Crumb

On this page

  1. 1. Who we are
  2. 2. Scope of this policy
  3. 3. Data we collect
  4. 4. How we use it
  5. 5. Lawful bases
  6. 6. How financial data is handled
  7. 7. Security
  8. 8. Who we share data with
  9. 9. International transfers
  10. 10. Retention & deletion
  11. 11. Your rights
  12. 12. Cookies & local storage
  13. 13. Analytics
  14. 14. Age requirement
  15. 15. Automated decision-making
  16. 16. Data breaches
  17. 17. Changes to this policy
  18. 18. Contact us
English | العربية

Legal

Privacy Policy

Version 1.13 Effective 11 September 2026 Last updated 11 September 2026

This policy explains what personal and financial data Crumb collects, why we collect it, who we share it with, how long we keep it, and the choices and rights you have over it. Crumb is currently in closed early access; where a feature described here — such as self-service account deletion — is not yet available, this policy says so plainly.

1. Who we are

Crumb ("Crumb", "we", "us", "our") is a financial-life tracking application at crumbmoney.com and app.crumbmoney.com, operated by Athena Private Management FZCO, part of the Athena Holdings group, registered at Suite 4333, Dubai Silicon Oasis, Dubai, United Arab Emirates, trade licence number 86166, issued by the Dubai Integrated Economic Zones Authority (DIEZ). Athena Private Management FZCO is the data controller for the personal data described in this policy.

For any privacy question, contact privacy@crumbmoney.com.

2. Scope of this policy

This policy covers two related but separate surfaces:

  • The Crumb application (app.crumbmoney.com) — the authenticated product where you track expenses, Payment Plans and your own savings and investments. It requires an account and is never indexed by search engines.
  • The Crumb marketing site (crumbmoney.com) — the public page you're reading this from, including the early-access request form. It's intentionally public and indexable.

Where the two collect or handle data differently, this policy says so explicitly rather than treating them as one system.

3. Data we collect

3.1 If you request early access

If you request early access to Crumb through this website, we collect your name, email address, a short description of your use case, any product areas you say you're interested in, whether you'd like to receive occasional product updates, and basic attribution information such as how you found us and your browser's user-agent string. We do not collect your IP address as part of this form.

3.2 When you create an account

When you're invited to Crumb and set up your account: your email address, and your name, which you can edit as a first name, last name, or a combined display name. You can also choose an account time zone so dates, reminders and monthly views follow your local calendar day. We store the time zone you select, not your precise location, and we do not infer it from your IP address. We do not currently collect a phone number, avatar image, or postal address as part of your profile. You can change the email address on your account later — see Section 3.3.

3.3 Authentication & security

Your password is never seen or stored by Crumb's own application code — it's managed entirely by Supabase Auth. We hold a session (kept in a browser cookie) that proves you're signed in.

You can optionally turn on two-factor authentication using an authenticator app. Crumb lets you enrol more than one authenticator, so you can keep a backup — each one is added by scanning a QR code or entering a setup key. Just like your password, the authenticator itself is never seen or stored by Crumb's own application code — it's managed entirely by Supabase Auth. Removing an authenticator requires a stronger, more recent proof that it's really you (a fresh two-factor code, or, where that's not available, a recently-entered password) before the removal is allowed.

When you enter a two-factor code, our authentication provider records that the check happened, whether it succeeded, and the internet (IP) address it came from, so that repeated failed attempts can be detected and rate-limited. That record is kept by the provider as part of running the sign-in check itself; it's not shown to you inside the app, and we don't use it for anything else. We'd rather be precise about how this fits with the rest of this section: it's provider-side account-security processing, of the same kind that already keeps your password itself outside our own code, rather than something Crumb's application logs against your account activity.

You can change the email address on your account at any time from Settings → Profile. Starting a change requires re-entering your current password, and — if you have two-factor authentication turned on and your session isn't already verified at that level — a two-factor code as well. Once a change is started, we send a confirmation link to both your old and new address, and the change only takes effect once you've opened the link at both — so either inbox can catch and stop a change that wasn't genuinely yours. You can cancel a change you've started before both confirmations arrive. We limit how many change attempts an account can make in a given period, so this current-password check can't be used to test whether a stolen password actually works.

3.4 Financial & expense data

The data you enter to track your spending: expense names, amounts, currencies, categories, due and paid dates, notes, and the payment methods you set up. You can optionally record a quantity and unit price behind an expense total. If the amount you actually paid differs from the amount expected, you can also record a short reason and optional note explaining the difference. If you use multiple currencies, we also store the exchange rate we used at the time, for accurate reporting.

A payment method is always a label you choose (e.g. "Visa •••• 4242"). You can optionally add one short reference detail to help you tell your payment methods apart: the last four digits of a card or bank account, the last four characters of a crypto wallet address, or the email address associated with a PayPal account. These details are optional — you decide whether to enter them, and you can change or remove them at any time. We never store a full card number, bank account number or IBAN, a full wallet address, a recovery phrase or private key, or any password, token, or login credential for a third-party payment account. We never process card payments and never connect to your payment accounts.

If you use Payment Plans to track a structured, multi-payment obligation — for example, a "Buy Now Pay Later" purchase or an instalment plan you've agreed with a retailer or lender — we store what you enter to describe and track it: a name, an optional plan type and description, the currency and total starting amount, a start date and optional final due date, an optional category and preferred payment method (from the same list described above), and its current status (active, paused, paid off, or archived). If you choose to record a provider name (for example, "Klarna" or "Affirm"), that's a label you type in — like a payment method label, it never connects Crumb to the actual provider, and we never authenticate with, share your data with, or receive any data from a real BNPL or lending provider on your behalf. You can optionally set a payment schedule (a regular instalment amount and how often it's due, or leave it open-ended with no fixed schedule) and one or more interest or fee rules of your own choosing (a fixed recurring charge, or a percentage rate you configure) — Crumb calculates the resulting charge and payment entries purely from the figures you provide; it does not fetch, verify, or independently determine a real interest rate or fee from any external provider, and never extends credit, assesses affordability, or makes a lending decision of any kind. You can also link specific expenses, or an entire recurring series, to a plan so its payments are tracked together. All of this is stored and protected exactly like the rest of your financial data (see Section 6) — Payment Plans introduces no new access model or sharing of its own. Deleting a Payment Plan does work a little differently from deleting an ordinary expense, though; see Section 10 for exactly what that means.

If you use Savings & Investments, we store the details you enter: account and institution labels, account type, currency, an optional reference of no more than four letters or digits, dated starting and updated values, deposits, withdrawals, notes, optional goals and dates, and regular-deposit schedules. We also keep corrections, removal markers, schedule changes, links between a recorded deposit and its planned date, and submission records used to prevent duplicate entries. Institution labels belong to your personal savings records and are separate from the Providers list used for expenses. Do not enter full account numbers, bank login details, recovery phrases or private keys.

3.5 Workspace & organisation data

The name of your organisation and any workspaces you create within it, who has access to them (your teammates' membership and role), and the country you select for your organisation when you first set it up. We use that country only to suggest a sensible starting set of payment methods for your region. You choose it explicitly during setup — we never infer it from your IP address, your connection, or anything else.

3.6 Device, session & technical data

See Section 12 for the full, itemised list of cookies and local-storage values the app and marketing site use. In short: a small number of strictly-necessary session cookies, plus a handful of on-device preference values (theme, workspace selection, list density) that never leave your browser as identifiable tracking data. We do not currently log your IP address against your account activity inside the app, and the device detail we do log is limited to the two narrow, disclosed exceptions below — we don't otherwise keep a general record of your device or browser tied to your account.

The first: when we send you a security notice (see Section 4.3), we read the browser and operating system the request came from — for example, "Chrome on macOS" — so that the email can tell you where the change was made from. It is used only to write that one message, it is not stored against your account, and we never use it to estimate your location. If we can't recognise it, the email simply says "Unknown device" rather than guessing.

The second: your sign-in activity list (Section 3.10) does store a more detailed, near-verbatim technical description of each session's browser, for as long as that session stays on the list. See Section 3.10 for exactly what that includes and how it differs from the short label described above.

3.7 Push notification data

If you turn on push notifications for a device in Settings, we store what's needed to deliver them to that specific device: a subscription address issued by your browser's own push service (a Google-, Mozilla- or Apple-operated address, depending on your browser — see Section 8), and two short cryptographic keys your browser generates for that subscription. We use those keys only to encrypt each notification before it's sent, so that the push service relaying it can never read its actual content — only your device can decrypt it. We also generate a short device label automatically from your browser's standard technical information (for example, "Chrome on macOS"), the same way we do for the account-security notices described above — this is never text you type in yourself.

We also store two settings of your own choosing: whether expense reminders should reach you by email, by push, or both, and how much detail a push notification is allowed to show — either a generic "Expense reminder" (the default) or a detailed message naming the expense and its amount. These are your preferences, not information about you, and you can change them at any time in Settings.

3.8 Notification inbox

When Crumb sends you an expense reminder, we also save it as an entry in your notification inbox — the bell menu inside the app — so you have a record of your reminders rather than only the email or push message itself, which is easy to miss or dismiss.

Each entry records which expense the reminder was about, the date that expense was due, how far ahead of the due date the reminder was triggered, when the entry was created, whether you've read it, and whether it has since been resolved because the expense was paid, skipped, moved to Trash, deleted, or rescheduled. It also stores an in-app link to that expense.

Whether an entry also stores any financial detail depends on the push-content setting described in Section 3.7. If you've chosen the detailed setting, the entry keeps a short snapshot of the expense's name together with its amount and currency, so your history still reads accurately later even if the expense has since been changed or deleted. If you've left the setting on its generic default, no expense name and no amount are stored in the entry at all — it simply reads "Expense reminder". The snapshot is decided once, when the entry is created, and is never filled in retrospectively if you change the setting afterwards.

Nothing else about the expense is kept in a notification entry: no notes, no provider, no payment method, no category, no workspace, and no other financial data. We store no more than the fields listed above for the purpose of running this inbox.

3.9 Security history

We keep a personal security history for your account — a record of security-relevant activity, currently covering: two-factor authentication being turned on, turned off, or an individual authenticator being added or removed; a two-factor code being entered incorrectly; your password being changed; other devices being signed out of your account; App Lock being turned on, off, or its timeout changed; a change to the email address on your account being requested, completed, or cancelled (see Section 3.3); and each step of an emergency account-recovery request (see Section 3.11). Each entry records only the type of event, a short human-readable description (for example, which authentication method was involved), and when it happened — for an email-change entry, that description never includes the email address itself, only that a change occurred. It never includes a raw IP address, your full browser/device string, a password, a two-factor secret, or any other credential or token.

This history is separate from, and additional to, the organisation-wide activity trail described in Section 6, which covers changes to your financial data and is visible to your organisation's administrators. Your personal security history is visible only to you.

3.10 Sign-in activity

Separately, we keep a short list of the browser sessions currently or recently signed in to your account, so you can review your own sign-in activity and, if you want to, sign other devices out. For each session we store the technical description your browser sends when it connects (a "user-agent" string — the same kind of information most websites can see, trimmed if it's unusually long), when we first saw that session, and roughly when it was last active. We'd rather be precise about this: it's more detailed than the short "Chrome on macOS"-style label used elsewhere in Crumb, such as in security-notice emails (Section 3.6) — it can include exact browser and operating-system version information. We don't separately log every individual sign-in — only this rolling per-session summary, and it's never used to estimate your location.

3.11 Emergency account recovery

If you've turned on two-factor authentication and lose access to every authenticator you've enrolled, Crumb offers a restricted, Crumb-owned recovery flow so you're not permanently locked out. It works differently from an ordinary password reset: it's only ever available from a session you're already signed in to, and it never accepts an email address as input — a recovery code is always sent to the email address already on your account, never one you type in.

Starting a recovery request sends a one-time code to your own account email, together with a separate confirmation email that also includes a link you — or, if you didn't request it, whoever actually controls the account — can use to cancel the request immediately. There is then a mandatory 24-hour security delay before recovery can proceed any further; this delay cannot be skipped or shortened, and if you abandon the request before this point it simply expires on its own without you needing to do anything. After the delay, continuing requires re-entering your current password together with the one-time code, which starts permanently removing every two-factor authenticator on your account. The moment we begin that removal, we sign every other device out of your account — even if the removal doesn't fully succeed on the first try — and once it does fully succeed, we sign your own current session out too, so this protection doesn't wait for the rest of recovery to finish. You're then required to set up a new authenticator before you can sign back in anywhere. If you get this far but don't finish setting up a replacement, your account deliberately stays in this protected, re-enrolment-required state rather than being silently restored to ordinary, unprotected access — and, unlike earlier stages, the request record itself is not deleted while it's in that state (see Section 10). You're never locked out, though: you can pick recovery back up at any time, from any device, simply by signing in again with your current password. We also send an email if the request is cancelled, and another once recovery is genuinely completed.

The one-time code itself is never stored in a form that could be read back — only a cryptographic hash of it, which can't be reversed into the original code, and which is cleared the moment the code is used or the request ends. We never log the code either. See Section 10 for how long a recovery request's own record is kept.

4. How we use it

4.1 Requesting early access

If you request early access, we use your email address to confirm and manage your request and to contact you about access to Crumb.

4.2 Creating and using your account

Once you have an account, we use your information to provide the core product — storing and displaying your expenses, categories, reports, and any Payment Plans you set up (see Section 3.4) — to authenticate you and keep your account secure, and to operate your organisation's workspaces and membership. We use your chosen time zone only to work out the local calendar day for date-based views, monthly figures, reminders and digest timing. It is not used to track where you are. A Payment Plan's figures also contribute to the same dashboard totals and overdue/upcoming views as an ordinary expense, and can generate the same optional reminders described in Section 4.3, if you choose to enable them for that plan.

We use your Savings & Investments records to show your manually recorded values, changes over time, goals and planned deposits. A planned deposit is not treated as money added until you record it as made. Linking an existing deposit to a planned date does not add it again. These records do not contribute to expense spending or the dashboard's Paid this month total, and do not generate shared expense notifications or email reminders. Figures are not bank-verified or live market prices, and changes after deposits and withdrawals are not an investment-return calculation.

4.3 Essential service communications

Crumb may send you essential communications related to your account:

  • Invitations and password-reset links — sent only when you or someone in your organisation requests them.
  • Security notices — telling you when something important to your account's security has changed: your password being changed; App Lock (the optional in-app PIN lock) being turned on, off, or its timeout changed; two-factor authentication being turned on or off, or an individual authenticator being added or removed; signing out everywhere, i.e. every device including the one you're using (see Section 4.11); each step of an emergency account-recovery request (see Section 3.11 and Section 4.12); and each step of a self-service email-address change (see Section 3.3 and Section 4.13). These include the time of the change and, for most of them, a short description of the browser and operating system it was made from (see Section 3.6).
  • Activity reminders and spending digests — which may include your name and relevant expense details, such as which payments are due, their amounts and dates.

Invitations, password resets, password-change notices, notices that an individual authenticator was added or removed, the notice sent when you sign out everywhere, every emergency-recovery notice, and every email-address-change confirmation cannot be turned off — they're sent only when the action they describe actually happens. App Lock notices, notices that two-factor authentication itself was turned on or off, activity reminders and spending digests can each be turned off in your notification settings.

4.4 Optional marketing communications

If you opt in — for example, by ticking the update box on the early-access form — we may send you occasional product updates. This is entirely separate from confirming a request you've made to us: leaving the box unticked never stops us responding to something you actively asked for, and you can withdraw your marketing consent at any time (see Section 11).

4.5 Support

To respond to support requests you send us.

4.6 Keeping the product working

Basic performance monitoring to keep the product reliable (see Section 13).

4.7 Push notifications

If you enable push notifications for a device, we use the technical values described in Section 3.7 to deliver notifications to that device. You can send yourself a test notification from Settings to confirm push is working, and you can choose whether individual expense due-date reminders reach you by email, by push, or by both. Weekly and monthly spending digests and account-security notices (Section 4.3) are not sent by push and remain email-only.

How much a push notification shows on your screen is your choice, using the content setting in Section 3.7. On the generic default it says only that an expense reminder is due, without naming the expense or its amount. On the detailed setting it names the expense and shows its amount. You can turn push notifications off, or remove a registered device entirely, at any time in Settings (see Section 10).

4.8 Your notification inbox

We use the entries described in Section 3.8 to show you a history of your expense reminders inside the app, to show how many are unread on the bell icon, and to let you mark an entry as read or mark everything as read. Opening an entry takes you to the expense it refers to.

The inbox is a separate record from the message itself. An email is delivered by our email provider and a push notification by your browser's push service (Section 8); the inbox entry lives in your Crumb account and stays there after the message itself is gone. Marking an entry as read reflects only what you did inside the app — it is not a receipt for the email or push notification, and we don't treat it as one.

Only you can see your own notification entries. Access is enforced by the same database-level row security that protects your expenses (Section 6), tied to your verified identity, so no other user — including other administrators in your organisation — can read your inbox through the product. If you use App Lock, your inbox is covered by it exactly as your expenses are: while the app is locked, its entries can't be read.

4.9 Two-factor authentication

If you turn on two-factor authentication, we use it — via Supabase Auth, which manages it exactly as it manages your password — to require a second proof of identity when you sign in. Removing an authenticator requires a stronger, more recent proof of identity first, so a stolen unlocked session alone isn't enough to turn your two-factor protection off.

4.10 Security history

We use the security history described in Section 3.9 to show you a record of security-relevant activity on your own account, in Settings → Security, so you can notice something you didn't expect. It's visible only to you — not to anyone else in your organisation, including administrators. Unlike your notification inbox (Section 4.8), you can view it even while App Lock is engaged, since it's purely informational and never reveals financial data.

4.11 Sign-in activity and signing out other devices

We use the session list described in Section 3.10 to show you your own recent sign-in activity in Settings → Security, and to let you sign out other devices, or sign out everywhere including your current device, if you don't recognise something or just want to be careful. Both options genuinely end those sessions — it isn't cosmetic — though not necessarily instantaneously: the session itself is revoked right away, but a request already in flight on the old session may still complete before its short-lived access token naturally expires shortly afterward. Signing out everywhere also sends you a confirmation email (see Section 4.3); signing out only your other devices doesn't, since your own session stays active and you're still looking at the result.

4.12 Emergency account recovery

We use the recovery process described in Section 3.11 solely to help you regain access to your account if you're locked out of two-factor authentication, and to keep that process itself secure. The mandatory delay, the password-and-code requirement, and the mandatory sign-out and re-enrolment on completion all exist so that a stolen device or a compromised email account alone can't be used to take over your account through this route.

4.13 Changing your email address

We use the confirmation process described in Section 3.3 to make sure a change to the email address on your account is genuinely something you asked for, not something done by someone who has only briefly gained access to your device or session. Re-entering your current password before a change can start means a stolen session alone isn't enough — the real password is needed too. Requiring a click from both the old and the new address before the change takes effect means that either inbox can catch and stop a change neither of you intended — from the account holder's side if the new address is wrong or unfamiliar, or from a shared/former device's side if the request wasn't made by you at all. The two-factor session requirement and the rate limit on attempts exist for the same reason: to keep the current-password check from becoming a way to test whether a stolen password actually works.

We do not sell your personal or financial data, and we do not use it for third-party advertising.

5. Lawful bases

Where a legal basis is required for our processing (for example, under UK/EU data protection law), we rely on:

  • Contract — processing needed to provide the Crumb service you've signed up to use.
  • Legitimate interests — keeping the product secure, reliable, and functioning correctly, and responding to and managing requests you send us, such as an early-access request.
  • Consent — for optional marketing communications, which are separate from the essential service communications described in Section 4 and which you can withdraw at any time (see Section 11).
  • Legal obligation — where we're required to retain or disclose information by law.

6. How financial data is handled

Crumb helps you track your financial life. It is not a bank, payment processor, accounting platform or investment adviser. We never move money or connect to your bank or investment accounts.

Your organisation's expenses and Payment Plans are isolated from other organisations at the database level. Access is tied to your verified identity and membership, not an organisation value supplied by your browser. Changes use controlled application functions and an organisation-scoped audit trail.

Savings & Investments uses a separate, personal access model. Other users, including your organisation's Super Admin and administrators, cannot read or change these records through Crumb. Access is checked against your own verified identity at the server and database layers and respects App Lock and two-factor sign-in requirements. These records and their changes are not written to the organisation's activity log or shared financial reports. This is access-controlled privacy within the product, not encryption that prevents Crumb or its infrastructure providers from accessing stored data.

Current limitation, stated plainly: expense and financial data is not currently encrypted with a key only you control (sometimes called client-side or "zero-knowledge" encryption). It is protected by the access controls described above and by our infrastructure providers' standard encryption (see Section 7). An additional, opt-in client-side encryption layer for particularly sensitive fields is planned but not yet built — this policy will be updated when it ships, and it will not replace the access controls described here, only add to them.

7. Security

We take reasonable, industry-standard measures to protect your data, including:

  • Encryption in transit (TLS) for all traffic to and from Crumb.
  • Encryption at rest for stored data, provided by our infrastructure providers.
  • Database-level access controls that restrict organisation records to authorised members and personal savings and investment records to their owner.
  • Payment method details limited to a label you choose plus, at most, one short optional reference detail — the last four digits of a card or account, the last four characters of a wallet address, or a PayPal account email. Never a full card number, account number, IBAN, wallet address, recovery phrase, or any credential for a third-party payment account.
  • Passwords hashed and managed by our authentication provider, never stored or handled directly by Crumb's own code.

We describe this as "encrypted and secure by design" deliberately, and not as "end-to-end encrypted," "zero-knowledge," or bank-grade/military-grade security — those are specific technical claims we don't currently meet, and we won't use them until we genuinely do. No system is perfectly secure, and we can't guarantee absolute security of information transmitted over the internet.

8. Who we share data with

We share data only with service providers who help us run Crumb, under terms that require them to protect it. We do not sell your data or share it for third-party advertising.

ProviderWhat it's forWhat it processes
SupabaseDatabase, authentication, scheduled jobsAccount, organisation and financial data described in Section 3, including personal savings and investment records
VercelHosting the application and this websiteStandard hosting/request data; anonymised, URL-stripped performance timing (see Section 13)
ResendEmail deliveryRecipient email address and email content
Frankfurter (FX rates)Currency conversion reference ratesCurrency codes and dates only — never your name, expenses, or any other personal data
Google (Firebase Cloud Messaging)Relays push notifications to Chrome, Edge and other Chromium-based browsers, and Android — only for a device where you've turned push notifications onYour device's push subscription address and an encrypted notification payload it cannot decrypt — never the plaintext content
Mozilla (Push Service)Relays push notifications to Firefox — only for a device where you've turned push notifications onSame as above
Apple (Push Notification service)Relays push notifications to Safari and iOS/iPadOS — only for a device where you've turned push notifications onSame as above

We may also disclose information where required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets — in which case we'd ensure your data continues to be protected under materially similar terms.

9. International transfers

Athena Private Management FZCO is based in the United Arab Emirates. We use infrastructure and service providers that may process, store or transmit personal data in countries outside the UAE and outside the country in which you live.

Our providers operate infrastructure across multiple regions, including locations in Europe, the United Kingdom and the United States. Some services may also use globally distributed infrastructure to provide application hosting, security, content delivery, email delivery and related services.

Where personal data is transferred internationally, we take appropriate steps intended to ensure that it remains protected in accordance with applicable data protection laws and that our service providers maintain appropriate safeguards for the information they process on our behalf.

10. Retention & deletion

We keep your data for as long as your account is active, so the product can keep working for you. Deleted expenses go to a Trash first and can be permanently removed from there.

Archiving a savings or investment account hides it from active totals and stops future deposit expectations; it does not delete its records. Restoring it does not automatically resume its deposit schedules. Correcting or removing a financial entry keeps the original version so the history can be explained and figures recalculated. These records, including duplicate-prevention submission records, remain while your Crumb account is active. There is no self-service permanent deletion of a savings account or its entry history in this version. To request deletion, contact privacy@crumbmoney.com through the process below.

Payment Plans (see Section 3.4) can be deleted, restored, or permanently deleted. Deleting a Payment Plan moves it to a Recently Deleted view rather than removing it straight away — the same Trash-first pattern as expenses, above. We don't currently run an automatic job that removes a plan from Recently Deleted; it stays there until you restore it or permanently delete it yourself. Restoring a plan simply brings it back to active, unchanged. Permanently deleting a plan is irreversible, and the app asks you to type the plan's name to confirm before it proceeds. It deletes the plan itself and its own schedule, interest rules, and history — but it never deletes the expenses or recorded payments you'd linked to it. Those remain fully intact in your ledger, simply no longer connected to the now-deleted plan.

A push notification subscription (Section 3.7) is kept until you remove that device in Settings, which deletes it immediately, or until your browser or its push service tells us the subscription is no longer valid, at which point we stop sending to it. Turning push notifications off for a device without removing it pauses delivery without deleting the subscription, so you can turn it back on later without registering the device again. Deleting your account removes every push subscription associated with it.

A notification inbox entry (Section 3.8) is kept for as long as your account is active. The inbox shows all of your unread entries, plus roughly the last 90 days of read or resolved history; older entries stop being shown to you. We'd rather be plain about what that 90 days is and isn't: it's a limit on what the inbox displays, not a deletion schedule. We don't currently run an automatic job that removes older entries from our database, so an entry stays until your account is deleted, which removes every entry belonging to it.

A notification entry deliberately outlives the expense it refers to. When an expense is paid, skipped, moved to Trash, or deleted, the entry is marked as resolved and stops counting towards your unread total, but it isn't erased — permanently deleting an expense doesn't erase the reminder history that mentioned it. An entry never gains any new information about that expense after it was created.

An emergency account-recovery request (Section 3.11) is kept only for as long as it's useful for the security purpose it exists for. A request that's completed, cancelled, or abandoned before your old authenticator has been removed is deleted automatically within roughly 30 days of reaching that state — our cleanup sweep runs once a day, so in practice this can occasionally take a day or so longer. A request abandoned after your old authenticator has already been removed is different: at that point your account is deliberately kept in a protected, re-enrolment-required state, and we do not auto-expire or delete that record while it's in this state, because doing so would remove the only thing still requiring you to finish setting up a new authenticator before regaining full access. You are never locked out, though — you can resume and finish setting up a new authenticator at any time, from any device, simply by signing in again with your current password (see Section 3.11). That record is cleared once you actually finish setting up the new authenticator, or if you delete your account. The one-time code itself is never stored in a form that could be read back — see Section 3.11.

Your personal security history (Section 3.9) is kept for as long as your account is active. We don't currently run an automatic job that removes older entries, so — like your notification inbox above — it isn't on a rolling deletion schedule. Deleting your account removes your entire security history.

Your sign-in activity list (Section 3.10) is kept the same way: for as long as your account is active, with no automatic removal of old or no-longer-valid sessions from the list, and removed entirely when your account is deleted.

Current limitation, stated plainly: Crumb is in closed early access and does not yet have a self-service "delete my account" or "delete my organisation" feature. If you'd like your account or organisation's data deleted, contact privacy@crumbmoney.com and we will action this manually. A self-service deletion feature is planned for a future release, and this policy will be updated to describe it once it ships.

11. Your rights

Under UAE data protection law, you have rights in relation to your personal data. These include the right to:

  • Request information about the personal data we process about you and how it is used.
  • Correct inaccurate or incomplete personal data. You can also update certain information yourself through Crumb's Settings.
  • Request deletion of your personal data in circumstances provided by law, subject to legal, regulatory and other permitted retention requirements.
  • Request that we restrict certain processing in circumstances provided by law.
  • Object to certain processing, including the use of your personal data for direct marketing.
  • Receive certain personal data in a structured, machine-readable format where the requirements for data portability are met.
  • Withdraw your consent at any time where we rely on consent to process your personal data. This does not affect processing that was lawful before consent was withdrawn.
  • Object to certain decisions based solely on automated processing where those decisions have legal or similarly significant effects on you.

You may also have additional rights under the laws that apply where you live.

To exercise any of these rights, contact privacy@crumbmoney.com. We may need to verify your identity before completing a request, and some rights may be subject to exceptions or limitations under applicable law.

Complaints

If you have a concern about how we handle your personal data, please contact us first so that we can investigate it.

You also have the right to submit a complaint to the UAE Data Office, the federal authority responsible for overseeing the UAE's personal data protection framework. Depending on where you live, you may also have the right to complain to your local data protection or privacy regulator.

12. Cookies & local storage

This marketing site itself does not set any cookies or local storage. The application, once you're signed in, uses the following. We distinguish below which are cookies (sent to our servers with each request) and which are local storage (kept only on your device, never transmitted to us at all).

Cookies

NameSet byPurposeCategory
sb-*SupabaseKeeps you signed inStrictly necessary
crumb-workspace-scopeCrumbRemembers your selected workspacePreference
crumb-pwa-themeCrumbRemembers light/dark modePreference
crumb-expenses-view-modeCrumbRemembers your preferred list layoutPreference

Local storage

Unlike cookies, these never leave your device — we cannot read them and they are never sent to our servers.

NamePurposeCategory
crumb-themeLight/dark mode, read directly by the interface on loadPreference
crumb-app-lock-last-activityPowers the optional in-app PIN lock's inactivity timerFunctional
crumb-app-lock-signoutSignals a forced App Lock sign-out to your other open tabsFunctional
crumb-app-lock-settingsYour App Lock configuration (e.g. timeout length)Functional
crumb-install-dismissed-atRemembers if you've dismissed the "install app" promptPreference
crumb.webpush.promptShownRemembers whether you've already been asked to allow push notifications on this browser, so we don't ask again unnecessarilyPreference

None of the above are used for advertising or cross-site tracking. None store a password, access token, or full payment card number.

13. Analytics

We use Vercel Speed Insights to understand how quickly the product loads for real users. It measures performance timing only — not what you click or type — and the page address it records has any query parameters and identifying fragments removed before it's sent. We do not use behavioural analytics, advertising trackers, or session-replay tools.

14. Age requirement

Crumb is intended for adults managing their own or their household's/business's finances. You must be at least 18 years old to create a Crumb account.

15. Automated decision-making

Crumb does not use your data to make automated decisions that produce legal or similarly significant effects about you, and we do not use profiling or machine-learning-based scoring anywhere in the product today.

16. Data breaches

If a data breach occurs that's likely to put your rights and freedoms at risk, we'll notify affected users and, where legally required, the relevant regulator, without undue delay.

17. Changes to this policy

We review this policy whenever a product change might materially affect it, and we version every update. You can see the full history of changes in our changelog. Material changes that affect how your existing data is used will be communicated to you directly, not just posted here silently.

18. Contact us

Questions about this policy or your data: privacy@crumbmoney.com.

Terms of Service Changelog Back to Crumb

© 2026 Crumb. All rights reserved.

Privacy Terms Status