Privacy Policy
Last Updated: November 15, 2025
Effective Date: November 15, 2025
Introduction
Cream ("we," "our," or "us") operates the Cream mobile application (the "App"), a Flutter-based finance tracking application available on iOS and Android platforms. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.
App Information:
- Platform: Built with Flutter framework (Dart programming language)
- Supported Platforms: iOS and Android
- Architecture: Local-first, offline-capable application
- Data Storage: All data stored locally on your device
By using our App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not use our App.
Information We Collect
Personal Information
We do not collect personally identifiable information from users. The Cream app is designed to work completely offline, and we do not require user registration, email addresses, names, phone numbers, or any other personal information to use the app.
Automatically Collected Information
The App may collect certain information automatically for app functionality and support purposes. All information is collected locally and is not transmitted to external servers unless explicitly stated below:
- Device Information: Basic device information such as device model, operating system version (iOS/Android), and app version. This information is collected using Flutter's
device_info_plus package and package_info_plus package for debugging and support purposes only. This information is stored locally and is not transmitted to external servers.
- App Version Information: App version number and build number are collected locally for support and debugging purposes. This information is included in support requests if you choose to contact us through the app.
- Platform-Specific Information:
- iOS: Device model, iOS version, system version
- Android: Device model, Android version, SDK version
This information is collected locally only and used for technical support.
- Usage Data: Usage patterns and interaction data may be collected locally within the app for debugging purposes in development mode only. This data is not shared with third parties and is only used for app improvement and bug fixing.
Note: All automatically collected information remains on your device and is never transmitted to our servers or third parties, except as explicitly disclosed in the Third-Party Services section below.
Financial Data
All financial data you enter into the App is stored locally on your device only. This includes:
- Transactions: Manual income and expense entries
- Budget Items: Recurring monthly income and expenses
- Subscriptions: Recurring subscription services and costs
- Financial Goals: Savings goals, target amounts, and progress tracking
- Monthly Summaries: Automated financial summaries and analytics
- User Profile (Optional): Optional demographic information (life stage, age range, household type) used only for personalized financial guidance within the app
All financial data:
- Is never transmitted to our servers
- Is never shared with third parties
- Remains under your complete control
- Can be exported by you at any time in CSV or JSON format
Third-Party Services and SDKs
The App uses the following third-party services and SDKs. We have carefully selected these services to minimize data collection while maintaining app functionality.
Google Mobile Ads (AdMob)
The App includes Google Mobile Ads (AdMob) SDK via the google_mobile_ads Flutter package. This SDK is only active when ad features are enabled by the user in app settings.
Information that may be collected by AdMob when ads are enabled:
- Device identifiers (such as advertising IDs)
- IP addresses
- Location information (if enabled on your device)
- App interaction data related to ads
- Device information (model, OS version)
AdMob Privacy:
- AdMob's use of information is governed by Google's Privacy Policy
- You can manage your advertising preferences through your device settings or Google's Ad Settings
- You can reset your advertising ID at any time through your device settings
Important: Ad features are opt-in only and can be disabled at any time in the app settings. When ad features are disabled, the AdMob SDK is not initialized and no ad-related data collection occurs.
Google Fonts
The App uses Google Fonts via the google_fonts Flutter package to provide consistent typography. When fonts are loaded, Google may collect:
- IP address (for font delivery)
- User agent information
- Referrer information
This data collection is governed by Google's Privacy Policy. Fonts are typically cached locally after first load to minimize subsequent requests.
Other Third-Party Packages
The App uses the following Flutter packages that operate entirely locally and do not transmit data:
- sqflite: Local SQLite database (no data transmission)
- shared_preferences: Local key-value storage (no data transmission)
- flutter_secure_storage: Local secure storage for sensitive data (no data transmission)
- local_auth: Biometric authentication (processed locally, no data transmission)
- path_provider: Local file system access (no data transmission)
- device_info_plus: Device information (collected locally only, as described above)
- package_info_plus: App version information (collected locally only, as described above)
All of these packages operate entirely on your device and do not transmit any data to external servers.
How We Use Information
We use the limited information we collect for the following purposes:
- App Functionality: To provide, maintain, and improve the App's features and performance
- Debugging and Support: To diagnose technical issues and provide user support
- Legal Compliance: To comply with legal obligations and protect our rights
Data Storage and Security
Local Storage
- All financial data is stored locally on your device using SQLite database
- No data is transmitted to external servers
- Data is encrypted at rest on your device using standard platform encryption
Security Measures
We implement appropriate technical and organizational measures to protect your data, following Flutter and mobile app security best practices:
Data Storage Security:
- Local-only data storage using SQLite database (via
sqflite package)
- Device-level encryption at rest (provided by iOS/Android platform)
- Secure storage for sensitive data using
flutter_secure_storage package
- Platform-specific secure storage:
- iOS: Keychain Services for secure credential storage
- Android: EncryptedSharedPreferences using Android Keystore
Authentication Security:
- Optional PIN lock with configurable length
- Optional biometric authentication (Face ID, Touch ID, Fingerprint) via
local_auth package
- Biometric data is processed locally and never stored or transmitted
- PIN storage uses platform secure storage (Keychain/Keystore)
- Failed authentication attempts are logged locally only
Network Security:
- No external data transmission for financial data
- No cloud synchronization or backup services
- HTTPS used for any external requests (fonts, ads when enabled)
- Certificate pinning not implemented (not required for local-only app)
Code Security:
- Built with Flutter framework following security best practices
- No obfuscation of financial data (data remains readable for export)
- Secure coding practices to prevent common vulnerabilities
Platform-Specific Security:
- iOS: App Sandbox restrictions, Keychain Services, App Transport Security
- Android: Android Keystore, App Sandbox, Secure Random number generation
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security. We recommend that you:
- Keep your device's operating system updated
- Use a strong PIN or biometric authentication
- Keep your device physically secure
- Regularly export and backup your data
Your Rights
Access and Control
You have the following rights regarding your data:
- Access: View all your data directly within the App
- Export: Export your data to CSV or JSON format at any time through the Settings screen
- Deletion: Delete individual items or all data at any time through the App's settings
- Control: Complete control over what data you enter and store
- Profile Management: Update or delete optional user profile information at any time
- App Lock: Enable or disable app lock (PIN/biometric) at any time
Data Retention
- Data retention settings can be configured in the App's settings
- You can choose how long to retain your financial data
- Data is automatically cleaned up according to your preferences
Opt-Out Options
- Ads: Disable ad features at any time in app settings
- Analytics: Local analytics are only active in debug mode and can be disabled
Children's Privacy
Our App is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us so we can delete such information.
If you become aware that a child under 13 has provided us with personal information, please contact us at creamfinanceapp@gmail.com.
California Privacy Rights
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
If you are a California resident, you have the following rights:
- Right to Know: You have the right to know what personal information we collect, use, disclose, and sell
- Right to Delete: You have the right to request deletion of your personal information
- Right to Opt-Out: You have the right to opt-out of the sale of personal information (we do not sell personal information)
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Note: Since we do not collect personal information from users, most CCPA/CPRA provisions do not apply. However, we provide transparency about our data practices and respect all user privacy rights.
California Online Privacy Protection Act (CalOPPA)
We comply with CalOPPA requirements:
- We do not track users across websites or apps
- We do not collect personally identifiable information
- We provide clear privacy policy disclosures
- Users can contact us to request information about data practices
General Data Protection Regulation (GDPR)
If you are located in the European Economic Area (EEA), you have certain data protection rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data
- Right to Restrict Processing: Request restriction of data processing
- Right to Data Portability: Request transfer of your data
- Right to Object: Object to our processing of your data
Note: Since we do not collect personal information from users and store all data locally on your device, GDPR compliance is ensured by design. Your data never leaves your device unless you explicitly export it.
International Data Transfers
Since all data is stored locally on your device and not transmitted to external servers, there are no international data transfers. Your data remains on your device, regardless of your location.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy in the App's About section
- Updating the "Last Updated" date at the top of this Privacy Policy
- For material changes, we may provide additional notice
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted.
Contact Us
Consent
By using our App, you consent to our Privacy Policy and agree to its terms.
Legal Basis for Processing (GDPR)
For users in the EEA, our legal basis for processing any data is:
- Consent: You provide explicit consent when using the App
- Legitimate Interests: To provide and improve app functionality
- Legal Obligation: To comply with applicable laws
Data Processing Information
- Data Controller: Cream App Development Team
- Data Protection Officer: Available via creamfinanceapp@gmail.com
- Processing Purposes: App functionality, user support, technical maintenance, debugging
- Data Categories:
- Financial Data (stored locally only):
- Transactions (income and expense entries)
- Budget items (recurring monthly income and expenses)
- Subscriptions (recurring subscription services and costs)
- Financial goals (savings goals, target amounts, progress tracking)
- Monthly summaries (automated financial summaries and analytics)
- User Profile Data (optional, stored locally only):
- Life stage information
- Age range
- Household type
- Used solely for in-app personalization and financial guidance
- App Settings and Preferences (stored locally only):
- Theme preferences (light/dark mode)
- Date format preferences
- Currency preferences
- App lock settings (PIN/biometric configuration)
- Ad preferences (enabled/disabled)
- Data retention settings
- Technical Data (stored locally only):
- Device information (model, OS version) - for debugging and support
- App version information - for support purposes
- Usage patterns - debug mode only, not shared
- Data Recipients: None (data stored locally only)
- Data Retention:
- Financial data: As configured by user in app settings
- App settings: Retained until app uninstallation or user deletion
- Technical data: Retained locally only, not shared
- Data Location: All data is stored locally on your device. No data is stored on external servers.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you believe your data protection rights have been violated.
Summary
Key Privacy Points:
- We do not collect personal information - No registration, emails, names, or phone numbers required
- All your financial data stays on your device - Transactions, budgets, subscriptions, goals, and summaries are stored locally only
- Optional user profile data is stored locally only - Used solely for in-app personalization
- No data is transmitted to external servers - Your financial data never leaves your device
- Complete user control over data - Export (CSV/JSON), delete, or modify at any time
- GDPR, CCPA, CPRA, and CalOPPA compliant - Meets all major privacy regulations
- Ad features are opt-in only - Can be disabled at any time in settings
- Full transparency about data practices - Clear disclosure of all data handling
- Secure local storage - Device-level encryption, optional PIN/biometric lock
- Built with Flutter - Modern, secure framework following industry best practices
- Third-party SDKs disclosed - Clear information about all external services used
Cream - Simple, Private, Offline Finance Manager
This Privacy Policy is designed to be transparent and user-friendly. If you have any questions or concerns, please don't hesitate to contact us.