Carry — Family Budget
Privacy Policy
Carry is designed so that you can start with a local space. Creating an account and moving data to a cloud space are optional, explicit choices.
Last updated: 3 September 2026
1. Who this policy covers
This policy applies to the Carry – Family Budget mobile application, carrybudget.com, and the authentication, support and cloud-sync services connected to them. The service is operated by independent developer Serhii Pavlov (referred to here as “Carry”, “we”, or “us”).
For privacy questions or requests, contact support@carrybudget.com.
2. Data that stays on your device
A local Carry space may contain its name, category budgets, plan items, transactions, notes, currencies and preferences. That information is stored in the app’s local database on your device and is not uploaded to Carry merely because you create it.
If you enable Personal Backup, Carry stores an encrypted recovery copy in your own iCloud or Google Drive app-data area. Apple or Google operates that storage under your account; it is separate from Carry Cloud and is not shared with other members. Files you export remain wherever you save or share them.
3. Data we process when you use an account or online service
- Account data: email address, authentication identifiers, linked sign-in providers, display name, locale, and security/session information.
- Subscription data: your stable Carry account identifier, store, product, purchase and expiration dates, entitlement status and purchase history needed to provide and restore Carry Cloud. Carry and RevenueCat do not receive your full payment-card details from the app store.
- Cloud spaces: spaces you explicitly make cloud-backed, memberships and roles, categories, plan items, transactions, notes, currencies, and their audit history.
- Support data: your email address and the information you choose to include in a support request. Never send passwords or unencrypted financial exports. Send an encrypted .carryrecovery file only when Carry support explicitly asks for it.
- Technical data: limited request metadata such as IP address, timestamps, user agent, error details and security logs generated by our hosting and authentication providers.
- Exchange-rate requests: the base currency and dates required to obtain a rate. Carry does not need your transaction descriptions to request an exchange rate.
4. Microphone, speech and device security
Carry asks for microphone and speech-recognition permission only when you choose a voice-entry feature. Speech is handled using the operating system’s speech services; availability and processing can depend on the device, language and Apple or Google settings. Carry does not use microphone access for advertising and does not keep a voice recording in your Carry budget after the entry flow.
If you enable app lock, Carry uses the device authentication framework to request biometric or passcode verification. Carry does not receive or store your fingerprint or facial biometric template.
5. Why we process data
- Provide spaces, budgeting, authentication, optional shared access, sync, import/export, currency and support features you request.
- Keep shared-space records consistent, attribute changes, enforce roles and prevent unauthorized access.
- Deliver account confirmation, recovery and service messages.
- Diagnose failures, secure the service, prevent abuse and meet legal obligations.
6. Service providers
We use service providers only where needed to operate Carry. Current providers include Supabase for authentication, database and server functions; RevenueCat for subscription purchase history, validation and entitlement status; Firebase Crashlytics for limited app-failure diagnostics without budget contents; Cloudflare for the public site, redirects, request security and support-email routing; Resend for transactional account email delivery; and Apple or Google when you choose their sign-in, store, device or speech services.
These providers process data under their own security and privacy terms. Carry does not sell personal data and does not use advertising or cross-site tracking SDKs in the current app or public site.
Legal bases for processing
- Contract: to provide the account, Carry Cloud, shared budgets, subscription access and support you request.
- Legitimate interests: to secure the service, prevent abuse, diagnose failures and keep shared records consistent, where those interests do not override your rights.
- Consent or device choice: for optional permissions and services such as microphone, speech recognition, Personal Backup and third-party sign-in where applicable.
- Legal obligation: where we must retain or disclose limited records under applicable law.
7. Shared spaces
When you join a shared space, other members can see budget information according to their role. Members may also see the display name attached to changes. Do not add information that other members should not see.
We may disclose information when required by law, to protect users or the service, or as part of a business reorganization subject to appropriate safeguards. We do not disclose budget data to data brokers or advertisers.
8. Retention and account deletion
Local-only data remains on your device until you delete the space, clear the app’s data, or uninstall without a retained device backup. Exported files remain wherever you saved or shared them.
When you delete your Carry account, personal cloud spaces owned only by you are deleted. Your membership is removed from shared spaces. Shared history is retained for the remaining members, but your display name is replaced with “Deleted user”. If you own a space with other members, you must transfer ownership before account deletion can complete.
Account and cloud-budget data is kept while the account or relevant shared space remains active. Authentication deletion uses the provider’s deletion mechanism. Limited security logs, transaction records and protected backups remain only for the provider’s normal security, backup or legal-retention cycle and are then deleted or anonymized.
Deleting a Carry account does not cancel an App Store or Google Play subscription. Store and RevenueCat transaction records may remain under their retention obligations; manage or cancel the subscription in the store before or after deleting Carry.
9. Your choices and rights
- Use Carry locally without creating an account.
- Choose whether a local space is kept local, imported separately, or explicitly made cloud-backed.
- Export budget data, edit account details, leave shared spaces, revoke device permissions, or delete the account in the app.
- Ask us to access, correct, delete, restrict, object to processing, or receive a portable copy of personal data by contacting support@carrybudget.com. You may withdraw consent for optional processing and complain to your local data-protection authority. We may need to verify your identity before acting.
10. Security
We use encrypted network connections, provider-managed authentication, row-level database access controls and role checks. Optional app lock adds a device-level access check. No service can guarantee absolute security, so keep your device, email account and recovery methods protected.
11. Children and international processing
Carry is not directed to children under the minimum age required to manage their own account in their country. A parent or guardian should manage any family budget information involving a child.
Our providers may process data in countries other than yours. Where required, we rely on the provider’s contractual and legal transfer safeguards.
12. Changes and contact
We may update this policy as Carry changes. The date on this page identifies the current version. Material changes will be communicated through the app, site or account email where appropriate. Questions and requests can be sent to support@carrybudget.com.