Privacy Policy
Effective: 27 July 2026 · Last updated: 27 July 2026
Boody is an iOS app for tracking your expenses and monthly budget. This policy explains what data is processed when you use the app, where it is stored, and how you can control it.
1. Data controller and contact
The app is published by an individual developer. For any privacy question or request: boody@obalabs.app
2. Data we process
a) Account information
- Email address and display name — collected when you create an account or sign in with Google.
- Password — stored encrypted by Firebase Authentication; the developer cannot see it.
- If you sign in with Google, Google shares your account email and name for authentication. We never see your Google password.
b) Budget and expense data
- Categories, budget items, planned monthly amounts
- Expense records: amount, date, note, category/item, payment method
- Payment methods you define (e.g. “Cash”, “Card” — labels you choose). Card numbers, IBANs and bank details are never requested or stored
- The currency preference of a budget space
- Who entered a record, in a shared budget
c) Shared budget (household) data
- Household name, member user IDs, invite code, creation date
- Members' name and email address, so the “who spent this” label can be shown — visible only to members of the same household
d) Purchases
Premium purchases are made through Apple. Your payment details (card, Apple ID password, billing address) go directly to Apple and never reach or get stored by us. The app only reads from Apple whether a valid premium entitlement exists on this device.
e) Siri and widget
Expenses added via Siri shortcuts are processed on your device and stored like any other expense. Siri's own voice processing is governed by Apple's privacy policy. The home screen widget reads from a shared app group on the same device (group.com.boodyapp); no data leaves the device for this.
3. What we do not collect
- Bank account connections, card numbers, IBANs, open banking data
- Location, contacts, photos, health data, microphone recordings
- Advertising identifier (IDFA), ad networks, third-party trackers
- Analytics, usage telemetry or crash reporting SDKs
Boody does not track you in the App Store's “App Tracking Transparency” sense and does not link your data across companies.
4. Where data is stored
- On your device: all budget data is kept in a local database and works offline.
- In the cloud: if you sign in, data is stored on Google Firebase (Authentication and Cloud Firestore). Firestore security rules restrict household data to members of that household.
- Firebase servers may be located outside your country (Google data centres), so cloud-synced data may be transferred internationally.
5. Why we process it
- To provide budget and expense tracking
- To sync across your devices and household members
- To verify your premium entitlement
- To answer support requests you send us
Your data is not used for advertising, profiling, credit scoring or marketing, and is not sold to third parties.
6. Sharing
Data is shared only with:
- Your household members: people you invite to a shared budget can see all budget and expense records in that household.
- Google (Firebase): as hosting and authentication provider — Firebase privacy information.
- Apple: for purchases and subscription management.
- Authorities, where required by law.
7. Retention
Data is kept until you delete it or close your account. Deleting the app removes the local copy but not the cloud record.
8. Your rights — data deletion
You can delete your account from inside the app: Settings → Account → Delete my account. It takes effect immediately and covers the Firebase Authentication record, the users/{uid} profile, local data on your device and — if no other member remains in the household — all of that household's budget and expense records. If other members remain, only your membership is removed and the shared budget stays with them.
Alternatively, email boody@obalabs.app from your account's email address; such requests are completed within 30 days.
If you are in a shared budget, records shared with the household may remain for the other members; say so in your request if you want those removed too.
Under Türkiye's KVKK (Law 6698) and, where applicable, the GDPR, you have the right to access, correct, delete, restrict processing of, port, and object to the processing of your data. Use the same address to exercise them.
9. Security
All traffic between device and server is encrypted with TLS. Access to cloud data is restricted by Firestore security rules based on household membership. No system is 100% secure; protect your account with a strong password you use nowhere else.
10. Children
Boody is not directed at children under 13 and does not knowingly collect data from them. Any such data found will be deleted.
11. Changes
This policy may be updated. For significant changes the effective date is revised and, where possible, you are notified in the app.
12. Languages
This policy is published in Turkish, English, German and Spanish. If the translations conflict, the Turkish text prevails.