Privacy Policy

At ControlarGastos we handle your personal data with the care it deserves. This policy explains in detail what we collect, why, with whom we share it and how you can exercise your rights.

Last updated:

1. Data controller

The controller of the personal data collected through this website is ControlarGastos, hereinafter "the Service".

For any query relating to privacy or the exercise of your rights you can write to us at [email protected].

2. Data we process and why

We only collect what is strictly necessary for the Service to work. These are the data we persist and the purpose of each:

2.1 User account

  • Email — unique account identifier, transactional communications (verification, password recovery, changes to your account) and the notices about your groups and debts described in section 2.7.
  • Name — personalisation within the Service.
  • Password — stored exclusively as a bcrypt hash; never in plain text and not recoverable.
  • Language and currency — display preferences.
  • Verification status, lock status and reason — access control and anti-fraud.
  • Temporary password-recovery token — valid for a limited period and deleted after use.
  • Interface preferences — your personal UI configuration, stored in JSON format.

2.2 Sessions and sign-in

  • User-Agent of the browser and device used to sign in.
  • SHA-256 hash of the IP address — we use a hash, not the plain IP, to detect token reuse and possible security incidents without storing the original address.
  • Refresh token hash and expiry or revocation dates.

2.3 Waiting lists

  • If you signed up to the waiting list for a paid plan: your email and the plan of interest you indicated, plus your IP address at the time of subscription, kept to prevent automated sign-ups for the period stated in section 6, after which it is erased and the subscription is kept without it.
  • If you signed up to the waiting list for neighbours' community mode: your email, the role you indicated (chair, committee member or resident) and the approximate size of the community. We do not keep your IP address there, nor any data about your home or your finances. That list no longer accepts new sign-ups: we only keep those collected while community mode was in preparation.

2.4 AI assistant and receipt analysis

  • The messages you send to the assistant and the generated responses, together with a model identifier and aggregated cost metrics.
  • Receipt images you upload so that the system can automatically extract their data.
  • A cryptographic fingerprint of the IP address you write to the assistant from —an HMAC-SHA256 from which the original address cannot be recovered—, for quota control and abuse prevention. The plain IP is not stored. No address at all is recorded for receipt analysis.

These cloud AI features require your explicit consent (GDPR art. 6(1)(a)), which we request via an unchecked box before first use and which you can withdraw at any time from your preferences. When you enable them, the receipt image —for scanning— or the assistant messages together with the financial data needed as context are sent to OpenRouter, Inc. (United States), which routes the request to the AI model provider (currently Alibaba Cloud International). OpenRouter does not store the content of requests: it has prompt logging and its associated discount disabled, and only performs an anonymous categorisation sampling using a zero-retention model. The model provider, however, may retain what is sent to it for an undetermined period, although it states that it does not use it to train its models. If you prefer not to send your data to the cloud, receipt scanning offers an alternative that runs locally on your device and does not transmit the image to any third party.

2.5 Financial data you enter

Expenses, income, debts, purchase items, amounts, tags, merchants and any other data you choose to record in the Service. This data belongs to you, is private, is not monetised, is not shared with third parties for commercial purposes and is not used to train artificial intelligence models.

2.6 Push notifications

  • Subscription endpoint generated by your browser and encryption keys (p256dh and auth) that ensure only your device can decrypt the notice.
  • User-Agent of the subscribed device and the subscription date.

Push notifications are an optional feature that you enable yourself from your preferences. When you enable them, the notices are delivered through the messaging service of the browser you useGoogle (Firebase Cloud Messaging) on Chrome and Android, Apple on Safari and iOS, or Mozilla on Firefox—, whose servers act as the delivery channel. The content travels encrypted; the private signing key (VAPID) never leaves our server.

2.7 Email notices about your groups and debts

In addition to account communications, the Service may send you email notices when another person does something that affects you: someone adds an expense that is split with you, confirms or undoes a payment between you, or settles a debt you had. These notices include the specific detail of that movement —its amount, the description given by whoever created it, the group and who did it—, that is, exactly the same information you can already see in the app and that you share with that person by being in the same group or the same debt. When several occur within a short time, they are grouped into a single email per hour or per day, depending on your choice.

We do not send summaries of your financial situation: no balances, no periodic reports, no statistics about your activity. Each notice responds to one specific event and contains only the detail of that event. You can turn email on and off for each type of notice separately from your preferences. Notices about everyday activity in your groups —a new expense, a confirmed payment, a debt being settled— are off by default. The ones listed below arrive enabled, all for the same reason: either the person receiving them is precisely the one not opening the app —so inside it the notice would arrive too late— or a deadline is running that could harm you if nobody tells you. These are they:

  • You have been invited to a group — you may not even have used the app yet.
  • You are offered a group — the offer expires by itself after two days: if you never hear about it, silence decides for you.
  • You are no longer in a group — someone else has removed your access; you decided nothing, and the group disappears from your lists with no explanation.
  • There is a new notice on your community's board — the board is only visible from inside the app, and what gets posted there may be a meeting call with a date.
  • A community of yours has been archived — with the limited window to recover its documentation.
  • A debt will be treated as settled if you do not reply in time.
  • A scheduled entry has stopped being created — only you can fix it, and every month that passes is another one missing.
  • You have used up your plan's monthly allowance.

All of them are service notices: they tell you about something that has already happened in your account and are part of providing the Service (GDPR art. 6(1)(b), performance of the contract). None of them sells you anything, so they are not commercial communications. You can turn any of them off, one by one, from your preferences.

2.8 Access tokens for external artificial intelligence agents

The Service lets you create, from your profile, access tokens with which to connect an external artificial intelligence agent —whichever assistant you choose and contract on your own— to your Service data. This is an optional feature: if you never create a token, none of what follows happens. Creating one requires re-entering your current password, and the secret is shown only once, at the moment you create it.

  • What we store — the name you give the token so you can recognise it, the token's SHA-256 hash (never the plain secret), the list of permissions you granted it, the creation date, the last-used date and, where they exist, the expiry and revocation dates.
  • What the agent can access — only what the permissions you granted cover, and those are granted one by one (for example, read-only access to expenses). The agent acts on your behalf: it never reaches beyond what you yourself could see or do, and always the same or less.

What happens to that data outside the Service is not under our control. The provider of the agent you choose will receive the information that agent queries —including your financial data— and will process it under their terms and privacy policy, not ours. That provider is not a processor of ours: it acts on your behalf, because you are the one who chooses it, contracts it and grants it access. Before creating a token, check what that provider does with what you send it and grant only the permissions it needs.

You can revoke any token at any time from your profile, with immediate effect. In addition, changing your password automatically revokes all your agent tokens, along with the rest of your account credentials: if you suspect improper access, changing your password also cuts off this route without you having to review token by token.

2.9 Service usage analytics

To know which parts of the Service are used, to detect errors and to decide what to improve, we record on our own servers usage events linked to your account, while you are signed in: the screens you visit, the action buttons you press, the features you use and the requests your browser makes to our API, with their path, method, response code and how long they took. None of those usage events is recorded while you are signed out. The measurement is done by our own server, with no analytics cookies and no third parties involved (see the Cookie Policy).

These events do not include the content of your financial data: they record the action, not what is inside it. No amounts, no descriptions, no tags, no merchants. The IP address and browser attached to each event are stored only when the account holds administration permissions over the Service itself —a safeguard against those accounts being compromised—; for everyone else, those two fields are left empty. Events are deleted automatically after 365 days.

Separately, we measure the technical performance of the pages (loading and interface response times). Those samples are anonymous: they carry no account, no identifier linking them to one another, no IP address and no data about your browser. Only the measurement, its value and the screen it was taken on. And to obtain them we neither write to nor read from your device. Unlike usage events, this measurement is collected even when you are signed out, on the public pages of the site (home, sign-in, sign-up, blog and these legal pages), because its purpose is to know whether a page loads slowly and that mostly happens before you sign in.

3. Legal bases (GDPR art. 6)

PurposeLegal basis
Create and manage your account, provide the ServicePerformance of a contract (art. 6(1)(b))
Store and display your financial dataPerformance of the contract (art. 6(1)(b))
Emailing you about what happens in your groups, debts and communities (section 2.7)Performance of the contract (art. 6(1)(b)): they are service notices about events in your own account, not commercial communications, and you can turn them off one by one
Running the neighbours' community mode (see section 10)Performance of the Service requested by the community (art. 6(1)(b)) and legitimate interest in managing the financial affairs of the property under commonhold law (art. 6(1)(f))
Subscription to the waiting listConsent (art. 6(1)(a))
Cloud AI assistant and receipt analysisExplicit consent (art. 6(1)(a))
Connecting an external AI agent through the tokens you create (section 2.8)Performance of the contract (art. 6(1)(b)): it is a Service feature you expressly request by creating the token
Service usage analytics (section 2.9)Legitimate interest (art. 6(1)(f)) in maintaining, fixing and improving the Service, with no profiling and no decisions about you
Detection of fraudulent use, quota control, security logsLegitimate interest (art. 6(1)(f))
Strictly technical cookiesPerformance of the contract (art. 6(1)(b))

4. Processors

To provide the Service we rely on providers that act as processors under contract and with adequate safeguards:

  • Shared hosting provider in the European Union — hosting of the application, database and backups.
  • Cloudflare, Inc. (United States) — anti-bot protection via Cloudflare Turnstile on public forms. Transfer covered by the Standard Contractual Clauses (SCC) approved by the European Commission.
  • OpenRouter, Inc. (United States) — artificial intelligence model gateway used, subject to your explicit consent, for the assistant and cloud receipt analysis. It routes the request to the model provider (currently Alibaba Cloud International), which may retain what is sent for an undetermined period without using it for training. Transfer covered by the Standard Contractual Clauses (art. 46 GDPR).
  • Transactional email provider based in the European Union — sending all Service emails: verification, password recovery, account changes, group and community invitations, the notices described in section 2.7, and waiting-list notifications. For the latter, your address is added to the contact list corresponding to the plan you indicated, hosted by the provider itself, and removed from there when you unsubscribe or when we no longer need it.
  • Browser push messaging servicesGoogle LLC (Firebase Cloud Messaging), Apple Inc. or Mozilla Corporation, depending on the browser you use, act as the delivery channel for the push notifications you enable: they receive the encrypted message in order to deliver it to your device. Google and Apple are established in the United States, with the transfer covered by the Standard Contractual Clauses (art. 46 GDPR).

The provider of the artificial intelligence agent you connect with a token (section 2.8) is not on this list and is not a processor of ours: we do not choose it, we do not contract it and we impose no terms on it. It receives the data because you granted it access, and it processes that data on your behalf and under its own policy.

5. International transfers

Some processors (Cloudflare, OpenRouter) are established outside the European Economic Area. These transfers are carried out under the Standard Contractual Clauses approved by the European Commission (Decision 2021/914), with additional technical measures such as encryption in transit.

6. Retention periods

  • User account and financial data — while the account is active. After voluntary cancellation we keep the data for 30 days as a grace period so you can recover the account; after that period it is permanently deleted. The data you share with other people (expenses, debts and their split within groups, community fees) is not destroyed, so as not to erase the legitimate information of third parties: your identity is anonymised and you appear as "Deleted user".
  • Waiting-list subscription — until whatever you signed up for launches —the plan, or neighbours' community mode— and, from that moment, for a further 90 days: the time needed to send you the launch notice and to handle any complaint, after which we erase it, whether or not you subscribed. You may also ask to be removed sooner, using the link we include in the email we send you when you sign up, explained in section 7.2. While the Service remains in early access there is no launch, so nothing is erased through this route; we periodically review the oldest subscriptions and erase them if what you were waiting for is no longer planned. The associated IP address has its own, shorter period: 90 days, after which it is erased and the subscription is kept without it. If your address had been added to the email provider's contact list, we first request its removal there and only then delete it from our database. And if you also have an account and delete it, your waiting-list subscriptions are deleted along with it, without waiting for those periods.
  • Group and community bin — when a group is archived it moves to a bin from which it can be restored for 30 days; if nobody does, it is permanently deleted along with the information that only lived inside it. For neighbours' communities that period is 90 days (see section 10).
  • AI agent tokens (section 2.8) — until you revoke them, until the expiry date you set when creating them and, in any case, until you change your password or delete your account.
  • Usage analytics (section 2.9) — 365 days, after which the events are deleted automatically.
  • Anonymous performance metrics (section 2.9) — 90 days.
  • In-app notifications — those you have already read are deleted after 180 days; unread ones are kept until you read them.
  • File import sessions — the record of the import process (counts of successful, skipped and failed rows so you can resume it) is deleted after 30 days. The file you import is not kept, because it is never uploaded: it is read inside your own browser.
  • Application logs — daily rotation with a maximum of 14 days.
  • Security event log — when we detect hostile activity (automated probes, attack paths, rate-limit abuse or failed access attempts) we record the plain IP address together with the path, method and user agent, on the basis of our legitimate interest in protecting the Service against attacks (art. 6(1)(f)). These records are kept for as long as they remain necessary for the security of the Service (forensic analysis of incidents and blocking of repeat attackers), with no predetermined erasure period.
  • Session tokens — deleted on expiry or 30 days after revocation.
  • Push notification subscription — removed when you turn notifications off, when you cancel your account, when your browser reports that the subscription is no longer valid, or automatically if delivery fails persistently (several consecutive failures or 30 days since the last failure).
  • Assistant messages — kept as browsable history for a maximum of 90 days and then deleted automatically.
  • Receipt analysis — the result (cost, model, how many lines it read, whether you already used it to create an expense, and your corrections; never the receipt image) is kept as personal history in your account until you delete it or cancel your account.
  • Record of community archival — the record of who ordered a community to be archived, restored or permanently deleted is kept for as long as it may be needed to evidence that instruction and to establish accountability, even after the community itself has been deleted (which is precisely the scenario where it is needed). The IP address attached to that record has its own, shorter period: 12 months, after which it is erased and the rest of the record is kept without it. See section 10.

7. Your rights

You can exercise the following rights recognised by the GDPR at any time:

  • Access — request a copy of the personal data we process about you. You do not need to ask for it: you can download it yourself at any time (section 7.3).
  • Rectification — correct inaccurate or incomplete data. Your name, email address and password can be changed directly from your profile.
  • Erasure — request the deletion of your data when it is no longer necessary.
  • Objection — object to processing based on legitimate interest.
  • Restriction — ask us to restrict processing in specific cases.
  • Portability — receive your data in a structured, machine-readable format, available instantly from your profile (section 7.3).
  • Withdrawal of consent — where processing is based on it, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, write to us at [email protected] indicating the right you wish to exercise and, where necessary, any information that allows us to verify your identity as the account holder.

7.1 Deleting your account

You can request the deletion of your account at any time from your profile, confirming it with your password. Deletion opens a 30-day grace period during which the account is inactive but you can recover it simply by signing in again. After the 30 days, the account is permanently deleted: data that is exclusively yours is erased and, in information shared with other people, your identity is anonymised and you appear as "Deleted user", so that the legitimate accounting of the group or community is preserved without keeping your personal data.

If you are the president of a neighbours' community, deletion cannot be completed while you remain president: removing your account would leave the community with nobody to administer it and its neighbours without access to their own management. In that case the Service tells you so and offers two routes, both in your hands: transfer the presidency to another member, or archive the community. Once you do either, deletion proceeds normally. Your right to erasure is not denied: it is merely put on hold for as long as strictly necessary so that third-party data is not left with nobody accountable for it.

7.2 Unsubscribing without needing an account

If you have received an email inviting you to a group or community but you do not have a ControlarGastos account, you can object to receiving more of them using the unsubscribe link included in the email itself. From that moment on we will not send any further invitations to that address.

If you signed up to a plan's waiting list, the email we sent you when you did includes its own unsubscribe link. Using it does not merely stop us writing to you: we delete your address from the list, and we also request its erasure from the email provider if a copy was held there. They are two independent opt-outs: unsubscribing from invitations does not remove you from the waiting list, nor the other way round.

7.3 A copy of your data, instantly and without asking

For the rights of access and portability you do not need to write to us or wait: from your profile, the export your data option immediately downloads a JSON file, structured and machine-readable, containing the personal data we process about you and the content you have recorded —profile and preferences, expenses, income, debts, tags, budgets, goals, shopping lists, recurring entries, groups, communities, notifications, receipt scans, assistant history, your waiting-list subscriptions, the community invitations you have received at that address and, if you ever asked not to receive invitation emails, the corresponding opt-out (its reason and its date)—.

That file is minimised with respect to third parties: of the people you share expenses, groups or communities with, it includes only the name you see them under in the app, never their email or any other data of theirs. Nor does it contain passwords or tokens. If you would rather request it in writing, the route in section 7 remains open.

8. Complaint to the supervisory authority

If you believe that the processing of your data does not comply with the regulations, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es), although we would be grateful if you would first give us the opportunity to resolve the matter directly.

9. Security

We apply reasonable technical and organisational measures to protect your data:

  • Encryption in transit using TLS for all communications.
  • Storage of passwords as a bcrypt hash, with no possibility of recovery.
  • Hashing of IP addresses instead of the plain address wherever possible: SHA-256 for sessions and HMAC-SHA256 for the AI assistant.
  • The full IP is kept only in the following cases, each with its own purpose and with the retention periods stated there: the attack-detection records —including the blocking of repeat-offending addresses and the alerts on sign-ins to administration accounts—, the waiting-list subscription, where it deters automated sign-ups and is erased after 90 days, the events of accounts holding administration permissions over the Service (section 2.9) and the record of community archival actions (section 10). It is kept in full —neither truncated nor hashed— because a partial value would allow neither the attacker to be blocked nor the author of an action to be evidenced, which is its sole purpose. None of those addresses is shown on the Service's screens: the security records can only be consulted from the administration panel, restricted to strictly necessary personnel.
  • In usage analytics, the IP and browser are stored only for accounts holding administration permissions over the Service; for all others, those fields are left empty.
  • Rotation of session tokens and automatic revocation upon detected reuse attempts.
  • Access tokens —both session and AI agent tokens— are stored only as a hash: not even we can recover the secret.
  • Internal access restricted to strictly necessary personnel.

No system is infallible: if we detect a security breach affecting your data, we will notify you without undue delay and within the timeframes set out by the regulations.

10. Neighbours' community mode

The Service offers a neighbours' community mode that lets a homeowners' association, through its president or board, manage its financial affairs (accounting years, fees and common expenses), a notice board and a document archive. Because this mode processes personal data of third parties —the neighbours—, it deserves a specific explanation.

10.1 Data processed

  • Neighbour identification — the name of the person who is a member of the community.
  • Invitation email — the address to which the president sends the invitation to join the community.
  • Dwelling and participation coefficient — the assigned property and its participation share, needed to split common expenses.
  • Your own fee status — the amount and status (paid or pending) of your fees.
  • Notice board announcements — the communications the board publishes for the community.
  • Board documents — minutes, budgets, notices of meeting and other files uploaded by the presidency, which may contain third-party data.
  • Record of archival actions — when someone orders a community to be archived, restores it, or when it is permanently deleted once the grace period lapses, we record the action: which community it was and its name, who ordered it (their account identifier, email address and the role they held at that moment), when, whether the copy of the data was delivered to them, which version of the responsibility statement they accepted, the warnings shown to them, how many neighbours were notified and through which channels, and the IP address it was done from. No financial content and no data about other neighbours is recorded: only the action, and of the notification only the number of recipients.

10.2 Legal bases

  • Running the community — provision of the Service requested by the community through its president or board (art. 6(1)(b)), complemented by the legitimate interest in managing the financial affairs of the property under Spanish Commonhold Law 49/1960 (art. 6(1)(f)).
  • Level of financial detail — the board resolution is the basis that determines what level of detail of the financial information each neighbour can see. By default, and unless resolved otherwise, each neighbour only accesses aggregated information; periodic detail requires a board resolution enabling it.
  • Record of archival actions — compliance with our legal obligation as a processor to act only on documented instructions from the controller and to be able to demonstrate it (art. 28(3)(a) and (h) GDPR).
  • IP address of those actions — our legitimate interest in information security (art. 6(1)(f) and recital 49 GDPR), specifically being able to evidence who performed an irreversible action on a community's data if it is claimed that someone accessed an account without authorisation. That interest is shared by you, as the account holder and the victim in such a case, and by the neighbours affected. It is kept in full —not truncated— because only then does it allow the responsible party to be identified should the need arise, and only for 12 months. We have documented the balancing of this interest against your rights and you may request it, as well as object to the processing, at [email protected].

The allocation of responsibilities between the community and the Service (who is the controller and who is the processor) is set out in the Terms and Conditions.

10.3 Who sees each piece of data

Within a community, access to the data depends on each member's role:

  • Each neighbour sees their own fees in detail, the notice board announcements and the community documents.
  • Arrears are shown to neighbours only in aggregated form (total outstanding and number of dwellings in arrears); never the name or dwelling of whoever owes.
  • The presidency, as the party responsible for administration, accesses the nominal fee status per dwelling, which is essential for its function.
  • No new external recipients are added: community data is hosted by the same European Union processors listed in section 4.

10.4 Retention

  • Neighbour data is kept while their membership of the community is active and for as long as the community's accounting requires.
  • Documents are kept while the community is active or until the board deletes them.
  • When a community is archived, its data moves to a bin from which any member can restore it; if nobody does, once the grace period stated in section 6 lapses it is permanently deleted along with its documents and announcements.
  • The record of the archival action outlives that deletion: it is what allows us to evidence who gave the instruction and that the neighbours were notified once nothing else remains. It contains no financial information and no data about other neighbours. The IP address it includes is erased after 12 months, and the rest of the record continues without it.

10.5 Exercising your rights

You can exercise the rights in section 7 before the controller by writing to [email protected]. Where the data was provided by the community's board —for example, your name in minutes uploaded by the presidency—, the handling of your request will be coordinated with the community's president, who is the one who decides on the content of those documents.

11. Minors

The Service is not directed at children under 14. If you are under that age, you must not register or provide us with personal data. If we detect an account belonging to a child under 14, we will close it.

12. Automated decision-making

We do not take automated decisions that produce legal effects concerning you or similarly significantly affect you (GDPR art. 22), nor do we carry out profiling for that purpose. It is still worth being precise about what is automated:

  • An internal system scores bad-faith use of the free plan from usage indicators. That score triggers no consequence on its own: at most it raises an internal alert, and any measure affecting an account —including its suspension— is always decided and carried out by a person.
  • Anti-abuse systems may throttle the rate of requests or temporarily block access from an IP address when they detect an attack pattern. That is a measure against the origin of the requests —not an assessment of the person— and it alters neither the data nor the content of any account.

If at any point an automated decision were to affect you significantly, you would have the right to obtain human intervention, to express your point of view and to contest the decision.

13. Changes to this policy

We may update this Privacy Policy to reflect changes in the Service or in the applicable regulations. When the changes are substantial we will notify you by email or via a prominent notice within the Service. The date of the last update appears at the top of this page.