Who we are
Wealth Bites ("we", "our", "us") is a personal finance application developed and operated by LotusQueen Labs. The app is available on iOS, Android, and the web and is designed to help individuals and households track accounts, transactions, investments, and financial goals.
If you have questions about this policy, see §12 Contact.
What data we collect
We collect only what is necessary to operate the app. The table below lists every category of personal or financial data we process.
| Category | Examples | Source |
|---|---|---|
| Account credentials | Email address, hashed password | Provided by you at sign-up |
| Profile | Display name (derived from your email by default), relationship label | Derived or provided by you |
| Financial accounts | Bank account names, account types, current balances | Entered by you |
| Transactions | Date, amount, category, description, currency, account | Entered by you |
| Investment portfolio | Security names, tickers, trade quantities, prices, brokerage accounts, investor names | Entered by you |
| Financial goals | Goal name, target amount, deadline, priority | Entered by you |
| Market prices | Last-synced security prices fetched via Yahoo Finance | Yahoo Finance (via our Edge Function) |
| Device preferences | Biometric login enabled/disabled flag, display currency preference | Set by you in the app |
| Google account | Google email address, OAuth access and refresh tokens (for Drive backup only) | Provided when you connect Google Drive (optional) |
What we do not collect
- Biometric data — Face ID and fingerprint authentication is handled entirely by your device's secure enclave. We never receive, store, or transmit biometric templates.
- Advertising identifiers — we use no ad SDKs and do not collect IDFA, GAID, or any advertising identifier.
- Behavioural analytics — we use no third-party analytics platforms (no Mixpanel, Amplitude, Firebase Analytics, etc.).
- Location data.
- Contacts or calendar data.
- Bank login credentials — we do not connect to your bank directly. All data is entered manually.
How we use your data
- To operate the app. Your financial data is stored so the app can display your net worth, transaction history, portfolio performance, and goal progress.
- To authenticate you. Your email and password (or biometric shortcut) are used to identify your account and protect your data.
- To sync market prices. When you enable price sync for a security, its ticker symbol is sent to Yahoo Finance (via our Edge Function) to fetch the latest price. No personal data is included in this request.
- To power the AI assistant. If you use the "Ask AI" button in the transaction chat, your in-progress transaction data and conversation history are sent to our Edge Function for processing. See §6.
- To back up your data. If you connect Google Drive, a JSON export of your data can be saved to and restored from your private Google Drive appDataFolder. See §5.
- To improve reliability. We may log server-side errors from our Edge Functions to diagnose failures. These logs do not contain your financial data.
We do not use your data for advertising, profiling, or sale to any third party.
Third-party services
The following third-party services process data on behalf of Wealth Bites. We have selected each for its strong privacy and security posture.
All your financial data is stored in a Supabase PostgreSQL database with Row-Level Security enabled — only your account can read your data. Authentication and Edge Function execution also run on Supabase infrastructure.
supabase.com/privacy ↗When you use the AI assistant, your conversation and transaction context are processed by Anthropic's Claude API via a server-side Edge Function. Your API key is never exposed to the client. See §6 for detail.
anthropic.com/privacy ↗If you choose to sign in with Google or enable Drive backup, your Google account email and OAuth tokens are used. We request only the drive.appdata scope — we cannot access your Drive files.
When price sync is enabled for a security, its ticker symbol is fetched from Yahoo Finance via our Edge Function. No account information or personal data is included in these requests.
yahoo.com/privacy ↗We do not share your data with any other third party, including data brokers, advertisers, or social networks.
Google Drive backup
Google Drive integration is entirely optional. If you connect it:
- Backups are saved to your Google Drive appDataFolder — a hidden, app-private folder that is not visible in your Google Drive UI and is not accessible to other apps.
- We store your Google OAuth access and refresh tokens on your device so you do not have to re-authorise on every backup.
- We request only the
https://www.googleapis.com/auth/drive.appdatascope — we have no access to any other Drive files. - You can disconnect Google Drive at any time from the Data Management screen, which clears all locally stored tokens.
- Deleting backups from Drive must be done through the Google Drive app or settings, as the appDataFolder is controlled by Google.
AI chat feature
The "Ask AI" button in the transaction entry screen is an optional feature. When you use it:
- Your in-progress transaction data (amount, account names, category names, date) and the conversation so far are sent to our Supabase Edge Function.
- The Edge Function forwards this to Anthropic's Claude API to generate the next response. The API key is held server-side and is never embedded in the app.
- Conversation data is processed in memory only and is not stored by Wealth Bites or Anthropic beyond Anthropic's standard API data handling policies.
- The AI assistant is purely optional. All transaction entry can be completed without it using the standard deterministic chat flow.
- We recommend you do not include sensitive personal information (such as account numbers, PINs, or passwords) in chat messages.
Anthropic's data handling is governed by their Privacy Policy and API usage terms.
Security
- Encryption in transit. All communication between the app and our servers uses TLS (HTTPS). We never transmit data over unencrypted connections.
- Row-Level Security. Your financial data in Supabase is protected by PostgreSQL Row-Level Security policies. Database queries are scoped to your household ID — no query from one user can return another user's data.
- Credential storage. Authentication session tokens are stored in your device's encrypted secure store (iOS Keychain / Android Keystore), not in unencrypted storage.
- Biometric authentication. If you enable biometric login, your credentials are verified locally using Face ID or Touch ID. Biometric data never leaves your device.
- No service-role key in the client. The Supabase service-role key (which would bypass Row-Level Security) is never included in the app binary.
No system is perfectly secure. If you discover a security vulnerability, please contact us at jeemurali.work@gmail.com before public disclosure so we can address it promptly.
Data retention
Your financial data is retained in your Supabase database for as long as your account is active. If you delete your account:
- All your data (transactions, accounts, portfolio, goals, categories) is deleted from our database.
- Supabase may retain encrypted backups for up to 30 days in accordance with their data handling practices.
- Google Drive backups you created are stored in your Google account and persist until you delete them through Google's interface.
- Device-stored data (secure session tokens, biometric preferences) is cleared when you sign out.
To request account deletion, contact us at jeemurali.work@gmail.com. We will process deletion requests within 30 days.
Your rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access. Request a copy of the personal data we hold about you.
- Correction. Correct inaccurate data — most data can be edited directly in the app.
- Deletion. Request deletion of your account and all associated data.
- Export. Export your data as a CSV or JSON file using the Data Management screen in the app.
- Portability. Receive your data in a machine-readable format for transfer to another service.
- Objection. Object to processing of your data in certain circumstances.
To exercise any of these rights, contact us at jeemurali.work@gmail.com. We will respond within 30 days. If you are in the EU/EEA, you also have the right to lodge a complaint with your local supervisory authority.
Children's privacy
Wealth Bites is not directed at children under 13 (or under 16 in the EU/EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you via email or an in-app notice.
Continued use of the app after changes take effect constitutes acceptance of the updated policy.
Contact us
If you have any questions about this privacy policy or how we handle your data, please contact us: