Zero personal data collected.
Sumptus uses Apple/Google sign-in only. We never see your name, email, or phone — just an opaque random ID.
Legal

Privacy Policy

Effective April 20, 2026 · v1.0
1. Who We Are
Sumptus is an expense tracking app operated by Sumptus (sumptus.app). Contact: support@sumptus.app.
2. What We Collect
Almost nothing. We store an opaque OAuth subject identifier (a random string from Apple or Google). No name, email, phone, address, or device fingerprint. DB-level triggers null out any email or metadata the OAuth provider leaks before the row commits.
3. What We Don't Collect
Name · Email · Phone number · Ad identifiers (IDFA/GAID) · Contacts · Third-party analytics SDKs · Device fingerprints.
4. Data Processors
Apple (Sign In) · Google (Sign In) · Supabase (Auth + Postgres DB) · Sentry (crash & error reporting, EU region — Frankfurt; stack traces + opaque user ID only, no PII).
5. Your Data
Your expenses, settings, and profile are stored in our Postgres database scoped to your opaque user ID. Row-level security prevents any cross-account access. Only you can read your own data.
6. Your Rights (RA 10173)
You may request export or deletion of your data at any time via Settings → Account. Export is a Premium feature that generates a downloadable report. Deletion cascades all database rows and signs you out. Deletion is soft (account deactivated) — contact us to request a hard delete.
7. Children
Sumptus is not directed at children under 13. We do not knowingly collect data from children.
8. Changes
We will update this policy as needed. The effective date is shown at the top. Continued use after changes constitutes acceptance.
9. Contact
support@sumptus.app