VuneraVunera

Local-first and user-controlled data approach

Privacy Policy

Last updated: September 20, 2026

Vunera is designed to keep users in control of their personal and business finance data. This page explains where Vunera stores data, when cloud services are used, and how users can manage their information.

App

Vunera

Developer

Vunera

Are you using Vuno Vision (Desktop Image Viewer)?

Review the 100% on-device and zero-cloud privacy policy tailored for Vuno Vision.

Vuno Vision Policy →

Are you using Vuno Çeviri (Screen Translator & Dubbing)?

Review the screen capture privacy, on-device OCR, and licensing policy for Vuno Çeviri.

Vuno Çeviri Policy →

1. Local-First Data Structure and Guest Use

Vunera is a finance management app designed with a local-first architecture.

Local Storage: Your financial records, such as income, expenses, wallets, debts, receivables, categories, and notes, are stored by default in your device's local storage (SQLite database). You retain full control over this data.

Guest Use: When you use the app without creating an account (as a guest), the first name, last name, and financial data you enter remain entirely on your device; they are not transferred to third-party servers or cloud infrastructure.

Risk of Data Loss: In guest use, backing up data is entirely the user's responsibility. If the app is deleted, the device is reset, or the device is damaged, local data cannot be recovered.

2. Authentication and Cloud Synchronization

Cloud features and synchronization tools are activated only when you explicitly request them and start the integration.

Google Sign-In and Firebase Auth: You may optionally sign in with your Google account. This process uses Firebase Authentication infrastructure to create a unique user identifier (UID) for cross-device synchronization, family group management, and backup features.

Cloud Backup: The backup feature is manually triggered by the user or explicitly approved. Depending on your backup preference, your data is transferred to secure cloud servers.

AES-256 Encrypted Backup: Vunera uses the industry-standard AES-256 encryption algorithm during backup and in certain messaging components. This encryption applies only to the relevant transfer packages and encrypted data blocks; it does not mean that all real-time raw data in the on-device SQLite database is end-to-end encrypted.

3. Family, Shared Wallet, and Vunera Connect

Shared features involving multiple users (family group, shared wallet, budget sharing, invite codes) require cloud infrastructure.

Infrastructure: Google Cloud / Firebase infrastructure (Cloud Firestore and Realtime Database) is used so these features can work in real time.

Data Access: The Vunera development team does not read, profile, analyze, or commercially track your private financial records, content, or personal data transferred to cloud servers. The server infrastructure acts only as a middleware layer to synchronize data between its authorized owners.

Temporary Messages and Data Minimization: Instant messages sent through Vunera Connect and comments in shared savings areas are not permanently stored on the server in line with the data minimization principle. This data is permanently deleted (hard delete) from Firebase servers no later than 24 hours after delivery.

4. Advertising, Trackers, and Third-Party Data Sharing

Anti-Advertising Policy: Vunera does not include any third-party advertising network (such as AdMob) or advertising tracking software.

No Data Trading: Your personal or financial data is not sold, rented, or processed for advertising targeting purposes under any circumstances.

5. Subscriptions and Payment Security

Payment Infrastructure: Google Play Billing is used for in-app purchases and subscription management, and RevenueCat is used as the subscription validation infrastructure.

Card Information: Your credit card, debit card, or other payment method information is never viewed, processed, or stored by Vunera at any stage. All payment processes are handled directly through Google Play Store's secure payment gateways.

6. Data Deletion, Rights, and User Control

Users have full authority over their data.

Local Data: You can instantly clear all local records on your device from the settings inside the app.

Cloud Data and Account Deletion: You can permanently delete your data stored on cloud servers or in shared wallets from Firebase servers by using the "Data Management" option inside the app.

7. Children's Privacy and Age Policy

Vunera's age policy differs by service type: personal finance tools (individual use) are intended for users aged 13 and over; Business Mode and Vunera Social with community features are intended only for adult users aged 18 and over.

If we determine that personal data has been collected from individuals below these age limits, the relevant data and accounts are deleted without delay. If we learn that data has been collected from a child under 13 without parental consent, that data is deleted without delay.

8. Artificial Intelligence (AI) Services and Data Processing

Vunera follows an on-device-first approach for AI features. Basic analyses run locally when no API key is configured, so data does not leave the device. If optional cloud AI or a personal API key is used, minimized and anonymized data is sent only to answer the request; personal financial data is not used to train models or stored by Vunera for that purpose.

9. Anonymous System and Crash Reports (Crashlytics)

Firebase Crashlytics collects anonymous technical information such as device model, operating system version, memory state, and crash diagnostics to improve stability. Names, email addresses, and financial or social records entered in the app are not included in these reports.

10. Third-Party Services and Data Privacy

Vunera integrates with various third-party service providers to offer media, content, location, and application search features:

YouTube and Google Services: Our app uses YouTube API Services (YouTube Data API v3). By using Vunera, you agree that the supplied data may be processed in accordance with the Google Privacy Policy. Vunera does not store your personal YouTube account data. Users may manage permissions at any time through the Google Security Settings page.

Movie, Music, Book, and Game Services: Movie and TV data is provided by TMDB; music and book data is provided by Apple (iTunes API, Apple Books) and Open Library; and game data is provided by IGDB (Twitch).

Location and Map Services: Place and map searches are performed through Google Places API and OpenStreetMap (Nominatim).

Data Storage and Right to Deletion: Content data retrieved from third-party services (including video, song, and movie information) is not permanently stored on Vunera servers. Users may delete their accounts, saved data, and in-app activity at any time through the settings within the app.

11. Vuno Flash and Third-Party News Feeds

When providing users with up-to-date news content and summaries through the Vuno Flash feature, Vunera applies the following data processing principles:

External Image and Link Loading: News cover images featured on Vuno Flash cards are not hosted on Vunera servers; they are loaded directly to the user's device via the publishers' publicly accessible server links (URLs). During this loading process, the user's IP address and standard browser/device metadata (User-Agent) may be processed by the relevant news source's servers out of technical necessity. These operations are subject to the respective publisher's own privacy policy.

On-Device Translation and Processing: Translation of news content in different languages into local languages is primarily carried out through on-device libraries (on-device machine learning) without transferring the user's personal data to external cloud services.

Usage and Interaction Data: Users' reactions to Vuno Flash cards (likes, saves, and reading history) are securely stored on Firebase infrastructure solely to provide a personalized content experience and are not shared with third-party advertising networks.

12. User-Defined AI API Keys (BYOK – Gemini)

Users can define their own Google Gemini API keys for content summarization or advanced translation features. API keys entered by users are stored encrypted in secure storage (Secure Storage) on the device and are never transmitted to Vunera servers. When this feature is activated, the content text to be translated or summarized is transferred directly to Google's API servers. This data transfer and processing is governed by the Google Privacy Policy and API Terms of Service. To protect the confidentiality of personal chats, it is recommended not to run external AI API services on private chat content.

13. Vunera Drive and Zero-Knowledge Architecture

End-to-End Client-Side Encryption: All files, images, and documents added to Vunera Drive are encrypted locally on your device using the AES-256-GCM standard before leaving your device. Unencrypted (plaintext) versions of files are never transmitted to, processed on, or backed up by Vunera servers.

Recovery Key (12 Words) Responsibility: Your encryption keys are derived from the 12-word secret seed phrase presented to you during setup. These keys are not accessible to any third party, including the developer or Vunera servers. Storing and securing the 12-word recovery key is entirely the user's responsibility. If this key is lost or forgotten, accessing encrypted files is technically impossible; the developer has no capability or obligation to reset keys, recover passwords, or decrypt data.

Third-Party Storage Infrastructure: Vunera Drive uses the user's authorized personal Google Drive account as an intermediary infrastructure for physical file storage. Vunera does not operate independent cloud storage servers. Data is transferred to the user's own storage space via Google Drive APIs (drive.file / appdata). Google's own terms of service, quota limits, and privacy practices apply separately to this storage process.

14. Data Retention Periods

In line with the data minimization principle, Vunera stores data only for as long as necessary. The retention periods that apply to each data type are as follows:

Local device data (income, expenses, wallets, debts, receivables, categories, notes, etc.): Remains on your device until you delete it. You fully determine the retention period.

Vunera Connect instant messages and shared savings area comments: Permanently deleted from the servers no later than 24 hours after delivery.

Timeline shares and stories (Vunera Social): Automatically deleted no later than 24 hours after publication. Permanent posts of business accounts (without an expires_at value) are not covered by this period.

Permanent photos, videos, and albums you share on your profile: Retained until you delete them yourself.

Vunomi Memories (highlights): Retained permanently until you remove them.

Account deletion records: Retained for 1 year as explained in section 16 below.

15. Data We Do Not Retain

Vunera does not collect data that is not required. The following data is deliberately not retained:

IP address history is not retained. An IP address may be processed temporarily only at the transmission-security and infrastructure level; no persistent IP history linked to a user is created.

Users' full activity history (behavior tracking / activity log) is not retained.

Location history is not retained. Location is processed only when you explicitly request it (for example, nearby place searches) and only at that moment.

Unnecessary sensitive data (health, biometric, religion, ethnicity, etc.) is not collected.

Additional data that is not required is not stored "just in case"; advertising targeting profiles are not created.

16. Records Retained After Account Deletion

When you delete your account, your data is permanently deleted from Firebase servers and the relevant shared areas. For the sake of transparency, the records retained on a limited basis after deletion are listed below:

Deletion transaction record: A technical record confirming that your request was received and applied (transaction date, transaction result, and an anonymized user reference belonging to you) is retained for 1 year. This record is kept to fulfil legal obligations and to verify the deletion request; it does not contain your messages, financial records, profile content, or location data.

Records that must be kept due to legal obligation (for example, financial records that must be retained under applicable law, or evidence in the event of a dispute): Retained only for the period required by the relevant legislation and only to the extent necessary.

Abuse and security records: Anonymized security records concerning prohibited content, fraud, or child-safety violations may be retained for up to 1 year in order to prevent recurrence.

These records are never used for advertising, profiling, or marketing purposes.

17. Legal Basis and Data Processing Principles

Vunera processes personal data in accordance with Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and, to the extent applicable, the GDPR (EU General Data Protection Regulation).

Performance of a contract: For core service functions such as account creation, cross-device synchronization, and backup, data is processed on the legal basis of performance of a contract.

Explicit consent: Optional cloud AI usage, personal API keys (BYOK), and location-based features are activated only with your consent.

Legitimate interest: Limited technical operations carried out for security, fraud prevention, and service stability rely on the legal basis of legitimate interest.

Legal obligation: Where required by law, data is processed only within the scope of the relevant request and on the legal basis of legal obligation.

Data minimization, purpose limitation, accuracy, and transparency are the principles underlying all processing activities.

18. Your Rights, Data Transfers, and Supervisory Authority

You have the following rights over your personal data: to learn whether your data is processed, to request information if it has been processed, to learn the purpose of processing, to request rectification of incomplete or inaccurate data, to request erasure or destruction, to request restriction of processing, to request transfer of your data in a portable format to yourself or another provider (data portability), and to object to processing.

To exercise these rights, you may contact vunerateam@gmail.com. Your requests are answered within 30 days at the latest.

You can delete your data at any time through the settings inside the app, or export it in a portable format.

Data transfers: Your data is not shared with third parties other than the infrastructure providers required for the service to operate (Google Firebase/Cloud and payment and subscription validation providers), and is never transferred for advertising purposes.

If your request is found insufficient, you retain the right to lodge a complaint with the personal data protection supervisory authority in your country (for Türkiye, the Personal Data Protection Authority – KVKK).