Privacy contact
NomadExpense services are operated by Code2Prog. For privacy questions or requests to access or delete data, email office@code2prog.com.
1. Scope and controller
This policy covers the NomadExpense app, nomadexpense.app, the beta waitlist, and optional NomadExpense AI. Code2Prog is the controller for data processed directly through these services; contact: office@code2prog.com.
Data in your private iCloud database is also governed by Apple’s terms and privacy policy linked to your Apple Account.
2. Website and waitlist
- If you join the beta waitlist, we store your email address, selected language, and signup date only to manage the list and contact you about testing or availability.
- The essential nomad_locale cookie remembers your language for up to 12 months. We do not use advertising or analytics cookies.
- Hosting and security providers may process standard request data such as IP address, time, page, browser type, and signals needed to prevent abuse.
3. Data stored by the app
- Expenses, income, transfers, amounts, currencies, exchange rates, payment methods, accounts, categories, and notes.
- Trips, countries, cities, dates, budgets, recurring subscriptions, and reminders.
- Selected receipt images or documents plus merchant, address, purchase time, items, tax, tips, and recognition results.
- The profile name, email and photo you enter, language, base currency, and other settings.
- Data is stored locally using SwiftData. When iCloud is available, the app automatically syncs it to the private CloudKit database associated with your Apple Account.
4. Device permissions
- Camera and photo-library access is used only after your action to scan or import a receipt. The app does not browse your whole library.
- Location while using the app is requested on demand to suggest a country or city. We do not track background location. Coordinates stay with a transaction only if you save it.
- For Face ID or Touch ID, NomadExpense receives only the authentication result, never biometric data. Reminders are scheduled as system notifications on your device.
5. Optional AI receipt analysis
Analysis runs only after you choose a receipt image or scan. A receipt may show personal or payment information, so obscure anything the analysis does not need before sending it.
- With your own API key, the image and instruction go directly from your device to OpenAI under your account.
- With a NomadExpense AI subscription, the image passes through the Code2Prog service on Cloudflare and then to OpenAI. Payload logging in Cloudflare AI Gateway is disabled.
- The service keeps the result for up to 1 hour so the app can retrieve it, and operation/quota metadata for up to 30 days. It does not persist the receipt image in its database after the request.
- OpenAI does not use API data to train models by default. Under its current policy, API inputs and outputs may be retained for up to 30 days for abuse prevention unless another configuration or legal requirement applies.
6. Sign-in and purchases
- NomadExpense AI uses Sign in with Apple. We process a pseudonymised Apple identifier, session-token hashes, and a service account ID. We do not store your Apple sign-in name or email.
- To confirm a subscription, we process signed Apple transaction data including IDs, entitlement period, and status. Apple handles payment and billing data.
- You can delete the AI account in app settings. After any running analysis finishes, deletion removes sessions, the pseudonymous identifier, entitlement, quota use, and AI operations.
7. Providers and disclosures
- Apple — iCloud/CloudKit, Sign in with Apple, App Store, StoreKit, MapKit, and system notifications.
- Cloudflare — website hosting, waitlist database, traffic protection, NomadExpense AI, and AI Gateway.
- OpenAI — optional receipt-image analysis. Frankfurter — a rate for the selected currency pair; stored transactions and profile data are not sent.
- We do not sell data or share it with data brokers or ad networks. We may disclose data when legally required or necessary to protect the service and its users.
8. Purposes, legal bases, and transfers
- Contract or pre-contract steps: storing and syncing app data, receipt analysis, the AI account, and subscription delivery.
- Consent: waitlist registration and beta messages; you can withdraw at any time.
- Legitimate interests: security, abuse prevention, diagnosis, and reliable operation. Legal obligation: payment records and valid authority requests.
- Apple, Cloudflare, and OpenAI may process outside the EEA using applicable safeguards such as an adequacy decision or standard contractual clauses.
9. Retention and deletion
- App data remains on your device and in private iCloud until you delete it or a chosen receipt-image retention setting applies. Removing an image does not remove extracted transaction fields.
- A waitlist email is kept until you withdraw or beta communications end, then deleted unless a short record of consent or opt-out must be retained by law.
- AI data follows section 5. Purchase records may be kept longer where accounting or tax law requires it.
- You can export stored expenses to CSV. Contact us about the waitlist or other data held by Code2Prog.
10. Your rights and security
Where the law provides, you may request access, correction, deletion, restriction, and portability, object to processing, withdraw consent, and complain to your competent data-protection authority.
Email office@code2prog.com; we may ask for information needed to verify the request. We use encrypted connections, private CloudKit databases, short-lived sessions, token hashes, and limited retention, although no method can guarantee absolute security.
We do not make solely automated decisions with legal effects or profile users for advertising. NomadExpense is not directed to children and we do not knowingly collect their data through the waitlist or AI account. We will provide appropriate notice of material policy changes.