Legal
Privacy Policy
Last updated: August 7, 2026
Orevalis is local-first: you enter your financial information manually, and day-to-day tracking works fully offline. If you're signed in, your financial records may also be backed up to our cloud service provider so they can be restored after a lost, replaced, or reinstalled device — alongside your account information and, if you use Premium receipt backup, the receipt files you choose to upload. This policy explains exactly what is stored where, which providers are involved, and the choices you have. Creating an Orevalis account with a confirmed email address is required before the app can be used — see "Your account" in the Terms of Service.
What we never collect
We never connect to your bank or financial institutions, and we never ask for banking credentials. Orevalis does not automatically connect to, import from, or scrape any financial account.
We never receive your payment card details. Purchases are processed by Apple's App Store or Google Play.
We never receive biometric data. If you enable the biometric app lock, Face ID / Touch ID / fingerprint verification is performed entirely by your device's operating system; Orevalis receives only a success or failure result — never fingerprint images, facial maps, or biometric templates.
We do not sell your personal or financial data, and we do not share it for behavioral advertising. The app contains no advertising SDK.
Information you provide
Account details: your email address and a password. Passwords are handled by Supabase Authentication using industry-standard practices; Orevalis staff never receive your plaintext password.
Profile details: a display name, and preferences such as language and currency.
Financial records you enter manually: Spaces, transactions, bills, balances, categories, merchants, payment methods, notes, purchase feelings, goals, forecast/planning data, and optional transaction locations. These are stored on your device and, if you're signed in, may also be backed up to our cloud service provider so they can be restored (see below).
Receipt images or files you choose to attach to transactions (see the dedicated receipt section below).
Support messages and any attachments you voluntarily send to our support channels.
Information generated through use
A Supabase user identifier, authentication and session information, and account-security events (such as sign-ins, email confirmation, and password resets), managed by Supabase.
A RevenueCat customer identifier — the same identifier as your Orevalis account — together with your email address and display name (sent to RevenueCat as customer-profile attributes), your purchase history, subscription state, product identifiers, and entitlement status, used to unlock, restore, and manage Premium access.
Financial-backup metadata and records — your backed-up Spaces, transactions, bills, and related records described in "Financial data backup and restore" below, associated with your account so they can be restored.
Receipt-backup metadata (database records that associate a backed-up receipt with your account and its transaction) so backups can be restored after a reinstall.
Local notification configuration for bill reminders, which stays on your device.
Basic device and platform information required for the app to operate (for example, operating system and app version, as processed by the platforms and our providers).
Apple and Google may provide us aggregated crash and diagnostic information under their own policies and your device settings. Orevalis has not integrated a separate analytics or advertising SDK; if that ever changes, this policy will be updated first.
Your financial records — local-first, with cloud backup for signed-in accounts
You enter your financial information manually. Orevalis does not require bank credentials and does not connect to or scrape bank accounts.
Orevalis is local-first: your manually entered financial records — Spaces, transactions, bills, balances, categories, notes, feelings, goals, planning data, and locations — are stored on your device, and day-to-day tracking works fully offline.
If you're signed in, these records may also be backed up to our cloud service provider so they can be restored after a lost, replaced, or reinstalled device. See "Financial data backup and restore" below for exactly what's included, what stays device-only, and how it's protected.
You can permanently delete your local financial data in the app at any time; deleting your account removes your cloud financial backup, as described in Account Deletion.
Location — optional, and only when you add it
Adding a location to a transaction is entirely optional and only happens when you choose to add one — either by typing an address or by using your device's current location, which requires you to grant location permission.
A location you add is stored on your device with the transaction, the same as any other financial record. If you're signed in, it may be included in your cloud financial backup like any other transaction detail, as described in "Financial data backup and restore" below.
When a saved location is displayed — for example, as a small map preview on a transaction, or when you choose to open a location in a maps app — the app may use your device's on-device location and mapping services, and platform mapping and geocoding services provided by Apple and/or Google, to show or look up that location. This means the coordinates or address involved can be processed by Apple's or Google's map services at the moment the map is shown or opened, separately from Orevalis.
Embedded map display is not guaranteed to be available on every device, operating system version, or platform, and may vary. Manually entered addresses can be stored as text even when an embedded map preview is unavailable.
Financial data backup and restore
If you're signed in, Orevalis backs up your financial records to our cloud service provider (Supabase) so you can restore them after losing, replacing, or reinstalling on a new device. This is separate from, and in addition to, the local storage described above — it does not change how the app works offline.
What's included: Spaces, balances, transactions and transaction metadata (such as notes, purchase feelings, and locations), bills and payment history, goals, forecast and planning data, custom merchants, custom transaction categories, custom bill categories, your recent selections where applicable, and your display currency.
Financial Pulse is derived from this underlying financial data whenever you view it — it is not stored as a separate cloud dataset.
What stays device-only: your theme, language, and biometric-lock preference, and the re-fetchable exchange-rate cache, are not part of the financial backup snapshot.
Profile data such as your display name and avatar continues to use its existing profile/avatar cloud storage, described elsewhere in this policy.
Your financial backup is associated with your authenticated account and protected by row-level security, so only your signed-in account can access it. Data is transmitted securely in transit.
If cloud backup fails or is temporarily unavailable, the app continues to work fully offline from your device's local copy — backup failure does not block local use.
Deleting your account removes your cloud financial backup, as described in Account Deletion.
Receipts — local by default, private cloud backup with Premium
Attaching a receipt is always voluntary. Be aware that receipt images can contain personal or financial information visible in the image itself.
Receipts you attach are stored locally on your device with the transaction they belong to. You can replace or delete a receipt at any time.
If you are a Premium user, your receipt files are backed up to a private Supabase Storage bucket associated with your account, with automatic upload, an intelligent retry system, and automatic recovery after you reinstall the app and sign in. Backup exists for one purpose: preserving and restoring your transaction attachments.
Access to backed-up receipts is restricted through authenticated storage controls (including row-level security policies) so that only your signed-in account can access your files. Receipt files are encrypted in transit.
We do not use receipt contents for advertising, we do not sell them, and we do not use them to train AI models.
Deleting a receipt in the app removes it from your device and, for Premium backups, from cloud storage through the app's deletion flow. Deleting your account removes your cloud receipt backups as part of account deletion, except where retention is legally required or deletion is temporarily pending in encrypted backups.
Important: uninstalling the app does not delete cloud receipt backups while your account remains active — that is what allows recovery after reinstall. To remove them, delete the receipts or delete your account.
Custom images you add
Certain images you create for merchants, transactions, or bills — for example, a custom merchant icon — may be stored in a private Supabase Storage bucket (separate from receipts) when eligible, so they can be restored on your account. The same authenticated access controls described for receipts apply.
Purchases — Apple, Google, and RevenueCat
Payments are processed by Apple's App Store or Google Play. Orevalis never receives your complete card information.
RevenueCat acts as our subscription-infrastructure service provider. It processes your purchase history, store transaction identifiers, subscription state, product identifiers, entitlement status, and the account identifier, email address, and display name described above. This data is used to unlock Premium, restore purchases on new devices, and manage your entitlement.
Supabase — accounts, financial backup, receipt storage, and deletion
Supabase provides account authentication, user and profile storage, financial-data backup and restore, the private storage buckets used for Premium receipt backups and eligible custom images, and the database records required to restore those backups.
Account deletion is performed by a server-side Supabase Edge Function that removes your authentication user, profile data, cloud financial backup, cloud receipt files, eligible custom images, and related backup metadata, and clears that account's namespaced local financial data and local user-owned files on the device where deletion is run (see the Delete Account page).
We send transactional email only: sign-up confirmation, password recovery, and account or security notifications. These are delivered by Resend through Supabase's email system, from no-reply@auth.orevalis.com.
Password-reset emails contain a secure recovery link — never a password. Resend does not receive plaintext passwords.
We do not currently send marketing email. Support email (support@orevalis.com) is hosted with Bluehost; messages you send there are used to help you.
Why we process data
To create and authenticate your account, secure access to it, and recover it when you forget a password.
To provide manual money-management functionality, including bill reminders delivered locally on your device.
To back up and restore your financial records and other eligible data for signed-in accounts, so you can recover your information after a device change, loss, or reinstall.
To store and restore Premium receipt attachments, and to process and restore purchases and deliver Premium entitlements.
To respond to support requests, prevent abuse and fraud, comply with legal obligations, and maintain service reliability.
Who processes data on our behalf
The following service providers (processors) handle data as described in this policy: Supabase (authentication, profile, financial-data backup, receipt storage, eligible custom-image storage, deletion), RevenueCat (purchases and entitlements), Apple and Google (payments, app distribution, platform diagnostics, and — only when you view or open a location you've added to a transaction — map and geocoding rendering), Resend (transactional email), Cloudflare (serving and protecting this website, which may process standard technical request data such as IP addresses), Bluehost (support email hosting), and Frankfurter (our exchange-rate provider, which receives rate requests that do not include your balances or transactions).
Because service providers necessarily process data to deliver these functions, we do not claim your data is "never shared." We do claim — and it is true — that we do not sell personal data and do not share it for behavioral advertising.
How long data is kept
Account and profile data: kept while your account is active, then deleted through account deletion, subject to a limited period in encrypted technical backups or where retention is legally required.
Cloud financial backups: kept while associated with your active, signed-in account, or until you delete the account, subject to the same limited encrypted-backup and legal-retention exceptions.
Cloud receipt backups: kept while associated with your active account, or until you delete the receipt or the account.
Purchase history: may remain with Apple, Google, and RevenueCat according to their own legal and operational retention requirements.
Support email: kept as reasonably needed to resolve your request, prevent abuse, and meet legal obligations.
Local records: remain on your device until you remove them, reset the app, or uninstall it, according to your operating system's behavior.
Authentication and security logs: retained according to the provider's settings and security requirements.
Your rights and controls
In the app you can: access and edit your profile; export supported app data (CSV/ZIP); delete individual receipts; delete your local financial records; enable or disable the biometric lock; and delete your Orevalis account entirely, which also removes your cloud financial backup.
Through Apple or Google you can cancel subscriptions and restore purchases.
You can also submit a deletion request from the web — see the Delete Account page — or contact support@orevalis.com with any privacy question or request.
International processing
AEUREON LLC is a United States company, and our service providers — including Supabase, RevenueCat, Apple, Google, Resend, and Cloudflare — may process data in the United States and other countries. Where data is transferred internationally, it is handled under the providers' applicable safeguards. We do not promise that data remains exclusively in your country.
Children
Orevalis is not directed to children, and it is not intended for anyone under the age of 13 (or a higher minimum age where local law requires one, such as the age applicable to consent under Brazil's LGPD). We do not knowingly collect personal data from children below the applicable minimum age, and accounts known to violate this restriction may be deleted.
Brazil — LGPD
If you are in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD), including: confirmation that we process your data; access to it; correction of incomplete or outdated data; portability where applicable; deletion or anonymization of data processed with your consent, where applicable; information about the third parties we share data with; and withdrawal of consent where consent is the legal basis for processing.
To exercise any of these rights, contact support@orevalis.com. We will respond within the timeframes required by law.
European Economic Area, United Kingdom, and Switzerland
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have rights regarding your personal data, including access, correction, deletion, restriction, portability, and objection to processing. Contact support@orevalis.com to exercise any of these rights, or to reach us about a complaint you may also have the right to lodge with your local data protection authority.
United States and other regions
Depending on where you live, you may have additional rights regarding your personal data under regional law. Orevalis does not sell personal data and does not share it for cross-context behavioral advertising. Contact support@orevalis.com and we will honor the rights that apply to you.
Changes and contact
If we materially change how data is handled — for example, by adding cloud synchronization of financial records or any analytics SDK — we will update this policy first and change the date above.
Questions: support@orevalis.com. Publisher: AEUREON LLC, St. Petersburg, Florida, USA.

