Privacy Policy

At ControlarGastos we handle your personal data with the care it deserves. This policy explains in detail what we collect, why, with whom we share it and how you can exercise your rights.

Last updated:

1. Data controller

The controller of the personal data collected through this website is ControlarGastos, hereinafter "the Service".

For any query relating to privacy or the exercise of your rights you can write to us at [email protected].

2. Data we process and why

We only collect what is strictly necessary for the Service to work. These are the data we persist and the purpose of each:

2.1 User account

  • Email — unique account identifier, transactional communications (verification, password recovery).
  • Name — personalisation within the Service.
  • Password — stored exclusively as a bcrypt hash; never in plain text and not recoverable.
  • Language and currency — display preferences.
  • Verification status, lock status and reason — access control and anti-fraud.
  • Temporary password-recovery token — valid for a limited period and deleted after use.
  • Interface preferences — your personal UI configuration, stored in JSON format.

2.2 Sessions and sign-in

  • User-Agent of the browser and device used to sign in.
  • SHA-256 hash of the IP address — we use a hash, not the plain IP, to detect token reuse and possible security incidents without storing the original address.
  • Refresh token hash and expiry or revocation dates.

2.3 Waiting list

  • Email and the plan of interest you indicate.
  • IP address at the time of subscription, kept to prevent automated abuse.

2.4 AI assistant and receipt analysis

  • The messages you send to the assistant and the generated responses, together with a model identifier and aggregated cost metrics.
  • Receipt images you upload so that the system can automatically extract their data.
  • IP address associated with the use of these features, for quota control and abuse prevention.

These cloud AI features require your explicit consent (GDPR art. 6(1)(a)), which we request via an unchecked box before first use and which you can withdraw at any time from your preferences. When you enable them, the receipt image —for scanning— or the assistant messages together with the financial data needed as context are sent to OpenRouter, Inc. (United States), which routes the request to the AI model provider (currently Alibaba Cloud International). OpenRouter does not store the content of requests: it has prompt logging and its associated discount disabled, and only performs an anonymous categorisation sampling using a zero-retention model. The model provider, however, may retain what is sent to it for an undetermined period, although it states that it does not use it to train its models. If you prefer not to send your data to the cloud, receipt scanning offers an alternative that runs locally on your device and does not transmit the image to any third party.

2.5 Financial data you enter

Expenses, income, debts, purchase items, amounts, tags, merchants and any other data you choose to record in the Service. This data belongs to you, is private, is not monetised, is not shared with third parties for commercial purposes and is not used to train artificial intelligence models.

2.6 Push notifications

  • Subscription endpoint generated by your browser and encryption keys (p256dh and auth) that ensure only your device can decrypt the notice.
  • User-Agent of the subscribed device and the subscription date.

Push notifications are an optional feature that you enable yourself from your preferences. When you enable them, the notices are delivered through the messaging service of the browser you useGoogle (Firebase Cloud Messaging) on Chrome and Android, Apple on Safari and iOS, or Mozilla on Firefox—, whose servers act as the delivery channel. The content travels encrypted; the private signing key (VAPID) never leaves our server.

3. Legal bases (GDPR art. 6)

PurposeLegal basis
Create and manage your account, provide the ServicePerformance of a contract (art. 6(1)(b))
Store and display your financial dataPerformance of the contract (art. 6(1)(b))
Running the neighbours' community mode (see section 10)Performance of the Service requested by the community (art. 6(1)(b)) and legitimate interest in managing the financial affairs of the property under commonhold law (art. 6(1)(f))
Subscription to the waiting listConsent (art. 6(1)(a))
Cloud AI assistant and receipt analysisExplicit consent (art. 6(1)(a))
Detection of fraudulent use, quota control, security logsLegitimate interest (art. 6(1)(f))
Strictly technical cookiesPerformance of the contract (art. 6(1)(b))

4. Processors

To provide the Service we rely on providers that act as processors under contract and with adequate safeguards:

  • Shared hosting provider in the European Union — hosting of the application, database and backups.
  • Cloudflare, Inc. (United States) — anti-bot protection via Cloudflare Turnstile on public forms. Transfer covered by the Standard Contractual Clauses (SCC) approved by the European Commission.
  • OpenRouter, Inc. (United States) — artificial intelligence model gateway used, subject to your explicit consent, for the assistant and cloud receipt analysis. It routes the request to the model provider (currently Alibaba Cloud International), which may retain what is sent for an undetermined period without using it for training. Transfer covered by the Standard Contractual Clauses (art. 46 GDPR).
  • Transactional email provider based in the European Union — sending verification, password-recovery and waiting-list notification emails (service currently being activated; this policy will be updated when it goes live).
  • Browser push messaging servicesGoogle LLC (Firebase Cloud Messaging), Apple Inc. or Mozilla Corporation, depending on the browser you use, act as the delivery channel for the push notifications you enable: they receive the encrypted message in order to deliver it to your device. Google and Apple are established in the United States, with the transfer covered by the Standard Contractual Clauses (art. 46 GDPR).

5. International transfers

Some processors (Cloudflare, OpenRouter) are established outside the European Economic Area. These transfers are carried out under the Standard Contractual Clauses approved by the European Commission (Decision 2021/914), with additional technical measures such as encryption in transit.

6. Retention periods

  • User account and financial data — while the account is active. After voluntary cancellation we keep the data for 30 days as a grace period so you can recover the account; after that period it is permanently deleted. The data you share with other people (expenses, debts and their split within groups, community fees) is not destroyed, so as not to erase the legitimate information of third parties: your identity is anonymised and you appear as "Deleted user".
  • Waiting-list subscription — until the corresponding plan launches or until you ask to be removed.
  • Application logs — daily rotation with a maximum of 14 days.
  • Security event log — when we detect hostile activity (automated probes, attack paths, rate-limit abuse or failed access attempts) we record the plain IP address together with the path, method and user agent, on the basis of our legitimate interest in protecting the Service against attacks (art. 6(1)(f)). These records are kept for as long as they remain necessary for the security of the Service (forensic analysis of incidents and blocking of repeat attackers), with no predetermined erasure period.
  • Session tokens — deleted on expiry or 30 days after revocation.
  • Push notification subscription — removed when you turn notifications off, when you cancel your account, when your browser reports that the subscription is no longer valid, or automatically if delivery fails persistently (several consecutive failures or 30 days since the last failure).
  • Assistant messages — kept as browsable history for a maximum of 90 days and then deleted automatically.
  • Receipt analysis — the result (cost, model and your corrections; never the receipt image) is kept as personal history in your account until you delete it or cancel your account.

7. Your rights

You can exercise the following rights recognised by the GDPR at any time:

  • Access — request a copy of the personal data we process about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request the deletion of your data when it is no longer necessary.
  • Objection — object to processing based on legitimate interest.
  • Restriction — ask us to restrict processing in specific cases.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdrawal of consent — where processing is based on it, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, write to us at [email protected] indicating the right you wish to exercise and, where necessary, any information that allows us to verify your identity as the account holder.

7.1 Deleting your account

You can request the deletion of your account at any time from your profile, confirming it with your password. Deletion opens a 30-day grace period during which the account is inactive but you can recover it simply by signing in again. After the 30 days, the account is permanently deleted: data that is exclusively yours is erased and, in information shared with other people, your identity is anonymised and you appear as "Deleted user", so that the legitimate accounting of the group or community is preserved without keeping your personal data.

7.2 Unsubscribing from invitation emails without an account

If you have received an email inviting you to a group or community but you do not have a ControlarGastos account, you can object to receiving more of them using the unsubscribe link included in the email itself. From that moment on we will not send any further invitations to that address.

8. Complaint to the supervisory authority

If you believe that the processing of your data does not comply with the regulations, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es), although we would be grateful if you would first give us the opportunity to resolve the matter directly.

9. Security

We apply reasonable technical and organisational measures to protect your data:

  • Encryption in transit using TLS for all communications.
  • Storage of passwords as a bcrypt hash, with no possibility of recovery.
  • SHA-256 hashing of the IP addresses associated with sessions, instead of storing the plain IP (attack-detection records are the exception: they keep the plain IP for as long as it is necessary for the security of the Service, as set out in the retention periods).
  • Rotation of session tokens and automatic revocation upon detected reuse attempts.
  • Internal access restricted to strictly necessary personnel.

No system is infallible: if we detect a security breach affecting your data, we will notify you without undue delay and within the timeframes set out by the regulations.

10. Neighbours' community mode

The Service offers a neighbours' community mode that lets a homeowners' association, through its president or board, manage its financial affairs (accounting years, fees and common expenses), a notice board and a document archive. Because this mode processes personal data of third parties —the neighbours—, it deserves a specific explanation.

10.1 Data processed

  • Neighbour identification — the name of the person who is a member of the community.
  • Invitation email — the address to which the president sends the invitation to join the community.
  • Dwelling and participation coefficient — the assigned property and its participation share, needed to split common expenses.
  • Your own fee status — the amount and status (paid or pending) of your fees.
  • Notice board announcements — the communications the board publishes for the community.
  • Board documents — minutes, budgets, notices of meeting and other files uploaded by the presidency, which may contain third-party data.

10.2 Legal bases

  • Running the community — provision of the Service requested by the community through its president or board (art. 6(1)(b)), complemented by the legitimate interest in managing the financial affairs of the property under Spanish Commonhold Law 49/1960 (art. 6(1)(f)).
  • Level of financial detail — the board resolution is the basis that determines what level of detail of the financial information each neighbour can see. By default, and unless resolved otherwise, each neighbour only accesses aggregated information; periodic detail requires a board resolution enabling it.

The allocation of responsibilities between the community and the Service (who is the controller and who is the processor) is set out in the Terms and Conditions.

10.3 Who sees each piece of data

Within a community, access to the data depends on each member's role:

  • Each neighbour sees their own fees in detail, the notice board announcements and the community documents.
  • Arrears are shown to neighbours only in aggregated form (total outstanding and number of dwellings in arrears); never the name or dwelling of whoever owes.
  • The presidency, as the party responsible for administration, accesses the nominal fee status per dwelling, which is essential for its function.
  • No new external recipients are added: community data is hosted by the same European Union processors listed in section 4.

10.4 Retention

  • Neighbour data is kept while their membership of the community is active and for as long as the community's accounting requires.
  • Documents are kept while the community is active or until the board deletes them.

10.5 Exercising your rights

You can exercise the rights in section 7 before the controller by writing to [email protected]. Where the data was provided by the community's board —for example, your name in minutes uploaded by the presidency—, the handling of your request will be coordinated with the community's president, who is the one who decides on the content of those documents.

11. Minors

The Service is not directed at children under 14. If you are under that age, you must not register or provide us with personal data. If we detect an account belonging to a child under 14, we will close it.

12. Changes to this policy

We may update this Privacy Policy to reflect changes in the Service or in the applicable regulations. When the changes are substantial we will notify you by email or via a prominent notice within the Service. The date of the last update appears at the top of this page.