Privacy Policy
Product information updated 23 September 2026. Publisher: Caspet SRL. Company registration details pending.
This policy covers two things: the Greenling website you are reading now, and the Greenling mobile app for iPhone and Android. Greenling is still in development and is not yet published on any app store. Where the app behaves differently from the website, it says so below.
1. The short version
Greenling has no accounts, no login, no server of ours, and no analytics. What you spend is written to a database file on your own phone and stays there. We do not receive those records. Access to your device and your device backup settings also affect who can access them.
Everyday tracking works offline. When you change currency, the app can request public exchange rates from Frankfurter. This request does not include your expenses, habits or budget. Receipt scanning is not included in the launch release.
2. Who is responsible for your data
The data controller, in the sense of the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), is:
- Controller
- Caspet SRL, a company established in Romania (CUI [CUI], registered office [REGISTERED OFFICE ADDRESS])
- Country
- Romania
- tibastefan321@gmail.com
- Data protection officer
- None appointed. The company is small and the processing does not meet the thresholds in GDPR Article 37.
Full publisher details are on the legal notice page.
3. What the app keeps on your phone
The app writes all of this to a local SQLite database inside its own private storage area on your device:
- Expenses: amount, date, category, optional note, and whether you typed it or scanned it
- Categories you keep or create
- Habit tags you set up, their learning period and the baseline the app works out from your own spending
- Settings: your daily budget, your currency and cached exchange rates
- Daily completion records, monthly tree growth, Garden history and the rewards you have earned
None of it is transmitted anywhere. There is no cloud backup built into the app, and no way for us to read it. Two consequences worth being clear about, because they cut both ways:
- Deleting the app deletes the data. There is no copy to restore from.
- Your phone's own backup may include it. If you have iCloud Backup or Google's Android backup switched on, your operating system may copy the app's files as part of the device backup. That is a service between you and Apple or Google, governed by their privacy policies, not ours. You can exclude it in your device settings.
4. Exchange rates and receipt scanning
Changing currency may fetch a public reference-rate table from Frankfurter over HTTPS. The app requests EUR-based rates; it does not upload your spending records, budget or habit data. The service receives the network information needed to answer the request, such as your IP address.
Rates are cached on your phone. If a fresh rate cannot be fetched, the app can use a cached or built-in reference table. Changing currency converts existing amounts locally after your confirmation.
Receipt scanning is not included in the launch release. The launch app does not send receipt images to a scanning service.
5. This website
The site is a set of static files. It has no login, no forms, no comments and no shop.
- No cookies. The site sets none, of any kind, so there is no cookie banner and nothing to consent to.
- No analytics. There is no Google Analytics, no Plausible, no Meta pixel, no tracking script of any kind.
- No third-party requests. Everything the page loads, including the images and the type, comes from this domain or from your own device's fonts. Nothing is fetched from a content delivery network, and no external service learns that you visited.
- Server logs. The site is served by a static hosting provider, currently GitHub Pages (GitHub, Inc.). Like any web host, it records requests, which can include your IP address, the time, the page requested and your browser's user agent. That is done by the host for security and delivery, not by us, and we do not receive, keep or analyse those logs. GitHub's privacy statement is at docs.github.com. Legal basis: Article 6(1)(f) GDPR, the legitimate interest in serving a website that stays up and is not abused.
6. If you email us
The site offers an email contact link for questions and feedback. If you use it, you send us your email address, whatever name your mail client attaches, and whatever you write. That reaches an ordinary Gmail mailbox operated by Google.
- Purpose: to read your answer, reply to it, and let it change what gets built.
- Legal basis: Article 6(1)(f) GDPR, the legitimate interest in answering someone who wrote to us, and in improving a product using feedback offered for that purpose.
- Retention: kept while the project is active. Ask us to delete your message and we will delete it.
- Publication: we may quote feedback anonymously when writing about the product. We will not publish your email address or your name, and if you tell us not to quote you at all, we will not.
7. What we never do
- No selling, renting or sharing of personal data. Not now, not later, not as an exit.
- No advertising, no advertising identifiers, no profiling for advertising.
- No automated decisions with legal or similarly significant effects, in the sense of Article 22 GDPR.
- No connection to your bank, your cards or your payment notifications. The app has no such access and asks for no such permission.
8. Permissions the app asks for
- Camera and photo library: the launch release does not offer receipt scanning and does not ask you to select or photograph a receipt.
- Internet: used to fetch reference exchange rates when needed for a currency change. Everyday expense tracking works offline.
9. How long data is kept
- On your phone: until you delete the entry, or delete the app. You are in control of it and we have no part in it.
- Emails you send: as described in section 6.
- Host logs: for the host's own retention period, typically a short one.
10. Your rights
Under the GDPR you have the right to ask for access to your personal data, correction, erasure, restriction of processing, portability, and to object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time, which does not affect what was lawful before you withdrew it.
Two honest caveats about exercising them here:
- For the spending data on your phone, there is nothing for us to give you or delete. We have never held it. You already have direct access, and deleting a transaction or the app removes it.
- For emails you have sent us, write to tibastefan321@gmail.com and we will act on the request within one month, as Article 12(3) requires.
If you think we have handled your data badly, you can complain to the Romanian supervisory authority:
- Authority
- Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Address
- B-dul General Gheorghe Magheru 28-30, Sector 1, 010336 Bucureşti, Romania
- Website
- dataprotection.ro
If you live in another EU country, you may complain to your own national authority instead.
11. Children
Greenling is not directed at children. Do not use it if you are under 16, which is the age Romania sets for a child's own consent to information society services under Article 8 GDPR. We do not knowingly collect anything from anyone under that age, and since there are no accounts, there is no age we could verify.
12. Security
The app relies on the protection your phone already gives an app's private storage: sandboxed files, and the device encryption that comes with your lock screen. Set a passcode. Exchange-rate requests travel over HTTPS.
What we will not pretend: an unlocked phone, a jailbroken or rooted device, or a device backup you have configured yourself are all outside what the app can defend.
13. Changes to this policy
The app is in development, so this will change. The version date is at the top of the page. Anything that materially widens what leaves your device will be flagged in the app before it takes effect, not slipped in quietly.
14. Contact
Questions about any of this go to tibastefan321@gmail.com. A real person reads it.
