Privacy Policy for Debtly
Last Updated: August 21, 2026
At Debtly, jointly operated by Jhoseph Jefferson Guerrero Puche and Alejandro José González Duarte (hereinafter, the "Operators"), we take your privacy and data security very seriously. This Privacy Policy describes how we collect, use, protect, and share your information when you use our mobile and web application (the "Application").
Our privacy practices are designed to support compliance with applicable data protection laws. The rights and obligations described below may vary depending on your location, including where the General Data Protection Regulation (GDPR) or California privacy laws apply.
1. Data Collection Map and Detailed Usage
The Application collects First-Party information strictly for the functional purposes described below:
| Data Category | Specific Data Collected | Technical Purpose |
|---|---|---|
| Account Data | Email address, password, display name, username, profile picture, and unique debtor code (debtorCode). | Secure profile authentication and allowing other users to search and invite you to financial groups. |
| Application Data | Debt amounts, descriptions, due dates, mathematical split rules, receipt or supporting images, friend requests, names and info from locally added contacts. | Core service: computing general balances (how much you owe/are owed) and syncing the history with involved parties. |
| Payment Methods | Text strings containing convenience data (e.g., Zelle username, account number, banking codes). | Acts as an informational clipboard to easily share account details outside the app when settling debts. |
| Technical Data | Notification Push Tokens, encrypted session tokens, IP address, device type, browser, error logs. | Maintaining secure active sessions, routing operational push alerts, and monitoring system performance. |
2. Local Storage and Persistence Technologies
In addition to the cloud processing described in this Policy, the Application uses native device and browser storage for limited technical and functional purposes:
- Secure Session: Stores an encrypted access token to safely maintain the user's active session without requiring credentials on every open.
- System Preferences: Persists the chosen base currency and preferred language to speed up interface rendering.
- Search History: Local ephemeral list of recently searched users to speed up the interface and reduce network load.
3. Third-Party Data Processors
Debtly DOES NOT sell, rent, or trade your personal data or financial logs. Data is transferred solely to essential infrastructure providers:
- Supabase: Cloud infrastructure provider hosting our secure database, handling user authentication, and storing multimedia assets such as profile pictures and receipt or supporting images.
- Expo / APNs (Apple) / FCM (Google): Infrastructure services that receive the technical device identifier (Push Token) to route and successfully deliver native operational alerts.
- Sentry / Datadog (Future Implementation): Technical monitoring tools that will receive automated system crash logs and performance telemetry to correct software errors.
4. Data Retention, Account Deletion, and Shared Records
We retain account data only for as long as needed to provide the Application, meet legal obligations, resolve disputes, enforce agreements, and protect the rights of other users. You may request deletion through the Application settings or by writing to develop@debtly.tech.
Deleting an account removes the profile, credentials, email address, profile picture, push token, payment methods, and records controlled solely by that account. We also delete multimedia files attached to debts owned solely by the deleted account.
Because Debtly is a shared ledger, deleting one account does not erase or rewrite records controlled by another user. A debt, payment, group entry, receipt, or supporting image that forms part of another participant's ledger may remain so that participant can preserve an accurate financial record, resolve a dispute, or establish a claim. Access remains limited to users who were authorized to access that record.
- After deletion, shared records identify the former participant only by the name already used in the ledger or by a generic deleted-user label. Debtly removes the deleted account's email address and profile picture from these retained snapshots.
- Backups and security logs may retain limited data for a short, controlled period before automatic deletion, unless longer retention is required by law, fraud prevention, security, or an active dispute.
- You may ask us to review or remove retained shared content by contacting develop@debtly.tech. We will assess the request against the privacy, evidentiary, and legal rights of all affected participants.
5. Contact
To exercise applicable rights to access, correct, or erase personal data, or to ask questions about this Policy, contact the Operators at develop@debtly.tech. We may need to verify your identity and will respond within the time required by applicable law.