Privacy Policy
This privacy policy applies to the Liquify application and website (the "Application"). The Application is provided by Daniel Carneiro Ferrari Rey, a sole proprietor based in Berlin, Germany (the "Service Provider"). He is the founder of Liquify and the data controller (Verantwortlicher) under the GDPR for personal data processed in connection with the Application. Legal identity and contact details are published in the Legal Notice (Impressum) at https://getliquify.com/impressum.
Information Collection and Use
The Application collects information when you download and use it. This information may include information such as:
- Your device's Internet Protocol address (e.g. IP address)
- The pages of the Application that you visit, the time and date of your visit, the time spent on those pages
- The time spent on the Application
- The operating system you use on your mobile device
- If you connect a bank account, account names, types, balances, and transaction details retrieved from your financial institution
Third Party Access
- Google AdMob (https://policies.google.com/privacy)
- Unity Ads (https://unity3d.com/legal/privacy-policy)
- Liftoff Monetize (https://liftoff.io/privacy-policy)
- Start.io (https://www.start.io/policy/privacy-policy)
- Firebase Analytics (https://firebase.google.com/support/privacy)
- Pluggy (https://blog.pluggy.ai/pages/Privacy) — bank account connection and data aggregation for Brazilian Open Finance (Bank Sync)
- Lunch Flow (https://www.lunchflow.app/privacy) — bank account connection and data aggregation for other regions (Bank Sync)
- Firebase (Authentication, Firestore/hosting, Cloud Functions, Analytics, Crashlytics, and technical logging) (https://firebase.google.com/support/privacy)
- Google Gemini API used through Firebase Cloud Functions for AI review generation (https://ai.google.dev/gemini-api/terms)
- RevenueCat (subscription entitlements and billing state) (https://www.revenuecat.com/privacy)
- Google Play Services / Apple App Store (distribution and platform billing records)
- Disclosures required by law, legal process, fraud prevention, or safety obligations.
AI Review & Financial Data Processing
To provide "AI Review" and "Transactions Analysis", Liquify sends selected budget and bank-sync data to Google Gemini through Firebase Cloud Functions. This includes plan data you entered and, when Bank Sync is enabled for linked boxes, selected recent transactions (typically from approximately the previous 30 days) used to compare plan versus reality.
- Fields sent for plan review can include: budget base currency, monthly totals, savings/needs/wants allocations, box names, category tags, planned expense names/amounts/frequencies/payment dates, and user-selected output language/number format.
- Fields sent for plan-vs-reality review can include: linked box identifiers/names, planned expense metadata, and selected recent linked outgoing transactions including transaction id, date, amount, and merchant/description text provided by your bank or aggregator.
- What is not sent: bank login credentials, full payment card numbers, government ID numbers, and direct bank account credentials. However, transaction descriptions may contain personal information (for example names, locations, health-related merchants, or donations), so AI input is not treated as fully anonymized.
- Service configuration: AI calls are processed through Firebase Cloud Functions and Google Gemini API. Access is restricted to authenticated users and protected with Firebase App Check on callable functions.
- Retention and training: AI request/response handling is subject to Google's Gemini API and Firebase terms. Google may retain prompts and responses for abuse prevention, security, and legal compliance under applicable terms. Liquify does not permit AI providers to use your Liquify AI payloads for Liquify model training beyond the provider terms that apply.
- Legal basis: where required by law, AI analysis is performed only after you actively trigger it (for example by using an AI review action in-app), and you can stop future AI processing by not using AI features and by disconnecting bank links used for analysis.
Bank Sync & Financial Data Processing
To provide the optional "Bank Sync" feature, the Application connects to your financial institution through our regulated aggregator partners: Pluggy in Brazil, and Lunch Flow in other regions (including the UK & EU, US & Canada, and more). You authorize the bank with the partner—not inside Liquify.
- What aggregators receive from Liquify: Your signed-in account email, so the partner can create or match their user record for the connection. For Lunch Flow we also send your Liquify account id. We do not send them your budget plan, box names, or other Liquify app content.
- What Liquify receives from aggregators: Account names, types, balances, and transaction details (dates, descriptions, and amounts) for accounts you connect, plus connection tokens needed to refresh that data. Liquify does not receive or store your bank login credentials.
- Account link: Bank sync data is stored under your Liquify account. The signed-in email (and the account id behind it) is the link between that email and your bank data. We do not collect government ID or legal name for bank sync. Bank sync data is used to power Accounts and plan comparison—it is not used for advertising and is not sold.
- Sync and retention: While a bank stays connected, Liquify refreshes balances about every six hours (manual refresh about every fifteen minutes) and keeps about 90 days of recent transactions. Banks and Open Banking rules often require you to re-authorize every few months (commonly around 90 days in many regions); when that happens Liquify asks you to reconnect. If you disconnect a bank or Ultra lapses, synced balances, transactions, and box links may be retained for up to about 30 days, then removed from Liquify active systems and access revoked with the aggregator. Limited backup, security, billing, or legally required records may remain for their applicable retention periods.
- Third parties: Pluggy (https://blog.pluggy.ai/pages/Privacy) facilitates Open Finance connections in Brazil; Lunch Flow (https://www.lunchflow.app/privacy) facilitates bank connections in other supported regions.
- Control: You can disconnect a bank at any time in the app. Disconnecting stops sync; synced data may be retained for up to about 30 days, then removed from Liquify active systems.
- Legal basis: Bank Sync processing that is necessary to provide the feature you requested is based on performance of that requested service. Connecting a bank is optional, and you can stop future synchronization by disconnecting at any time. Partner- and bank-side authorization/consent may still be required under applicable Open Banking rules.
Your Choices and Controls
Uninstalling the app does not by itself delete server-side account, sync, analytics, billing, or legal records. To stop specific processing: disconnect Bank Sync in-app, revoke ad/analytics consent in settings (where shown), stop using AI actions, and request account deletion through the app or the Account Deletion form.
Retention Periods
Retention depends on data type and purpose: account/profile and budget data are retained while your account is active; after account deletion, data is removed from Liquify active systems within up to 30 days (with limited restoration during that period). Limited backup, security, billing, and legally required records may remain for their applicable retention periods before deletion or overwrite. Bank Sync balances/transactions and links may be retained for up to about 30 days after disconnection or entitlement lapse before removal from active systems. Recent transaction windows used in analysis are typically around 30 days, and in-app synced transaction history is typically around 90 days while connected. Advertising and analytics providers may process advertising identifiers, IP address and approximate location, device/app information, ad interactions, and consent status; personalized ads are enabled only where required consent has been obtained through the applicable consent flow.
Children
Legal Bases (GDPR/LGPD)
Depending on the activity, processing is based on: (a) performance of a contract (account operation, core budgeting features, subscription handling, and requested Bank Sync operation), (b) consent (for example personalized advertising, analytics where consent is required, and AI actions where consent is required by local law), (c) legitimate interests (service security, fraud prevention, abuse detection, and essential diagnostics), and (d) legal obligations (tax, accounting, and lawful requests). You may withdraw consent at any time; withdrawal does not affect processing already performed before withdrawal.
International Transfers and Your Rights
Your data may be processed outside your country, including outside the EEA/UK/Brazil, when our providers operate internationally. Where required, transfers rely on lawful safeguards such as adequacy decisions or standard contractual clauses. Subject to local law (including GDPR and LGPD), you can request access, correction, deletion, anonymization, restriction, portability, objection/review of certain automated decisions, and information about sharing/transfer recipients. You can also lodge a complaint with your supervisory authority (EU/EEA) or with the ANPD in Brazil.
Security, Updates, and Marketing
The Service Provider applies technical and organizational safeguards to protect data. This policy may be updated from time to time; material changes will be announced in-app or on this page before they apply when required by law. Continued use alone is not treated as consent where consent is legally required. Marketing emails are sent only when a valid legal basis exists and include an unsubscribe method.
Contact Us
If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at support@getliquify.com