Privacy Policy
Cento — by Funcode SRL · Effective date: 9 September 2026
This Privacy Policy explains how Funcode SRL ("we", "us") processes personal data
in the Cento mobile application ("Cento", "the app"). We are the data controller.
1. Who we are
Funcode SRL, Eugen Ionescu, Cluj-Napoca, Romania.
Fiscal code (CUI/CIF): RO31945144 · Trade Register no.: J12/2104/01.07.2013.
Contact for privacy questions and data-subject requests: contact@funcode.ro.
2. Local-first by design
Cento's expense tracking works offline and signed-out. When you are signed out, your expense
data stays on your device and is never uploaded. Personal data leaves your device
only when you sign in and use cloud or AI features, or when you turn on the optional analytics
described in section 3, which sends anonymous usage events and never your expenses.
3. What we collect and why
- Account identity — when you sign in with Google, we receive your
email address and display name via Firebase Authentication, to identify your account.
- Anonymous identifier for free scans — if you try AI receipt scanning
without signing in, we create an anonymous Firebase Authentication identity (no email,
no name) with a random pseudonymous ID, used solely to count your scans against the
limits that apply to scanning: a lifetime total on the free tier, and a daily ceiling
that applies to every account. The same anonymous identity is created the first time
you open the Premium screen, so that the aggregate counts below can be written.
- Anonymous Premium-screen counts — we record how many times the Premium
screen is opened and what happens next (which plan is tapped, whether a purchase starts or
completes, how the screen is left). These are plain running totals per calendar day. They
contain no account, device or advertising identifier and no time of day, so they cannot be
traced back to you or to any single visit. We use them to see where people give up on the
Premium screen and to improve it. They are kept for 400 days and then deleted
automatically.
- Household member name — a name you choose for yourself in a shared
household (stored instead of your email), so household members can tell entries apart.
- Financial data — your expenses, categories, people and transfers.
This is synced to the cloud only when you have Premium and cloud sync is enabled.
- Receipt images — if you use AI receipt scanning, the image is sent
to Google's Gemini API to extract the amount and details, then processed transiently.
- Usage & subscription — AI-scan usage counters (a lifetime total
and a per-day count) and your subscription/entitlement status, to enforce plan limits
and unlock Premium.
- Feedback you send — if you use the in-app feedback form, your message
plus a short diagnostic footer (app version, device model and OS, and basic account
status such as your plan, household mode and household identifier) are placed into an
email that you review and send to us from your own email app, to help us
reproduce and fix issues. You can edit or remove any of it before sending.
- Analytics & marketing measurement (optional, off until you turn it on, off again
any time in Settings): while this is on, we use Google Analytics for Firebase to collect
anonymous product-usage events and to measure and optimise our advertising campaigns (for
example, which campaign led to an install or a subscription). On Android this uses the Google
Play install referrer and the Android advertising ID, which you can reset or delete in your
device's Google settings. On iOS no advertising identifier is read and no tracking permission
is requested; instead, if you are signed in, Google's SDK matches a hashed form of your email
address on your device, and the address itself never leaves it. It never includes what you
spend, and no ads are shown in Cento.
4. Legal bases
We process account, financial and subscription data to perform our contract
with you (providing the service you asked for). AI scanning is provided on your
request. Analytics & marketing measurement runs only on your consent
(Art. 6(1)(a) GDPR), given by turning the option on at first launch or in Settings; you can withdraw
it there at any time, which stops collection going forward without affecting what was lawfully
processed before. Where we rely on legitimate interests (e.g. security and
abuse prevention), you may object as described below.
5. Who processes your data (sub-processors)
- Google Firebase — Authentication, Firestore, Cloud Functions, Hosting (EU region, europe-west1).
- Google Play Billing — subscription purchases and verification.
- Google Gemini API — AI receipt extraction.
- Google Analytics for Firebase / Google Ads — anonymous product-usage and advertising-campaign
measurement (only if you turn on Analytics & marketing measurement).
Some processing may involve transfers outside the EU under Google's standard safeguards.
6. How we keep your data secure
We apply technical and organisational measures to protect your data. Cloud data is stored
in the European Union (europe-west1) and access is restricted by server-side rules to the
members of your own household. Your financial data is stored under a random
pseudonymous identifier rather than your account identity or email address,
so records in our database are not directly linked to you (pseudonymisation under Art. 32 GDPR).
Data stored on your device is protected by Android's app sandbox and your device's built-in
encryption — we recommend setting a screen lock.
7. Retention
We keep cloud data while your account exists. When you delete your account, your
server-side data is erased. If you were part of a shared household and other members
remain in it, the records you contributed — your expenses, the member name you chose,
and any categories or transfers you added — stay with that household so the remaining
members keep their shared history; they are erased when the household itself is deleted.
On-device data is removed when you delete the app or its data. Analytics events, if you turned
analytics on, are kept by Google Analytics for Firebase for up to 14 months and are not linked to
your account; turning analytics off stops new events immediately, erases the analytics data held on
your device and resets its analytics identifier, so earlier events cannot be linked to later use.
Deleting your account does the same.
8. Your rights
You have the right to access, rectify, erase, restrict, port, and object to the
processing of your personal data, and to withdraw any consent you have given. You can
delete your account and erase your cloud data directly in the app (Settings → Your
account → Delete account) and withdraw analytics consent in Settings → Privacy. For any
other request, email contact@funcode.ro. You may also
lodge a complaint with the Romanian supervisory authority (ANSPDCP).
9. Children
Cento is not directed at children under 16 and we do not knowingly collect their data.
10. Changes
We may update this policy; material changes will be reflected by a new effective date here.