Privacy Policy for Coinly
Coinly — Android app com.norvanestudio.coinly,
published on Google Play by Norvane Studio.
Last updated: October 4, 2026
Coinly ("the App") is an income and expense tracking application developed by Norvane Studio. This Privacy Policy explains what information the App collects, how it is used, stored, and protected, and what choices you have regarding your data.
By using Coinly, you agree to the terms described in this Privacy Policy.
What changed in this version. Coinly now offers AI capture: you can photograph a receipt, dictate a note, type a sentence, or submit a bank statement or an export file from another app, and have it turned into a transaction draft. That reading does not happen on your device. When — and only when — you start a capture, the file or text you chose is uploaded to the Coinly extraction service and passed to a third-party model provider. Earlier versions of this policy described receipt reading as happening entirely on the device; that is no longer accurate. Section 1 sets out exactly what leaves your device, and Section 6 lists every transmission the App makes.
Also new: automatic exchange rates. If you keep an account in a currency other than your default one, the App can now keep its exchange rate up to date by asking a public rate service, Frankfurter, for the day's reference rates. The request names the currencies involved — three-letter codes such as USD — and nothing else. Section 1 describes it, and you can turn it off at any time.
1. Information We Collect
Financial Data (Stored Locally on Your Device)
Coinly stores all financial data locally on your device. This includes:
- Income and expense transactions (amounts, dates, categories, notes, payees)
- Bank accounts, credit cards, and savings accounts
- Budgets and savings goals
- Recurring transaction rules
- Payment methods
- Personal financial notes
Your records are never automatically uploaded to any external server. Nothing is synced. The only data that leaves your device is listed in Section 6, and each item leaves only after you take the action that sends it.
Location Data (Optional)
If you choose to tag a transaction with your current location, the App captures your latitude, longitude, and a place name using your device's GPS. Location tagging is entirely optional and requires your explicit permission. Location data is stored locally on your device.
Receipt Attachments (Optional)
You may attach photos or files (e.g., receipt images, PDFs) to transactions. These files are stored locally in the App's private directory on your device. They are not uploaded anywhere unless you manually export or share them.
Attaching a receipt does not send it anywhere. Having a receipt read is a separate action you start yourself — see AI Capture below.
AI Capture (Optional — Data That Leaves Your Device)
AI capture turns something you already have into a transaction draft. It does not run on the device. To read what you submit, the App uploads it over HTTPS to the Coinly extraction service at https://coinly-api.norvane-studio.com (builds released before September 2026 use https://scribsnap.com), operated by Norvane Studio, which passes it to a third-party AI model provider whose models perform the extraction and the speech-to-text transcription.
Nothing is sent unless you start a capture. There is no background scanning, no automatic upload, and no monitoring of your photos, files, or microphone. Each capture is a separate action that you begin; the metered ones cost coins, and migrating a file from another app is free. The App contacts the extraction service only when you start a capture.
| What you choose to do | What leaves your device | What comes back |
|---|---|---|
| Scan a receipt | The photo you take with the camera | One draft transaction |
| Record a voice note | The audio recording (up to 2 minutes) | The transcript and one draft |
| Type a sentence | The text you typed | One draft |
| Import a bank statement | The PDF you select | Several drafts and a balance check |
| Import a file from another app | The CSV or Excel file you select | Several drafts and a note of how the columns were read |
Sent alongside the file or text, so the draft comes back usable: your own category list (the category names, their identifiers within the App, and whether each is for expense, income, or both) and the current date from your device (so "yesterday" resolves against your phone rather than the server). An uploaded file also carries its own filename and media type, as any file upload does. Nothing else accompanies a capture: the service will also accept a locale, a currency, and a payment method, but this version of the App does not send them.
The request carries no name, no email address, no account, and no device identifier. Coinly has no user accounts, and the App does not create or send one for this feature.
What happens to what you send:
- The extraction service keeps no copy. It is stateless: the uploaded file is held in memory for the length of the request, is not written to disk or to any database by the service, and is gone once the response has been returned. What is retained is the operational metadata described under Service Telemetry below.
- Nothing is written to your records without you. The service returns drafts. They appear in a review screen, and only what you confirm is saved to the database on your device. Your ledger stays on your device throughout — the service never receives your existing transactions.
- Voice recordings are not kept. The recording is written to a temporary file while you speak, read into memory when you stop, and deleted from your device immediately afterwards. Only the transcript comes back.
- Content is processed by the model provider under that provider's own terms. How it handles and retains what is sent to it is governed by its policy, not by this one. See Section 5.
- CSV and Excel imports send less to the model than you might expect. The whole file is uploaded to the extraction service, but only the header row and up to 15 sample rows are shown to the model, and only when the column layout cannot be worked out without it; the rows themselves are converted by ordinary code on the service. Where category names cannot be matched automatically, the distinct names are sent as a list, without the transactions they came from.
If you do not use AI capture, none of the above applies to you: no receipt, recording, statement, file, or text is sent anywhere.
Service Telemetry (Operational Metadata)
The extraction service records one row per request so that it can be monitored and debugged. Each row holds the date and time, a randomly generated identifier for that request, the endpoint called, the HTTP method and status, the outcome, how long the request took, which model was used and how long it took, token counts and billed audio seconds, the size of the upload in bytes, the media type, the confidence scores of the result, the number of rows extracted, whether a statement's balances reconciled, the number of warnings, and — when something fails — the error type and a truncated error message.
It does not hold amounts, merchant or payee names, transcripts, statement rows, category names, any part of the file you uploaded, or the model's output. This is a deliberate design rather than a side effect, and the service's automated test suite asserts that extracted values and transcripts cannot reach this store.
These rows are not linked to a Coinly account (there is none) and contain no name, email address, or device identifier. They are kept for 30 days by default and then deleted; the deletion runs periodically as newer requests are recorded.
As with any website, the web server in front of the extraction service also writes standard access logs — the connecting IP address, the timestamp, the request path, the response status and size, and the client's user agent. These are used to operate and secure the service and are rotated by the server.
Crash Reports
The App uses Firebase Crashlytics to collect crash logs and error reports. This helps us identify and fix bugs. Crashlytics may collect:
- Device model and operating system version
- App version and build number
- Stack traces and error messages
- Custom diagnostic keys (non-personal)
Crashlytics does not collect your financial data, email address, name, or any personally identifiable information.
App Configuration (Forced-Update Gate)
The App uses Firebase Remote Config to fetch a small server-side configuration value (the minimum supported app build number) that lets us require a security or compatibility update when necessary. This is a download-only configuration fetch and is used solely to decide whether the installed version must be updated. To deliver this configuration, Firebase assigns a randomly generated installation identifier to your app install. No financial data or personally identifiable information is collected through this feature.
Exchange Rates (Optional — Currency Codes Only)
If any of your accounts is in a currency other than your default one, the App can keep that currency's exchange rate up to date automatically. To do so it requests the day's reference rates from Frankfurter (api.frankfurter.dev), a free, open-source service that publishes rates compiled from central banks. The request contains only the three-letter codes of the currencies involved (for example USD,GBP) — never an amount, an account, a transaction, a category, or any identifier for you or your device. Like any request made over the internet, it reaches Frankfurter from your device's IP address; Frankfurter states that it does not log IP addresses or request URLs.
The App asks in two situations: to keep the currencies you have set to update automatically current — at most every few hours, including just before recurring transactions are recorded in the background — and to show you today's market rate when you open the exchange-rate settings, add or edit an account in another currency, or change your default currency. A rate fetched this way applies to transactions you add from then on; every transaction keeps the rate it was saved with. You can set any currency's rate yourself instead, or turn automatic updates off entirely, in Settings > Preferences > Exchange rates; with them off, the App makes no exchange-rate requests at all.
Google Account Information (Optional)
If you choose to back up your data to Google Drive, the App uses Google Sign-In to authenticate your Google account. The App accesses only your Google Drive file storage to upload and download encrypted backup files. The App does not store your email address, Google profile name, or any other Google account information.
Purchase Information
Two kinds of purchase can happen in the App. Both are processed entirely by the Google Play Store or the Apple App Store, and we never see or store your payment details.
- Sponsor purchases are voluntary and unlock nothing. The App stores only the purchase amount and date locally on your device.
- Coin packs pay for AI capture. Coins are a consumable in-app currency: each metered capture costs a fixed number of them (migrating a file from another app costs none), and packs are bought through the store. New installs receive a one-off grant of free coins, so using the feature does not require a purchase.
The App keeps a coin ledger in its local database. Each entry records the number of coins added or removed, the reason (welcome grant, purchase, capture, or refund), a detail (which kind of capture, or which pack), the store's own purchase identifier for a purchase, and a timestamp. The store's purchase identifier is stored so that the same purchase cannot be credited twice; it is never sent to the extraction service. The ledger stays on your device and is not uploaded.
2. How We Use Your Information
We use the information described above to:
- Provide income and expense tracking features
- Turn a receipt, voice note, sentence, bank statement, or export file that you submit into transaction drafts for you to review, correct, and confirm
- Operate, monitor, and debug the extraction service, using the operational metadata described in Section 1
- Sell coin packs and keep your coin balance accurate
- Generate financial reports and charts
- Send local reminders to log transactions and budget alerts
- Export your data in CSV, Excel, or PDF format
- Back up and restore your data via Google Drive or to a folder you select on your device (when you choose to)
- Diagnose and fix crashes and errors
- Check for app updates and prompt you to install them, including requiring a critical update when needed
- Invite you to rate the App via the official app store (optional, never obligatory)
- Display home screen widgets with your balance summary
3. Permissions
The App requests the following device permissions, each for a specific purpose:
| Permission | Purpose |
|---|---|
| Internet | Send what you submit for AI capture to the Coinly extraction service; fetch daily exchange rates (Frankfurter) for currencies set to update automatically; upload/download Google Drive backups; send crash reports to Firebase Crashlytics; fetch update configuration (Firebase Remote Config) and check for app updates |
| Camera | Capture receipt photos to attach to transactions, and to photograph a receipt for AI capture (optional) |
| Microphone | Record a short voice note for AI capture (optional) |
| Photo Library | Select receipt images from your gallery (optional) |
| Location | Tag transactions with your current location (optional) |
| Notifications | Send local reminders and budget alerts |
| Biometric / Fingerprint | Unlock the App using fingerprint or Face ID (optional) |
| Boot Completed | Resume background tasks (recurring transactions) after device restart |
All permissions are optional or required only for specific features. The App functions without granting camera, microphone, location, or biometric permissions.
4. Data Storage and Security
Local Storage
All financial data is stored in a local SQLite database within the App's private directory on your device. This directory is protected by your device's operating system and is not accessible to other apps.
Secure Storage
Sensitive settings such as your PIN hash and biometric preferences are stored using platform-native secure storage (Android Keystore on Android, Keychain Services on iOS).
Data in Transit (AI Capture)
Everything you submit to AI capture travels over HTTPS. The extraction service is reachable only over TLS, and the address the App uses is a fixed https:// one built into the app — there is no unencrypted fallback. Uploads are size-limited on the device before sending — 12 MB for an image, 25 MB for a recording, 20 MB for a document — so an oversized file is refused rather than transmitted.
Backup Encryption
When you create a backup — whether you upload it to Google Drive or save it to a folder you select on your device — your data is encrypted using AES-GCM-256 encryption with a passphrase you provide. The encryption key is derived using PBKDF2-SHA256 with 200,000 iterations. Without your passphrase, the backup cannot be decrypted — not even by us. Backups saved to a local folder remain entirely on your device and are never uploaded anywhere by the App.
A backup contains your financial records. It does not currently include your coin balance.
Home Screen Widgets
If you use Coinly's home screen widgets, summary data (balance, income, expense totals) is stored in shared preferences to display on your home screen. This data is visible without unlocking the App.
5. Third-Party Services
The App integrates with the following services:
| Service | Purpose | Privacy Policy |
|---|---|---|
Coinly extraction service (coinly-api.norvane-studio.com, and scribsnap.com for builds released before September 2026) | Receives what you submit for AI capture and forwards it to the model provider; returns drafts | Operated by Norvane Studio, covered by this policy |
| Third-party AI model provider | Runs the models that read receipts, speech, text, bank statements, and spreadsheet column layouts | Governed by that provider's own terms. We do not name it here; write to the address in Section 11 and we will tell you who it is and link you to its policy. |
Frankfurter (api.frankfurter.dev) | Daily reference exchange rates, for currencies set to update automatically; receives only currency codes | frankfurter.dev — states that it logs no personal data, IP addresses or request URLs |
| Firebase Crashlytics | Crash and error reporting | Google Privacy Policy |
| Firebase Remote Config | Deliver forced-update configuration | Google Privacy Policy |
| Google Drive API | Encrypted backup storage | Google Privacy Policy |
| Google Sign-In | Authentication for Google Drive backup | Google Privacy Policy |
| Google Play Services | In-app purchases, in-app updates, in-app review, and app distribution | Google Privacy Policy |
| Apple App Store | In-app purchases, app review, and app distribution (iOS) | Apple Privacy Policy |
The App does not use:
- Advertising SDKs (no AdMob, no ads)
- Analytics SDKs (no Google Analytics, no Firebase Analytics)
- Third-party tracking or attribution services
- Any server-side store of your transactions — your ledger is never synced or uploaded
6. Data Sharing
We do not sell or trade your personal or financial data. Data is shared with a third party only in the ways described here, and only to deliver a feature you use.
The only data transmitted from your device is:
- What you submit to AI capture — a receipt photo, a voice recording, text you typed, a bank statement PDF, or a CSV/Excel file, together with your category list and your device's current date. It is sent to the Coinly extraction service and forwarded to the third-party AI model provider for reading. This happens only when you start a capture, never automatically. See Section 1 for what is kept and what is not.
- Exchange-rate requests to Frankfurter, naming only the currency codes involved — no amounts, accounts or identifiers. These are made only while automatic exchange rates are on: automatically, at most every few hours, for the currencies set to update automatically, and when you view or set an exchange rate in the App
- Crash reports sent to Firebase Crashlytics (no personal or financial data included)
- Encrypted backup files uploaded to your own Google Drive account (only when you initiate a Google Drive backup)
- Configuration requests to Firebase Remote Config to retrieve the minimum supported app version (no personal or financial data included)
- Update and review requests to the Google Play Store or Apple App Store to check for app updates and to display the rating prompt (handled by the store, no personal or financial data included)
7. Data Retention
- Local data remains on your device until you delete it.
- Deleted transactions are moved to a "Deleted Transactions" section within the App. You can permanently delete them from there or restore them.
- Files and text submitted to AI capture are not retained by the Coinly extraction service once the response has been returned. Their handling and retention on the model provider's systems is governed by that provider's own policy.
- Voice recordings are deleted from your device as soon as they have been read for upload.
- Service telemetry (the operational metadata in Section 1, which holds no document content) is kept for 30 days by default and then deleted.
- Web server access logs for the extraction service are kept to operate and secure it, and are rotated by the server.
- Your coin ledger stays on your device until you delete the App's data or uninstall the App.
- Google Drive backups remain in your Google Drive account until you manually delete them. The App does not automatically delete backups.
- Crash reports are retained by Firebase Crashlytics according to Google's data retention policies.
8. Your Rights and Data Deletion
You have full control over your data:
- View your data: All data is visible within the App.
- Export your data: You can export transactions to CSV, Excel, or PDF at any time.
- Delete individual records: You can delete any transaction, account, budget, or goal.
- Delete all data: You can erase all App data from Settings > Data > Wipe all data. This action is irreversible. Your coin balance is deliberately kept, so that coins you paid for are not destroyed by clearing your records.
- Decline AI capture: The feature is opt-in on every use. It never runs on its own, so choosing not to start a capture is all that is needed to keep everything on your device.
- Remove Google Drive backups: You can delete backup files directly from your Google Drive.
- Uninstall the App: Uninstalling Coinly removes all locally stored data from your device.
The App does not maintain user accounts on a server, so there is no profile to delete. The extraction service keeps no copy of what you send it, so there is nothing there to retrieve or erase. The operational metadata described in Section 1 is not linked to you and cannot be traced back to an individual user, which also means it cannot be selectively deleted on request; it is deleted on the 30-day schedule above. If you have any questions or requests regarding your data, please contact us at the email address below.
9. Children's Privacy
Coinly is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided data through the App, please contact us and we will take steps to delete it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be reflected by updating the "Last updated" date at the top of this page. We encourage you to review this Privacy Policy periodically. Continued use of the App after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:
Email: norvane.studio@gmail.com
This privacy policy applies to the Coinly app available on Google Play Store and Apple App Store.