United Kingdom, the UK GDPR and Data Protection Act 2018 apply. Your rights under UK GDPR are identical to those described in section 7.2 (access, rectification, erasure, restriction, portability, objection, and rights regarding automated decision-making).
Transfers of personal data to the United States rely on the UK International Data Transfer Agreement (IDTA) Addendum to the SCCs, as incorporated in the Google Cloud DPA.
8.1 UK representative
To be appointed prior to launch — details will be published here. An Article 27 UK representative will be designated before the App is made available to users in the United Kingdom.
8.2 Complaints
You may lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint/
9. California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights:
- Right to Know: you may request details about the categories of personal information we collect and the purposes for which we use it.
- Right to Delete: you may request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale or Sharing (§1798.120): if you have opted in to data collection, anonymised receipt data may be sold or licensed to third parties (see section 4.1). See our dedicated Do Not Sell or Share My Personal Information page for opt-out instructions.
- Right to Limit Use of Sensitive Personal Information (§1798.121): see our Limit the Use of My Sensitive Personal Information page. We do not currently collect sensitive personal information as defined by CPRA.
- Global Privacy Control (GPC): we honour GPC signals as a valid opt-out of sale/sharing.
- Non-discrimination: we will not discriminate against you for exercising any CCPA/CPRA rights.
To exercise any CCPA/CPRA right, email support-budget.app@logicalsolutionsinnovations.com with the subject line "CCPA Request". We respond within 15 business days.
10. Account Deletion and Data Export
You can manage your data at any time from Settings > Profile:
- Delete account & data: immediately erases your Firebase account, all associated cloud data, and local data on your device. Residual backups roll off within 30 days. Already-anonymised training examples and aggregated price observations cannot be re-linked to your identity and may be retained.
- Export my data: downloads a copy of all your financial data in a portable format for your own records.
11. Children
The App is not intended for persons under 18. We do not knowingly collect personal data from children. If you believe a person under 18 has provided personal information to us, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via an in-app notice and you may be asked to re-consent. The date at the top of this page reflects the last update. Continued use of the App after changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy questions, to exercise your rights under POPIA, GDPR, UK GDPR, or CCPA/CPRA, or to request data deletion, contact us at:
Information Officer: Guy Church
Email: support-budget.app@logicalsolutionsinnovations.com