Skip to content
Flex Cashflow

Privacy Policy

Version 1.0.0 · Effective July 19, 2026 · Last updated July 19, 2026

This Privacy Policy explains how Flexcode Labs Ltd (“we”, “us”, or “our”) collects, uses, stores, shares, and deletes personal data when you use Flex Cashflow on mobile, web, or desktop (the “Service”).

By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service. For our contract with you, see the Terms of Use.

1. Who we are

The Service is operated by Flexcode Labs Ltd. For privacy questions or data-subject requests, contact hi@flexcodelabs.com.

Where Tanzanian law applies, we act as a data controller for personal data we process on our systems. Apple, Google, RevenueCat, Expo, email providers, AI providers, and FX data providers act as independent controllers or processors for their own services as described below.

2. Data we process

2.1 Data you create on your device (local vault)

The app stores a local database (and related files) on your device or browser, which may include:

  • Profile details you enter (such as display name and preferences)
  • Accounts, balances, transactions, budgets, savings, bills, loans, investments, exchange rates you save, schedules, todos, occasions, categories, and in-app notifications
  • Media you attach (photos, videos, documents, and similar files) and related metadata
  • Local sync logs and settings (theme, biometric unlock preference, widgets)

Without Premium cloud sync, this vault generally stays on the device. We cannot read your local vault unless you export it, transfer it, or sync it to us.

2.2 Premium account, devices, and subscription data

If you create or restore a Premium profile, we may process:

  • A profile identifier and optional recovery email address
  • Device identifiers, device name/platform, cryptographic public keys used to authenticate the device, revoke/wipe flags, and last-seen timestamps
  • Subscription status, product/entitlement identifiers, expiry and grace dates, and billing event payloads received from RevenueCat / the app stores
  • Push tokens or web-push subscriptions if you enable notifications

2.3 Cloud vault (Premium)

When Premium cloud backup/sync is enabled, we store a server-side copy of vault records (including financial amounts and related metadata) and may store gallery binaries on our file storage. Sync change logs are also retained so your devices can catch up.

2.4 Authentication and recovery

We use short-lived one-time passwords (OTPs) emailed to your recovery address, hashed challenge records in Redis, rate-limit counters, and session cookies (typically stored in Redis) that associate your browser/app session with your profile. Sessions use HttpOnly cookies where applicable.

2.5 AI features (Premium)

If you use AI tools, we store chat threads/messages on our servers and may send your prompt plus a limited screen context snapshot (which can include account/category names and recent transaction amounts) to our AI provider so the assistant can respond. Do not paste secrets you do not want processed by that provider.

2.6 Live exchange rates (Premium)

Live FX lookups may query third-party market-data APIs. Requests can include the currencies you ask about. Saved rates on your device/vault are otherwise treated like other vault data.

2.7 Device-to-device transfer and LAN sync

QR / same-Wi‑Fi transfer and peer sync encrypt payloads with AES-GCM using keys exchanged during pairing. Those transfers happen on your local network between your devices; they are not the same as cloud storage.

2.8 SMS and pasted text

The Service does not request permission to read your SMS inbox. If you paste a message or receipt, parsing happens to help you create a transaction; only what you save becomes vault data.

2.9 Technical logs

Our API may log request metadata such as path, timing, approximate IP address, and associated profile/device identifiers for security, abuse prevention, and operations. We do not currently integrate a separate product-analytics or crash-reporting SDK in the app codebase.

3. How we use data

  • Provide, maintain, and secure the Service
  • Sync, restore, and transfer your vault when you ask us to
  • Authenticate you, register devices, and recover access via OTP
  • Process subscriptions and entitlement status with the stores / RevenueCat
  • Send transactional email (OTP, recovery notices) and optional push notifications
  • Power optional AI and live FX features you choose to use
  • Detect abuse, debug failures, and comply with law

We do not sell your personal data. We do not use your vault contents for third-party advertising.

4. Legal bases (where required)

Depending on applicable law (including Tanzania’s Personal Data Protection Act and, where relevant, other privacy laws), we rely on:

  • Performance of a contract — providing the Service you request
  • Consent — optional features such as push notifications, biometrics, or AI where consent is required
  • Legitimate interests — security, fraud prevention, and service improvement, balanced against your rights
  • Legal obligation — where we must retain or disclose information

5. Sharing and processors

We share data only as needed with:

  • Apple App Store / Google Play — in-app purchases and subscription management
  • RevenueCat — entitlement verification and subscription webhooks
  • Hosting / infrastructure — database, file storage, Redis, and application hosting providers we configure
  • Email delivery — SMTP provider used to send OTPs and account notices
  • Expo (mobile) — build/update infrastructure and Expo push delivery when enabled
  • Browser push services — when web push is enabled
  • OpenAI (or configured AI provider) — optional AI chat and context snapshots
  • CurrencyLayer / Coinlayer (or configured FX providers) — optional live exchange rates
  • Professional advisors or authorities — when required by law or to protect rights and safety

These providers process data under their own terms and privacy policies for the services they provide.

6. International transfers

Our servers, email, AI, FX, push, and billing providers may process data in countries other than where you live (including outside Tanzania). Where required, we take steps designed to protect transferred data in line with applicable law.

7. Retention

  • Local vault data remains until you delete it or uninstall/clear the app/browser storage
  • OTP challenges are short-lived (on the order of minutes)
  • Session cookies expire according to server configuration (on the order of days unless renewed)
  • Cloud vault and AI history generally remain while your Premium profile exists and you have not deleted the account
  • Subscription/billing event records may be retained as needed for accounting, dispute handling, and fraud prevention even after some profile fields are cleared
  • Operational logs are kept only as long as reasonably needed for security and debugging

We may keep limited residual copies in encrypted backups for a short period after deletion until those backups rotate.

8. Security

We use administrative and technical measures appropriate to the Service, including TLS in transit, access controls, hashed OTPs, device public-key authentication for Premium sessions, and encrypted LAN transfer. No method of transmission or storage is perfectly secure. Protect your device, recovery email, and any biometrics you enable.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, and to withdraw consent where processing is consent-based. You can usually:

  • Edit or delete records inside the app
  • Export reports or backups from supported export features
  • Disable push notifications in system or in-app settings
  • Remove a device from your Premium profile
  • Delete local data and, with OTP verification, request deletion of your cloud Premium profile and vault database records
  • Contact us at hi@flexcodelabs.com for other requests

If Tanzanian law applies, you may also lodge a complaint with the Personal Data Protection Commission (PDPC). Users in other regions may contact their local regulator.

10. Children

The Service is a personal finance product and is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 provided data, contact us and we will take appropriate steps to delete it. Where local law requires a higher age for consent, you (or a parent/guardian) must ensure compliance before use.

11. Third-party links and OS features

The Service may open store subscription pages, mail apps, or other system features. Their privacy practices are governed by those providers. Biometric unlock stays on-device via the operating system.

12. Changes

We may update this Policy. We will change the “Last updated” date and, when changes are material, provide additional notice in the app or by email where appropriate. Continued use after the effective date means you accept the updated Policy.

13. Contact

Flexcode Labs Ltdhi@flexcodelabs.com. Product: Flex Cashflow.