Drippy Privacy Policy
Effective: 7 October 2026
Drippy is a Pixel Crafts app for organising subscriptions and payment records. Contact support@pixelcrafts.app about privacy, access, corrections, exports or deletion. This policy covers Drippy, not every website or service linked from it.
Information Drippy uses
Account services process your sign-in identity, such as your email address, name and account identifier. Payment records can include merchant names, amounts, dates, categories, recurring schedules, masked payment identifiers and corrections you make. These are financial information, even when the original message is not included.
On Android, SMS scanning requires your message permission. Drippy reads the history you select to identify payment activity. Email connections require the email provider's authorisation. Email processing can access message headers and receipt content within the selected scan scope; connecting an inbox is not a promise that every subscription will be found.
Device, cloud and AI processing
SMS parsing runs on the device. Derived records can be saved locally and synchronised with your account. Synchronised records are not end-to-end encrypted: our services can read them to provide backup and restore. Source evidence can be available in the app for review; do not assume that only the visible totals are stored locally.
Email processing depends on the source and the mode you choose. Cloud email processing reads receipt content through our services after a separate disclosure. The extraction flow returns payment facts rather than exposing the provider's access token to the mobile app. Provider authorisation credentials are handled by the account service. While a cloud read is completed, our services can temporarily keep the extracted payment facts and short receipt excerpts; these are removed after the read is acknowledged or cleaned up, or when you withdraw cloud email consent.
If you choose AI assistance for unclear messages, the app redacts personal and account identifiers before sending the selected text for extraction. Redaction reduces exposure; it does not make financial text anonymous. Money chat sends your question and the relevant financial context supplied by the app's service layer for a response. Avoid entering passwords, complete card numbers or other unnecessary sensitive information in chat.
Why information is processed
Information is used to provide your account, recognise payments, organise the ledger and subscriptions, answer questions you initiate, synchronise records and support the app. Optional source permissions and AI processing are separate from acknowledging this policy. You can decline optional processing and use the features that remain available.
Technical diagnostics can include device and app information, crash reports and error details. Detection reporting is off by default. If you turn it on, the app sends scan counts, short sender codes and the corrections you make so detection can be improved; turning it off stops future reports but cannot recall reports already sent. Purchase services process identifiers and purchase status when you use paid features. Drippy does not receive the complete payment-card details you enter into an app-store checkout.
Service providers
Account, hosting, diagnostics, email and purchase providers process information needed for their functions. The implementation uses Google/Firebase, cloud infrastructure including Neon and Fly.io, and RevenueCat for supported store purchases. AI requests use the provider configured by our service. Contact support for the current provider information relevant to your account; do not assume that processing takes place only on your phone or only in your country.
Google account and email information is used for the user-facing features you authorise. It is not used for personalised advertising, sold to data brokers or used for creditworthiness decisions. Use and transfer of information received from Google APIs must follow the Google API Services User Data Policy, including its Limited Use requirements.
Storage, retention and security
The app uses encrypted local storage and secure transport to its services. Access tokens are handled separately from displayed payment records. These measures do not eliminate all security risks.
Account records, synchronised payment history, local records, diagnostics and provider records have different lifecycles. Disconnecting a source stops its future authorised use; it does not itself erase previously imported records. Signing out is not a deletion request and can leave local history on the device. Uninstalling the app does not erase records held by the account or app services.
Request deletion or a retention explanation at support@pixelcrafts.app. Support must consider the relevant services and any records required for legal, security or billing purposes; there is no claim here that all data is automatically erased after a fixed interval. A closed account can be restored through support for 30 days; remaining records are not erased automatically when that window ends.
Your choices and requests
You can manage connected sources, revoke provider permissions, correct imported records and change supported privacy preferences in the app. You can also revoke access in your provider's account settings. For access, export or deletion, identify Drippy and the account email in your request. We may need to verify ownership. Never send a password, verification code or complete card number.
See Account and data deletion for the distinction between deleting records, closing an account and cancelling billing. Privacy rights available under applicable law are not limited by these instructions.
Audience and updates
Drippy is intended for adults managing their own finances. Contact support if a child has supplied information. Changes to data use will be reflected in this policy; acknowledging an update does not replace a separate consent required for new processing.
Effective: October 7, 2026