Fluid Back to Fluid

Privacy, stated plainly.

Fluid can live entirely on your phone. If you choose to share a household, the app stores a copy online so the people you invite can see the same ledger. This policy explains both modes.

Effective 30 August 2026

1. Who we are

Fluid (“Fluid,” “we,” “us,” or “our”) is the developer and operator of the Fluid: Family Budget app and fluidbudget.io. Fluid is a household budgeting tool, not a bank, lender, payment processor, investment adviser, or regulated financial service.

Questions or privacy requests can be sent to me@rubenbristian.com.

2. Local mode and shared mode

Local mode: you can use Fluid without an account and without an internet connection. Your ledger stays in the app’s database on your device. We do not receive it.

Shared mode: if you create an account or join a household, Fluid sends a copy of the household data to our hosted backend so invited household members can synchronize their devices. Each device still keeps its own local copy.

Creating an account is optional for solo use. It is required only for sharing a household across people or devices.

3. Data we handle

Data kept on your device

  • Budgets, balances, expenses, dates, currencies, categories, tags, recurring rules, savings pockets, goals, and notes you enter.
  • Your local profile name and optional profile photo.
  • App settings such as language, timezone, and onboarding choices.
  • Technical synchronization state and locally generated identifiers needed to keep the ledger consistent.

Data sent to our backend when you use an account or shared household

  • Contact information: your email address and the email addresses used for household invitations.
  • Profile information: your display name and optional profile photo.
  • Identifiers: account, household, device-generated row, and synchronization identifiers.
  • Financial and user content: the household ledger, including amounts, currencies, dates, categories, tags, recurring rules, savings movements, pockets, goals, and notes.
  • Authentication information: session and refresh tokens stored in the iOS Keychain. Fluid does not receive your Apple or Google password.

Optional Shortcut data

If you configure the optional iOS Wallet automation described by Fluid, your Shortcut can send transaction amount, currency, merchant, card label, and transaction date to our backend. Fluid cannot read your Apple Pay or Wallet history by itself. The Shortcut runs only after you create it and provide it with a revocable device token.

Website data

The Fluid website contains no analytics, advertising scripts, account forms, or tracking cookies. It loads web fonts from Google Fonts, so your browser may make a request to Google when you visit. Our hosting provider may process ordinary request information such as IP address, timestamp, requested page, and browser information for delivery, security, and abuse prevention.

Data we do not collect

We do not collect advertising identifiers, precise location, contacts, health data, microphone recordings, bank credentials, payment-card numbers, or Apple Pay history. We do not use your data for targeted advertising or cross-app tracking.

4. How we use data

We use data only to provide and protect Fluid, including to:

  • create and authenticate an optional account;
  • synchronize one household across authorized members and devices;
  • show who added an expense and display an optional profile photo;
  • deliver and manage household invitations;
  • process an optional Shortcut transaction and prevent duplicates;
  • maintain security, enforce household access rules, diagnose failures, and prevent abuse;
  • comply with legal obligations and respond to lawful requests.

We do not sell personal data. We do not use household financial data for advertising, marketing profiles, credit decisions, or training public artificial-intelligence models. Fluid currently includes no advertising or analytics SDK.

5. Services that process data

We use a limited number of service providers:

  • Supabase provides authentication, database, file storage, realtime synchronization, and server functions for account and shared-household features.
  • Apple processes Sign in with Apple when you choose it and distributes the iOS app.
  • Google processes Google Sign-In when you choose it. Google Fonts may also receive a normal web request when you visit fluidbudget.io.
  • GitHub Pages hosts the public Fluid website and may process ordinary server-request information.

These providers process data under their own terms and privacy notices and only for the services described above. We may disclose information where required by law, to protect people or the service, or as part of a business transfer subject to appropriate safeguards.

Some providers may process data outside your country. Where applicable, those transfers rely on the provider’s contractual and legal transfer safeguards.

6. Device permissions

  • Photos: requested only when you choose a profile photo. You can use Fluid without granting access.
  • Camera: may be requested only if receipt scanning is enabled in a future or specific build, to photograph a receipt and prefill an expense. Receipt scanning is not required for the core app.
  • Keychain: stores account session tokens securely when you sign in.

Fluid does not need location, contacts, microphone, tracking, or advertising permission for its current features. You can change granted permissions in iOS Settings.

7. Retention and deletion

Without an account

Local data remains on your device until you delete it in Fluid, remove the household, or delete the app. Because we do not receive local-only data, we cannot retrieve or delete that copy for you.

With an account

Account and shared-household data remains on our backend while the account and household are active. Deleted or replaced synchronization records may be retained briefly where needed to synchronize deletions safely between devices.

You can delete your account inside Fluid under Settings → Account → Delete account. This deletes the account, identity information, profile photo, and the household copy held on our active servers. If you own a shared household, its server copy is deleted for every member; the app explains this before confirmation. Local copies already stored on phones are not remotely erased.

If you signed in with Apple, deleting your account also revokes Fluid's Sign in with Apple credential, so the app no longer appears under Apple ID → Sign in with Apple on your devices. To make that possible we store one Apple refresh token per account on our backend. It is never sent to any device, it cannot be read by any account including your own, and it is deleted along with the account.

Service-provider backups and security records may remain for a limited period according to provider backup cycles or where retention is legally required. They are isolated from ordinary product use and expire or are deleted under those schedules.

You may also request deletion or ask a question at me@rubenbristian.com. We may need to verify that the request comes from the account holder.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal data, and to complain to your local data-protection authority.

  • You may use the core app without creating an account.
  • You may change your name or remove your profile photo in Settings → Profile.
  • You may sign out without deleting the local ledger.
  • You may delete an account from Settings → Account.
  • You may decline or leave a household invitation.
  • You may revoke a Shortcut token to stop that automation from adding transactions.
  • You may deny Photos or Camera permission and continue using the core app.

For requests that cannot be completed in the app, email me@rubenbristian.com. We will respond as required by applicable law.

9. Security

Fluid uses device-local storage, iOS Keychain storage for session tokens, encrypted network connections, database row-level access rules, household membership checks, and revocable Shortcut tokens. Profile photos in shared mode are stored in a private bucket restricted to household members.

No system is perfectly secure. Keep your device, Apple or Google account, email account, and Fluid credentials protected. Contact us promptly if you believe an account or household has been accessed without permission.

10. Children

Fluid is intended for adults managing a household and is not directed to children. We do not knowingly ask children to create accounts or provide personal data. If you believe a child has provided personal data to Fluid, contact us so we can investigate and delete it where appropriate.

11. Changes to this policy

We may update this policy when Fluid’s features, providers, or legal obligations change. We will publish the revised policy here and update the effective date. If a change materially affects how account data is used, we will provide additional notice where appropriate.

12. Contact

Fluid privacy contact
Email: me@rubenbristian.com
Website: fluidbudget.io

If you are in the European Economic Area, you may also lodge a complaint with the data-protection authority in your country. In Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP).