Privacy Policy
Last updated: September 21, 2026
This policy covers the Coinly Android app and this website. The company responsible for both — the data controller — is:
Truetech Solutions (SMC-Private) Limited
Gulshan-e-Mohammadi, Sakrand, District Nawab Shah (Shaheed Benazirabad), Sindh 67210, Pakistan
Registered with the Securities and Exchange Commission of Pakistan, CUIN 0350021
info@truetechsol.org
Coinly has no servers. We do not run a backend, we do not have a database of users, and we never receive a copy of your financial data. Almost everything below is about data that stays on your device or goes directly to services you already own. The exceptions — anonymous analytics, crash reports, and the waitlist form on this website — are each described in full.
Data stored on your device
All of your wallets, transactions, categories, budgets, and any receipt photos you attach are stored locally on your device using a local database. This data never leaves your device unless you explicitly enable backup — and receipt photos never leave it at all, since a backup contains only your wallets, categories, transactions and budgets, never the images themselves.
When you attach a receipt from your gallery, Coinly uses Android's system photo picker. You choose the single image; the app is never granted access to the rest of your photo library.
Using Coinly without an account
Signing in is optional. You can install Coinly and use every tracking feature — wallets, transactions, categories, budgets, recurring entries, reports — without creating an account or giving us anything at all. An account is only needed for the two features that genuinely require an identity: Google Drive backup, and carrying a Coinly Pro purchase across devices.
Google Drive backup (optional)
- Backup is off by default and only activates if you sign in and enable it.
- Backups are written to your own Google Drive account, inside a private, hidden application-data folder that only Coinly can access — not your visible Drive files.
- We request the narrowest Google Drive scope available (
drive.appdata), which cannot see or touch any other file in your Drive. - Coinly has no servers of its own — we never receive or store a copy of your backup.
Sign-in
If you choose to sign in with Google, we use Google's Credential Manager to authenticate you. Your name, email address, and profile photo are stored on your device so the app can show who is signed in. We only use this to identify your account for backup and restore — we do not use it for advertising and we do not share it with third parties.
Purchases
If Coinly Pro is purchased, payment is handled entirely by Google Play. Coinly never sees, collects, or stores your card or payment details.
- We use RevenueCat to check whether a purchase is active. It receives a purchase identifier and, if you are signed in, an anonymous per-account identifier derived from your Google account — not your email address.
- This is used only to unlock features you have paid for and to restore them on another device. It is not used for advertising or profiling.
- Google Play keeps its own billing records under Google's privacy policy, which we do not control.
Notifications
If you turn on the daily reminder or budget alerts, Coinly asks Android for notification permission and schedules them on your device. There is no push server, nothing is sent to us, and no notification content ever leaves the phone.
Exchange rates
To convert your wallets into your Base Currency, Coinly fetches published exchange rates from open.er-api.com once a day and caches them on your device. The request asks for rates and nothing else — it carries no account, no identifier, and none of your financial data. Like any web request it does reveal your device's IP address to that provider; we never receive it.
Analytics and crash reporting
Coinly contains no advertising SDKs. Nothing in the app profiles you for advertising, and we do not sell or share your data with data brokers. We still run no backend of our own — the two services below are third parties, and neither receives your financial records.
- PostHog
(product analytics, hosted in the EU) receives anonymous usage events: that a wallet was
created, that a budget was created, that a free-plan limit was reached, that an export was
created (its format and period, never its contents), that a purchase was
started or completed, that a backup or restore finished, that onboarding was completed or
skipped. It also receives simple counts — how many wallets, budgets, categories and
transactions exist, whether you have any recurring entries or receipts, how many currencies
you use, whether you are signed in, and your base currency code — attached as properties of
an anonymous, device-scoped identifier.
Because it is a standard analytics SDK, each event also carries ordinary technical context: your device model, Android version, app version, locale and timezone, plus app-lifecycle events (first install, opened, updated, sent to the background).
It never receives transaction amounts, notes, wallet names, category names you typed, your name, or your email address. Coinly never calls PostHog'sidentifyAPI, so the device identifier is never connected to your real-world identity, and both session replay and screen tracking are switched off entirely. - Firebase Crashlytics (crash reporting) receives a stack trace, your device model and your Android version when the app crashes, together with an anonymous installation identifier, so that the crash can be found and fixed. It does not receive your financial data.
Both exist to find bugs and to understand which features are worth building. Nothing else.
Turning analytics off. Coinly does not currently include an in-app switch to disable analytics. If you would rather not send them, email us and we will tell you the current options; uninstalling the app stops all collection immediately. We would rather say this plainly than imply a control that is not there yet.
This website
coinly.truetechsol.org sets no cookies and runs no analytics or tracking scripts of any kind. Two things are worth knowing anyway:
- The waitlist form. If you enter your email address to be told when Coinly launches, that address is passed to Resend, an email delivery provider, which forwards it to our inbox at info@truetechsol.org. We use it once, to send you the launch notice, and for nothing else — no newsletter, no marketing list, no sharing with anyone. Ask us at any time to remove it and we will delete the message.
- Fonts. The site loads its typeface from Google Fonts, so your browser requests files directly from Google and Google therefore sees your IP address and user agent. We receive nothing from that request.
Why we are allowed to process this
Where data-protection law such as the GDPR applies to you, our legal bases are:
- Performance of a contract — verifying purchases and restoring Coinly Pro, so we can give you what you paid for.
- Consent — Google Drive backup, notifications, and adding your address to the waitlist. Each is off until you switch it on, and you can withdraw at any time by turning it off, disconnecting Drive, or asking us to delete the message.
- Legitimate interests — anonymous analytics and crash reporting, to keep the app working and decide what to build. We have kept both to the minimum that serves that purpose, which is why neither receives your financial data or your identity.
How long anything is kept
- On your device — until you delete it in the app or uninstall Coinly.
- Your Drive backup — until you delete it, from inside the app or from Drive itself. It sits in your Drive, not ours, so it outlives any decision of ours.
- Crash reports — Firebase Crashlytics deletes crash data after 90 days.
- Analytics events — retained by PostHog under our project's settings and used only in aggregate. Being honest about a limitation: because these events carry no identifier we can tie to you, we generally cannot single out one person's events to delete them. That is a consequence of collecting them anonymously in the first place.
- Waitlist emails — kept until the launch notice goes out, then deleted, or sooner if you ask.
Where your data goes
We are based in Pakistan. PostHog processes analytics in the European Union. Firebase Crashlytics, Google Drive, Google Play and Google Fonts are operated by Google, and Resend operates in the United States. If you are in the EEA or the UK, this means some data is transferred outside your region; those providers rely on their own transfer safeguards, published in the privacy policies linked above. Your financial records are not part of any of it — they never leave your device or your own Drive.
Security
The strongest protection here is structural: we hold nothing to lose. There is no Coinly account database and no server holding your transactions, so there is no store of user financial data for anyone to breach. On your device, your data is protected by Android's app sandbox and whatever device encryption, PIN or biometric lock you have set. Backups sit in a hidden folder in your own Google Drive, under your Google account's own security. All network requests use HTTPS. No system is perfect, and we would rather point at the design than promise the impossible.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive a copy in a portable form, to object to or restrict processing, and to withdraw consent at any time. You also have the right to complain to your local data protection authority.
In practice, most of these you can exercise yourself, immediately, without asking us — which is the point of the design:
- Access and portability — your complete records are already on your device and in your own Drive backup.
- Erasure — More → Account → Delete Account removes your device data and your Drive backup. Uninstalling removes everything local.
- Withdrawing consent — disconnect Drive, turn off notifications, or ask us to remove your waitlist address.
For anything you cannot do yourself, email info@truetechsol.org and we will respond within 30 days. We will not charge you for it or ask you to justify the request.
Deleting your account and data
You can delete your account and everything associated with it — device data and your Google Drive backup — from inside the app at any time, under More → Account → Delete Account. Full instructions, including what happens to subscriptions and how to proceed if you have already uninstalled the app, are on our account deletion page.
Children
Coinly is listed on Google Play for an adult audience and our Terms of Service require you to be 18 or older. The app is not directed at children, and we do not knowingly collect data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We will update this page when the app changes what it handles. The date at the top always shows the current version, and we will describe anything significant here rather than change it quietly. If a change ever means collecting something materially new, we will ask first.
Contact
Questions about this policy, or a request about your data? Reach out at info@truetechsol.org.