Privacy Policy

Last updated: July 27, 2026

1. Who We Are

GetALife (package name: app.tinygiants.getalife) is operated by GetALife by Michael Hofmann.

For any privacy-related inquiries, please contact us at:
Email: info@getalife.app

2. What Data We Collect and Why

2.1 Crash Reporting (Firebase Crashlytics)

We collect crash logs, stack traces, and basic device information (device model, OS version, app version) to identify and fix bugs. This data is collected automatically when a crash or non-fatal error occurs.

2.2 Performance Monitoring (Firebase Performance)

We collect app performance metrics such as startup time, network request latency, and screen rendering times to improve the user experience.

2.3 Push Notifications (Firebase Cloud Messaging)

We collect a device push token to send you notifications. You can disable push notifications at any time in your device settings.

2.4 Customer Support (Crisp Chat)

When you contact us via in-app chat, we process your name, email address, and chat messages to provide customer support. This data is only collected when you actively initiate a conversation.

2.5 Subscriptions and Purchases (RevenueCat)

We use RevenueCat to manage subscriptions and in-app purchases. RevenueCat processes anonymous user IDs, purchase history, and subscription status. No payment details (such as credit card numbers) are collected by us; payments are handled by the respective app store (Apple App Store or Google Play).

2.6 Paywall Analytics (Superwall)

We use Superwall to manage and optimize our paywalls. Superwall collects data about paywall impressions, interactions, and conversion events using anonymous identifiers.

2.7 Banking Data (finAPI) - coming soon

The optional bank connection is not yet available. Once it becomes available, processing will be handled by finAPI GmbH (Munich, Germany), a BaFin-regulated payment institution, as our open banking provider to access your account data and transactions. GetALife will never store your bank login credentials. Authentication will happen directly and securely between you and finAPI. We will receive read-only access to account balances and transaction data to provide our budgeting features.

2.8 AI Features (Anthropic Claude, fal.ai)

Some features of GetALife use artificial intelligence to process your inputs. For this we use the Claude AI models of Anthropic PBC (USA). Requests are always routed through our own servers (Firebase Cloud Functions); the app never talks to Anthropic directly. The following features send data to Anthropic:

  • Voice entry: When you dictate a transaction, speech-to-text conversion is performed by your operating system's speech recognition service (Google on Android, Apple on iOS), which may process audio on its own servers according to its provider's privacy policy. Only the resulting text - never the audio recording - is then processed together with the names of your categories, accounts, payees, and tags so the transaction can be filled in for you.
  • Receipt scanning: When you photograph a receipt, the photo is processed together with your category and payee names to extract the transaction details.
  • Automatic categorization of bank transactions: Only the payee name and the amount of imported transactions are processed to suggest a matching category - no IBAN, no account balance, and no transaction date. This feature only runs after you have explicitly agreed to it in the app, and you can turn it off at any time in your profile settings.
  • Budget suggestions and category emoji: Category names and budget figures are processed to generate suggestions.
  • Savings-goal background images: When you create a savings goal with a custom name, that name is processed to derive a short visual scene description for the background image of your goal.

Where supported by your device, some of these features run entirely on-device, in which case no data is sent to Anthropic. Under Anthropic's commercial terms, data submitted via its API is not used to train AI models and is retained only temporarily for abuse prevention before being deleted.

AI-generated images (fal.ai): The background image for a savings goal is generated by fal.ai (Features and Labels, Inc., USA). Our servers send only the scene description derived from your goal name - never your budget figures or other personal data - to fal.ai, which processes it solely to generate the image in accordance with its privacy policy. The generated image is stored in our cloud storage and deleted when you delete the goal or your account.

2.9 Payment Recognition from Notifications (Android only)

When you set up the “Detect payments” feature, GetALife reads the notifications of the apps you select yourself in order to suggest payments for your budget. You choose each app individually and can deselect it at any time; without your selection, not a single notification is evaluated. The feature requires the Android notification access permission, which you can revoke in your system settings at any time. This feature does not exist on iOS.

The reading itself happens exclusively on your device. The notification text is matched there against known recognition patterns; it is not transmitted to us and not stored by us.

Learning unknown bank formats (optional, off by default). If no known pattern matches a notification that looks like a payment, you can allow us to create a new recognition pattern from it. This consent is not granted by default, requires an active subscription, and can be withdrawn in the app at any time. Without it, no notification text ever leaves your device.

If you have consented, the following happens: the sending app's name plus the title and text of that single notification are transmitted once to our servers (Firebase Cloud Functions) and from there to Anthropic in order to derive a recognition pattern. Only the recognition pattern itself (a technical search expression) is then stored. The notification text, the amount, and the payee name are not stored by us. At most ten such requests are possible per day.

A newly created pattern is initially only a proposal. To prevent a lucky single match from becoming generally valid, it must work for three different users before it is added to a shared pattern catalogue from which all users of the same bank receive it. To count how many different people have confirmed a pattern, we store an irreversible checksum of your user identifier with each proposal, not the identifier itself. It serves solely to avoid counting the same person twice; it cannot be traced back to you, and once your account is deleted it can no longer be attributed to anyone. The shared pattern catalogue itself contains only the search expressions and no information about individuals.

2.10 Usage Analytics (Firebase Analytics)

After you accept our terms, we use Google Analytics for Firebase to understand how the app is used (for example, which screens are opened and which features are used). This data is used solely to improve the app. We do not use it for advertising and do not combine it with advertising identifiers.

2.11 Data We Do NOT Collect

  • Advertising: We do not use ad tracking or advertising SDKs.
  • Location data: We do not collect your location.
  • Cross-app tracking: We do not track your activity across other apps or websites.

3. Legal Basis for Processing

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

Legal Basis Applies To
Contract performance (Art. 6(1)(b) GDPR) Banking data (finAPI, coming soon), subscription management (RevenueCat) - necessary to provide the core service you signed up for.
Legitimate interest (Art. 6(1)(f) GDPR) Crash reporting (Crashlytics), performance monitoring (Firebase Performance), paywall optimization (Superwall) - necessary to maintain and improve the app.
Consent (Art. 6(1)(a) GDPR) Push notifications (FCM), customer support chat (Crisp), usage analytics (Firebase Analytics), AI categorization of bank transactions (explicit in-app consent), payment recognition from notifications and the learning of unknown bank formats (each a separate in-app consent that can be withdrawn at any time), AI processing of voice entries and receipt photos (based on your explicit action of using these features).

4. Data Retention

Data Retention Period
Crash reports (Crashlytics) 90 days
Performance data 90 days
Push notification tokens Until you uninstall the app or revoke permission
Crisp chat messages 12 months after last interaction
Subscription data (RevenueCat) Duration of your account plus 30 days
Paywall interaction data (Superwall) 12 months
Banking data (finAPI, coming soon) Until you disconnect your bank account or delete your account
AI requests (Anthropic) Not stored by us; retained by Anthropic only temporarily for abuse prevention, then deleted
AI-generated goal images (fal.ai) Image stored in our cloud storage until you delete the goal or your account; the request itself is not stored by us
Notification texts used for payment recognition Not stored by us; the evaluation happens on your device
Bank format recognition patterns and the accompanying checksum of the user identifier Indefinite, as the pattern serves all users of the same bank; it contains no personal data, and the checksum can no longer be attributed to anyone once your account is deleted
Analytics data (Firebase Analytics) 14 months

When you delete your account, we will delete or anonymize all personal data within 30 days, unless we are legally required to retain it. You can request account deletion here.

5. Third-Party Data Processors

We share data with the following third-party processors, each bound by data processing agreements:

Processor Purpose Location
Google LLC (Firebase) Crashlytics, Performance Monitoring, Cloud Messaging, Analytics USA / EU
Anthropic PBC AI processing of voice entries, receipt photos, transaction categorization, budget suggestions, and savings-goal scene descriptions (Claude) USA
Features and Labels, Inc. (fal.ai) AI generation of savings-goal background images USA
Crisp IM SAS Customer support chat EU (France)
RevenueCat Inc. Subscription and purchase management USA
Superwall Inc. Paywall management and analytics USA
finAPI GmbH Banking data access (PSD2-regulated, BaFin-licensed) - coming soon Germany

6. International Data Transfers

Some of our processors are based in the United States. For these transfers, we rely on:

  • EU-U.S. Data Privacy Framework (DPF): Google and other processors certified under the DPF.
  • EU Standard Contractual Clauses (SCCs): For processors not covered by the DPF (including Anthropic and fal.ai), we use the European Commission's standard contractual clauses to ensure an adequate level of data protection.

Once the optional bank connection becomes available, your banking data processed through finAPI will be processed in Germany and will remain within the EU.

7. Your Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15) - Request a copy of your data.
  • Right to rectification (Art. 16) - Correct inaccurate data.
  • Right to erasure (Art. 17) - Request deletion of your data ("right to be forgotten").
  • Right to restrict processing (Art. 18) - Limit how we use your data.
  • Right to data portability (Art. 20) - Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21) - Object to processing based on legitimate interest.
  • Right to withdraw consent - Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at info@getalife.app. We will respond within 30 days.

You also have the right to lodge a complaint with your local Data Protection Authority (DPA).

8. Children's Privacy

GetALife is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected data from a child under 16, we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the app or by other appropriate means. The "Last updated" date at the top of this page reflects the most recent revision.

10. Contact

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

GetALife by Michael Hofmann
Email: info@getalife.app

← Back to homepage