Privacy Policy di Flufiny
Questa informativa descrive come Flufiny tratta i dati personali
nell'app mobile, nel sito flufiny.it e nei canali di
supporto. Flufiny e' local-first: i dati finanziari restano sul
dispositivo, salvo scelta esplicita di attivare la sincronizzazione
cifrata su iCloud Drive (BYOC).
1. Titolare del trattamento
Salvatore Buratti, freelance P.IVA
Indirizzo: Via Trieste 79c, 00041 Albano Laziale (RM), Italia
P.IVA: IT18186281004
Email privacy/supporto: support@flufiny.it
Non e' stato nominato un DPO, in quanto non obbligatorio per l'attivita' attuale.
2. Dati trattati
L'app puo' contenere conti, saldi, categorie, tag, periodici variabili, movimenti, importi, date, note, regole dei periodici fissi, dati fiscali stimati per Partita IVA, testo estratto tramite OCR on-device, preferenze e dati tecnici del vault cifrato. Questi dati restano localmente sul dispositivo e non sono accessibili al titolare, salvo invio volontario al supporto.
Se l'utente attiva la sincronizzazione, Flufiny crea un vault cifrato
end-to-end su iCloud Drive (Bring Your Own Cloud). La chiave o frase di
recupero non viene inviata al titolare ne' ad Apple. L'app accede
esclusivamente al proprio contenitore iCloud (cartella
Flufiny/), nessun altro file dell'utente.
Analytics e crash reporting sono disattivati di default. Se attivati, gli analytics inviano a PostHog EU solo eventi nominali, ID anonimo e dati tecnici. I crash report inviati a Sentry sono filtrati per rimuovere PII, token, path locali e contenuti finanziari.
Gli acquisti in-app sono gestiti da Apple StoreKit/App Store. I dati di pagamento e Apple ID sono trattati da Apple. RevenueCat non e' usato nella versione attuale.
3. Finalita' e basi giuridiche
| Finalita' | Base giuridica |
|---|---|
| Funzionamento dell'app local-first | Esecuzione del contratto, art. 6.1.b GDPR |
| Sincronizzazione iCloud Drive | Consenso, art. 6.1.a GDPR |
| Analytics opt-in | Consenso, art. 6.1.a GDPR |
| Crash reporting opt-in | Consenso e legittimo interesse, artt. 6.1.a e 6.1.f GDPR |
| Acquisti e abbonamenti | Esecuzione del contratto, art. 6.1.b GDPR |
| Supporto via email | Esecuzione del contratto e legittimo interesse, artt. 6.1.b e 6.1.f GDPR |
| Obblighi legali e difesa di diritti | Obbligo legale e legittimo interesse, artt. 6.1.c e 6.1.f GDPR |
4. Conservazione
- Dati locali: finche' l'utente li cancella, usa "Cancella tutto" o disinstalla l'app.
- Vault cloud: finche' resta su iCloud Drive dell'utente.
- Token e preferenze: finche' necessari o fino a disattivazione/cancellazione.
- Analytics: fino a 24 mesi, salvo configurazione piu' breve.
- Crash report: fino a 90 giorni, salvo configurazione piu' breve.
- Supporto email: di regola non oltre 24 mesi dalla chiusura, salvo necessita' legali.
5. Destinatari e trasferimenti
A seconda delle funzioni attivate, possono trattare dati Apple,
PostHog, Sentry, Aruba S.p.A. (hosting di
flufiny.it e gestione email support@flufiny.it,
con datacenter in Italia) ed eventuali consulenti tecnici, fiscali o
legali. Alcuni fornitori possono trattare dati fuori dallo SEE con
garanzie come decisioni di adeguatezza o Standard Contractual Clauses;
i flussi gestiti da Aruba restano invece all'interno dell'Unione
Europea.
6. Sicurezza
Flufiny usa database locale, Keychain, cifratura end-to-end prima dell'upload, accesso al solo contenitore iCloud dell'app, OCR on-device, analytics/crash off di default e nessuna raccolta di credenziali bancarie o PSD2/open banking.
7. Diritti
L'utente puo' esercitare accesso, rettifica, cancellazione, limitazione, portabilita', opposizione, revoca del consenso e il diritto a non essere sottoposto a decisioni automatizzate con effetti giuridici. Per richieste: support@flufiny.it. Reclami: Garante Privacy.
8. Decisioni automatizzate e minori
Flufiny puo' calcolare proiezioni, riepiloghi, suggerimenti e stime fiscali, ma non produce decisioni giuridiche automatiche e non sostituisce un professionista. L'app non e' destinata specificamente a minori.
Flufiny Privacy Policy
This Privacy Policy explains how Flufiny processes personal data in
the mobile app, on flufiny.it, and through support
channels. Flufiny is local-first: financial data stays on the device
unless the user explicitly enables encrypted sync through iCloud Drive
(Bring Your Own Cloud).
1. Data controller
Salvatore Buratti, freelance VAT holder
Address: Via Trieste 79c, 00041 Albano Laziale (RM), Italia
VAT number: IT18186281004
Privacy/support email: support@flufiny.it
2. Data processed
The app may contain accounts, balances, categories, tags, budgets, transactions, amounts, dates, notes, recurring rules, estimated freelance tax data, text extracted through on-device OCR, preferences and encrypted vault technical data. This data stays local and is not accessible to the controller unless voluntarily sent to support.
If sync is enabled, Flufiny creates an end-to-end encrypted vault on
iCloud Drive (BYOC). The recovery phrase or key is not sent
to the controller or Apple. The app accesses only its own iCloud
container (folder Flufiny/), no other user files.
Analytics and crash reporting are off by default. If enabled, analytics sends only named events, an anonymous ID and technical data to PostHog EU. Crash reports sent to Sentry are filtered to remove PII, tokens, local paths and financial content.
In-app purchases are handled by Apple StoreKit/App Store. Payment and Apple ID data are processed by Apple. RevenueCat is not used in the current version.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Local-first app functionality | Performance of a contract, Art. 6(1)(b) GDPR |
| iCloud Drive sync | Consent, Art. 6(1)(a) GDPR |
| Opt-in analytics | Consent, Art. 6(1)(a) GDPR |
| Opt-in crash reporting | Consent and legitimate interest, Art. 6(1)(a) and 6(1)(f) GDPR |
| Purchases and subscriptions | Performance of a contract, Art. 6(1)(b) GDPR |
| Email support | Performance of a contract and legitimate interest, Art. 6(1)(b) and 6(1)(f) GDPR |
| Legal obligations and claims | Legal obligation and legitimate interest, Art. 6(1)(c) and 6(1)(f) GDPR |
4. Retention
- Local data: until the user deletes it, uses "Delete all" or uninstalls the app.
- Cloud vault: until it remains on the user's iCloud Drive (BYOC).
- Tokens and preferences: while needed or until disabled/deleted.
- Analytics: up to 24 months, unless configured for a shorter period.
- Crash reports: up to 90 days, unless configured for a shorter period.
- Support emails: usually no longer than 24 months after closure, unless legally required.
5. Recipients and transfers
Depending on enabled features, data may be processed by Apple,
PostHog, Sentry, Aruba S.p.A. (hosting of flufiny.it and
email service for support@flufiny.it, with datacenters
located in Italy) and technical, tax or legal advisors. Some providers
may process data outside the EEA with safeguards such as adequacy
decisions or Standard Contractual Clauses; the flows handled by Aruba
remain within the European Union.
6. Security
Flufiny uses a local database, Keychain, end-to-end encryption before upload, access only to its own iCloud container, on-device OCR, analytics/crash reporting off by default, and no bank credentials or PSD2/open banking.
7. Rights
Users may exercise access, rectification, erasure, restriction, portability, objection, consent withdrawal and the right not to be subject to automated decisions with legal effects. Requests: support@flufiny.it. Complaints: Italian Data Protection Authority.
8. Automated decisions and children
Flufiny may calculate projections, summaries, suggestions and tax estimates, but it does not produce automated legal decisions and does not replace professional advice. The app is not specifically intended for children.