Privacy Policy — Sổ Nhà
Sổ Nhà (the "app") lets members of a household record and track their spending together in a shared space. This document describes what data the app collects, why, how it is stored, and your rights. In case of any discrepancy, the Vietnamese version prevails.
1. Data we collect
You provide directly
| Data | Purpose |
|---|---|
| Email address | Account identity, sign-in, access recovery |
| Display name | Showing you to other members of your household |
| Household name | Naming the shared space |
| Transactions: amount, type (expense/income), category, note, date, payer | Core function — recording and reporting spending |
| Category budget limits | Over-limit warning feature |
| Custom categories | Letting the household organise its own spending |
| Invite code (when you join with a code) | Verifying you were invited to the correct household |
Recorded automatically
| Data | Purpose | Notes |
|---|---|---|
| User ID (UID) issued by Firebase Authentication | Linking data to your account | |
| Timestamps of account creation / joining a household / creating a transaction | Ordering, reconciliation | |
| "Invite code used" log (who used which code, when) | Traceability, security | Visible only to the household Owner |
| Chosen language and theme (Light/Dark) | Remembering your preferences | Stored on the device only, not sent to our servers |
| Abuse-prevention counters (number of calls to certain actions) | Blocking invite-code guessing / abuse | Not tied to your display identity |
Crash diagnostic data
When the "Send crash reports" switch is on (Settings → Privacy — on by default), if the app crashes, a technical report (error type, call stack, operating system version, device model) is sent to Sentry (Functional Software, Inc., USA). Crash reports do not include your transaction amounts, notes or contents.
Usage data
We currently use no dedicated analytics service (no PostHog / Firebase Analytics). When the "Send usage data" switch is on (Settings → Privacy — on by default), a few aggregate events ("household created", "transaction added", "budget set") are attached to the crash report above (as Sentry breadcrumbs) to give context when something goes wrong. Transaction contents are not included.
2. What we do NOT collect
- No location, contacts, photos, calendar or health data.
- No ads, no third-party advertising trackers.
- No in-app payment information (if a paid plan is offered later, payment is handled by the App Store / Google Play; we only receive a "purchased" status).
3. Data sharing
- With members of your household: all transactions, categories, budgets and display names are shared with other members of the same household, according to role (Owner / Member / Viewer). Each member's email is visible to other members.
- With infrastructure providers (processors acting on our behalf):
- Google Firebase (Google LLC / Google Ireland) — Authentication, Cloud Firestore, Cloud Functions. Data stored in the
asia-southeast1region (Singapore). - Sentry (Functional Software, Inc., USA) — crash diagnostics only (error type, stack, device model, OS; no financial content). Sent only if you have not turned the switch off in Settings.
- Resend (Resend, Inc., USA) — sending system emails (email verification, password reset). Receives only the recipient email address and the email's content; no financial content.
- Google Firebase (Google LLC / Google Ireland) — Authentication, Cloud Firestore, Cloud Functions. Data stored in the
- We do not sell data. We do not share it with third parties for their own commercial purposes.
- We disclose data only where validly required by law.
4. Storage and security
- Data is stored on Google Cloud infrastructure, encrypted in transit and at rest.
- Access is controlled by Firebase Security Rules (deny by default, opening only the scope for each role) and server-side authenticating Cloud Functions.
- No system is perfectly secure; we cannot guarantee 100% security.
5. Retention
- Account and transaction data is kept until you delete it.
- Deleting your account (section 6) deletes your sign-in account and your user record, and removes you from the household. Transactions you created in a household are retained within that household for the remaining members' reconciliation purposes, attached to the payer name as of creation time (no longer linked to your deleted account).
- When you are the last member to leave a household (leaving, being removed, or deleting your account), that entire household space — all transactions, categories, budgets and pending invites — is permanently deleted immediately afterwards, automatically, with no recovery. No one can access it, so nothing is retained.
- A scheduled job (every 24 hours) scans for and deletes households that have no members left, in case the automatic deletion above was missed.
- Abuse-prevention counters and crash reports are kept for a limited time and then deleted automatically.
6. Your rights
- View / edit: directly in the app.
- Export data: Coming soon — exporting all of the household's transactions to CSV/JSON (for the Owner). In the meantime, you can request a copy via the contact email.
- Delete account: in the app, at Settings → Delete account. This deletes your sign-in account and cannot be undone. See also how to delete your account.
- Withdraw consent for crash reports / usage data: Settings → Privacy — a separate switch for each type; turning it off stops sending immediately.
- Contact support@tahonest.com for any other personal-data requests.
7. Children
The app is not directed at children under 13 and does not knowingly collect data from children. If you believe your child has provided us data, contact us to have it deleted.
8. Changes to this policy
When we update it, we will change the "Effective date" at the top and, for significant changes, notify you in the app.
9. Contact
Tahonest — support@tahonest.com