Privacy Policy
Duit Urang ("we," "our," or "the application") is committed to protecting your privacy. This policy explains what information is collected, how it is used, where it is stored, and the controls you have over your data.
Duit Urang operates on a user-owned storage model. Your financial records are saved directly to your personal or shared Google Spreadsheet within your own Google Drive account. We do not operate a centralized backend database storing your financial records, accounts, debts, or transaction history.
1. Application Identity and Purpose
Duit Urang is a mobile-first Progressive Web Application (PWA) designed for personal and household financial tracking, budget planning, expense analysis, and debt tracking. The application allows individuals and household members to synchronize financial data collaboratively through Google Spreadsheets.
Production website: https://duit-urang.online
2. Information We Collect or Process
A. Information from Google Accounts
When you sign in with Google via Google Identity Services (GIS), we receive:
- Profile Information: Your Google name, email address, profile picture URL, and Google user ID (sub).
- OAuth Tokens: A short-lived OAuth 2.0 access token (stored in browser session storage) and an authorization refresh token (stored in an encrypted, HTTP-only secure cookie) used strictly to interact with Google APIs on your behalf.
B. Financial & Operational Data Entered by You
You may input financial and planning records into the application, including:
- Accounts: Account names, institution types, liquid status, account ownership email, and opening balances.
- Transactions: Dates, amounts, categories, descriptions, transaction types (income, expense, transfer), scopes (personal or household), and the creator email (
created_by). - Budgets & Goals: Monthly budget limits and savings targets.
- Recurring Obligations: Scheduled bills, subscription amounts, frequencies, and next occurrence dates.
- Debts: Balances, interest rates, minimum payments, and creditor names.
- Household Members: Collaborator email addresses and assigned household roles.
3. Google OAuth & Google API Access
Duit Urang requests the minimum necessary Google OAuth 2.0 scopes required to deliver its core functionality:
Purpose: Allows the application to read, create, update, and clear values in the specific Google Spreadsheet that you connect or initialize for Duit Urang.
Purpose: Used to display your avatar and name in the application header and account drawers.
Purpose: Used to identify your account, resolve household membership, verify account ownership, and attribute transaction entries (created_by).
Duit Urang's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We only use Google user data to provide and improve user-facing features (financial tracking, budget calculation, and cross-device spreadsheet syncing).
- We do not transfer Google user data to third parties, unless necessary to provide core features, comply with applicable law, or as part of a merger/acquisition.
- We do not use or transfer Google user data for serving advertisements, personalized advertising, or retargeting.
- We do not allow humans to read your Google user data or spreadsheet content unless we have your affirmative agreement for specific troubleshooting, to comply with applicable law, or where data is aggregated and anonymized for internal security operations.
5. Data Storage, Local Persistence & Cross-Device Sync
A. Google Sheets (Cloud Persistence)
When connected to cloud storage, your transactions, accounts, budgets, debts, recurring bills, and household member lists are saved directly to sheets within your chosen Google Spreadsheet (such as accounts, transactions, and household_members). You retain full ownership and administrative control over this file inside Google Drive.
B. Browser Local Storage & Session Storage (Client Device)
To support offline capability, immediate UI responsiveness, and session resilience, Duit Urang stores certain non-sensitive data on your device:
- Session Storage (
sessionStorage): Holds the short-lived Google OAuth access token and expiration timestamp so that page refreshes within the same browser tab do not discard active authentication. This data is purged when the tab is closed or when you sign out. - Local Storage (
localStorage): Caches the active Spreadsheet ID, spreadsheet title, public user profile info (name, email, avatar URL), last sync timestamp, and cloud storage preference. - In-Memory Mutation Queue: Pending offline creates, updates, and deletes are held in memory during network disconnections and flushed to Google Sheets once connection is restored.
C. Cross-Device Synchronization
When returning to the PWA (window focus or lifecycle resume), the application checks whether cloud data has been updated by another household collaborator after a 30-second staleness interval. Synchronization is performed directly between your client browser and the Google Sheets API.
6. Third-Party Services and Sharing
We do not sell, rent, trade, or monetize your personal or financial data. We do not use third-party behavioral analytics, ad networks, or data brokers.
The external services involved in running Duit Urang are strictly technical infrastructure providers:
- Google LLC (Google Identity Services & Google Sheets API): For authentication, token exchange, and spreadsheet persistence based on your consent.
- Vercel Inc.: Application hosting and Next.js edge/serverless compute for delivering web assets and facilitating the secure OAuth authorization code exchange. Vercel processes HTTP requests in accordance with their privacy standards and does not maintain a database of your spreadsheet records.
7. Security Practices
We implement industry-standard safeguards to secure your session and interactions:
- HTTPS Encryption: All communication between your device, Vercel hosting, and Google APIs is encrypted in transit using Transport Layer Security (TLS/HTTPS).
- HttpOnly Cookie Isolation: The OAuth refresh token is stored in a secure,
HttpOnly,SameSite=Laxcookie that cannot be accessed by client-side JavaScript, mitigating Cross-Site Scripting (XSS) token theft. - Formula Injection Sanitization: User-entered text in transactions, categories, and accounts is sanitized before writing to Google Sheets to prevent formula injection exploits (
=,+,-,@).
8. User Rights, Data Control & Deletion
Because your financial records reside in your own Google Spreadsheet, you have direct, unhindered control over your data:
9. Children's Privacy
Duit Urang is not intended for or directed at children under the age of 13 (or under 16 in the European Economic Area). We do not knowingly collect or solicit personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate steps.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in functionality, regulatory requirements, or Google API policy guidelines. Any revisions will be published on this page with an updated "Effective Date" at the top. We encourage you to review this page periodically.
11. Contact Us
If you have any questions, comments, or concerns regarding this Privacy Policy or our data handling practices, please contact us: