Privacy Policy
Gloam is a receipt and spending tracker for Android. This policy explains what it stores, where that data lives, and who is able to read it. It is written to be checkable against the app's actual behaviour rather than to sound reassuring.
The short version
- Your receipt photos never leave your phone. They are not uploaded, and we never receive them.
- Receipts are read on your device. There is no cloud OCR service, no AI service, and no parsing server in this product.
- We do not use analytics, advertising, or third-party trackers in the app or on this website.
- We never sell your data and we do not share it for advertising.
- You can use Gloam in an on-device-only mode that syncs nothing at all.
How storage mode changes everything
What we hold depends entirely on which mode you use. This is the most important section of this policy.
| Mode | What we store | Can we read it? |
|---|---|---|
| On-device only | Nothing. No receipt data is transmitted. | There is nothing to read. |
| Cloud sync (default when signed in) | Receipt fields — store name, category, amount, currency, date, and your optional note — as readable values in our database. | Technically yes. Access is restricted and audited, but we are not going to claim otherwise: if you do not want this, use the Private Vault or on-device-only mode. |
| Private Vault (opt-in) | The same fields, but encrypted on your device first. We hold ciphertext. | No. The key is derived from your passphrase, which we never receive. If you lose it, the data is unrecoverable — including by us. |
What we collect
Account information
If you create an account you sign in with Google or Discord. We receive your email address and a provider account identifier. We never receive your password for those services.
Profile and settings
A display name, preferred currency, time zone, and app preferences.
Receipt data
As described in the table above. Receipt images are never uploaded in any mode — they remain in your device's storage.
Shared Ponds
If you share receipts with someone, we store the shared copies end-to-end encrypted, along with who is a member of the Pond and encrypted key material that only members' devices can open. We cannot read shared receipt contents. Pond membership itself — who shares with whom — is visible to us.
Subscription status
Purchases are processed by Google Play, not by us: we never see your card or payment details. We receive entitlement status (active, expired, and similar) through RevenueCat so the app knows what to unlock.
What we do not collect
No location data, no contacts, no device advertising identifier, no behavioural analytics, no crash-reporting SDK. The app keeps a log of corrections you make to its suggestions in order to improve accuracy; that log stays on your device, never uploads, and contains no image data.
Where your data is stored
Cloud receipt data is stored in Australia (Sydney), in our database hosted by Supabase on Amazon Web Services.
Some service providers necessarily operate outside Australia, so it would be wrong to tell you nothing leaves the country. The complete list of processors we use:
| Provider | Purpose | Location |
|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage | Australia |
| Cloudflare | This website | Global edge network |
| RevenueCat | Subscription entitlement | United States |
| Sign-in, Play billing | Global | |
| Discord | Sign-in (if you choose it) | Global |
There is deliberately no OCR provider and no AI provider on that list. Nothing exists to add, because the reading happens on your phone.
How long we keep it
Receipt data is kept until you delete it or delete your account. Deleting your account removes your account and its data from our systems; some backups may persist for a short period before being overwritten in the ordinary course.
If you own a shared Pond and delete your account, the Pond is handed to another member, or — if no one can take it over — becomes read-only for seven days and is then removed.
Your choices and rights
- Delete everything. Settings → Data → Delete data removes your account and its data. It cannot be undone.
- Delete only the cloud copy and keep using the app on your device: Settings → Data → Cloud Data.
- Export your data at any time from Settings → Data.
- Access or correct what we hold: use the app, or email us.
Under the Australian Privacy Principles you may also ask for access to your personal information, ask us to correct it, or complain about how we have handled it. Email Android-Support@valaciel.com and we will respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Children
Gloam is not directed at children under 13 and we do not knowingly collect their personal information.
Security
Data in transit is encrypted with TLS. Our database enforces per-user access rules at the database level, so one account cannot read another's rows. Private Vault and shared-Pond contents are encrypted on your device before transmission. On your phone, keys are held in the Android Keystore.
No system is perfectly secure, and we would rather say so than imply otherwise.
Changes to this policy
If we change it materially we will update the effective date above and notify you in the app. Continuing to use Gloam after a change means you accept the updated policy.
Contact
valaciel Pty Ltd (ACN {{ACN}}), {{REGISTERED_ADDRESS}} · Android-Support@valaciel.com