Mosara
HomeAccount Deletion
← Back to home

Privacy Policy

Last updated: 24 June 2026

Mosara ("the App") is a local-first personal finance app. This policy explains what data the App processes, why, where it is stored, and the choices you have. Contact: support@mosara.app.

1. Summary

By default, your financial data stays on your device in an encrypted database. If you choose to create an account and sign in, your data is synced to our backend so you can use it across devices and restore it. We do not sell your data, show ads, or use third-party analytics or tracking.

2. What we process

Account / identity (only if you sign in)

  • Email address — to create and identify your account, via Firebase Authentication (a Google service). Sign-in with Google is also supported.

Your finance content (only if you enable cloud sync)

  • The records you enter — transactions, amounts, account names, categories, currencies and related settings. This is data you create; the App does not import bank or card data automatically.

Device / technical

  • A push-notification token (Firebase Cloud Messaging) to deliver notifications and reminders you enable.

On your device only (never sent to us)

  • Biometric unlock / app-lock is handled by your device's operating system; we never receive or store biometric data.
  • Your encrypted local database stays on the device unless you sign in and sync.

We do not collect location, contacts, photos, health data, message contents, advertising identifiers, or analytics.

3. How we use data

  • Provide the core app (store and show your finances).
  • Authenticate you and sync/restore your data across devices when you sign in.
  • Send transactional emails (email verification, password reset) and notifications you enable.
  • Maintain the security and integrity of the service.

We do not use your data for advertising or profiling, and we do not sell or rent it.

4. Where your data is stored (service providers)

We do not share your data with third parties for their own purposes. We rely on the following providers to run the service:

  • Oracle Cloud Infrastructure — our PostgreSQL database that stores your synced finance data, hosted in the EU (Frankfurt, Germany) region.
  • Google Firebase (Authentication & Cloud Messaging) — sign-in and push delivery, on Google's infrastructure.
  • Google Drive — encrypted database backups are stored here (Google's infrastructure; storage location is managed by Google).
  • Oracle Cloud Email Delivery — sends transactional emails from noreply@mosara.app.

If you use the App from outside the EU, your synced data may be transferred to and processed in the EU (Frankfurt). Authentication and backups are handled by Google's global infrastructure.

Payments and subscriptions (Mosara Premium). If you buy Mosara Premium, RevenueCat processes your purchase history and subscription status to manage your Premium access. RevenueCat does not receive your card or payment details. When you delete your Mosara account, deletion of the related RevenueCat customer record is requested and completed within 30 days. Deleting your Mosara account does not cancel a subscription managed by Google Play or the App Store. After account deletion, Mosara offers a "Manage subscription" action that opens the relevant store's official subscription-management screen. You can cancel renewal there, or keep the subscription and later use "Restore purchases" after signing in to another Mosara account. Restore can re-enable Premium, but it does not restore, transfer, or merge financial data from the deleted account.

5. Data retention

  • Local data stays on your device until you delete it or uninstall the App.
  • Cloud (synced) data is kept while your account exists. When you delete your account, your synced data and your authentication account are deleted immediately.
  • Encrypted backups of the database are retained for up to 30 days and then deleted.

6. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your data. You can:

  • Export your data from within the App (CSV export or an encrypted backup).
  • Delete your account and cloud data from within the App (Settings → Delete cloud account) or via our Account Deletion page.
  • Contact us at support@mosara.app for any other request.

7. Security

  • Data in transit is encrypted with HTTPS/TLS.
  • The on-device database is encrypted at rest (SQLCipher); secrets are kept in the platform secure store; Android system backup of app data is disabled.
  • Database backups are encrypted before they leave the server.

No system is perfectly secure, but we work to protect your data.

8. Children

Mosara is not directed to children under 13 and we do not knowingly collect their data.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, by an in-app notice.

10. Contact

Mosara. Email: support@mosara.app.

Privacy Policy Account Deletion Contact
© Mosara