Privacy Policy
Effective: 29 August 2026
Troškomir is a personal finance app for tracking expenses, incomes, loans, savings, budgets, trips and reminders.
The data controller is Nikola Dašić (Serbia). For any privacy question, write to nikdale@duck.com.
What we store
- Account details: name, e-mail address and session data.
- Financial records you enter: expenses, incomes, loans, savings, budgets, cards and trip-related entries.
- Data from scanned fiscal receipts: merchant, amount, date and line items.
- Reminders and app preferences.
- Technical sign-in records: IP address, user-agent and device metadata.
Data Protection (end-to-end encryption)
Troškomir offers optional Data Protection. With it on, sensitive text fields — descriptions, notes and receipt details — are encrypted on your device with AES-256-GCM before they reach the server. The key is derived from your Data Protection password using Argon2id and never leaves the device. Household sharing uses X25519/HKDF key exchange.
This means the server cannot read that content. It also means nobody, including us, can recover it if you lose both your password and your one-time recovery code.
Amounts, dates and the link to your account are not encrypted this way — the server needs them to calculate. Data Protection is off by default; while it is off, the server can see everything you enter.
The app also keeps an offline copy of your data on the phone itself, so you can read it with no connection. That copy is encrypted under a separate device key rather than your Data Protection password — which means it stays readable while the app is locked. It is erased on logout and on account deletion.
Where data is stored
The server is in Serbia, on private infrastructure run by the controller rather than a commercial cloud. Traffic uses HTTPS. Database backups are encrypted.
Third-party services
Troškomir uses no advertising SDKs and no cross-app tracking. It does use the following services, each for exactly the stated purpose:
- Google Firebase Crashlytics — crash reports and diagnostic data, so faults can be fixed. Reports go to Google.
- Google Firebase Cloud Messaging — your device push token, so you can receive the notifications you enable. The token goes to Google.
- Government fiscal portals (suf.purs.gov.rs, suf.poreskaupravars.org, mapr.tax.gov.me, mydatapi.aade.gr) — when you scan a receipt QR code, our server fetches the receipt contents from the relevant tax authority's portal on your behalf.
- Tax authority receipt verification (suf.purs.gov.rs) — if you choose to verify a scanned receipt, the app opens the tax authority's own verification page directly on your device, in a real browser view, and fills in the invoice number, control number, amount and date/time already read from your scan. This connection runs directly between your device and the tax authority; our server is not involved in it and does not see it.
- EU VIES (ec.europa.eu) — when a Greek receipt has no seller name, we look up the tax number (ΑΦΜ) on the European VIES service to get the official company name.
- Hugging Face — the source of whichever of three optional local models you choose (in the app, Settings > Local AI) if you enable on-device receipt processing. Only one model is kept on the device at a time; whichever one you pick runs locally, and receipt images are not sent anywhere.
- App feature-usage analytics (Aptabase) and website analytics (Umami) — both are self-hosted on our own server, send no data to any third-party company, use no cookies or device identifiers, and cannot be linked to your account or identity.
Camera and photos
Camera access is used to scan receipt QR codes and loyalty-card barcodes. Photo library access is used so you can pick a receipt photo. Image processing and text recognition happen on the device; the image itself is not uploaded. Only the expense you create from it is sent to the server.
How long we keep data
- Account details and financial records: until you delete the record or your account.
- Technical sign-in records (IP address, user-agent): 90 days.
- Request idempotency keys, including response bodies: 7 days.
- Crash reports: per Firebase Crashlytics retention.
Deleting your account
You can delete your account from inside the app or on the web at https://troskomir.stryna.com/delete-account/. We confirm with a code sent to your e-mail address.
Deletion removes your account and every financial record attached to it, your household memberships, stored request responses and technical sign-in records. It is permanent and cannot be undone.
Your rights
Under the GDPR and Serbia’s Personal Data Protection Act you have the right to access your data, correct inaccurate data, have it erased, restrict processing, receive it in a portable form and object to processing.
Send requests to nikdale@duck.com. You also have the right to complain to Serbia's Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs), or to the supervisory authority in your own country.
Age
Troškomir is not directed at children. You must be at least 16 to create an account. If we learn we have collected data about someone younger, we delete it.
Tracking and advertising
Troškomir shows no ads, uses no advertising SDKs, and does not combine your data with third-party data for advertising or measurement.
Anonymous, aggregate feature-usage statistics (see “Third-party services” above) are used solely to understand what's useful — never for advertising, and never to identify an individual user.
Changes to this policy
We may update this policy for product, legal or security reasons. The effective date at the top always reflects the current version.
Contact
Nikola Dašić, Serbia — nikdale@duck.com