Crumb

Legal

Changelog

Every version of our Privacy Policy and Terms of Service, with the date it took effect and what changed.

Privacy Policy

VersionEffectiveChange
1.17 (current) 14 Sep 2026 Added the preference cookie that remembers whether you chose 10, 25 or 50 expenses per page, for up to one year unless you clear it sooner. It is not used for advertising or cross-site tracking. Terms remains version 1.4. Previous English version · النسخة العربية السابقة.
1.16 14 Sep 2026 Explained the minimal records used to prevent duplicate saves when adding an expense that is already paid. Successful save receipts remain while your account is active, even after the expense is permanently deleted. Also clarified temporary exchange-rate eligibility and when unfinished save records can be removed. Terms remains version 1.4. Previous English version · النسخة العربية السابقة.
1.15 13 Sep 2026 Added private monthly Save & Invest reminders and a separately optional email, with generic message content and owner-only reminder and delivery records. Clarified the rolling 90-day cleanup and its possible delays, and the temporary session timestamp used for the optional sign-in or unlock sound. Terms remains version 1.4. Previous English version · النسخة العربية السابقة.
1.14 11 Sep 2026 Added disclosures for account-access labels, display preferences, linked manual transfers and the optional private monthly check-in in Save & Invest. Turning off check-in stops its reminder without deleting its saved history. Existing sharing, retention and deletion rules remain unchanged. Terms remains version 1.4. Previous English version · النسخة العربية السابقة.
1.13 11 Sep 2026 Added Savings & Investments: personal accounts and institutions, manual values, deposits, withdrawals, optional goals and notes, and planned deposits. These records are private to your account, not shared with your organisation or its administrators. Corrections retain their original records, and archiving does not delete them. Crumb does not connect to your bank, move money or provide investment advice. Previous English version · النسخة العربية السابقة.
1.12 11 Sep 2026 Added disclosure for your chosen account time zone, optional expense quantity and unit price, and a reason or note when a payment differs from the expected amount. Your time zone helps dates, monthly views and reminders follow your local calendar day. It is not used to track your location. There are no changes to sharing, retention, your rights, cookies or analytics.
1.11 20 Aug 2026 Updated to disclose Payment Plans' new Safe Deletion capability. You can now delete a Payment Plan — it moves to a Recently Deleted view with no automatic expiry, staying there until you restore it or permanently delete it, exactly like how deleting an expense already works. Restoring simply reactivates the plan unchanged. Permanently deleting removes the plan itself, but never deletes the underlying expenses or payments linked to it — those are simply detached, not removed, so your expense and payment history stays intact. This is a data-management capability you control yourself, not a new financial capability, and it doesn't change how Crumb shares, retains, or protects the rest of your data. Nothing changed about our lawful bases, who we share data with, your rights, cookies, or analytics.
1.10 20 Aug 2026 Updated to cover Payment Plans, a new way to track a structured, multi-payment obligation — a "Buy Now Pay Later" purchase or an instalment plan you've agreed with a retailer or lender. Section 3.4 explains what's stored: a name, optional type and description, currency and starting amount, start and final due dates, an optional category and preferred payment method, and its status. If you record a provider name, it's a label you type in — like a payment-method label, it never connects Crumb to the real provider, and we never authenticate with or exchange data with an actual BNPL or lending service. You can optionally set a payment schedule and your own interest or fee rules; Crumb only ever calculates from the figures you enter, and never fetches a rate from, or makes a lending decision on behalf of, any external provider. Payment Plans data is protected exactly like the rest of your financial data, with no new sharing, access model, or retention behaviour. Nothing changed about our lawful bases, who we share data with, your rights, cookies, or analytics.
1.9 16 Aug 2026 Updated to cover a new self-service capability: you can now change the email address on your account from Settings → Profile. Starting a change requires re-entering your current password, and a two-factor code too if you have two-factor authentication on and haven't already verified it earlier in your session. We then send a confirmation link to both your old and new address, and the change only takes effect once you've opened it at both — so either inbox can catch and stop a change that wasn't genuinely yours. You can cancel a change you've started before both confirmations arrive, and we limit how many attempts an account can make in a given period. This is now recorded in your personal security history alongside your other account-security activity (Section 3.9), and the confirmation emails join the other essential, non-optional account notices in Section 4.3. Nothing changed about our lawful bases, who we share data with, your rights, cookies, analytics, or the other current limitations already disclosed.
1.8 16 Aug 2026 Updated to cover the account-security features Crumb now offers. You can turn on two-factor authentication with an authenticator app (and add more than one, as a backup) — just like your password, the authenticator itself is managed by our authentication provider and never seen by Crumb's own code, and removing one requires a fresh proof it's really you. We've also disclosed, precisely, that our authentication provider records the IP address a two-factor code was entered from, purely to rate-limit repeated failed attempts — it's kept by the provider, not shown to you inside the app, and not used for anything else. We also now keep a personal security history in Settings → Security, showing things like two-factor and password changes, other devices being signed out, and App Lock changes — visible only to you, viewable even while App Lock is engaged, and kept for as long as your account is active with no automatic deletion job. A related "sign-in activity" list shows the technical description ("user-agent") your browser sends — more detailed than the short device labels used elsewhere, so we've said so plainly — and roughly when each session was last active, and lets you sign out other devices or sign out everywhere. If you're ever locked out of two-factor authentication, a built-in recovery flow can help: it emails a one-time code to your own account address, enforces a mandatory 24-hour delay, requires your current password too, and — once complete — removes your old authenticators, requires setting up a new one, and signs every device out; recovery-request records are deleted automatically within 30 days. We also expanded which security notices are mandatory versus can be turned off in your notification settings. Nothing changed about our lawful bases, who we share data with, your rights, cookies, analytics, or the other current limitations we already disclosed.
1.7 13 Aug 2026 Updated to cover the new notification inbox — the bell menu that keeps a history of your expense reminders instead of leaving you with only the email or push message. Section 3.8 explains what an entry stores: which expense the reminder was about, its due date, how far ahead the reminder went out, when the entry was created, whether you've read it, and whether it has since been resolved because you paid, skipped, trashed or deleted the expense. Whether an entry keeps the expense's name and amount depends on the push-content setting you choose: on the detailed setting it does, on the generic default it stores no name and no amount at all. Nothing else about the expense is kept — no notes, provider, payment method, category or workspace. Only you can see your own entries, App Lock covers them the same way it covers your expenses, and marking one as read isn't a receipt for the email or push message. On how long we keep them: the inbox shows your unread items plus roughly the last 90 days of history, but we've been explicit that this is a display limit rather than a deletion schedule — entries stay until your account is deleted, and an entry deliberately outlives the expense it mentions. We also corrected Section 4.7, which still said push was limited to a test notification you send yourself; expense reminders can now genuinely be delivered by email, push, or both, at your choice — digests and security notices remain email-only. Finally, we removed a local-storage entry (crumb-seen-attention-ids) the app no longer uses. Nothing changed about our lawful bases, who we share data with, your rights, cookies, analytics, or how we handle financial data.
1.6 12 Aug 2026 Updated to cover Push notifications. If you turn push on for a device in Settings, we store a subscription address and two short encryption keys your browser generates, plus an automatic device label (like "Chrome on macOS") — the same kind we already use for security-notice emails. Those keys mean the service that relays a notification (Google, Mozilla or Apple, depending on your browser — now listed in Section 8) can never read its actual content. Today, push is limited to a test notification you can send yourself from Settings; we may extend it later to optional expense-reminder delivery, but digests and security notices will stay email-only either way, and we'll update this policy first if that changes. Removing a device deletes its subscription immediately; disabling push just pauses it. Nothing changed about our lawful bases, who we otherwise share data with, your rights, or analytics.
1.5 11 Aug 2026 Updated to cover three new things Crumb now does. You can now optionally save a short reference detail against a payment method — the last four digits of a card or bank account, the last four characters of a crypto wallet address, or the email address of a PayPal account — so the policy no longer describes payment methods as a label and card last-four digits only. It also now says clearly what we still never store: a full card number, account number, IBAN, wallet address, recovery phrase, or any login credential for a payment account. We now record the country you pick for your organisation when you set it up, used only to suggest a sensible starting set of payment methods for your region — you choose it yourself, and we never infer it from your IP address. Finally, Crumb now sends account-security notices when your password is changed or App Lock is turned on or off; these say which browser and operating system the change was made from, which we use only to write that one email and never to estimate your location. Password-change notices can't be turned off; App Lock notices, reminders and digests can. Nothing changed about our lawful bases, how long we keep data, who we share it with, your rights, cookies, or analytics.
1.4 9 Aug 2026 Reorganised the policy around what you actually do — requesting early access, creating an account, using Crumb, receiving essential service communications, and optionally receiving product updates — instead of describing how our internal systems are put together. The "data we collect" section now lists early-access form data alongside account, financial, workspace and technical data, and the "how we use it" section states each purpose separately. Clarified that invitations and password resets are only ever sent when you or someone in your organisation asks for them, and that optional product updates are a separate consent you can withdraw at any time. Simplified the Resend subprocessor entry to email delivery. No new personal data is collected, we still do not collect your IP address via the early-access form, and our stated limitations on account deletion and encryption are unchanged.
1.3 9 Aug 2026 Added trade licence identification (licence no. 86166, issued by DIEZ) and a dedicated privacy contact (privacy@crumbmoney.com). Rewrote the international-transfers and rights/complaints sections, naming the UAE Data Office. Finalised the 18+ minimum age. Published a full Arabic translation at /ar/privacy with a language switch.
1.2 8 Aug 2026 Corrected the cookies & local storage section to name the actual final cookie/storage names after the platform's naming update, and to clearly separate cookies from local storage.
1.1 8 Aug 2026 Added confirmed data-controller identity (Athena Private Management FZCO, part of Athena Holdings) and registered address. Company registration number, specific regulator, and a dedicated privacy contact remain open items.
1.0 8 Aug 2026 First published draft, grounded in a full review of the live product's actual data practices. Not yet approved for public use.

Terms of Service

VersionEffectiveChange
1.4 (current) 11 Sep 2026 Updated the service description to include manually tracked Savings & Investments and clarified that organisation administrators cannot access these personal records. No changes to pricing, liability limits or governing law. Previous English version · النسخة العربية السابقة.
1.3 16 Aug 2026 Small factual correction: the note that two-factor authentication "is not yet available" was removed, since it's now available and optional — we recommend turning it on, with more than one authenticator as a backup. Nothing else changed.
1.2 9 Aug 2026 Added trade licence identification (licence no. 86166, issued by DIEZ). Rewrote §16 as "Governing law and disputes": UAE law as applied in Dubai, disputes routed to support@crumbmoney.com first, Dubai courts have jurisdiction. Published a full Arabic translation at /ar/terms — the Arabic version controls in the event of inconsistency where UAE law requires it.
1.1 8 Aug 2026 Added confirmed contracting-entity identity (Athena Private Management FZCO, part of Athena Holdings) and registered address. Governing-law clause remains an open item pending counsel.
1.0 8 Aug 2026 First published draft, based on Crumb's actual product and closed-early-access business model. Not yet approved for public use.
Privacy Policy Terms of Service Back to Crumb

© 2026 Crumb. All rights reserved.

Privacy Terms Status