Privacy Policy
Backpacker Spender
Last updated: August 4, 2026. This policy describes how the Backpacker Spender application and this website process personal data, in compliance with the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018) and with the European Union General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
1. Who the controller is
Backpacker Spender is developed by Moggy Digital, the controller of the data processed by the application. Contact for privacy matters (including the data protection officer / DPO role): contato@moggydigital.com.br.
2. What data the application processes
- Account data (optional): if you sign in with Google, we process the name, e-mail address and profile picture provided by Google Sign-In. If you sign in with Apple (Sign in with Apple), we process the e-mail address and the name you authorize to be shared, the name being provided by Apple only on the first authorization. If you choose to hide your e-mail address, Apple provides us with a private relay address (in the privaterelay.appleid.com domain), and it is that address that we store and use for contact and for trip invitations. Signing in is optional: without it, the app works with an anonymous identifier generated on the device itself.
- Trip and expense data: trips, budgets, expenses, categories, currencies, notes and savings goals that you record in the app.
- Location (optional): if you authorize it, the app records the location associated with expenses and the trip's movement history. The permission may be revoked at any time in the device settings, on Android or on iOS.
- Images (optional): photos of receipts and items captured by the camera or chosen from the gallery are stored on your device. If you use receipt reading with artificial intelligence, the photo of the receipt is sent, in encrypted form, to our servers (Cloud Functions) and processed by Google's Gemini API, exclusively to extract the amount and description of the expense, never for advertising. The cover image of a trip is synchronized to the cloud when you are signed in, so that it appears on your other devices and on those of the people taking part in the trip.
- Usage data (only with your consent): usage and performance metrics (Firebase Analytics and Performance Monitoring) are collected only if you accept the consent request displayed on first use of the app. The choice may be changed at any time in Settings > Privacy.
- Crash reports: technical records of crashes (Firebase Crashlytics) to diagnose and fix defects. They may be disabled in the app settings.
- Subscriptions: if you subscribe to a paid plan, the payment is processed entirely by the store the application was obtained from, Google Play or the App Store, according to the device; we have no access to your card data. From the store we receive only the purchase confirmation (a technical identifier of the transaction) in order to validate the subscription on our servers and unlock the plan's features on your account.
- Notifications: a technical notification identifier (token) is used to send collaboration notices on shared trips. Communications about news and offers are optional and disabled by default.
3. Where the data is stored
Your records are kept, first of all, in the local database on your device and work offline. If you sign in, the trip and expense data is synchronized with Firebase Firestore (a Google service), to allow backup, use on more than one device and shared trips.
4. Shared trips
When you share a trip by invitation, the participants of the trip come to see the data of that trip: recorded expenses, who paid each expense, balances and settlements. Your name and your profile picture are visible to the other participants. To allow invitations, signed-in users can be found by their exact e-mail address; that search returns only name and picture and may be disabled in the app's privacy settings. Share trips only with people you trust.
5. Legal bases
- Performance of the service (LGPD, art. 7, V; GDPR, art. 6(1)(b)): to store and synchronize the data you record and to unlock the features of paid subscriptions;
- Consent (LGPD, art. 7, I; GDPR, art. 6(1)(a)): for usage and performance metrics (accepted or refused on the consent screen shown on first use and reversible in the settings) and for optional permissions such as location, camera and gallery;
- Legitimate interest (LGPD, art. 7, IX; GDPR, art. 6(1)(f)): for crash reports and security measures against abuse, aimed at the stability and the protection of the service.
6. Who we share data with
We use Google services (Firebase Authentication, Firestore, Cloud Functions, Analytics, Crashlytics, Performance, Cloud Messaging and Remote Config, as well as the Gemini API for receipt reading and Google Play for payments), which act as processors and process data on our behalf. Learn more in Google's privacy policy.
When you sign in with Apple or take out a subscription on the App Store, Apple Inc. processes the data necessary to authenticate the sign-in and to process and charge the purchase, acting independently and according to its own privacy policy; on our side, we receive only the data described in section 2. Learn more in Apple's privacy policy.
We do not sell personal data and do not share it with third parties for advertising purposes.
7. International transfer
Google and Apple services may process data on servers outside Brazil and the European Economic Area. Those transfers rely on the safeguards of the LGPD (art. 33) and of the GDPR (Chapter V), including standard contractual clauses adopted by those providers.
8. Retention and deletion
Data remains stored for as long as you use the application. You may delete trips, expenses and images at any time through the app itself, and erase the local data by uninstalling the application or clearing the data in the device settings.
Account deletion may be carried out directly in the app, under Settings, and removes the access account and the data synchronized to the cloud. If you signed in with Apple, deletion also revokes the Sign in with Apple token associated with the application. If you prefer, request deletion by e-mail at contato@moggydigital.com.br. Records of expense deletions on shared trips keep a technical marker for up to 180 days, so that the deletion propagates to devices that were offline. Crash reports and aggregate metrics follow Firebase's retention periods.
9. Your rights
If you are in Brazil, the LGPD (art. 18) guarantees, among others, the rights to confirmation of processing, access, correction, anonymization, portability, erasure and withdrawal of consent. If you are in the European Union or in the European Economic Area, the GDPR (arts. 15 to 22) guarantees the rights of access, rectification, erasure, restriction, portability and objection.
To exercise them, use the e-mail address indicated above. You may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD), in Brazil, or with the data protection authority of your country, in the European Union.
10. Children and adolescents
Backpacker Spender is not directed at persons under 13 years of age and does not intentionally collect children's data. If you believe that a child has provided us with personal data, get in touch so that it may be removed.
11. Security
We adopt technical and organizational measures to protect the data, including encrypted communication with the cloud services, per-user access rules in the cloud database, invitation-based access control on shared trips and application integrity verification (Firebase App Check, with Play Integrity on Android and Apple's DeviceCheck on iOS) to prevent tampered apps from accessing our servers.
13. Changes to this policy
This policy may be updated to reflect changes in the application or in the law. The date of the last update appears at the top of the page and material changes will be highlighted here.