Dimeleaf Download

Privacy Policy

Effective 1 October 2026

The short version
  • We use your data only to run Dimeleaf for you and the people you choose to share a space with.
  • No ads, no advertising trackers, no analytics SDKs. We never sell your data.
  • We never ask for your bank login, card number or PIN, and Dimeleaf does not connect to your bank.
  • You can delete your account at any time from the app. We then delete your data as described below.

1. Who we are

Dimeleaf ("Dimeleaf", "we", "us") is a personal and family finance app provided by Dimeleaf, Indonesia. We are the controller of the personal data described in this policy. This policy covers the Dimeleaf apps for iOS and Android, the web version, and the website https://dimeleaf.com.

2. Data we collect

CategoryWhat it includesWhere it comes from
AccountEmail address, name, sign-in method (email code, Google or Apple), profile photo or avatar, colour, language, time zone. For Sign in with Apple, a token used only to revoke access when you delete your account.You, and Google or Apple if you sign in with them (name and email only).
Financial records you enterWallets and balances, transactions (amount, date, category, note, tags, splits), budgets, savings goals, recurring bills, debts and loans (including the names of the other people involved you type in), shopping lists.You and the members of your space.
Family collaborationSpaces you belong to and your role, invitations (the invitee's email address), comments, reactions, spending requests, and an activity history of changes in a space.You and the members of your space.
Receipt photos (optional)Photos you attach to transactions. Photos you send to the AI receipt scanner are processed but not stored by the scanner.Your camera or photo library, only when you choose a photo.
SubscriptionPlan, store (App Store or Google Play), status, renewal and expiry dates, trial status. We never receive your card or payment details. The store handles payment.Apple or Google, through RevenueCat.
ReferralsYour invite code, and who invited whom. The person who invited you can see how many of the people they invited joined and upgraded to Premium (counts only). If someone invited you, you can see their first name.You.
Device & technicalPush notification token and platform, notification settings, time zone. Our hosting provider keeps short-term security logs (for example IP address and time of a request).Your device, automatically.

What we do not collect: your precise location, contacts, microphone audio, bank or card credentials, advertising identifiers, or data from other apps. We do not use analytics, advertising or tracking SDKs.

Stored only on your device: your sign-in session, app preferences (theme, language, "hide balances", reminders) and whether app lock is on. Fingerprint and Face ID are checked by your phone's operating system. We never receive biometric data.

3. How we use your data

Insights such as "spending in this category is up" are calculated on your device from your own records. We do not use your data for advertising, profiling for marketing, or to train AI models, and we do not sell or "share" personal data as those terms are used in US state privacy laws.

4. Sharing inside your space

A space can be personal or shared with up to 5 invited members. Who sees what depends on each member's role:

If a member leaves or is removed, or an owner hands over ownership, that person's private wallets in the space and their own transactions are permanently deleted; transfers between them and shared wallets stay in the shared wallet as income or expense.

Members of a space can see each other's name, profile photo and email address. Members may receive notifications about activity in the space, such as "Rina spent $12 on groceries", according to their role and settings. Please only add information about other people, such as a name in a debt, if you have the right to do so.

5. Service providers

We use a small number of providers who process data on our behalf, under contracts that limit their use of it:

ProviderPurposeData involved
SupabaseDatabase, sign-in, file storage and server functions (hosting region: Japan (Tokyo))All data stored in your account
Anthropic (Claude)AI receipt scanning, only when you use itThe receipt photo (compressed and resized, with location and camera metadata removed), your currency, language and category list. Under Anthropic's commercial terms it is not used to train their models, and it is kept only temporarily (for example for safety review) before being deleted.
RevenueCatManaging subscriptionsA random user ID and purchase records from the store
Apple, GoogleSign in with Apple or Google, in-app purchases, push delivery (APNs, FCM)What is needed for each function
ExpoRelaying push notifications to Apple and GooglePush token and notification text
Email delivery provider (for example Resend)Sign-in emails and invitation emailsEmail address, and for invitations the inviter's name and the space name
CloudflareHosting this website and forwarding emails sent to our support addressesTechnical data of website visits (such as IP address) and the emails you send us
Google (Gmail)Our support mailboxThe emails you send us and our replies

We may also disclose data if required by law or a valid legal request, to protect rights and safety, or as part of a merger or acquisition. In that case this policy continues to apply, or you will be notified.

6. International transfers

Our servers are located in Japan (Tokyo), and some providers above may process data in other countries, including the United States. When data leaves your country we rely on appropriate safeguards required by applicable law, such as standard contractual clauses and our providers' security commitments. This includes Indonesia's Personal Data Protection Law (UU No. 27/2022) and, where applicable, the GDPR.

7. How long we keep data

DataRetention
Your account and recordsUntil you delete them or delete your account.
Deleted transactionsKept for 30 days in Recently deleted, where you can restore them, then permanently deleted.
Receipt photosDeleted automatically within about 2 days after the transaction they belong to is permanently deleted.
AI receipt scansWe keep only a usage counter (date, no image) to enforce fair-use limits.
Space activity historyUntil the space is deleted. If you delete your account, entries stay but are no longer linked to you.
InvitationsExpire after 14 days. The record stays in the space's history until the space is deleted.
NotificationsDeleted 30 days after sending (7 days if they could not be sent). Technical duplicate-prevention keys are kept for up to 400 days.
Server logs and backupsKept for a limited period by our hosting provider for security and recovery, then overwritten.

8. Deleting your account

In the app, go to Settings → Delete account. You can also follow the steps on dimeleaf.com/delete-account. When you delete your account:

9. Your rights

Depending on where you live, you have the right to access, correct, delete or receive a copy of your data (portability). You may also object to or restrict certain processing, withdraw consent at any time, and not be discriminated against for using these rights. You can do most of this directly in the app: edit or delete records, change your profile, export transactions to CSV (Premium) and delete your account. For anything else, email [email protected] from the address linked to your account. We respond within the time required by law, for example within 3 × 24 hours where Indonesian law requires it and within one month under the GDPR. You may also complain to your data protection authority. In Indonesia this is the ministry responsible for communication and digital affairs or the personal data protection agency.

10. Security

Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider. Every space is isolated in the database using row-level security, so one family can never read another family's data. Receipt photos and profile photos are stored privately and shown through short-lived links. In the app you can turn on fingerprint or Face ID lock and hide balances. No system is perfectly secure. If a personal data breach affects you, we will notify you and the authorities as the law requires (in Indonesia, within 3 × 24 hours).

11. Children

You must be an adult to create an account and own a space (see our Terms). Dimeleaf is not directed at children under 13, and they may not use it. A parent or legal guardian may invite their child aged 13 or older into the family space with the "Child" role, and by doing so gives the consent required by law for the child's use of Dimeleaf (for example under Article 25 of Indonesia's PDP Law or Article 8 of the GDPR). Children see only their own wallets. A parent can change the child's role or remove the child at any time. If you believe a child under 13, or a minor without that consent, has used Dimeleaf, contact us and we will delete the data.

12. Notifications and AI choices

Notifications may show amounts and notes on your lock screen. You can turn each type off in Settings → Notifications, or turn all of them off in your phone's settings. The AI receipt scanner is optional. You agree to it once per device, and you can simply stop using it, or ask us to delete your usage records.

13. Website and cookies

https://dimeleaf.com does not use cookies, analytics or third-party fonts and scripts. The invitation and referral pages read the code in the link only to open the app. The site does not store it; it is only part of the page address your browser requests, which may appear briefly in our hosting provider's technical logs.

14. Changes to this policy

We will post any update here and change the effective date. If a change is significant, we will tell you in the app or by email before it takes effect.

15. Contact

Dimeleaf, Indonesia
Privacy questions: [email protected] · Support: [email protected]