Privacy
Suma Privacy Policy
Suma helps manage personal finances. This Policy explains when data remains on your phone and when it is sent to the API, technical providers, or AI services.
Last updated: July 22, 2026.
Controller and contact
The data controller is Paweł Stawikowski, plac Cukrowni 1/2, 83-130 Pelplin, Poland. For privacy, account, deletion, or security questions, email [email protected].
This Policy covers the Suma Android app, appsuma.pl, and the API at api.appsuma.pl.
The main principle
Core use is local: you can record accounts, expenses, budgets, and categories on your device. Data reaches a server only when you sign in, enable synchronization, or use a feature requiring off-device processing, such as receipt OCR, import analysis, AI, Premium verification, or push notifications.
Suma does not connect to bank accounts, retrieve bank history, or know your online-banking credentials.
Information you may store
- accounts, balances, currencies, goals, limits, liabilities, credit cards, and investment accounts;
- transactions, splits, categories, budgets, recurring payments, notes, receipt photos, and attachments;
- transaction location when you add it or enable automatic location assignment;
- settlements, including a person’s name, amount, due date, note, and optional email;
- assets and investments, including names, symbols, quantities, prices, currencies, and notes.
Without synchronization or server features, this information remains in the app’s local database on your device.
Account and sign-in
An account requires an email address. Email passwords are stored as protected hashes, never in plain text. Google sign-in provides an account identifier, email, and technical proof of authentication.
The app stores access tokens, user ID, and email on the device as needed. Signing out detaches the push token and removes local authentication tokens.
Waitlist and pre-launch contact
If you join the waitlist at appsuma.pl, we process your email, language, signup source or referrer, and technical submission data such as IP address and user agent. We use these details to record consent, protect the form against abuse, understand signup sources, and send information about Suma testing or launch.
Messages are based on your consent. You can withdraw it at any time by emailing [email protected]. We delete waitlist data when consent is withdrawn or no later than 12 months after launch-related communication ends.
Cloud synchronization
Synchronization is optional. When enabled, the app sends data needed to restore your database on another device, including accounts, categories, transactions, budgets, settlements, investments, interest data, transaction photos, and change/deletion metadata. Photos may be transferred as files or encoded synchronization data.
Disabling sync stops future uploads. To remove data already stored on the server, use the account-deletion procedure below.
Banking and payment-app notifications
Notification reading is off by default and starts only after Android permission and your selection of observed apps. Suma then reads only selected apps and sends the app name/package, title, content, time, technical notification key, and your category list to the API for transaction recognition.
OpenAI is used to analyze the notification. The API log stores metadata and parsed output, such as amount, currency, type, merchant/recipient, and confidence; it does not retain title and body as a plain server log. You can review recognized transactions before saving.
Receipts, imports, exports, and AI
Receipt OCR and file import run on the server. Depending on the feature, you may upload an image, PDF, CSV, JSON, XLS, XLSX, XML, or Suma export archive. The API may store the file, extracted text, analysis, and category suggestions to return results.
OpenAI supports receipt recognition, import-column mapping, category-icon suggestions, notification analysis, and financial insights. Only information needed for the requested feature is sent. AI output may be wrong and must be reviewed.
Exports are created at your request and may be uploaded if you use cloud export. They can contain financial data and transaction photos.
Location
Location is optional. With Android permission, Suma may read the last known location, search for a place/address, and store it with a transaction. Google Maps/Places and, where needed, Android’s geocoder support the search. Synced transactions may include coordinates, place name, and address.
Push notifications and reminders
For push notifications, Suma registers a Firebase Cloud Messaging token, platform, language, and technical device identifier. The token supports reminders, app messages, and settlement notifications.
When you remind another Suma user about a settlement, the API may locate their account by email and send your email, amount, currency, person name, and settlement note.
Premium and Google Play payments
Google Play handles Premium purchases. Suma does not receive card or payment details. The API stores data needed to verify subscriptions, including purchase token, product/package IDs, status, dates, auto-renewal, order ID, and technical Google response.
Diagnostics, analytics, and security
Production versions use Firebase Analytics for usage statistics such as app launches, screens and features used, app version, device type, operating system, language, approximate country, and an app-installation identifier. We do not send Firebase Analytics your email or Suma account ID.
We use Sentry for error and performance diagnostics. Screenshots, session replay, and view hierarchy are disabled in the app; a signed-in user is represented by a technical account identifier rather than email. The backend may also send errors and performance metrics to Sentry, with automatic personal-data collection disabled.
The API and website may record standard technical logs such as IP address, request time, endpoint, response status, user agent, and abuse-prevention information. Production logs should not contain passwords or authorization tokens.
Service providers and international transfers
- website, API, database, and file hosting;
- Google for sign-in, Google Play, payments, Firebase, and Maps/Places;
- OpenAI for the AI features described above;
- Sentry for error and performance diagnostics;
- email or support providers when you contact us.
We do not sell user data or share it with advertisers.
Some providers, particularly Google, OpenAI, and Sentry, may process data outside the European Economic Area. Transfers rely on a mechanism permitted under the GDPR, particularly an adequacy decision or the provider’s standard contractual clauses.
Data sent to the OpenAI API is not used for model training by default. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days unless the law requires longer retention.
Legal bases
- Performance of the service for accounts, sign-in, sync, API, Premium, import, export, OCR, push, and features you request.
- Consent for Android permissions such as location and notification access, joining the waitlist, and optional communication.
- Legitimate interests for security, diagnostics, abuse prevention, stability, and support.
- Legal obligations for billing, claims, and statutory duties where applicable.
Retention
Local data remains until you delete it, clear app data, or uninstall Suma. Account and synchronization data is retained while you have an account or actively use synchronization.
OCR files, notification-recognition results, exports, and synchronized photos are deleted with the account. Firebase Analytics and Sentry technical data follow the retention configured for those services and are not associated with your Suma account email. Data sent to OpenAI may remain in abuse-monitoring logs for up to 30 days.
After deletion, we remove or anonymize data that is no longer required. Backups, security logs, and technical traces may remain for up to 90 days unless law, billing, security, or claims require longer retention. They are then deleted or irreversibly anonymized.
Account and data deletion
Instructions are available at appsuma.pl/en/account-deletion. You may also email [email protected] from the account address.
In-app deletion removes server data without undue delay. If you own a shared trip, that trip and its history are deleted. In a trip owned by someone else, your membership is disconnected from your account and anonymized as “Deleted Suma user” so that other participants retain the shared expense history.
Deleting the account does not automatically cancel a Google Play subscription.
Your rights
You may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent where consent is the basis. You may complain to the President of the Polish Personal Data Protection Office or another competent supervisory authority. We may verify that a request comes from the account owner.
Changes to this Policy
We will update this page when a feature materially changes data processing. We may show an in-app notice or email account holders about significant changes.