BANGAM · Cyprus Wallet

Privacy Policy

Effective date: 27 August 2026. This policy explains how personal and financial data is processed in the BANGAM / Cyprus Wallet application.

1. What data do we process?

2. Why do we process data?

To provide account creation and secure sessions, storage and synchronisation of personal financial records, user-initiated OCR/SMS import, payment and cash-flow tracking, Social Finance features, exchange-rate comparison, error/security prevention, financial-analysis features requested by the user, Premium subscription verification/management, optional rewarded-ad verification, and required advertising privacy choices.

3. Service providers and data transfers

BANGAM may use Vercel for hosting/distribution and Supabase for authentication, database, and storage. Microsoft Azure Document Intelligence may process OCR jobs explicitly initiated by the user; for the AI financial-explanation feature, a server-minimised context may be processed by the OpenAI Responses provider. Android Play monetization may use Google Play Billing / Google Play Developer API, while optional rewarded ads and advertising privacy choices may use Google Mobile Ads / AdMob and Google User Messaging Platform. Raw source documents or user passwords are not sent to the AI provider, and the current AI request is configured not to request persistent provider storage.

4. Sharing and sale

We do not sell personal or financial data for advertising purposes. Financial records are not shared for ad targeting. Data may be shared only to provide the service, operate features explicitly requested by the user, protect security, or where legally required, and only with the relevant processors/authorities for those limited purposes.

5. Security

Cloud traffic uses HTTPS, user-bound authorisation/RLS, and canonical RPC boundaries. Cleartext traffic and application backup are disabled in the Android app. Sensitive signing/service keys are not placed in client code or the Git repository. Raw Google Play purchase tokens and AdMob SSV signatures are not persisted as application/database evidence.

6. Retention and deletion

Active-account data is retained to provide the service. After identity verification, personal data linked to an account-deletion request is deleted or irreversibly anonymised. Records that must be retained for security, fraud prevention, legal/regulatory obligations, or the integrity of shared financial transaction history with other users are kept only to the extent necessary and, where possible, separated from personal identity.

Deleting a BANGAM account does not automatically cancel a Google Play subscription. The subscription must be managed or cancelled separately in Google Play. Purchase identity previously bound to a deleted BANGAM account is not silently rebound to a different newly registered BANGAM account by matching email, amount, or date.

To delete an account, use the account deletion page; for access, correction, or other privacy questions, use the data request page.

7. Children

BANGAM is not designed as a financial application for children. Any additional restrictions required by app-store age classification and local law will be applied before release.

8. Changes and contact

If this policy changes, the effective date on this page will be updated. Privacy questions and data-rights requests can be submitted without publishing a personal email address by using the BANGAM privacy request form.