Cube logoCube

Privacy & data policy

Cube is a personal finance app, so this page states plainly what is stored, why, where it lives and how to get rid of it. Last updated 9 August 2026.

What we collect

  • Account info — your email address, the display name you choose and a profile picture if you upload one.
  • Financial entries you type — monthly budget amounts, expense amounts and categories, notes, and lending or borrowing amounts together with the person names you attach to them.
  • Receipt photos — only when you use the receipt scanner, plus the line items extracted from them.
  • Basic device and usage data — the minimum needed to keep the app running and to diagnose errors.

Cube does not connect to your bank, does not ask for card numbers, and does not read your phone contacts or messages. Nothing is imported automatically — everything in Cube is there because you entered or uploaded it.

What each type of data is used for

  • Budget and expense data powers your dashboard, category breakdowns and history pages. That is its only use.
  • Receipt photos are processed to extract the merchant, total and line items, and are then kept in your private storage so you can review a receipt later. You can delete any receipt photo at any time.
  • Lending and borrowing contact names exist only to label rows in your own ledger. They are never shared with that person, never notified and never shared with anyone else.
  • Device and usage data is used only for reliability and error diagnosis, never for profiling.

Your data is never sold, rented, or used for advertising.

Retention and deletion

  • When you delete an expense, ledger entry or receipt in the app, the record is removed from the database straight away.
  • You can request deletion of your entire account. Once requested, your profile, budgets, expenses, ledger entries and receipt photos are removed within 30 days.
  • Routine encrypted backups may retain a copy for up to 30 days after deletion before they roll over; nothing is restored from them except to recover from an outage.

Security

  • Passwords are hashed and are never stored in a readable form — nobody, including the app owner, can read your password.
  • All traffic between your device and the server is encrypted over HTTPS.
  • Data is stored in a managed PostgreSQL database with per-user access rules, so a query can only ever return rows belonging to the signed-in account.
  • Receipt photos and profile pictures live in private storage buckets that are not publicly listable; images are served only through short-lived signed links to their owner.
  • Authentication, session tokens and password resets are handled by Supabase.

Your rights

  • Access — you can view all of your data inside the app at any time.
  • Correction — every entry, name, note, category and amount is editable from the screen it appears on.
  • Export — you can request a copy of your data.
  • Deletion — you can delete individual entries or request full account deletion.

For access, export or deletion requests, contact privacy@example.com — replace this with your own contact address before sharing the app publicly.

Back to Cube