Two Bob
Home Privacy Terms
Legal — 02Last updated 28 July 2026

Privacy Policy

You're handing a small app your wages, your bills and the tax you'll owe. Here's precisely what happens to all of it, who else touches it, and how to get it back or get rid of it. No paragraph in here exists to give us wriggle room later.

SOLD OR RENTED
Nothing
ADVERTISING TRACKERS
None
CARD DETAILS WE HOLD
Zero
01

Who's responsible

Two Bob is built and run from Australia by the small team behind the app, and we're the data controller for everything described here. We're bound by the Australian Privacy Principles under the Privacy Act 1988, and by the UK GDPR for people using the app in Britain.

Reach us through Settings → Help & Support in the app, or via the waitlist page before launch. Privacy requests go to the same place and are handled by a person, not a form.

02

What we collect, and why

Account details

Your email address and a hashed password, or an Apple/Google sign-in identifier if you use one. Needed to give you an account and let you back into it.

The budget data you enter

Income sources and amounts, pay frequency, bills and due dates, expenses, categories, savings percentage, tax region and contribution rate, and any notes you type. This is the app's whole reason to exist; without it there's nothing to show you.

Receipt and invoice images

When you use the camera scan, the merchant, amount and date are read directly on your phone using on-device text recognition (Google ML Kit) — the photo itself is never sent to us or anyone else for this. We keep the extracted fields; the image is kept only if you choose to attach it to the entry, and you can delete it with the entry.

Purchase and entitlement records

Which plan you're on, when the trial started, and Apple's anonymised receipt identifiers — held via RevenueCat so the app knows you've paid. No card numbers, ever: Apple handles the money and doesn't share your payment details with us.

Device and notification tokens

A push token and basic device/OS information, used to send the bill reminders you've asked for and to work out which platform a bug is on.

Product analytics

Anonymised events — screens opened, features used, where people drop out of sign-up, crash reports. We can see that the Trends screen was opened; we can't see what your trends say. Your amounts and merchant names are never sent as analytics properties.

Under UK/EU rules, our lawful bases are: performing our contract with you (running the app and your account), legitimate interests (keeping the service secure, fixing crashes, understanding which features earn their place), consent (push notifications, camera access, and optional bank linking), and legal obligation (tax and financial records of purchases).

03

Who else touches your data

A short list, and it stays short. Each of these is a processor acting on our instructions, under contract, and none of them is permitted to use your data for their own purposes. Receipt scanning isn't on this list because it doesn't involve one — the text recognition runs on-device via Google ML Kit, so no receipt photo is ever sent anywhere for that purpose.

SUPABASE
Hosts the Postgres database and authentication. Your rows are protected by row-level security keyed to your user ID, encrypted in transit and at rest.
APPLE · GOOGLE PLAY
Take the payment, issue the receipt, handle refunds and cancellations. Their privacy terms cover the transaction itself.
REVENUECAT
Validates those receipts and tells the app whether your plan is active. Sees an anonymous app user ID and purchase metadata — not your budget.
ONESIGNAL
Delivers push notifications. Holds your device token and the text of the reminder being sent — so keep bill nicknames polite if that bothers you.
POSTHOG
Product analytics and crash reporting, keyed to a pseudonymous ID. No financial figures are attached to events.
BASIQ — NOT YET LIVE
When optional bank linking ships, this regulated provider will handle the connection. Read-only, off unless you switch it on, revocable in a tap, and you'll see its consent screen before anything connects.

We will also disclose data if we're legally compelled to — a court order, a regulator with the authority to demand it — and we'll tell you unless we're prohibited from doing so. If the app were ever sold or merged, your data would move with it under this same policy, and you'd be told before it happened.

04

What we don't do

We don't sell or rent your personal information. We don't run advertising SDKs or third-party trackers in the app. We don't build marketing profiles from your spending, and we don't use your financial entries to train machine-learning models. There's no data-broker relationship to disclose, because there isn't one. The app is paid for — that's the business model, and it's deliberately the only one.

05

Where it's stored, and how long

Data is held on Supabase infrastructure and may be processed in Australia, the United States or the EU depending on the service. Where data leaves your country, we rely on standard contractual clauses and equivalent safeguards with each provider.

Your entries are kept for as long as your account is open. Delete an entry and it goes from the live database immediately; delete your account and everything goes, with encrypted backups cycling out within 30 days. Purchase records are kept up to seven years because tax law requires it. Analytics events are retained in aggregate for up to 24 months.

06

Your rights

You can ask for a copy of your data, correct it, delete it, or object to a particular use. Account deletion and data export are in Settings so you don't have to ask anyone's permission; for anything else, message support and we'll act within 30 days.

You can turn off push notifications and camera access at the operating-system level at any time — the app keeps working, minus those bits. If you're in the UK you may complain to the Information Commissioner's Office; in Australia, to the Office of the Australian Information Commissioner. We'd rather you came to us first, but that's your call, not ours.

07

Security, honestly stated

Transport is encrypted, storage is encrypted, access is row-level restricted, passwords are hashed and never visible to us, and administrative access is limited to what's needed to keep the service running or to help you with a support request you've raised. No system is perfect, and anyone who tells you theirs is should be treated with suspicion. If there's ever a breach affecting your data, we'll notify you and the relevant regulator as the law requires, and tell you what actually happened.

08

Children

Two Bob isn't intended for under-16s and we don't knowingly collect their data. If a child's account has been created, tell us and we'll delete it.

09

Changes to this policy

When something material changes — a new processor, a new category of data, bank linking going live — we'll update the date at the top and flag it in the app before it takes effect. We won't quietly widen what we collect and hope you don't reread it.

DOCUMENT VERSION 1.0 · EFFECTIVE 28 JULY 2026 · SEE ALSO THE TERMS OF USE

Two Bob
Home Terms of Use Waitlist
© 2026 TWO BOB