Privacy Policy — Wallos Mobile
Draft to complete before publication — last reviewed: August 3, 2026
This document is a template based on the app’s current behavior. Replace the fields in brackets and have it reviewed by the person or entity publishing the app.
1. Data controller and contact
For questions about this policy or your data, contact: hello@valemko.app.
2. Scope
This policy explains what information is processed when you use the Wallos Mobile app (the “app”). Wallos Mobile is a client for a self-hosted Wallos instance selected by the user. Business data stored on that instance remains under the control of the user and the instance administrator.
3. Data processed
Connection data
To connect, the app may process:
- the URL of the Wallos instance you choose;
- your Wallos API key;
- if you choose credential sign-in, your Wallos username and password during the sign-in flow.
When credential sign-in is used, the password is sent directly to the Wallos URL you entered to open the web session. It is used temporarily and is not stored by Wallos Mobile. After a successful sign-in, the app keeps only the URL and API key needed for subsequent requests.
The URL and API key are stored in the secure storage supplied by the device operating system. They remain on the device until you disconnect, clear the app data or uninstall the app.
Data returned by Wallos
Depending on the features you use, the configured instance returns profile information, subscriptions, prices, currencies, categories, payment methods, household members, payment dates, notification settings, notes, links and logos. This data is needed to display and manage your instance. It is held in memory while the app is being used and is sent back to the same instance when you create or edit data.
Logos and photos
You may select an image from your device for a subscription. The selected image is sent to your Wallos instance only when you save it on a subscription. The app does not upload it to an editor-operated server.
App preferences
The following preferences are stored locally in the device’s secure storage: light/dark/system theme, interface language and the global notification setting.
Local notifications
If you grant permission, the app schedules payment reminders on the device. These are local notifications: Wallos Mobile does not operate a push-notification server and does not collect your location.
Exports and sharing
When you export subscriptions as JSON or CSV, the file is generated on the device. If you choose to share it, the file is handed to the app you select in the operating system share sheet. Processing by that third-party app is governed by its own privacy policy.
4. Purposes and legal bases
Data is processed to:
- connect to and maintain access to your Wallos instance;
- display, synchronize and manage subscriptions and their settings;
- calculate due dates, totals, budgets and statistics shown in the app;
- schedule the local reminders you request;
- save your interface preferences;
- generate exports you request.
The applicable legal basis is performance of the service you request and, where required by law, your consent (in particular for notifications and photo selection). You can withdraw these permissions in your device settings.
5. Recipients and no advertising tracking
Wallos Mobile currently uses no analytics tool, advertising, advertising profiling or editor-operated backend intended to centralize your data.
Data is sent to the Wallos instance whose address you entered. The Wallos Mobile publisher does not control that instance’s hosting, backups, location or authorized users. Operating-system services (such as the share sheet or notification platform) and apps you choose may process data under their own terms.
6. Security and local HTTP
Saved credentials use the platform’s secure storage. HTTPS is strongly recommended for the Wallos instance. The app also supports HTTP for a trusted local instance and displays a warning; on an untrusted network, HTTP can expose data and the API key. No transmission or storage method can be guaranteed to be completely secure.
7. Retention and deletion
- The URL and API key remain on the device until you disconnect, clear app data or uninstall the app.
- Interface and notification preferences follow the same local-retention behavior.
- Subscriptions and other business data remain on your Wallos instance according to the instance administrator’s policy. To permanently delete them, use Wallos or contact that administrator.
- Exported files and shared copies are under your control and may need to be deleted in the receiving app.
8. Your rights
Depending on where you live, you may request access, correction, deletion, restriction, objection or portability of your data, and withdraw consent where processing is based on consent. Contact [CONTACT EMAIL] and identify the relevant instance. You may also contact your local data-protection supervisory authority.
For data hosted on a third-party Wallos instance, that instance’s administrator may be the data controller; you may need to send the request directly to them.
9. Children
The app is not directed at children and does not knowingly seek to collect data from anyone below the applicable age in their country of residence.
10. Changes
This policy may be updated when the app or its processing activities change. The “Last updated” date will be revised and appropriate notice will be provided where required by law.
11. Contact
For questions, contact hello@valemko.app.
Last updated: August 3, 2026
Contact