Privacy Policy
1. Scope and contact
This policy explains how AuSpace collects, uses, shares, retains and protects personal data and how you may exercise your rights. Contact privacy@auspace.xyz. Address: Hong Kong.
2. Data we process
- Account data: email, password hash, verification records, display name and avatar.
- Google/Apple sign-in: provider subject, email and verification status, name, avatar, and encrypted access or refresh credentials where needed.
- Security/device data: IP, User-Agent, sessions, CSRF identifiers, login times and security logs.
- User content: gold ledgers, transaction entries, alert rules, notifications and Push subscription endpoints.
- Subscriptions: plan, checkout reference, Waffo buyer identity, order ID, status and billing period. We do not directly store full card details.
- Analytics: pages, referrer, device, limited events and, with consent, a random account identifier, language and Free/Pro status.
3. Purposes and legal bases
We process data to create and secure accounts, perform requested features and subscriptions, deliver necessary messages, support refunds, prevent abuse, comply with law and improve the product. Depending on location, bases include contract performance, legitimate interests, legal obligations and consent. Non-essential analytics begins only after consent where required, and consent may be withdrawn.
4. Providers and transfers
We disclose data as needed to Google and Apple for sign-in; Resend for verification and alert email; Waffo Pancake, our merchant of record, for checkout, payment, tax, receipts, subscriptions and refunds; Web Push providers for delivery; self-hosted Umami for consented analytics; and the configured AI/VL provider for image recognition you request. Providers may process data in other countries under contracts and applicable transfer safeguards.
5. Image recognition
When you request receipt recognition, the image is sent to the configured AI/VL provider to extract transaction fields. AuSpace does not retain the raw image as a ledger attachment. Images may contain names, addresses, order numbers or payment information; redact anything unnecessary and do not upload third-party data without authority.
7. Retention
Account data generally remains until deletion; active sessions last up to about 30 days. Verification and security records remain as needed to prevent abuse. User content remains until deleted or the account closes. Subscription, refund, tax and dispute records remain as required for law, accounting and fraud prevention. Legal acceptance records remain long enough after the contract to evidence consent and resolve disputes. We then delete, aggregate or de-identify data.
8. Your rights
Depending on local law, you may request access, correction, portability, deletion, restriction or objection, withdraw consent and complain to a regulator. Account settings support profile changes, provider connections, alerts, Push, subscription management and deletion. Send other requests to privacy@auspace.xyz; reasonable identity verification may be required.
9. Security and children
We use transport encryption, password hashing, token encryption, access controls and security logging, but no system is perfectly secure. The service is for users able to contract and is not designed for children. If we learn that unauthorised child data is present, we will delete it, restrict the account and arrange any required refund.
10. Changes
We publish new versions and effective dates here. Material changes affecting rights, subscriptions or consented uses will receive prominent product or email notice, with renewed choice where law requires.