Privacy Policy
1. Who We Are
GetALife (package name: app.tinygiants.getalife) is operated by GetALife by Michael Hofmann.
For any privacy-related inquiries, please contact us at:
Email: info@getalife.app
2. What Data We Collect and Why
2.1 Crash Reporting (Firebase Crashlytics)
We collect crash logs, stack traces, and basic device information (device model, OS version, app version) to identify and fix bugs. This data is collected automatically when a crash or non-fatal error occurs.
2.2 Performance Monitoring (Firebase Performance)
We collect app performance metrics such as startup time, network request latency, and screen rendering times to improve the user experience.
2.3 Push Notifications (Firebase Cloud Messaging)
We collect a device push token to send you notifications. You can disable push notifications at any time in your device settings.
2.4 Customer Support (Crisp Chat)
When you contact us via in-app chat, we process your name, email address, and chat messages to provide customer support. This data is only collected when you actively initiate a conversation.
2.5 Subscriptions and Purchases (RevenueCat)
We use RevenueCat to manage subscriptions and in-app purchases. RevenueCat processes anonymous user IDs, purchase history, and subscription status. No payment details (such as credit card numbers) are collected by us; payments are handled by the respective app store (Apple App Store or Google Play).
2.6 Paywall Analytics (Superwall)
We use Superwall to manage and optimize our paywalls. Superwall collects data about paywall impressions, interactions, and conversion events using anonymous identifiers.
2.7 Banking Data (finAPI)
If you choose to connect your bank account, we use finAPI GmbH (Munich, Germany), a BaFin-regulated payment institution, as our open banking provider to access your account data and transactions. GetALife never stores your bank login credentials. Authentication happens directly and securely between you and finAPI. We receive read-only access to account balances and transaction data to provide our budgeting features.
2.8 AI Features (Anthropic Claude, fal.ai)
Some features of GetALife use artificial intelligence to process your inputs. For this we use the Claude AI models of Anthropic PBC (USA). Requests are always routed through our own servers (Firebase Cloud Functions); the app never talks to Anthropic directly. The following features send data to Anthropic:
- Voice entry: When you dictate a transaction, speech-to-text conversion is performed by your operating system's speech recognition service (Google on Android, Apple on iOS), which may process audio on its own servers according to its provider's privacy policy. Only the resulting text - never the audio recording - is then processed together with the names of your categories, accounts, payees, and tags so the transaction can be filled in for you.
- Receipt scanning: When you photograph a receipt, the photo is processed together with your category and payee names to extract the transaction details.
- Automatic categorization of bank transactions: Only the payee name and the amount of imported transactions are processed to suggest a matching category - no IBAN, no account balance, and no transaction date. This feature only runs after you have explicitly agreed to it in the app, and you can turn it off at any time in your profile settings.
- Budget suggestions and category emoji: Category names and budget figures are processed to generate suggestions.
- Savings-goal background images: When you create a savings goal with a custom name, that name is processed to derive a short visual scene description for the background image of your goal.
Where supported by your device, some of these features run entirely on-device, in which case no data is sent to Anthropic. Under Anthropic's commercial terms, data submitted via its API is not used to train AI models and is retained only temporarily for abuse prevention before being deleted.
AI-generated images (fal.ai): The background image for a savings goal is generated by fal.ai (Features and Labels, Inc., USA). Our servers send only the scene description derived from your goal name - never your budget figures or other personal data - to fal.ai, which processes it solely to generate the image in accordance with its privacy policy. The generated image is stored in our cloud storage and deleted when you delete the goal or your account.
2.9 Usage Analytics (Firebase Analytics)
After you accept our terms, we use Google Analytics for Firebase to understand how the app is used (for example, which screens are opened and which features are used). This data is used solely to improve the app. We do not use it for advertising and do not combine it with advertising identifiers.
2.10 Data We Do NOT Collect
- Advertising: We do not use ad tracking or advertising SDKs.
- Location data: We do not collect your location.
- Cross-app tracking: We do not track your activity across other apps or websites.
3. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
| Legal Basis | Applies To |
|---|---|
| Contract performance (Art. 6(1)(b) GDPR) | Banking data (finAPI), subscription management (RevenueCat) - necessary to provide the core service you signed up for. |
| Legitimate interest (Art. 6(1)(f) GDPR) | Crash reporting (Crashlytics), performance monitoring (Firebase Performance), paywall optimization (Superwall) - necessary to maintain and improve the app. |
| Consent (Art. 6(1)(a) GDPR) | Push notifications (FCM), customer support chat (Crisp), usage analytics (Firebase Analytics), AI categorization of bank transactions (explicit in-app consent), AI processing of voice entries and receipt photos (based on your explicit action of using these features). |
4. Data Retention
| Data | Retention Period |
|---|---|
| Crash reports (Crashlytics) | 90 days |
| Performance data | 90 days |
| Push notification tokens | Until you uninstall the app or revoke permission |
| Crisp chat messages | 12 months after last interaction |
| Subscription data (RevenueCat) | Duration of your account plus 30 days |
| Paywall interaction data (Superwall) | 12 months |
| Banking data (finAPI) | Until you disconnect your bank account or delete your account |
| AI requests (Anthropic) | Not stored by us; retained by Anthropic only temporarily for abuse prevention, then deleted |
| AI-generated goal images (fal.ai) | Image stored in our cloud storage until you delete the goal or your account; the request itself is not stored by us |
| Analytics data (Firebase Analytics) | 14 months |
When you delete your account, we will delete or anonymize all personal data within 30 days, unless we are legally required to retain it. You can request account deletion here.
5. Third-Party Data Processors
We share data with the following third-party processors, each bound by data processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Google LLC (Firebase) | Crashlytics, Performance Monitoring, Cloud Messaging, Analytics | USA / EU |
| Anthropic PBC | AI processing of voice entries, receipt photos, transaction categorization, budget suggestions, and savings-goal scene descriptions (Claude) | USA |
| Features and Labels, Inc. (fal.ai) | AI generation of savings-goal background images | USA |
| Crisp IM SAS | Customer support chat | EU (France) |
| RevenueCat Inc. | Subscription and purchase management | USA |
| Superwall Inc. | Paywall management and analytics | USA |
| finAPI GmbH | Banking data access (PSD2-regulated, BaFin-licensed) | Germany |
6. International Data Transfers
Some of our processors are based in the United States. For these transfers, we rely on:
- EU-U.S. Data Privacy Framework (DPF): Google and other processors certified under the DPF.
- EU Standard Contractual Clauses (SCCs): For processors not covered by the DPF (including Anthropic and fal.ai), we use the European Commission's standard contractual clauses to ensure an adequate level of data protection.
Your banking data processed through finAPI is processed in Germany and remains within the EU.
7. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) - Request a copy of your data.
- Right to rectification (Art. 16) - Correct inaccurate data.
- Right to erasure (Art. 17) - Request deletion of your data ("right to be forgotten").
- Right to restrict processing (Art. 18) - Limit how we use your data.
- Right to data portability (Art. 20) - Receive your data in a structured, machine-readable format.
- Right to object (Art. 21) - Object to processing based on legitimate interest.
- Right to withdraw consent - Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at info@getalife.app. We will respond within 30 days.
You also have the right to lodge a complaint with your local Data Protection Authority (DPA).
8. Children's Privacy
GetALife is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected data from a child under 16, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the app or by other appropriate means. The "Last updated" date at the top of this page reflects the most recent revision.
10. Contact
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
GetALife by Michael Hofmann
Email: info@getalife.app