FYVLO · Transparency
Your data, plainly.
Updated on September 22, 2026 · Publisher: TR Insight.
This translation is provided for convenience. The French version of this document is the one that applies; if they differ, the French version prevails.
Document being finalised. Still to be filled in: Consumer mediator. This version is not a statement of compliance.
1. Who uses your data, and why?
Thomas Richet, sole trader operating TR Insight and publisher of FYVLO, is the controller of the processing described here. His address is in the legal notice. The dedicated data protection contact is still to be confirmed.
FYVLO processes the information needed to open a session, keep a group’s accounts, calculate splits, sync devices and answer support requests. The service makes no transfers and asks for no bank connection.
2. What data is involved?
- Account: sign-in email, hashed password, sessions, display name and preferences. Starting as a guest creates a technical identity tied to the device.
- Launch list: if you leave your email on fyvlo.app before the app’s release, your address, your place on the list, the date and the page you came from. It’s used only to tell you about the launch; it’s kept only if you confirm with the link you receive, and every email has a link to remove yourself. It’s deleted after the launch announcement.
- Shared spaces: participants’ names, expenses, amounts, payers, items, splits, recorded repayments and history.
- Receipts: images or PDFs you send, and the analysis results if you start a scan.
- Optional features: notification devices, AI assistant permissions and drafts, support requests.
- Future purchases: customer ID, purchase references, plan, duration, renewal status and associated entitlements, with no card number.
- Technical data: session information, operating logs and abuse protection. Hosting providers may receive the IP address and request headers.
3. Who can see it?
A space’s data is available to its participants according to their rights. A receipt participation link gives access to that receipt: share it only with the people concerned.
Convex provides storage and server functions. Cloudflare serves the web pages. If you start an analysis, the receipt photos are sent to Google (Gemini) to extract the information. If notifications are on and allowed, Expo and the platforms’ notification services receive what they need to deliver them. If you accept audience measurement, PostHog (European Union region) receives the visit information described on the cookies and storage page.
By connecting an assistant, you allow its provider to read the data for the spaces and permissions you selected. This access can be revoked in FYVLO. That provider’s own processing is also governed by its policy.
Address verification, password reset and launch list emails go through the configured email provider (Resend), only when you request them. Resend then tells us whether each was delivered, delayed, rejected or reported as spam, and whether one of its links was opened: links therefore pass through links.fyvlo.app before reaching their destination. No pixel measures email opens. This tracking helps emails arrive and tells us which ones are useful; details are kept 90 days, then only totals remain. To filter out disposable or non-existent addresses, only the address’s domain is checked against Cloudflare’s public DNS. The site’s fonts are served from FYVLO: no request goes to a font provider. If purchases open, RevenueCat receives a customer ID and the transaction data needed to manage entitlements; the app stores (Apple, Google) take the payment. FYVLO never receives your bank details.
Sentry receives technical error diagnostics to help us fix failures. JavaScript reports are filtered before sending: they exclude free-text messages, account data, expenses, receipts and request contents. No screen or interaction recording is enabled. The Sentry project is hosted in the European Union.
4. On what basis, and where to?
Each processing relies on a legal basis set out in the GDPR (art. 6):
- Performing the service you ask for — your account, your spaces, expenses, splits, syncing, verification emails and analysing a receipt when you start it.
- Legitimate interest — the service’s security, abuse prevention, rate limits and the technical logs needed to diagnose a failure.
- Consent — notifications on your device (permission asked by the system) and connecting an AI assistant. You can withdraw these consents at any time from the app or your device settings.
- Contract — managing the plan and its entitlements, if you buy a subscription or a Pass.
- Legal obligation — keeping accounting records for a purchase, once paid plans open (10 years, art. L123-22 of the French Commercial Code).
The providers mentioned (Cloudflare, Convex, Google, Expo, PostHog) are based in the United States. Transfers rely on the EU–US Data Privacy Framework for certified companies, or otherwise on the European Commission’s standard contractual clauses. Each provider’s certification and hosting regions are still to be checked: FYVLO doesn’t currently guarantee hosting exclusively in Europe. The Google offering used for real receipts must exclude training on content before analysis opens to the public.
5. For how long?
- Account data is used for the account’s lifetime, then private data is progressively cleaned up after deletion.
- Operations and attached receipts follow the lifetime of the space and the operation. A reversible deletion keeps the receipt until a final purge.
- A file uploaded but never attached to an operation is scheduled to be purged after 24 hours, when the planned clean-up runs.
- Assistant suggestions stay tied to the lifetime of their connection. Personal notifications follow the lifetime of the account or the space.
- Support requests and purchase references stay tied to the account until it’s deleted, subject to accounting retention obligations for purchases.
- Drafts, files and offline copies can remain on the device. A server-side deletion doesn’t guarantee they’re erased on every device or from the recipients of an export.
Retention periods for infrastructure backups, logs, support data and data kept by providers are still to be set out before this policy is finalised.
6. What happens when you delete your account?
The profile, sign-in identity and sessions are deleted; the associated private data is cleaned up in batches. Spaces where you are the only participant are deleted.
In a shared space, operations and a name detached from your account are kept so the other participants’ balances don’t change. This is not a guaranteed anonymisation of the whole history. See the deletion instructions for the details.
7. Your rights
Depending on the situation, you can ask for access to your data, its correction, erasure or portability, restriction of processing, or object to it. The personal export is in the account settings. Revoking an assistant and notification preferences are also managed in the app.
The contact point must be confirmed by TR Insight before final publication. You can also consult the CNIL (the French data protection authority) to learn about your rights and lodge a complaint. Deleting an account doesn’t delete files you’ve already exported and shared.
8. Cookies and on-device storage
FYVLO uses strictly necessary cookies and storage: the session, drafts, the theme, offline operation. No advertising tools, no social networks. Audience measurement (PostHog, hosted in the European Union) is only active if you accept it in the banner; legal basis: your consent, which you can withdraw at any time. The full list, with each item’s duration, and the setting for your choice are on the cookies and storage page.