TotesnapBack to site

Privacy Policy

Totesnap is built so that the things you record — your photos, amounts, and limits — stay on your phone. This page explains the few cases where information does leave it.

Last updated 12 August 2026

The short version

  • There is no account, no sign-up, and no bank connection. We never ask for banking credentials or card numbers.
  • Your snaps, amounts, limits, and history live in a database on your device. We cannot read them.
  • What does leave your device: anonymous usage and crash diagnostics, map tile requests, purchase validation, and anything you deliberately send us in a support report or share to another app.

01

What stays on your device

Everything you create in Totesnap is written to a local database and to your device’s app storage. That includes the photo attached to each snap, the amount, any name or note, the mood you tag it with, the capture time, your daily limit, and your rollover history.

None of it is uploaded to a Totesnap server, because there is no Totesnap server holding user records. We have no way to read your snaps, and no ability to recover them for you if you lose your device or uninstall the app.

02

Location and places

A snap can carry a location so it can appear on your map. That location comes from one of two places:

  • Your device’s location, read at the moment you create the snap, if you have granted location permission.
  • Coordinates already embedded in the photo you choose. Cameras write GPS data into a photo’s EXIF metadata, and Totesnap reads it so an older picture lands in the right place.

Coordinates are stored on your device alongside the snap. Two things involve a third party:

  • Turning coordinates into a place name (for example “Inverness”) uses the geocoding service built into your operating system, which is provided by Apple or Google depending on your device.
  • Drawing the map requests tile images from OpenStreetMap. Loading a map necessarily tells the tile server which part of the world you are looking at, and is subject to the OpenStreetMap Foundation privacy policy.

If you never grant location permission and your photos carry no GPS data, snaps simply have no location and the map stays empty.

03

Diagnostics and analytics

Totesnap uses Google Firebase to understand whether the app is working, specifically Analytics, Crashlytics, and Remote Config. These report which screens are opened, general device and app version information, and the technical details of a crash when one happens. They are not used to read the contents of your snaps.

This data is processed by Google as described in the Firebase privacy documentation. Analytics collection is switched off in development builds.

04

Purchases

Premium is sold through the App Store and Google Play, with RevenueCat handling entitlement checks. Your payment is taken by Apple or Google — we never see your card details. RevenueCat receives a purchase identifier so the app knows whether premium is active on your device.

05

Support reports

If you send a report from Settings, it is delivered to our support channel and includes the category you picked, the description you wrote, your app version and build number, your device model and operating system version, the build mode, and your purchase identifier. If you fill in the optional reply email, that is included too, and is used only to answer you.

Please don’t put anything in the description you would rather we didn’t see. Nothing is sent unless you tap send.

06

Sharing and backups

When you export a snap, a monthly recap, or a map as a share card, the image is generated on your device and handed to whichever app you choose. Once you send it, it is governed by that app’s privacy policy, not this one.

Backups work the same way: the archive is written on your device and you decide where it goes. A backup you place in a cloud drive is subject to the terms of that drive.

07

Permissions we ask for

  • Camera and photo library — to attach a picture to a snap.
  • Location — to place a snap on the map. Optional; the app works without it.
  • Files — only when you export or restore a backup.

Every one of these can be refused or revoked in your device’s settings. Refusing location or camera access limits the related feature but does not stop you recording spending.

08

Keeping and deleting your data

Your snaps stay on your device until you delete them. Deleting a snap removes it and its photo from the app’s storage; uninstalling Totesnap removes the whole database. Because we hold no copy, an uninstall is final unless you exported a backup first.

Diagnostics already sent to Firebase and reports already sent to support are retained by those services under their own schedules. Write to us if you want a support report removed.

09

Children

Totesnap is not directed at children and should not be used by anyone under the age required to hold an App Store or Google Play account in their country.

10

Changes to this policy

If this policy changes in a way that affects what leaves your device, we will update the date at the top of this page and, where the change is significant, note it in the app.

11

Contact

Questions about this policy can go to totesnap@hidayata.dev, or through Settings → Support in the app.

See also our Terms & Conditions.