BudgetDice, Privacy Policy
Last updated: 4 October 2026
BudgetDice keeps the financial sheet of a board game session. There is no account to create, no ads and no analytics. As long as you play on your own, the app keeps your sheet on your phone. The moment you join a game table, what you fill in on your sheet is stored in Google Firebase so the other players at that table can see it. The app never asks for your email address, phone number, location, contacts or photos. It does rely on two Firebase services that handle technical data: the anonymous sign-in, which sees your IP address, and App Check, which checks that the app is genuine. Both are described below.
Who is responsible
BudgetDice (com.ontagonal.budgetdice, iOS and Android) is made by
Timotei Petre, an independent developer based in Romania, acting as
data controller. You can reach me at
[email protected] for anything in this policy.
The app is an unofficial companion. It is not affiliated with, endorsed by, or connected to the owner of the Cashflow board game.
There is no account
You never create an account, and you never give a password, an email address or a phone number. When the app starts, it signs in anonymously through Firebase Authentication, so it can talk to its database: your identity is a random identifier tied to the installation, not to you. On iOS that identifier is kept in the system keychain, so it can survive uninstalling the app and reappear if you install it again. On Android it goes away with the app, unless your phone's backup brings it back when you reinstall.
Firebase Authentication runs only from Google's data centers in the United States. Like any sign-in service, it uses your IP address and your device's user agent to keep the service secure and to prevent abuse. Google keeps the logged IP addresses for a few weeks.
What is stored when you join a table
Only when you join a game table, and only for that table, the following is written
to Google Cloud Firestore, in the europe-central2 region
(Warsaw, European Union):
- the code of the game table;
- the display name you type when you sit down at it, which can be any nickname you like, it does not have to be your real name;
- the figures on your financial sheet: salary, expenses, assets, liabilities and cash;
- the log of your operations, including the labels you type for them;
- the cards players add to that table's catalog.
That is the whole list. Anything you type into those fields is up to you, so please do not put personal details in a display name or in an operation label.
Who can see it
Only the players at the same table. Of a neighbour's sheet, each player sees only what the app's rules allow. Google acts as a processor for this data, through Firebase, and does not use it for advertising. There is no server of mine in the picture.
What stays on your phone
The app keeps these on your phone and does not send them anywhere:
- the sheet and the log of the game you are playing right now, kept so they survive closing the app, including when you play without a table;
- the cards you add while playing without a table;
- the profession cards you have applied, remembered for your next games.
Uninstalling the app deletes them. If your phone's own backup is turned on, iCloud on iPhone or Google on Android, the system can include them in that backup like the data of your other apps, and Android can bring them back when you reinstall the app.
Firebase App Check
The app uses Firebase App Check, which checks that requests to the database come from the genuine app rather than from a script. To do that, it relies on the attestation service of each platform:
- on iPhone, Apple's App Attest: Apple's servers certify that a key created on your phone belongs to a genuine copy of the app;
- on Android, Google Play Integrity: Google Play services send Google the app's details, its Play license status and an attestation from the device, and Google answers whether the app and the device are genuine.
App Check does not keep this attestation material, which Apple and Google handle under their own terms. What the app gets back is a token, valid for at most seven days.
What the app does not have
No analytics, no crash reporting, no advertising, no cookies, no third-party tracking of any kind.
Why, and on what legal basis
- Storing your table data and showing it to the players at your table: that is the service you ask for when you join a table (Article 6(1)(b) GDPR).
- The anonymous sign-in and App Check, which protect the database from abuse: my legitimate interest in keeping the service secure (Article 6(1)(f)).
None of this relies on your consent.
Who handles the data
- Google, through Firebase, as my processor: it stores table data in the European Union and runs the anonymous sign-in from the United States.
- Apple on iPhone and Google on Android: they check that the app is genuine, for App Check, under their own terms.
When data leaves the European Union, as it does for the sign-in, the transfer relies on the EU-U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the standard contractual clauses approved by the European Commission.
How long it is kept, and how to have it deleted
Table data stays until you ask for it to be deleted. The app does not have a delete button yet, so write to [email protected] with the table code and the display name you used, and I will delete it. Everything held on your phone you can delete yourself, by uninstalling the app.
Your rights
Under the GDPR you can ask me to:
- tell you whether I hold personal data about you, and give you a copy (access);
- correct it (rectification);
- delete it (erasure);
- limit what I do with it (restriction);
- send the data you entered at a table to you or to another provider, in a common machine-readable format (portability);
- stop using it where I rely on my legitimate interest (objection).
Nothing here relies on your consent, so there is no consent to withdraw. Write to [email protected] and I will respond. Because the app does not know who you are, the table code and the display name you chose are what I need in order to find your data at all.
You can also complain to the Romanian data protection authority, ANSPDCP, or to the authority in the EU country where you live or work.
Changes
If a future version changes anything above, this policy is updated before that version ships, and the date at the top changes with it.
The rest of the site, the other apps and the contact form are covered by the Ontagonal privacy policy.