Comprehensive Privacy Notice - FlashBill
Last updated: September 12, 2026
Document version: 2026-09-12
1. Who is responsible for your data
JESUS ALBERTO DUERTO PRADO, an individual with business activity trading as "JDev Studio", owner and operator of the mobile app, the web platform and the site flashbill.app (together, "FlashBill"), with address for notices in Alcaldia Venustiano Carranza, C.P. 15750, Mexico City, Mexico, is the controller responsible for processing your personal data.
Privacy email: revocacion@jdevstudio.mx. Support WhatsApp: +52 55 3915 7184. Website: https://jdevstudio.mx.
This document explains what data we collect, why we use it, who we share it with, how long we keep it and how you can exercise your rights. It is written to be read in full: if anything is unclear, write to us before accepting it.
2. Applicable legal framework
This Privacy Notice is issued under Mexico's Federal Law on Protection of Personal Data Held by Private Parties, published in the Official Gazette of the Federation on March 20, 2025 and in force since March 21, 2025 ("LFPDPPP"), which repealed the 2010 law and its implementing rules to the extent they conflict with it, together with any regulations that develop it. Following the dissolution of the National Institute for Transparency, Access to Information and Personal Data Protection (INAI), the competent Mexican authority for personal data held by private parties is the Ministry of Anti-Corruption and Good Governance, through the administrative unit exercising those powers.
In addition, and to the extent they apply based on where you live, we observe: the European Union's General Data Protection Regulation (GDPR) and the UK GDPR; the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and the other US state consumer privacy laws; the US Children's Online Privacy Protection Act (COPPA); Brazil's Lei Geral de Protecao de Dados (LGPD); and the privacy, data safety and account deletion requirements of the Apple App Store and Google Play.
Nothing in this Notice limits non-waivable rights granted to you by the law of your country of residence. Where local law gives you greater protection, that law prevails.
3. What personal data we process
A. Identification and contact data
Name or display name, email address, profile photo (optional), the language and country or region set on your device, and the unique user identifier assigned by the authentication system.
Identifiers provided by the sign-in provider you choose: Google Sign-In or Apple Sign-In. If you use Sign in with Apple and choose to hide your email, we only receive the private relay address that Apple generates.
B. Financial and asset data
Accounts, cards and balances you enter manually; income, expenses, budgets, categories, dates, currency and notes; debts, person-to-person loans, payments, collections and the names or references you use to identify those people; receipts, tickets or invoices you choose to attach as images.
FlashBill does not connect to your bank. We do not request or store full card numbers, security codes (CVV), PINs, online banking passwords or credentials for financial institutions, and we have no technical ability to move money from any account.
C. Purchase and subscription data
If you subscribe to FlashBill Premium: transaction identifier, product identifier, store of origin (App Store or Google Play), purchase, renewal and expiration dates, and subscription status.
Payment is processed entirely by Apple or Google. FlashBill never receives, sees or stores your card or payment method details; it only receives from the store the confirmation that a purchase is valid and until when it is active.
D. Technical and device data
Installation identifier, device model and operating system, app version, push notification token (FCM), session status and the list of devices signed in to your account, the result of device integrity checks (for example, whether the device is rooted or jailbroken) and Firebase App Check anti-abuse signals.
Technical operation and security logs (IP addresses, timestamps and error codes) generated by the infrastructure when serving your requests.
Crash diagnostics (optional, on by default and switchable off): the app tells you so on the welcome screen, with its switch in plain sight. While it is on, when the app fails we will send Firebase Crashlytics and our own support panel the technical trace of the error, the screen where it happened, the last actions taken inside the app (which screens you opened and which buttons you tapped, always the fixed labels of the app and never what you typed), the app version, the device model and OS version, plus an installation identifier added by Crashlytics. That report is not linked to your account or your email, and never includes your transactions, amounts, accounts, categories, names or the content of your receipts: before leaving the device, the error text is stripped of emails and figures. You can turn it off at any time, from that same welcome screen or later in Preferences, Privacy section, and when you do, any reports still pending are deleted. While it is off, absolutely nothing is collected or transmitted.
Usage statistics (optional, on by default and switchable off): with the same notice and the same switch on the welcome screen. While it is on, we store alongside your account how many transactions you have recorded in total and on each of the last fourteen days, the date of the first and the last one, how many accounts you have set up, when you finished the welcome flow, and a yes-or-no mark for each feature you have ever used (loans, installment purchases, receipts, transfers, recurring transactions, tips and more than one currency). These are counts and dates: never the amount, the description, the category, the name of an account or a person, or the content of a receipt. It lets us decide what to improve with data instead of assumptions. You can turn it off at any time from the welcome screen or in Preferences, Privacy section; when you do, counting stops immediately and whatever was already stored is deleted from our servers.
We do not use GPS or precise location. We do not read your phone's contact list. We do not use advertising identifiers (IDFA/AAID) or tracking technologies for advertising purposes.
E. Passwordless credentials (Passkeys / FIDO2)
If you enable fingerprint or face sign-in, we store only the public credential identifier, the public key and the name you give the device. Your biometric data never leaves your device's security chip (Secure Enclave or KeyStore): we do not receive it, transmit it or have any way to read it. We do not process biometric data as sensitive personal data.
F. Content you send us voluntarily
Messages to support and to the contact form, error reports and any attached captures, answers to in-app surveys, data deletion requests and the correspondence we exchange with you to handle them.
G. Third-party data you enter
When using the loans section, you may enter the name or nickname of other people and, if you choose to invite or link them, their email address. This data is processed solely to provide the service you requested. Section 8 explains your responsibility here.
H. Website browsing data
The flashbill.app site does not use advertising cookies, tracking pixels or third-party analytics tools. We only use browser local storage to remember the language you chose and, in the admin panel, to keep the session open. The hosting server keeps technical access logs, like any web server.
4. End-to-end encryption and what it means for you
The most sensitive fields in your records - amounts, description, notes, person name and lender name - are encrypted on your own device with AES-256-GCM before being sent to the cloud. The encryption key is generated on your device and stored in the operating system's secure keychain; it is never transmitted to our servers.
Direct consequence: neither JDev Studio, nor its personnel, nor the infrastructure provider can read those fields. To us they are an unreadable block.
An equally important consequence: that key needs a backup, or switching phones would cost you your history. When we encrypt your account, the app generates an eight-digit PIN on its own, wraps the key with it and stores that wrapped copy on our servers. The PIN is emailed to you once and we keep no copy of it: once you receive it, you are the only one who has it.
One nuance deserves to be explicit, because it is the only point where our system touches something that opens your data: in order to write you that email, the PIN passes through our servers at the moment of sending. It is not stored in any database and the message is deleted from our queue as soon as it is delivered. From then on, the wrapped copy we keep cannot be decrypted without the PIN, not even by us.
You can replace it with a PIN of your own from the app's profile screen. If you do, that new PIN is never sent anywhere and never passes through our servers, and your memory is the only copy.
If you lose access to your device and do not keep your PIN — nor the email holding it — that data can never be decrypted, not even by us. There is no back door and no rescue procedure.
Data that is not end-to-end encrypted, because the app needs to query and sort it - date, entry type, account, category and internal flags - travels and is stored encrypted in transit and at rest using the mechanisms described in section 10.
5. Why we use your data
Under the LFPDPPP we distinguish between purposes that are necessary to provide the service and purposes that are not, which you may refuse without affecting your use of FlashBill.
A. Necessary purposes
Creating, authenticating and maintaining your account, and verifying that it is you who is signing in.
Recording, calculating, sorting and displaying your entries, balances, budgets, debts and reports, and syncing them across the devices where you sign in.
Storing and displaying the receipts and images you attach.
Sending operational and functional alerts: payment and budget reminders you configured yourself, due-date alerts, changes to a shared loan and notices about your account or subscription status.
Validating with Apple or Google that a purchase is genuine, and enabling or disabling the corresponding Premium features.
Enabling, if you ask for it, the linking of a loan with another FlashBill user, and showing that person only the entries of that shared loan.
Preventing fraud, abuse, unauthorized access and automated use of the service, and enforcing the Terms of Use.
Handling your support requests, error reports and rights requests, and keeping a record of your acceptance of our legal documents.
Complying with legal obligations and responding to requests from competent authorities.
B. Non-necessary purposes
Sending you product news, personal finance tips and communications from JDev Studio.
Emailing you a monthly summary with what you earned, what you spent and your three largest spending categories. Those figures are calculated by your own device —the server cannot read your amounts, which travel encrypted— and are used only to write that email: they are not stored in our systems, and the message is deleted from the sending queue as soon as it is delivered. It is on by default, the app tells you on screen every time that email goes out, and you can turn it off at any time in the app or from the unsubscribe link in the email itself.
Inviting you to satisfaction surveys and to votes on new features.
Producing internal aggregated and de-identified statistics about general use of the service.
How to refuse: you can object to any non-necessary purpose in the app settings, through the unsubscribe link included in every communication, or by writing to revocacion@jdevstudio.mx. Refusing does not affect the service and is never a ground for suspension.
6. Consent
Your financial and asset data requires express consent. When you create your account you accept this Privacy Notice and the Terms of Use through an affirmative and unambiguous action: pressing the sign-in button after both documents have been presented to you and made available to read. That act is recorded with the server date and time, the exact version of the documents shown to you, their cryptographic fingerprint, the language you read them in, the platform and the app version.
When we publish a new version of this Notice that materially changes how we process your data, we will ask you to accept it again before you continue using FlashBill.
You may withdraw your consent at any time as described in section 12. Withdrawal has no retroactive effect on processing already carried out lawfully.
7. Legal bases for users outside Mexico
For residents of the European Economic Area, the United Kingdom and Brazil, our legal bases are: performance of the contract you enter into with us by using FlashBill, for the necessary purposes; your consent, for non-necessary communications and for push notifications; our legitimate interest in security, fraud prevention and service improvement, balanced against your rights; and compliance with legal obligations.
8. Other people's data that you enter
When you record a third party in the loans section, or enter their email to invite or link them, you are the one deciding to provide that information. In doing so you represent that you have that person's consent, or another lawful basis, to share their data with us, and you undertake to tell them that their data will be processed under this Notice.
Our role is strictly limited: we store the name or reference you entered and, only if you instruct it, we send a single invitation email or show the linked person the entries of the loan you share. We do not use that data for advertising, do not add it to mailing lists, do not build profiles from it and do not transfer it to anyone.
If you are a person whose data was entered by a FlashBill user and you want us to stop processing it, write to revocacion@jdevstudio.mx and we will handle your request.
9. Who we share your data with
We do not sell, rent or trade your personal data. We do not share it with advertisers, data brokers or ad networks, in any country and under any circumstances.
A. Processors and providers
Google LLC / Google Cloud Platform and Firebase: authentication, database (Cloud Firestore), file storage (Cloud Storage), server-side functions (Cloud Functions), push delivery (Firebase Cloud Messaging), anti-abuse protection (App Check), crash diagnostics (Crashlytics, only if you turn it on) and hosting of the site and admin panel. They act as processors, handle data on our instructions and are bound by their own contractual data protection commitments.
Apple Inc.: Sign in with Apple, push notifications on iOS, and processing and validation of purchases made on the App Store.
Google Play (Google LLC): processing and validation of purchases made on Android.
Transactional email provider engaged through the Firebase infrastructure: delivery of invitation emails, notices and support replies.
B. Where your data lives
FlashBill's main database resides in the Google Cloud region located in Mexico (northamerica-south1). Some server-side functions and the authentication, notification and email services run in Google data centers in the United States of America. Apple services are provided from Apple's own international infrastructure.
This involves an international transfer of data. It takes place under the LFPDPPP provision on transfers necessary for the performance of the legal relationship between the data subject and the controller and, for EEA and UK data subjects, on the basis of the Standard Contractual Clauses approved by the European Commission that form part of the Google and Apple agreements.
C. Other cases
Competent authorities: where there is a duly founded and reasoned request from a judicial, administrative or tax authority. We will notify you unless the law prohibits it.
Legal defense: to exercise or defend rights before the courts.
Succession: if ownership of FlashBill were transferred, the acquirer would be bound by this same Notice; we would inform you before the change takes effect and you could delete your account.
None of these disclosures requires your additional consent under the LFPDPPP.
10. How we protect your data
End-to-end encryption of sensitive fields, on the device, with AES-256-GCM and a key that never leaves your equipment.
Encryption in transit with TLS 1.2 or higher on all communications, and encryption at rest in the Google Cloud infrastructure.
Database security rules that isolate information per account: each user's identifier is the only key that opens their own documents, and entitlement, purchase and sharing data can only be written by the server.
Purchase verification against Apple's and Google's servers, so that no subscription can be activated from the client.
Firebase App Check to reject requests that do not come from a legitimate installation of the app, and rate limits on sensitive operations.
Passwordless authentication with passkeys, detection of compromised devices and a register of signed-in devices, with the ability to close sessions remotely.
Minimal internal access: only the controller has administrative access, authenticated with a named account, and that access cannot read end-to-end encrypted fields.
No security measure is infallible. If a breach occurred that significantly affects your economic or moral rights, we will notify you without undue delay by email and inside the app, telling you what happened, what data was affected, what we recommend you do and what actions we took, as required by the LFPDPPP and, where applicable, by US breach notification laws, the GDPR and the LGPD.
11. How long we keep your data
Account data and financial content: for as long as your account exists. When you delete it, the data is erased as described in section 13.
Receipts and images: for as long as your account exists or until you delete them.
Purchase and subscription data: for the life of the subscription and up to five years after it ends, to handle disputes, refunds and tax or commercial obligations.
Records of acceptance of the legal documents: up to five years after account deletion, because they are the evidence that processing was lawful. They are kept in isolation and in minimal form: user identifier, email, date, version and fingerprint of the documents accepted.
Rights and deletion requests and our responses: two years, to show they were handled on time.
Support messages and error reports: up to twenty-four months.
Technical and security logs: up to ninety days, unless one of them must be kept longer because of an ongoing security investigation or legal request.
Encrypted backups: overwritten on cycles no longer than thirty days.
Once these periods expire, data is deleted or irreversibly de-identified.
12. Your ARCO rights and withdrawal of consent
As a data subject you have the right to access your data, to rectify it when it is inaccurate or incomplete, to cancel it when you believe it is not required for the stated purposes, and to object to a specific processing, as well as to withdraw the consent you gave us and to limit the use or disclosure of your data.
Many of these rights can be exercised immediately and with no paperwork inside the app: view and export your information, correct any record, turn off notifications and non-necessary communications, close open sessions and delete your account entirely.
For a formal request, write to revocacion@jdevstudio.mx from the email associated with your account, or use https://flashbill.app/delete-account, stating: your full name and account email; which right you are exercising and over which data; and documentation proving your identity or legal representation where necessary to prevent a third party from accessing your data. For a rectification request, attach the documentation supporting the change.
Deadlines: we will reply within a maximum of twenty business days from receipt of the complete request; if it is granted, we will implement it within the following fifteen business days. The process is free; only justified shipping or physical reproduction costs could be charged.
An important limitation caused by encryption: for end-to-end encrypted fields, access and portability are exercised from your device, where the data is readable, using the app's export function. We can give you the encrypted copy and all non-encrypted data we hold, but we cannot decrypt for you what we are technically unable to read. Cancellation, by contrast, is always carried out with no limitation whatsoever.
If you believe your right to data protection has been infringed, or that our response was unsatisfactory, you may file a proceeding with the competent Mexican authority, currently the Ministry of Anti-Corruption and Good Governance, within the periods set by the LFPDPPP.
13. Deleting your account
You can delete your account and your data completely and irreversibly, free of charge and without contacting us, in two ways:
In the app: Profile, Help and support, Delete all data, Delete account.
On the web, even if you already uninstalled the app or cannot sign in: https://flashbill.app/delete-account. There you can also request deletion of only part of your data while keeping your account. Every request receives a reference number, your identity is confirmed by email, and it is handled within a maximum of thirty calendar days.
What is deleted: your credentials in the authentication system; your entries, accounts, categories, budgets, loans, people and notes; your images and receipts; your public profile and registered devices; your passkeys; your loan links, which are revoked for the other party; and your notification tokens. If you signed in with Apple, we also revoke the Sign in with Apple token so that your Apple ID is no longer linked to FlashBill.
What survives and why: only the legal acceptance records and the minimal purchase records described in section 11, for the periods stated there, and any data an authority has ordered us to preserve.
What we cannot delete: deleting your account does not cancel your subscription, because billing is managed by the store. Cancel first in the App Store or Google Play to avoid renewals. It also does not delete copies you exported or shared yourself, nor the entries that the other party to a shared loan recorded in their own history.
14. Specific rights for residents of the United States of America
Express statement: in the past twelve months we have not sold personal information and have not shared it for cross-context behavioral advertising, and we will not do so. We do not sell the personal information of people under sixteen, or of anyone else. We do not use your data for targeted advertising.
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida or another state with a consumer privacy law in force, you have the right to know what personal information we process and why; to obtain a copy in a portable format; to correct it; to request its deletion; to opt out of sale, sharing and targeted advertising, options that do not apply in our case because we do not engage in those activities; and not to be discriminated against for exercising your rights. We do not carry out profiling with legal or similarly significant effects.
Categories processed under the CCPA: identifiers; information in the California Civil Code customer records category; commercial information, limited to subscription status; internet activity information, limited to technical logs; and financial data you enter, which remains end-to-end encrypted. The source of all of it is you, except the purchase confirmation, which comes from Apple or Google. The purpose is as described in section 5.
How to exercise them: write to revocacion@jdevstudio.mx or use https://flashbill.app/delete-account. We will verify your identity through the account email. You may appoint an authorized agent by providing proof of the authorization. We will respond within forty-five calendar days, extendable by another forty-five where necessary, and we will tell you about the extension. To appeal our decision, reply to the same email with the word "appeal" and we will review it within sixty days.
15. Specific rights for the EEA, the UK and Brazil
In addition to the above, you have the right to data portability, to restriction of processing, to object to processing based on legitimate interest, not to be subject to automated decisions - which we do not make - and to withdraw your consent at any time. You may also lodge a complaint with the supervisory authority of your country of residence or, in Brazil, with the Autoridade Nacional de Protecao de Dados.
We have not appointed a representative in the European Union because we do not target FlashBill at that market and do not monitor the behavior of people there; if that changes, we will appoint one and say so in this Notice.
16. Minors
FlashBill is not directed to children under thirteen and we do not knowingly collect their data. If you live in a country where the minimum age to consent to online data processing is higher - sixteen in several European Union Member States - that age applies instead.
People under eighteen who use FlashBill must do so with the knowledge and supervision of a parent or guardian, who accepts these documents on their behalf. If we detect or are told of an account created by a minor without that authorization, we will delete it along with its data. To report this, write to revocacion@jdevstudio.mx.
17. Permissions the app asks for
Camera and photo library: only so that you can capture or attach a receipt or your profile photo. We do not access your library in the background.
Notifications: for the reminders and alerts you configure.
Network and Internet: to sync your information.
System secure storage: to store the encryption key and your credentials.
All of them are optional, are requested at the moment they are needed, and you can revoke them at any time in your iOS or Android settings. Revoking camera or notifications only disables those features; the rest of the app keeps working.
18. Automated decisions and advertising
We do not make automated decisions that produce legal effects on you or significantly affect you. We do not build profiles for advertising. FlashBill shows no third-party advertising. The financial calculations and projections shown in the app are arithmetic operations on the data you entered and do not constitute financial, tax or investment advice.
19. Changes to this Privacy Notice
We may update this Notice to reflect legal changes, new features or better practices. The current version will always be available inside the app, under Help and support, and at https://flashbill.app/privacypolicy, identified by its date and version.
Minor or drafting changes take effect on publication. Material changes - new categories of data, new purposes, new recipients or a reduction of your rights - will be communicated to you by email or inside the app at least thirty calendar days in advance, and we will ask you to accept the new version before continuing. If you disagree, you can delete your account before it takes effect.
20. Contact
Controller: JESUS ALBERTO DUERTO PRADO, JDev Studio.
Address: Alcaldia Venustiano Carranza, C.P. 15750, Mexico City, Mexico.
Email for privacy and ARCO rights: revocacion@jdevstudio.mx.
Support WhatsApp: +52 55 3915 7184.
Website: https://jdevstudio.mx and https://flashbill.app.
Account and data deletion: https://flashbill.app/delete-account.
FlashBill - Transparent and secure personal finances.