Saltar al contenido

CashWhisper — Política de privacidad

English version below

Última actualización: 14 de septiembre de 2026

Esta política describe CashWhisper desde la versión 1.9. Hasta la 1.8.3 de Android, la app no pedía permiso antes de usar la IA, no tenía «Borrar todos mis datos» ni el botón «Reportar», y las estadísticas incluían el importe y la categoría de los gastos (apartado 4.2).

1. Quién es el responsable

CashWhisper es una app de Sobeklab SL (CIF B05560719, Plaza Violonchelista Miguel Ángel Clares, 23, 30157 Algezares (Murcia), España), que es la responsable del tratamiento de los datos descritos aquí. Contacto para cualquier asunto de privacidad: info@sobeklab.com.

2. Resumen

  • Tus gastos se guardan en tu teléfono. No tienes que crear una cuenta, no conectamos con tu banco y no tenemos una base de datos con tu historial.
  • Solo si lo permites, lo que escribes en el chat se envía a la IA Gemini de Google, a través de nuestro servidor, para convertirlo en un gasto; y si haces una pregunta, también se envían los totales de tus gastos (nunca las descripciones).
  • Usamos Firebase (Google) para estadísticas de uso anónimas e informes de fallos, que puedes desactivar en Ajustes, y RevenueCat para gestionar la suscripción. Desde la versión 1.9 no incluyen tus gastos ni sus importes.
  • No vendemos tus datos, no mostramos publicidad dentro de la app y no te rastreamos entre apps de otras empresas.
  • Puedes borrarlo todo desde Ajustes > Datos > Borrar todos mis datos.

3. Datos que se quedan en tu teléfono

La app guarda dentro del teléfono:

  • en una base de datos SQLite, tus gastos (importe, moneda, categoría, descripción y fecha), tus presupuestos, tus gastos recurrentes y tus logros;
  • en sus preferencias, tus ajustes y el estado de la app (moneda, recordatorios y su hora, tus decisiones sobre la IA y los datos de uso, si has visto la introducción, rachas, número de preguntas del mes, etc.).

Estos datos no los cifra la propia app; la protege el propio sistema del teléfono (el aislamiento entre apps y, con el teléfono bloqueado, el cifrado del dispositivo). Nosotros no tenemos acceso a ella.

Copias de seguridad. En iPhone, estos datos entran en la copia de seguridad del dispositivo (iCloud o el ordenador) si la tienes activada: esa copia es tuya y la gestiona Apple, no nosotros. En Android, la app no permite la copia de seguridad automática de Google, así que si desinstalas la app o cambias de móvil, los datos se pierden (puedes exportarlos a CSV si tienes PRO).

Los recordatorios se programan en el propio teléfono; no pasan por ningún servidor.

4. Datos que salen de tu teléfono

4.1 La IA: Google Gemini (solo con tu permiso)

Antes de enviar nada, la app te explica qué se envía y te pide permiso. Si eliges «Ahora no», no se envía nada y puedes apuntar los gastos a mano. Puedes retirar el permiso en cualquier momento en Ajustes > Privacidad > Leer gastos con IA.

Con tu permiso:

  • Al apuntar un gasto por el chat se envía: el texto que escribes, tu moneda, la lista de categorías de la app, el idioma, la fecha de hoy y la diferencia horaria de tu teléfono. Sirve para extraer el importe, la moneda, la categoría, la descripción y la fecha del gasto, que tú confirmas antes de guardarlo.
  • Al hacer una pregunta («¿en qué gasto más?») se envía: la pregunta, el idioma, tu moneda, el total del mes en curso, el total por categoría de este mes, los totales de los últimos 6 meses y tus presupuestos del mes (límite y gastado). Nunca se envían gastos sueltos ni sus descripciones.

Cómo viaja: la app llama a una función de nuestro servidor (Google Cloud Functions de Firebase, región de EE. UU.), que es la que llama a la API de Gemini de Google LLC. Nuestro servidor no guarda ni el texto ni la respuesta. Google trata estos datos como encargado del tratamiento según las condiciones de la API de Gemini de pago: no los usa para mejorar sus productos y los conserva durante un tiempo limitado para detectar abusos.

Las respuestas a las preguntas las genera una IA: pueden equivocarse y no son asesoramiento financiero. Cada respuesta tiene un botón Reportar que solo nos envía el motivo que elijas, nunca la pregunta ni la respuesta. El reporte llega a nuestro servidor aunque tengas desactivados los datos de uso, y allí solo suma uno al recuento de ese motivo en ese día (punto 4.6).

4.2 Estadísticas de uso: Google Analytics for Firebase

Nos ayuda a saber qué partes de la app se usan y dónde se atasca la gente. Está activada por defecto y puedes desactivarla en Ajustes > Privacidad > Compartir datos de uso; al desactivarla deja de recoger datos al momento, incluidos los eventos automáticos.

Qué recoge: eventos de uso (abrir la app, pantallas, pasos de la introducción, que has guardado un gasto — sin importe, categoría ni descripción —, que has creado un presupuesto, avisos de presupuesto — solo el umbral, 80 % o 100 % —, logros, vistas de la pantalla de suscripción, plan elegido, compras y su precio en la moneda de la tienda, tus decisiones sobre la IA, fallos de la IA — solo el tipo —, recordatorios mostrados y abiertos, el motivo de un reporte a la IA); propiedades como tu moneda configurada, el idioma, si tienes PRO y de qué tipo, y la primera versión de la app que usaste; y datos técnicos: un identificador de instancia de la app, modelo y sistema del dispositivo, versión de la app y país aproximado (deducido de la IP).

No vinculamos estos datos con tu identidad: no hay cuentas ni usamos identificadores de usuario. En iPhone la app no usa el identificador de publicidad (IDFA). En Android, el componente de Google puede leer el identificador de publicidad del dispositivo salvo que lo hayas eliminado o desactivado en los ajustes de Android, y usamos el evento «primer gasto guardado» (sin importe) para medir la eficacia de nuestras campañas de Google Ads. Los datos de iPhone no se usan para medir anuncios.

Versiones anteriores: hasta la versión 1.8.3 de Android, el evento de gasto guardado incluía su importe y su categoría. Desde la 1.9 ya no.

Conservación: 2 meses para los datos de eventos y 14 meses para los datos de usuario (ajuste de la propiedad de Google Analytics).

4.3 Informes de fallos: Firebase Crashlytics

Si la app falla, se envía un informe técnico (traza del error, modelo y sistema del dispositivo, versión de la app, memoria y espacio libres, y un identificador de instalación) para poder arreglarlo. Antes de enviarlo, la app elimina de los errores de base de datos y de formato los valores que podrían contener un gasto. Va con el mismo interruptor que las estadísticas de uso. Según Firebase, estos informes se conservan 90 días.

4.4 Funcionamiento y seguridad: Firebase Remote Config, App Check e Installations

  • Remote Config descarga la configuración de la app (límites del plan gratuito, funciones activas). Usa un identificador de instalación, la versión de la app, el sistema, el idioma y el país.
  • App Check comprueba que las llamadas a nuestro servidor vienen de la app auténtica, con Play Integrity (Android) o App Attest / DeviceCheck (iPhone).
  • Installations genera el identificador de instalación que usan los servicios anteriores.

Base: nuestro interés legítimo en que la app funcione y no se abuse de nuestro servidor.

4.5 Suscripciones: RevenueCat, App Store y Google Play

  • El pago lo procesan Apple (App Store) o Google (Google Play) con tu cuenta de la tienda, según sus propias condiciones y políticas de privacidad. Nosotros nunca vemos tu tarjeta ni tus datos de pago.
  • RevenueCat, Inc. (EE. UU.) gestiona el estado de tu suscripción por nosotros. Recibe un identificador anónimo que crea la propia app ($RCAnonymousID:…), los recibos y el historial de compras de la tienda (producto, precio, moneda, fechas, periodo de prueba), y datos técnicos del dispositivo y de la app. Si tienes activados los datos de uso, también el identificador de instancia de Google Analytics, para que las compras aparezcan en nuestras estadísticas; si los desactivas, ese vínculo se elimina.

Base: la ejecución del contrato de suscripción.

4.6 Nuestra base de datos (Cloud Firestore)

  • Las instalaciones de Android que recibieron en su día los 7 días de PRO gratis (versiones hasta la 1.8.3) tienen un registro con su identificador anónimo de RevenueCat, el estado y las fechas de esa concesión, para no darla dos veces.
  • Contadores diarios de uso de la IA, para limitar costes y abusos: uno global y otro por instalación. El de cada instalación no guarda ningún identificador en claro, solo un resumen cifrado (hash) de un código aleatorio que crea la app para esto y que no se usa para nada más (no es el de la analítica ni el de RevenueCat). Caducan a los 2 días. Borrar todos mis datos cambia ese código.
  • Recuentos diarios de los reportes a respuestas de la IA: cuántos hubo de cada motivo cada día. Sin identificadores ni texto.

4.7 Registros del servidor

Google Cloud registra metadatos técnicos de las llamadas a nuestras funciones (hora, resultado, duración) durante 30 días. No registramos el texto que escribes ni las respuestas de la IA.

5. Bases legales (RGPD)

  • Consentimiento (art. 6.1.a): el envío de tus textos y totales a la IA. Lo retiras en Ajustes.
  • Ejecución de un contrato (art. 6.1.b): gestionar tu suscripción y darte acceso a PRO.
  • Interés legítimo (art. 6.1.f): estadísticas de uso e informes de fallos para mejorar la app, seguridad del servidor y configuración remota. Puedes oponerte desactivando los datos de uso.

6. Transferencias internacionales

Google y RevenueCat pueden tratar los datos en Estados Unidos. Google LLC está adherida al Marco de Privacidad de Datos UE-EE. UU.; con RevenueCat, la transferencia se ampara en las cláusulas contractuales tipo de la Comisión Europea de su acuerdo de tratamiento de datos.

7. Cuánto tiempo

  • En tu teléfono: hasta que los borres (Borrar todos mis datos) o desinstales la app.
  • Google Analytics: 2 meses los eventos y 14 meses los datos de usuario. Crashlytics: 90 días. Registros del servidor: 30 días.
  • Gemini: el tiempo limitado que fijan las condiciones de Google para detectar abusos.
  • RevenueCat y el registro de los 7 días de PRO: mientras la suscripción o ese registro sean necesarios y, después, lo que exijan las obligaciones legales, o hasta que nos pidas borrarlos.

8. Tus derechos y cómo borrar tus datos

  • En el teléfono: Ajustes > Datos > Borrar todos mis datos borra tus gastos, presupuestos, gastos recurrentes, logros y ajustes, cancela los recordatorios y renueva el identificador de analítica y el código de instalación de los contadores de la IA. No cancela tu suscripción, que se gestiona en la tienda. Desinstalar la app también borra los datos (salvo la copia de seguridad del iPhone, si la tienes).
  • En servidores: escríbenos a info@sobeklab.com con el identificador que aparece en esa misma pantalla y borraremos lo que tengamos ligado a él en RevenueCat, en nuestra base de datos y, cuando sea posible, en las estadísticas.
  • Puedes ejercer tus derechos de acceso, rectificación, supresión, oposición, limitación y portabilidad escribiendo a info@sobeklab.com. Como no hay cuentas, necesitaremos ese identificador para encontrar tus datos. También puedes reclamar ante la Agencia Española de Protección de Datos (www.aepd.es).

9. Menores

CashWhisper no está dirigida a menores de 13 años (o de la edad mínima de consentimiento digital de tu país; 14 en España) y no recogemos a sabiendas datos suyos.

10. Cambios

Si cambia lo que la app hace con tus datos, actualizaremos esta política y la fecha de arriba. Si el cambio necesita tu permiso (por ejemplo, enviar algo nuevo a la IA), te lo pediremos en la app.


CashWhisper — Privacy Policy

Last updated: September 14, 2026

This policy describes CashWhisper from version 1.9 on. Up to Android version 1.8.3, the app didn't ask for permission before using the AI, had no "Delete all my data" or "Report" button, and usage statistics included the amount and category of expenses (section 4.2).

1. Who is responsible

CashWhisper is an app by Sobeklab SL (tax ID B05560719, Plaza Violonchelista Miguel Ángel Clares, 23, 30157 Algezares (Murcia), Spain), the controller of the data described here. Contact for any privacy matter: info@sobeklab.com.

2. Summary

  • Your expenses are stored on your phone. There is no account to create, we don't connect to your bank and we don't keep a database of your history.
  • Only if you allow it, what you type in the chat is sent to Google's Gemini AI, through our server, to turn it into an expense; when you ask a question, your spending totals are sent too (never descriptions).
  • We use Firebase (Google) for anonymous usage statistics and crash reports, which you can turn off in Settings, and RevenueCat to manage subscriptions. From version 1.9 on they don't include your expenses or their amounts.
  • We don't sell your data, we don't show ads in the app and we don't track you across other companies' apps.
  • You can delete everything from Settings > Data > Delete all my data.

3. Data that stays on your phone

The app keeps on the phone:

  • in a SQLite database, your expenses (amount, currency, category, description and date), budgets, recurring expenses and achievements;
  • in its preferences, your settings and app state (currency, reminders and their time, your AI and usage-data choices, whether you have seen the intro, streaks, questions asked this month, etc.).

The app does not encrypt this data itself; it is protected by the phone's own system (app sandboxing and, while the phone is locked, device encryption). We have no access to it.

Backups. On iPhone, this data is included in the device backup (iCloud or your computer) if you have it turned on: that backup is yours and handled by Apple, not by us. On Android, the app opts out of Google's automatic backup, so uninstalling the app or changing phones loses the data (PRO users can export it to CSV).

Reminders are scheduled on the phone itself; they never go through a server.

4. Data that leaves your phone

4.1 The AI: Google Gemini (only with your permission)

Before anything is sent, the app explains what will be sent and asks for your permission. If you choose "Not now", nothing is sent and you can log expenses by hand. You can withdraw permission at any time in Settings > Privacy > Read expenses with AI.

With your permission:

  • When you log an expense in the chat, we send: the text you type, your currency, the app's list of categories, your language, today's date and your phone's time-zone offset. It is used to extract the expense's amount, currency, category, description and date, which you confirm before it is saved.
  • When you ask a question ("what do I spend most on?"), we send: the question, your language and currency, this month's total so far, this month's total per category, the totals of the last 6 months and this month's budgets (limit and amount spent). Individual expenses and their descriptions are never sent.

How it travels: the app calls a function on our server (Firebase Cloud Functions on Google Cloud, US region), which calls Google LLC's Gemini API. Our server does not store the text or the answer. Google processes this data as our processor under the paid Gemini API terms: it does not use it to improve its products and keeps it for a limited time to detect abuse.

Answers to questions are AI-generated: they can be wrong and are not financial advice. Each answer has a Report button that only sends us the reason you pick, never the question or the answer. The report reaches our server even with usage data turned off, and there it only adds one to that reason's count for the day (section 4.6).

4.2 Usage statistics: Google Analytics for Firebase

It tells us which parts of the app are used and where people get stuck. It is on by default and you can turn it off in Settings > Privacy > Share usage data; turning it off stops collection at once, automatic events included.

What it collects: usage events (opening the app, screens, intro steps, that you saved an expense — without its amount, category or description —, that you created a budget, budget alerts — only the threshold, 80% or 100% —, achievements, views of the subscription screen, the plan you picked, purchases and their price in the store's currency, your AI choices, AI failures — only their type —, reminders shown and opened, the reason for an AI report); properties such as your chosen currency, language, whether and how you have PRO, and the first app version you used; and technical data: an app instance identifier, device model and OS, app version and approximate country (derived from the IP address).

We don't link this data to your identity: there are no accounts and we don't set user identifiers. On iPhone the app does not use the advertising identifier (IDFA). On Android, Google's component may read the device's advertising ID unless you have deleted or disabled it in Android settings, and we use the "first expense saved" event (without amount) to measure how our Google Ads campaigns perform. iPhone data is not used to measure ads.

Earlier versions: up to Android version 1.8.3, the "expense saved" event included its amount and category. From 1.9 on it doesn't.

Retention: 2 months for event data and 14 months for user data (Google Analytics property setting).

4.3 Crash reports: Firebase Crashlytics

If the app crashes, a technical report (error trace, device model and OS, app version, free memory and storage, and an installation identifier) is sent so we can fix it. Before sending, the app strips from database and format errors any values that could contain an expense. It follows the same switch as usage statistics. According to Firebase, these reports are kept for 90 days.

4.4 Operation and security: Firebase Remote Config, App Check and Installations

  • Remote Config downloads the app's configuration (free-plan limits, enabled features). It uses an installation identifier, app version, OS, language and country.
  • App Check verifies that calls to our server come from the genuine app, using Play Integrity (Android) or App Attest / DeviceCheck (iPhone).
  • Installations creates the installation identifier the services above use.

Basis: our legitimate interest in the app working and our server not being abused.

4.5 Subscriptions: RevenueCat, App Store and Google Play

  • Payments are processed by Apple (App Store) or Google (Google Play) with your store account, under their own terms and privacy policies. We never see your card or payment details.
  • RevenueCat, Inc. (USA) manages your subscription status for us. It receives an anonymous identifier created by the app ($RCAnonymousID:…), the store receipts and purchase history (product, price, currency, dates, trial period) and technical device and app data. If usage data is on, it also receives the Google Analytics instance identifier, so purchases show up in our statistics; if you turn usage data off, that link is removed.

Basis: performing the subscription contract.

4.6 Our database (Cloud Firestore)

  • Android installs that once received 7 days of PRO for free (versions up to 1.8.3) have a record with their anonymous RevenueCat identifier and the status and dates of that grant, so it isn't given twice.
  • Daily counters of AI usage, to cap costs and abuse: a global one and one per install. The per-install counter stores no identifier in the clear, only a hash of a random code the app creates for this and uses for nothing else (it is neither the analytics nor the RevenueCat identifier). They expire after 2 days. Delete all my data changes that code.
  • Daily counts of reports on AI answers: how many there were for each reason each day. No identifiers and no text.

4.7 Server logs

Google Cloud logs technical metadata of the calls to our functions (time, result, duration) for 30 days. We don't log the text you type or the AI's answers.

5. Legal bases (GDPR)

  • Consent (Art. 6(1)(a)): sending your text and totals to the AI. Withdraw it in Settings.
  • Contract (Art. 6(1)(b)): managing your subscription and giving you PRO access.
  • Legitimate interest (Art. 6(1)(f)): usage statistics and crash reports to improve the app, server security and remote configuration. You can object by turning usage data off.

6. International transfers

Google and RevenueCat may process data in the United States. Google LLC participates in the EU-U.S. Data Privacy Framework; transfers to RevenueCat rely on the European Commission's Standard Contractual Clauses in its data processing agreement.

7. How long

  • On your phone: until you delete it (Delete all my data) or uninstall the app.
  • Google Analytics: 2 months for events and 14 months for user data. Crashlytics: 90 days. Server logs: 30 days.
  • Gemini: the limited period set by Google's terms to detect abuse.
  • RevenueCat and the 7-day PRO record: while the subscription or that record is needed and then as long as legal obligations require, or until you ask us to delete them.

8. Your rights and how to delete your data

  • On the phone: Settings > Data > Delete all my data deletes your expenses, budgets, recurring expenses, achievements and settings, cancels reminders and renews the analytics identifier and the install code of the AI counters. It does not cancel your subscription, which you manage in the store. Uninstalling the app deletes the data too (except an iPhone backup, if you have one).
  • On servers: email info@sobeklab.com with the identifier shown on that same screen and we will delete what is linked to it in RevenueCat, in our database and, where possible, in our statistics.
  • You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to info@sobeklab.com. As there are no accounts, we will need that identifier to find your data. You can also complain to the Spanish Data Protection Agency (www.aepd.es) or your local authority.

9. Children

CashWhisper is not directed at children under 13 (or the minimum age of digital consent in your country; 14 in Spain) and we don't knowingly collect their data.

10. Changes

If what the app does with your data changes, we will update this policy and the date above. If a change needs your permission (for example, sending something new to the AI), we will ask for it in the app.

Consulta gratuita por WhatsApp