Pe scurt
Sollus is local-first. This version has no accounts and no cloud sync: your financial records are held by the app on your device, and we never receive them. Scanning a receipt keeps no photograph, and automatic import of payment notifications, if you turn it on, works on your device only. The app contains no advertising and no analytics SDKs, and nothing in your ledger is sold or shared. You can export everything at any time, and erase it from the device yourself.
Disponibil doar în engleză
Acest document are valoare juridică și este publicat în engleză pentru ca sensul său să fie neechivoc. Interfața este tradusă, dar acest text nu este. Dacă ai nevoie de ajutor pentru a înțelege vreo parte, scrie la support@kelesh.dev și îți vom explica în limba ta.
A plain-language summary. The sections below are the full policy and take precedence if the two ever read differently.
Sollus (the "app") is developed and published by Ivan Kelesh, an independent developer. The Android app is distributed on Google Play under the package identifier com.ivankelesh.moneytracker, and the web version is available at https://sollus-app.kelesh.dev. This policy also covers this website, https://sollus.kelesh.dev.
For the purposes of the EU and UK General Data Protection Regulation, we act as the data controller only for any message you send us directly and for the limited website analytics described in section 11. We are not a controller or a processor of your financial records: this version keeps them on your device, and that data never reaches us.
You can contact us about privacy at any time at support@kelesh.dev.
Sollus is local-first, and in this version it is local-only. You install it and record income, expenses, accounts, categories and planned transactions without creating an account, without signing in, and without a network connection. There is no other mode to choose.
Your financial records are held in the application's own storage on the device — the app sandbox on Android, and browser storage in the web version. We do not receive them, and we cannot recover them for you.
Local data is only as durable as the device it lives on. Uninstalling the app, clearing app or browser storage, or losing the device removes it. Browsers in particular may clear site storage on their own when space is short or a site is unused. If your records matter to you, export a backup — Sollus writes a complete JSON file, and it is yours to keep.
This version of Sollus has no account system. There is no sign-in screen, no registration, and no way to create a Sollus account: the released build ships without the credentials that would be needed to reach any such service. You use the app, in full, as an anonymous local application.
Because there is no account, we hold no email address, no user identifier, no authentication tokens and no sign-in history for you. Nothing in this policy about accounts applies to the version you can install today.
An optional account, for synchronising between devices, is planned — you can read about it on our roadmap. It is not in this release, and this policy will be updated before any version that can create one is published.
There is no Cloud Sync in this version. No transaction, account, category, scanned receipt, tracked debt or saved calculation is copied to our infrastructure — there is no account to attach it to, and the released build carries no credentials for any such service.
Everything your ledger contains therefore stays where you put it. The table below is the complete picture for the version you can install today.
| Data | Examples | Leaves your device? |
|---|---|---|
| Transactions | Amount, currency, date, category, account, and any note you wrote | No |
| Accounts | Account name, currency and balance | No |
| Categories | Category and subcategory names, icons and colours | No |
| Scanned receipts | Details read from the receipt’s QR code — shop or till identifier, receipt number, date, currency and amounts, plus the code’s own address. See section 7. | No |
| Receipt photographs | The camera image or picture a receipt was read from | No — no image is stored or sent, ever |
| Payment notifications (automatic import) | Amount, currency, merchant and the last four digits of a card, read from notifications on the device. See section 8. | No |
| Debts you track | Obligation details, interest-rate history and payment allocations | No |
| Saved calculator scenarios | The figures you entered into a calculator and chose to keep | No |
| Calculator input | Anything typed into a loan, mortgage or card calculator | No — the calculation engine makes no network request at all |
| Reference rates and the bank list | Public index values, lender names and links | Public data comes in; nothing of yours goes out |
| App settings | Theme, language, display currency | No — these stay on the device |
The corollary matters as much as the promise: because nothing is synchronised, there is no cloud copy of your records. If you lose the device, reset it, or clear the app's storage, the data is gone and we cannot restore it for you. Export a backup if your records matter to you.
Optional, opt-in synchronisation is planned for a future version. When it ships it will require an account, it will be off until you turn it on, and this policy will be rewritten to describe exactly what it stores before that version is published.
Financial records are sensitive, and we treat the contents of your ledger as the most consequential data Sollus handles. Everything in it is information you typed or imported yourself, or — if you switch on automatic import — that Sollus read from payment notifications on your own device (section 8). Sollus has no connection to any bank, card or payment provider: it never signs in anywhere, and it reads nothing but what your phone already shows you.
In this version that information is processed in exactly one place: your device. There is no account and no synchronisation, so nothing in your ledger — including the free-text notes attached to a transaction, which are often the most revealing part of it — is transmitted to us or stored on our infrastructure.
The Financial Tools calculators deserve a specific mention, because people type real salaries and real property prices into them. Every loan, mortgage and credit-card calculation runs entirely on your device — the calculation engine makes no network request of any kind — and in this version there is nowhere those figures could be sent even if one were made.
Sollus can read the QR code printed on a shop receipt so you do not have to type the purchase in by hand. Using it is optional, and the camera is requested only at the moment you open the scanner — never when the app starts.
No photograph of your receipt is kept. The camera image is examined on your device to find the QR code and is then discarded: it is not saved to your device, not uploaded, and not stored on our infrastructure. There is nowhere in your Sollus account for a receipt image to go.
What Sollus keeps is the information the code itself contains. Depending on the receipt that can include the shop or till identifier, a tax registration number, the receipt number, the date and time of purchase, the currency, and the total, tax and tip amounts — together with the web address the code pointed to, so you can open the original later, and a short, length-limited copy of the code’s raw contents where it is not an address.
That information is financial data about a purchase, and it is treated exactly like the rest of your ledger: it stays on your device, as section 5 sets out.
For almost every receipt Sollus understands, reading it contacts nobody: the shop, the date, the total and the rest are decoded from the code’s own text on your device, and nothing is sent anywhere. If you choose to open the original receipt page, that opens in your browser and is your action, not the app’s. Moldova is the exception, because its codes carry no such text — see below.
A Moldovan receipt’s QR code contains only an identifier — no shop, no date, no amount. To fill the purchase in for you, your device therefore asks the Moldovan fiscal service (Serviciul Fiscal de Stat, mev.sfs.md) for that receipt’s own page, exactly as your browser would if you opened the printed link yourself.
What leaves your device on that request is the receipt identifier, plus the IP address any internet request necessarily carries. Nothing else: no account, no device identifier, no photograph, and none of your other receipts or transactions. It goes to the fiscal service, not to us — on this path no data reaches a Sollus server at all, and we neither receive nor store it. The request happens only when you scan such a receipt, only for that country, and the session cookie the site sets is discarded after each lookup.
If you would rather not use the camera, you can pick an existing picture instead. Sollus asks your device’s own file picker for a single image, so it receives only the one file you chose and never gains access to your photo library. That picture is read in the same way and is not stored or transmitted either.
Automatic import is optional and off until you switch it on — in the app’s first-run setup or in Settings → Automatic import. Before anything is read, Sollus shows what it will read, why, where it is kept and how to turn it off, and only your explicit agreement switches it on. It is available in the Android app.
You then grant Sollus notification access in Android’s system settings. Android gives an app with that access every notification on the device. Sollus looks only for payments, from any bank, wallet or payment app: it never reads chats, email, SMS messages or calls, it skips any app you exclude and its own notifications, and a notification that is not a payment is discarded on the device at once and never saved. It never keeps one-time codes and it does not use accessibility services. While automatic import is off, Sollus’ notification reader is switched off and receives nothing.
What is processed is the title and text of payment notifications: typically an amount, a currency, a merchant, the last four digits of a card and the name of the app that showed it. Longer card numbers are masked before anything is stored. All of it is processed on your device. Nothing is sent to us or to anyone else, it is not synced, and it is not included in the backup file Sollus exports.
By default nothing is added to your records on its own: a recognised payment appears in “Suggested transactions” and as a Sollus notification with Add and Reject, and becomes a transaction only when you add it. If you choose automatic adding, recognised purchases are added for you the next time Sollus runs; payments that are unclear, possibly repeated, on hold, refunds or transfers still wait for you, and every automatically added transaction can be undone. A transaction added either way is an ordinary record and is treated like the rest of your ledger.
Sollus’ own notification about a recognised payment shows the merchant and the amount. On the lock screen it only says that there is something to review, unless you allow details in Sollus, and its buttons work only once the phone is unlocked.
The captured text is deleted as soon as you add or reject the payment, and in any case within 7 days of being captured. The recognised details stay in the list for up to 30 days while they wait for you, and an entry you handled, or that expired, is removed 30 days after that. You can delete all of it at any time in Settings → Automatic import; transactions you already added are not affected.
Sollus produces a financial-health score, plain-language summaries, spending observations and forecasts. These are calculated on your device from data already present there. They are not generated by an external AI service, and your spending history is not sent anywhere to produce them.
We use a small number of providers, each for a specific function. We do not sell your data, and we do not share it for advertising.
| Provider | What it does for Sollus |
|---|---|
| Google Play distribution of the Android app | |
| Vercel | Hosting for this website and the web version of the app |
| Frankfurter (api.frankfurter.dev) | Public exchange-rate lookups, so totals can be shown in your display currency |
| CoinGecko | Public cryptocurrency prices and the list of available crypto assets, requested only if you open the crypto list, convert a crypto amount, or hold a crypto balance |
| Federal Reserve Bank of New York | The published SOFR reference index, when a Financial Tools calculation uses it |
| Serviciul Fiscal de Stat (mev.sfs.md) | The Moldovan fiscal service’s own receipt page, requested by your device only when you scan a Moldovan receipt — see section 7 |
The app also checks our own website for a published version number, so it can tell you when an update is available and flag a critical one as necessary. That check downloads a small public file at most once every twelve hours. It sends nothing about you: no identifier, no query string, and not even the version you have installed — the comparison happens on your device after the file arrives.
The exchange-rate, cryptocurrency and reference-index lookups are requests for public numbers. They carry no account, no identifier and no transaction data — structurally the same as loading a public web page — though, as with any internet request, the service necessarily sees the technical metadata it needs to reply, such as your IP address.
Of those three, the cryptocurrency lookup is the only one whose content depends on what you do: to price an asset the app has to name it, so the request says which cryptocurrencies are being priced — for example "bitcoin" — and which currency to price them in. It says nothing about how much you hold. The request made for a wallet with a fraction of a coin is identical to the one made for a wallet with hundreds, and no balance, account or transaction is part of it. If you never open the cryptocurrency list and never hold a crypto balance, the app does not contact this provider at all.
This website uses Vercel Web Analytics and Vercel Speed Insights. Both are cookie-free: they set no cookie, use no cross-site identifier and do not follow you to other sites. Web Analytics records the page viewed, the referring site and coarse technical facts such as country, browser and device type; Speed Insights records page-loading performance. Neither runs inside the Sollus app, and neither can see anything in your ledger.
The Sollus app contains no advertising SDKs, no analytics SDKs, no attribution SDKs and no crash-reporting SDKs. Your spending is not profiled, and there is nothing in the app that reports your behaviour back to us or to a third party.
We describe this as the current state of the app rather than as a permanent promise. If that ever changes, this policy will be updated before the change ships, and the change will be described here.
The website sets no advertising cookies, embeds no social widgets and loads no remote fonts. It uses the two cookie-free analytics products named in section 11.
It stores a small number of functional values in your browser: a cookie remembering your language choice, so you are not re-asked on every visit, and local-storage entries for your light or dark theme preference. Clearing your browser data removes them.
You can delete individual records at any time inside the app, and you can reset it completely from the Data screen. In this version that is the whole picture: the data is on your device, and removing it or uninstalling the app removes it for good.
There is no account to delete and no cloud copy to ask us to erase, because this version creates neither. Deletion is entirely in your hands and takes effect immediately — which also means it is irreversible, and we cannot restore anything for you afterwards.
Your financial data is retained until you remove it — by deleting records, resetting the app, clearing browser or app storage, or uninstalling. That is the only retention period that exists, and you are the one who controls it.
Automatic import keeps its working data on your device only for the limited periods set out in section 8.
We retain nothing about your finances ourselves, because this version sends us nothing to retain. A message you send us directly is kept for as long as we need it to answer you and to keep a record of the exchange.
Your records live in the operating system's own protected storage for the app — the app sandbox on Android, and browser storage in the web version. On Android, the system's automatic cloud backup is deliberately switched off, so your ledger is not copied to Google's servers behind your back. Every network request the app makes is over HTTPS.
The strongest security property of this version is structural: there is no server holding your financial data, so there is no server-side breach that could expose it. The matching weakness is just as plain, and we would rather state it than let you discover it — the safety of your records is the safety of your device, and we cannot recover them if it is lost.
No service can promise perfect security, and we do not. We do not claim certifications we do not hold, and we do not describe data as encrypted in ways it is not.
Depending on where you live, you may have rights over the personal data we hold about you — typically to access it, to correct it, to have it deleted, to receive a copy in a portable form, to object to or restrict certain processing, and to withdraw consent where processing relies on it.
The two that matter most you can exercise immediately, without asking us and without waiting: Sollus exports your complete data as JSON or CSV from inside the app, and erases it from the Data screen. For anything else — including any message you have sent us — write to us and we will respond as quickly as we reasonably can.
To exercise any right, email support@kelesh.dev. If you believe we have handled your data improperly, you may also complain to the data protection authority where you live.
Your financial data is not transferred anywhere, because it does not leave your device. What does cross a border is the technical metadata any internet request carries — an IP address, for instance — when the app looks up the public data described in section 11, or when you visit this website.
The providers behind those requests operate internationally, including outside the European Economic Area, and we rely on the safeguards they put in place for international transfers. We do not claim that this metadata stays within any particular country or region, because we are not in a position to guarantee it.
Sollus is not directed at children. You must be at least 13 years old to use it, and older where the law where you live sets a higher age for consenting to services like this one without a parent or guardian. We do not knowingly collect personal data from anyone below that age; if you believe a child has provided us with data, contact us and we will remove it.
We may update this policy from time to time. The current version and its effective date are always published on this page. Where a change materially affects how your data is handled, we will give notice in the app or by another appropriate means before it takes effect.
Questions about this policy, or about how Sollus handles data: support@kelesh.dev. General support: support@kelesh.dev.
Întrebări despre acest document?
Scrie-ne la support@kelesh.dev dacă ai nevoie de ajutor cu acest document.