Page 1 of 1

Privacy Policy - Amigo

Effective date: May 12, 2026

This Privacy Policy explains how the Amigo application collects, uses, stores, and protects users' personal data.

Amigo is an app designed to manage and share expenses between multiple people. By using the app, you agree to the practices described in this policy.

## 1. Data Controller

The data controller is the publisher of the Amigo application.

Contact: doritrelay@proton.me

## 2. Data We Collect

Depending on how you use the app, we may collect the following data:

- Account data: name, email address, user identifier.
- Authentication data: information required to sign in using email/password, Apple, Google, Facebook, or guest/anonymous mode.
- Profile data: profile photo possibly provided by your sign-in provider, currency preference.
- Group data: group name, description, member list, invitation code, and group image if you add one.
- Expense data: title, amount, category, split between members, payer, dates, recurring expenses, and settlements between members.
- Limited technical data: internal identifiers required for the app to function and for authentication security.

## 3. Sources of Data

Data may come from:

- you directly, when you create an account, a group, or an expense,
- your sign-in provider
- other members of a group, when they add or modify shared information related to you within that group.

## 4. How We Use Data

We use the data collected to:

- create and manage your account,
- authenticate you and secure access to the app,
- create, display, and sync your groups and expenses,
- calculate balances, reimbursements, and settlements between members,
- enable group sharing through a link or invitation code,
- allow you to optionally add a group image,
- maintain, secure, and improve the technical operation of the service.

## 5. Legal Basis

Where required by applicable law, the processing of your data is based on:

- the performance of the service you request when using Amigo,
- your consent, when you voluntarily choose certain optional features such as selecting an image from your photo library,
- our legitimate interest in securing, maintaining, and operating the application.

## 6. Access to Your Photos

If you choose to add or change a group image, the app may request access to your photo library. This access is strictly optional and is used only to select the image chosen by you.

The selected image may be stored with the group data so that it is visible to the relevant group members.

## 7. Data Sharing

We do not sell your personal data.

Your data may be shared only in the following cases:

- with other members of your groups, to enable the normal operation of shared expense features,
- with our technical service providers acting as processors, including Firebase and related authentication services,
- where required by law, or where necessary to protect our rights, prevent fraud, or ensure the security of the service.

## 8. Third-Party Services

The app may rely on third-party services, including:

- Firebase Authentication,
- Cloud Firestore,
- Sign in with Apple,
- Google Sign-In,
- Facebook Login.

These services may process certain data in accordance with their own privacy policies.

## 9. Data Retention

We keep your data for as long as your account remains active or as long as necessary to provide the service.

If you delete your account, we delete your user profile where technically possible within a reasonable timeframe. However, some shared data in groups, expenses, or common history may be retained where necessary to preserve the integrity of other members' data or to comply with legal obligations.

## 10. Security

We implement reasonable technical and organizational security measures to protect your data against unauthorized access, loss, alteration, or disclosure.

Despite these efforts, no system is entirely risk-free and we cannot guarantee absolute security.

## 11. Your Rights

Depending on your country of residence and applicable law, you may have the following rights:

- the right to access your data,
- the right to correct your data,
- the right to erase your data,
- the right to restrict processing,
- the right to object,
- the right to data portability,
- the right to withdraw your consent when processing is based on consent.

To exercise these rights, you can contact us at: [to be completed with your contact email address]

## 12. Account Deletion

You may request deletion of your account or use the deletion feature if it is available in the app.

Deleting your account removes your user profile from our primary database. However, content previously shared in groups may remain visible to other members where necessary to preserve the understanding of past expenses and settlements.

## 13. Children's Data

Amigo is not intended for children under 13, or under the minimum age required in your country. We do not knowingly collect personal data from minors in violation of applicable law.

If you believe that a minor has provided us with personal data inappropriately, please contact us so that we can take the necessary steps.

## 14. International Transfers

Some of our technical service providers may host or process data outside your country of residence. In such cases, we take reasonable steps to ensure that those transfers are governed in accordance with applicable law.

## 15. Changes to This Policy

We may update this Privacy Policy to reflect changes to the application, our practices, or legal requirements.

The update date at the top of this document will be modified accordingly.

## 16. Contact Us

If you have any questions about this Privacy Policy or the processing of your data, you can contact us at:
doritrelay@proton.me