Legal
Privacy Policy
How Spood collects, uses, stores, and protects personal and budget data when you use our iOS app.
Effective date: August 7, 2026
1. Who we are
Spood is a personal budgeting app for iOS. The data controller responsible for your personal data is:
Erik Hindr, IČO 23749199
Husova 316, 508 01 Hořice, Czech Republic
Contact: support@spood.app
As we are established in the Czech Republic (EU), we are not required to appoint a separate EU representative under Art. 27 GDPR. Given our size and the nature of our processing, we are not required to appoint a Data Protection Officer, but the contact above serves as our privacy contact point.
2. What data we collect
The categories of data we collect are described in the subsections below.
2.1 Account data
- Email address (if you sign up with email/password)
- Apple ID identifier (if you sign in with Apple) — we do not receive your Apple password
- Authentication tokens, managed by our backend provider Supabase
2.2 Financial data you enter
This data is entered manually by you, or automatically when you set up an optional Apple Pay / Shortcuts automation. We do not connect directly to your bank accounts and do not use bank-linking services (such as Plaid).
- Budget periods, envelopes/categories, and their limits
- Transactions you log (amounts, dates, notes, categories)
- Income entries you log
- Subscriptions you track inside the app
- Savings goals and contributions
2.3 App preferences
- Selected currency and budget period start date
- Promo code and referral code redemptions, if you use one
2.4 Subscription and payment data
If you subscribe to Spood Pro, your payment is processed entirely by Apple through the App Store — Apple, not us, is the merchant of record for these transactions (see Terms of Service). We do not receive or store your card details. We receive subscription status information (active, expired, cancelled) via our subscription management provider, so the app knows which features to unlock.
3. How we use your data
We use your data for the following purposes:
We do not sell your data. We do not share or use your financial data for advertising. As of the date above, the app does not display third-party advertising and does not use third-party analytics or advertising SDKs. If this changes, we will update this policy and, where required, ask for your consent first.
- To provide the core budgeting functionality of the app
- To sync your data across your devices while you are signed in
- To verify and apply promo codes and referral rewards
- To manage your subscription status
- To maintain the security and integrity of the service, including preventing abuse of promo codes and referrals
4. Legal basis for processing (GDPR)
- Performance of a contract (Art. 6(1)(b) GDPR) — creating your account, storing and syncing the budgeting data you enter, and providing the subscription features you sign up for
- Legitimate interest (Art. 6(1)(f) GDPR) — securing the service, preventing fraud or abuse of promo codes and referrals, and maintaining data integrity
- Consent (Art. 6(1)(a) GDPR) — where applicable, such as optional communications; you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal
- Legal obligation (Art. 6(1)(c) GDPR) — where we must keep certain records for accounting or tax purposes
6. International data transfers
Some of our service providers (including Apple and our subscription management provider) are based in, or process data in, the United States. Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework, to ensure your data remains protected.
7. Security
We take reasonable technical measures to protect your data:
No method of transmission or storage is 100% secure, but we use commercially reasonable means to protect your information.
- All data is transmitted using encrypted connections (TLS/HTTPS)
- Data is protected at the database level (Row Level Security) so only your own authenticated account can access your records
- Authentication tokens are stored securely on your device (iOS Keychain), not in plain text
- We do not store your Apple ID password or App Store payment details
8. Data retention
We keep your data for as long as your account is active. If you delete your account (available at any time in Settings → Delete Account, or by emailing us):
This deletion is permanent and cannot be undone once initiated.
- Your data is removed from our active, production database within 30 days
- Copies that may remain in encrypted backups or security logs are purged within 12 months as part of our normal backup rotation
9. Your rights (EU/EEA users)
Under GDPR, you have the right to:
We aim to respond to requests within one month. To exercise any of these rights, contact us at support@spood.app.
- Access the personal data we hold about you
- Correct inaccurate data
- Erase your data (available directly in-app via account deletion, or by contacting us)
- Restrict or object to certain processing
- Data portability, where technically feasible
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, uoou.cz), or the supervisory authority in your EU country of residence
10. Notice to California and other U.S. residents
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you additional rights:
We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising. Because Apple processes your subscription payment directly, we typically do not receive or store sensitive financial account or payment credentials ourselves.
You may submit a request by emailing support@spood.app or through account deletion in the app. We will confirm receipt within 10 business days and respond substantively within 45 calendar days (extendable once by another 45 days where permitted). This policy is reviewed and updated at least once every 12 months.
Residents of other U.S. states with comparable privacy laws (e.g. Virginia, Colorado, Connecticut, Nevada) may have similar rights; contact us to make a request and we will honor applicable rights regardless of your specific state.
- Right to Know / Access — the categories and specific pieces of personal information we have collected about you
- Right to Delete your personal information
- Right to Correct inaccurate personal information
- Right to Opt-Out of Sale or Sharing of personal information
- Right to Limit the Use of Sensitive Personal Information
- Right to Non-Discrimination for exercising any of these rights
12. Children
Spood is not directed at children under 16, and you must be at least 16 years old to create an account (see Terms of Service). We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified in-app or via email before they take effect.
14. Contact
Questions about this policy or your data can be sent to support@spood.app.