Privacy Policy

Walleon  ·  Effective: May 10, 2026  ·  Version: 1.2

Our core commitment: Your sensitive financial data — transactions, budgets, categories, and recurring entries — is stored locally and securely on your device and is never transmitted to our servers. Account and authentication data is handled by Google Firebase as described below.

Walleon ("we", "our", or "us") respects your privacy and is committed to full transparency about how your data is handled. This policy applies to the Walleon mobile application on iOS and Android. By using the app you agree to the practices described here.

1 Information We Collect

1.1 Account Information

When you register or sign in, we collect:

This data is processed by Google Firebase Authentication and is subject to Google's privacy practices (see Section 6).

1.2 Financial Data — Stored Locally and Securely on Your Device

Your sensitive financial data is stored locally and securely on your device in an encrypted SQLite database. This includes: expense and income transactions, budget allocations, spending categories, upcoming bills, recurring transactions, and linked payment method metadata (see 1.4). This data is never transmitted to our servers.

If you enable Cloud Sync (where available), your financial data is additionally backed up to Google Firebase Firestore under strict per-user security rules — only you can access your own records.

1.3 Usage and Analytics Data

We use Firebase Analytics to collect anonymous, aggregated usage data — such as which screens are visited most. This contains no financial information and cannot be linked back to you personally.

1.4 Wallet Feature — Payment Method Metadata

If you link a payment card, we store the following locally on your device only:

We do not collect, store, or transmit full card numbers, CVV codes, or banking credentials. Payment processing is handled exclusively by Stripe, a PCI-DSS Level 1 certified processor (see Section 6).

1.5 Crash and Diagnostic Reports

Firebase Crashlytics automatically sends crash reports when the app encounters an unexpected error. Reports contain technical data only: device model, OS version, app version, and error stack trace. They contain no financial data.

1.6 Device Permissions

2 Information We Do Not Collect

3 How We Use Your Information

4 Security

No method of electronic storage or transmission is 100% secure. While we implement strong protections, we cannot guarantee absolute security.

5 Data Retention and Deletion

Account data is retained while your account is active. On deletion, all associated data in Firebase Auth, Firestore, and Storage is permanently removed within 30 days.

Local financial data is deleted when you uninstall the app or use "Delete All Data" in the app settings.

Analytics and crash data is retained by Google Firebase for up to 14 months.

To delete your account: Profile → Account Info → Delete Account.

6 Third-Party Services

The following services process data on our behalf, each under their own privacy policy:

7 Children's Privacy

Walleon is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided personal information, contact us at the address below and we will delete it promptly.

8 Your Rights

To exercise any right: support@walleon.app

Account and Data Deletion

You can delete your account and all associated data directly from the app (Profile → Account Info → Delete Account) or by submitting a request.

For email requests, contact support@walleon.app. Requests are processed after account ownership verification.

9 Changes to This Policy

We may update this policy periodically. The "Effective" date above reflects the latest revision. Material changes will be communicated via an in-app notice. Continued use of the app after changes are posted constitutes acceptance of the updated policy.

10 Contact

Email: support@walleon.app