Moonshot LabsMoonshot Labs

Fluxly Privacy Policy and Privacy Notice

Last updated: September 20, 2026

Fluxly is a finance-tracking service for personal and shared budgets on iPhone, iPad, Mac and the web. This notice explains what we process, why we process it, what budget members can see and how to exercise your rights.

Privacy and support contact

support@moonshotlabs.app

1. Controller and scope

Fluxly is provided by Orçun Demir, operating under the Moonshot Labs brand. Contact support@moonshotlabs.app for privacy, support and data-rights requests.

This notice covers Fluxly apps, the web workspace and related support. Where applicable, it provides information under the EU GDPR, UK GDPR and Türkiye's Law No. 6698 (KVKK). Using Fluxly is not blanket consent to every processing activity.

2. Data we process

We receive data from you, members of budgets you join, selected login and payment providers, and limited technical records generated while operating the service.

  • Account and profile: email address, Supabase user ID, chosen login provider, language, default currency and app preferences.
  • Financial records: budgets, accounts, income and expenses, categories, amounts, currencies and recorded exchange rates, dates, notes, recurring items, debt plans, goals, sub-budgets and their status.
  • Shared budgets: membership, role, invitation and joining information, and records members add to a shared budget. Separately marked private accounts have additional access limits.
  • Receipts: if introduced later, the selected image, merchant, date, total, currency, extracted text and linked transaction may be processed. Receipt capture/text extraction, file import, Google Drive backup and the AI assistant are not offered in the initial release.
  • Subscriptions: Apple product and transaction information; purchase, restore, renewal, cancellation, refund, grace-period and expiry status; Premium entitlement; and your Fluxly user ID. We do not receive full card details.
  • Notifications and security: APNs device token, platform, last activity, notification preferences, and security/session events. Infrastructure providers can see IP addresses and standard request data when connections are made.

3. Purposes and legal bases

We process account, authentication, storage, sync, shared-budget access and purchased features to perform the service contract. Limited security, reliable-sync, troubleshooting, subscription-verification and support processing relies on performance of the contract or our legitimate interest in operating Fluxly safely. Records required by law may be processed for legal obligations.

Optional notifications and Adapty product analytics activate only with the relevant preference and, where required, device permission. Product analytics is off by default and can be changed in Privacy Center. Withdrawing an optional choice does not automatically erase core account records.

Under KVKK, the applicable basis may include establishing or performing a contract, legal obligations, establishing or protecting rights, legitimate interests that do not harm fundamental rights, or explicit consent where required.

4. Visibility in shared budgets

Authorised members can see or change shared accounts, transactions, categories, plans, goals, receipt references and membership information according to their role and record scope. These spaces are not private journals. Private accounts are separated from other members, although relationships you choose between records can affect visibility.

Share invitations only with intended participants. Removing a member or deleting your account does not automatically erase legitimate shared financial history or copies others already received.

5. Service providers

We do not sell personal data or share it for behavioural advertising.

  • Supabase for authentication, the primary European-region database, authorisation, sync, file storage and server functions.
  • Adapty for Apple subscription validation, paywalls, Premium access and optional product analytics. Financial transaction content is not sent to Adapty.
  • Apple for Sign in with Apple, App Store payments and APNs delivery.
  • Cloudflare for delivery and network security of the Fluxly web workspace and limited technical request logs.
  • Email and infrastructure providers for support communications and attachments. Never send passwords, verification codes or full card details.

6. Device data, offline use and permissions

The iPhone and iPad app keeps an offline copy of financial data, preferences and pending changes. The Mac app displays the Fluxly web workspace in a secure native shell. Browsers may keep session and necessary preference data locally.

The camera is used when you choose to scan another device's Fluxly sign-in QR code under Settings > Web Sessions and grant system permission. Receipt capture and text extraction are disabled in the initial release. If receipt-image selection is introduced later, the system photo picker gives the app only the image you select; we do not scan the full photo library. Notifications are optional. Amount-hiding and notification privacy settings reduce visible content, but you should also secure access to your device.

7. Retention, deletion and account closure

We retain accounts and financial records while needed to provide the service. Deletion may use tombstones for device sync; disappearance from the interface does not mean immediate physical removal from every backup. Retention depends on account and shared-budget activity, sync requirements, unresolved financial records, security review, support needs and applicable legal duties. Inbox and security records are retained for their limited service purposes.

Use account deletion in Settings or email support@moonshotlabs.app from your account address. We may proportionately verify identity. Shared ownership, other members' rights, unresolved records and legal duties can require retaining shared entries or reducing their link to you. Removing the app does not delete your account or cancel Apple billing; manage the subscription separately with Apple.

8. International transfers

The primary Supabase database is configured in a European region. Apple, Adapty, Cloudflare and support providers may process data outside your country, and we do not promise every sub-service remains in one country. Where applicable, transfers rely on adequacy decisions, standard contractual clauses or another valid mechanism.

9. Your rights

Depending on applicable law, you may request access, a copy, correction, deletion, restriction, objection and portability of eligible data. You may withdraw consent prospectively where processing relies on consent. Rights under KVKK Article 11 remain available.

Email support@moonshotlabs.app from the address associated with your account. GDPR requests normally receive a response within one month and KVKK applications within thirty days; permitted extensions or exceptions are explained. You may complain to the competent data-protection authority.

10. Security, children and changes

We use HTTPS, session authentication, server-side budget membership controls and device protections. No system is absolutely secure, and Fluxly is not offered as an end-to-end encrypted vault.

Fluxly is not directed to children. Do not place unnecessary health data, identity documents, full card numbers or another person's sensitive data in notes or receipts. We update the date when this notice changes and provide any notice required for a new purpose or permission.