Privacy Policy

Effective date: 12 August 2026

This Privacy Policy describes how Cartofin, a product by TrimSoft Studio, handles information when you use the Cartofin mobile application and related website.

1. Product architecture

Cartofin is designed as a local-first household organisation and personal-finance application that provides tools for family planning, shared tasks, shopping, calendars, records, vehicles, safety workflows, and financial information. Records remain authoritative on your authorized devices and continue to work offline. Household synchronization is designed to exchange end-to-end encrypted records only with authorized devices; Cartofin’s service does not become the readable household or financial system of record.

Household membership does not grant blanket access. Accounts, lists, tasks, vehicles, calendar items, and plan spaces are shared only according to the applicable role and resource permission. Shared household spending remains an expense record and does not create debts or settlement balances between members. Cartofin does not provide a general household chat system.

2. Information you enter into Cartofin

You may enter accounts, transactions, transfers, categories, budgets, bills, reminders, household and permission records, shopping lists, tasks and task comments, calendar records, spaces, vehicles, attachments, preferences, and other information required by enabled features. Receipt capture may also process receipt images and extracted details such as merchant, location clues printed on the receipt, date, currency, line items, quantities, prices, discounts, tax, total, payment hints, and receipt identifiers. These records are stored locally and may be shared only with authorized devices or exported destinations that you choose.

When you use meals, pantry, family-vault, or safety features, you may also enter recipes, ingredients, dietary preferences, pantry inventory, household documents, important contacts, expiry dates, and optional emergency or medical notes such as allergies or blood group. This information can be sensitive. It remains subject to the owner and access scope you select and is not made visible to every household member merely because they belong to the household.

Task comments are attached to a specific task and may include an author, timestamp, edit state, reply relationship, unread state, deletion marker, notification state, and synchronization metadata. They are not used to create a separate general messaging profile.

3. Purchases and subscriptions

Cartofin may offer an optional Premium subscription. The initial Android release will use Google Play Billing, and a subsequent iOS release may use Apple's App Store billing. Cartofin may receive purchase status and entitlement information needed to determine whether Premium features should be available. TrimSoft Studio does not receive your full payment-card details from the applicable app store.

4. Advertising and third-party services

Free and Trial versions of Cartofin may display advertising. Third-party services used by the app, including Google Play services and any advertising technology included in a released build, may process device, advertising, diagnostic, purchase, or other technical information according to their own privacy practices and applicable platform rules.

When you enable an integration, the device calendar, a supported external calendar, Google Drive, iCloud, or another clearly identified provider may process information needed to perform the action you requested. Calendar synchronization is optional. Cartofin records remain authoritative even when selected dates are copied to another calendar.

Cartofin aims to perform receipt image preparation and text extraction on the device where practical. If a released version offers optional cloud-based receipt or AI processing, Cartofin will identify that processing before use, send only the information needed for the requested operation, use secure transport, disclose the provider or provider category and applicable retention behavior, and require you to review proposed financial records before they are saved. Receipt or AI processing does not give a provider access to your entire household ledger.

Before each public release, TrimSoft Studio reviews the third-party SDKs included in that release and aims to keep Cartofin's Google Play Data safety declarations and this Privacy Policy consistent with the app's actual behavior.

5. Diagnostics and technical information

Depending on the services included in a particular release, platform or third-party services may process technical information such as app version, device characteristics, crash or diagnostic information, network-related information, entitlement status, and limited operational analytics. Operational reporting may include aggregate users, active users, Free/Premium state, conversion, churn, advertising or subscription revenue, platform/version distribution, feature adoption, and AI usage or cost. Owner analytics and administration are designed around product operations and must not become a readable financial-ledger, family-vault, meal, location, or household-content dashboard. Cartofin does not use this section to claim collection that is not present in a released build; the applicable store privacy or Data safety declaration should be consulted for the distributed version.

6. Exports and encrypted backups

If you export or share data or reports from Cartofin, the exported copy may leave the app's local storage and be handled by the application, storage location, communication service, or other destination you select. You are responsible for choosing where readable exported financial information is sent or stored.

Backup is different from a readable export. Cartofin creates a backup snapshot locally, encrypts it on the client, and then places the encrypted package in Google Drive or iCloud storage controlled by you. The backup feature is designed so the cloud provider receives an encrypted Cartofin artifact rather than readable financial records. You are responsible for protecting the recovery key or password.

7. Data retention and deletion

Because financial records remain authoritative on authorized devices, you can remove records using available app controls or remove locally stored app data through system controls. Uninstalling the app or clearing its data may permanently remove the local copy if you have not created a usable encrypted backup or retained another authorized synchronized copy.

Revoking household access stops future authorized synchronization. It cannot erase screenshots, readable exports, or other copies a recipient created while they legitimately had access. Tombstones and limited integrity or synchronization metadata may be retained where necessary to propagate deletion and protect consistency.

Google Play purchase records and information processed by third-party providers are subject to those providers' retention requirements and policies.

8. Security

TrimSoft Studio takes reasonable steps to design Cartofin around local storage, resource-specific authorization, authenticated device trust, end-to-end encrypted synchronization, and client-side encrypted backups. A restore establishes a legitimate new device identity rather than simply cloning the identity of the backed-up installation. No method of storage or electronic processing can be guaranteed completely secure. Protect your devices, recovery secrets, and readable exports.

9. Permissions

Cartofin requests platform permissions only when they are needed for an enabled feature. These may include camera or selected-photo access for receipt capture, notifications, calendar access, files or cloud-provider authorization, microphone access for voice capture, and location-related permission for an intentionally started SOS workflow. Permissions are requested in context and can be denied or revoked, although the related feature may then be unavailable.

An SOS workflow is user-controlled and does not replace local emergency services. Cartofin does not claim that an SOS action will always reach a particular person, provider, or emergency authority.

10. Children's privacy

Cartofin is a general household organisation and personal-finance utility intended for household use and is not specifically designed or directed to children. If the product's audience or features change, TrimSoft Studio will reassess applicable child-privacy requirements before release.

11. International use

Cartofin may be made available in more than one country. Privacy rights and obligations can vary by jurisdiction. Where applicable law gives you specific rights concerning information processed by TrimSoft Studio, you may contact us using the details below.

12. Changes to this policy

We may update this Privacy Policy when Cartofin's features, third-party services, or legal obligations change. The effective date above will be updated when a revised policy is published.

13. Contact

Privacy questions and general support requests may be sent to support@cartofin.com.

Operator: TrimSoft Studio
Product: Cartofin
Website: cartofin.com