1. Introduction
RiceBowl ("we," "our," or "us") is a personal finance app that helps you understand how much you have left to spend. We built RiceBowl around a simple belief: your financial data belongs to you.
This Privacy Policy explains what data we collect, how we use it, and your rights — across all tiers of the app (Free, Plus, and Auto).
Questions? Contact us at [email protected].
2. The Short Version
The short version
- Your data lives on our encrypted servers so it syncs across your devices. You control it and can export or delete it at any time.
- We never sell your data. Not to advertisers. Not to data brokers. Not to anyone.
- We never move your money. RiceBowl is read-only. We can only read transaction data — we cannot initiate transfers, payments, or any financial action.
3. What We Collect
Collection follows the features you use, not the plan you're on. The core is identical on Free, Plus and Auto; paid plans only unlock optional features that involve extra data.
3.1 Always — every plan, including Free
- Account info: your name, email address, and password (stored as a PBKDF2 hash, never in plaintext).
- Financial data you enter: transactions, recurring items, savings buckets, and debts. Stored on our encrypted servers on every plan, so your data is there when you sign in on another device or reinstall. Deleting the app does not delete it.
- App usage analytics (pseudonymous, opt-out): which features you use — for example adding a bucket, tracking a debt, scanning a receipt, or using voice entry — plus screen views, session length, and crash reports. Linked to a random user ID and your plan tier, never to your name, email address, or financial values. Transaction amounts, names, and categories are never sent. Turn it off any time in Settings → Legal & Privacy → Analytics.
3.2 Only if you use these Plus features
Nothing here is collected unless you actively turn the feature on.
- Apple FinanceKit (iPhone, iOS 17.4+, with your permission): transactions read from Apple Card, Apple Cash and Apple Savings. Read-only — RiceBowl can never move money or change anything in Apple's data.
- CSV or Google Sheet import: the file you choose to upload, used to create the transactions and then discarded.
- Receipt and statement scanning (OCR): the photo is sent over HTTPS to our server and forwarded to Google Cloud Vision for text extraction. Neither we nor Google retain the image. The extracted text is returned to your device, parsed into a transaction, and discarded. We store neither the image nor the raw text.
3.3 Only if you share your account (Plus)
If you invite someone to your account, or accept an invitation to theirs, everyone on that account can see the data on it — including what each person adds. Each person signs in with their own email, password and two-factor; nobody's password is shared. Accounts are never merged: your own account and its data stay separate and private to you, and you can leave a shared account at any time. If the account owner deletes their account, the data on it is deleted for everyone — your own account is unaffected.
3.4 Only if you connect a bank (Auto — not available yet)
The Auto plan is not offered at this time. When it is, bank connections will be handled by a licensed financial data aggregator, and we will collect:
- Bank connection credentials: managed and encrypted by the provider directly. We never see or store your bank username or password.
- Transaction data: read-only transaction history from the accounts you connect. We cannot initiate payments, transfers, or any financial action.
- Account metadata: account names, types, and balances as returned by your bank.
The provider's privacy policy governs how they handle the data they transmit to us.
4. How We Use Your Data
We use your data to:
- Provide and improve the RiceBowl app
- Sync your data across your devices (Plus and Auto)
- Generate your "one number" — your remaining spending for the month
- Send transactional emails (e.g., account confirmation, support responses)
- Analyze anonymous usage patterns to improve the product
We do not use your data to:
- Sell to or share with advertisers or data brokers
- Train AI or machine learning models on your personal financial information
- Make automated decisions that have legal or significant effects on you
5. Data Storage & Security
- Your account and transaction data is stored on encrypted servers. All data in transit is protected with HTTPS/TLS.
- Passwords are stored using PBKDF2 hashing — they are never stored or transmitted in plaintext. Two-factor secrets and refresh tokens are encrypted at rest with keys held separately from the database.
- Bank login credentials (Auto tier) are never seen or stored by us — they are handled entirely by our data provider. We only receive read-only transaction data through their API.
- Operational logs and analytics events do not contain your name, email, or financial values. They contain only error types, timestamps, and a random user identifier needed to operate the service.
- Where your data lives: Our infrastructure runs on Cloudflare's global edge network. When you use RiceBowl from outside the United States, your data may be transferred to Cloudflare regions including the US. Cloudflare relies on Standard Contractual Clauses (SCCs) approved by the European Commission for GDPR-compliant cross-border transfers.
6. Data Sharing
We share your data only as necessary to operate the service:
| Recipient | Purpose | Data Shared |
|---|---|---|
| Licensed financial data aggregator | Bank connection (Auto tier) | Account credentials (they store, not us); transaction data we receive |
| Google Cloud Vision | Server-side text extraction (Plus tier) | Receipt/screenshot image; image not retained |
| Apple FinanceKit | Transaction sync (Plus/Auto, iOS) | Read-only transaction data |
| Cloudflare | Hosting, database (D1), and edge compute | Encrypted account and transaction data |
| PostHog | Pseudonymous usage analytics | Random user ID, plan tier, screen views, feature events. No name, email, or financial values. |
| Sentry | Crash and performance reporting for app stability | Diagnostic crash/performance data and a pseudonymous identifier. No transaction amounts, names, or categories. |
| RevenueCat | In-app purchase processing and subscription state | Pseudonymous user ID, purchase events, plan tier |
| Apple App Store / Google Play | Payment processing for subscriptions | Whatever the platform requires to charge your account; governed by Apple's / Google's privacy policies |
We do not sell, rent, or trade your personal information to any third party.
7. Your Rights & Choices
You have the right to:
- Access your data: Export all your data at any time from within the app.
- Delete your data: Delete your account and all associated data from within the app or by emailing [email protected]. We will process deletion requests within 30 days.
- Disconnect bank accounts: Revoke bank access at any time from within the app.
- Revoke FinanceKit access: Revoke Apple FinanceKit permissions at any time from iOS Settings.
- Opt out of analytics: Turn analytics off any time in Settings → Legal & Privacy → Analytics. When off, no usage events leave your device.
California residents (CCPA / CPRA)
You have the right to know what personal information we collect, request deletion, opt out of any “sale” or “sharing” of your data (we do neither), and not be discriminated against for exercising these rights.
- Categories we collect:
- Identifiers — your name, email, and a random user ID we generate.
- Commercial information — your subscription tier (Free, Plus, Auto) and purchase events.
- Financial information — only what enters the app: transactions you type in, recurring items, buckets, and debts. For Auto users, transaction data we receive from your linked bank via a licensed financial data aggregator. We never see your bank login, we cannot move money, and we do not collect bank account or card numbers.
- App usage activity (the CCPA statutory category is “internet or other similar network activity”) — which RiceBowl screens you open and which features you use. This is limited to within our own app; we do not track your activity elsewhere on the internet.
- Sources: directly from you, from Apple FinanceKit if you connect it (Plus, iOS), from a licensed financial data aggregator if you link a bank (Auto), and from your interactions with the app.
- Business purposes: providing the service, syncing across your devices, processing payments, and improving the product.
- Sale of personal information: we do not sell your data and have not in the prior 12 months.
EEA, UK, and Swiss residents (GDPR / UK GDPR)
You have the right to access, rectify, port, or delete your personal data; to restrict or object to our processing; to withdraw consent at any time where processing is based on consent; and to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your national DPA).
Our lawful bases for processing your data:
- Contract (Art. 6(1)(b)): providing the RiceBowl service, syncing your data across your devices, and processing your subscription.
- Consent (Art. 6(1)(a)): pseudonymous usage analytics (you can withdraw at any time in Settings → Legal & Privacy → Analytics), and optional features like FinanceKit and bank sync.
- Legitimate interest (Art. 6(1)(f)): preventing fraud, securing the service, and operating reliable infrastructure. We do not process for direct marketing.
We do not engage in automated decision-making or profiling that produces legal or significant effects.
8. Data Retention
- We retain your account and transaction data for as long as your account is active. When you delete your account, we remove your data within 30 days, except where retention is required by law.
9. Children's Privacy
RiceBowl is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us at [email protected].
10. Changes to This Policy
We may update this policy as the product evolves. When we do, we'll update the "Last updated" date at the top and notify you via the app or email if the changes are material. Your continued use of RiceBowl after changes take effect constitutes acceptance of the updated policy.
11. Contact
Operator and jurisdiction. RiceBowl is operated from the United States. By using the app you consent to processing in the United States and any region where our infrastructure provider operates (see §5 for international transfer mechanisms).
This policy covers the RiceBowl iOS and Android applications and the ricebowlapp.com website.