Last updated: August 22, 2026
1.Who this covers
This policy applies to the Cosum mobile app on Android and iOS, and to cosum.app. Cosum is operated by Oğuzhan Ozgökce, based at İnönü Mahallesi, Bağcılar, İstanbul, Türkiye, reachable at support@cosum.app.
It does not cover the app stores, or any third-party service you reach by leaving the app.
2.Account data
Creating an account stores:
- your email address
- your password, stored only as a salted hash — we never see or store the password itself
- a display name of up to 40 characters, which you choose
- an identifier our app generates for your installation, and the platform you signed in from — we do not read hardware identifiers
- which version of the terms you accepted, and when
3.What you record in the app
Ledgers, the participant names you type, expenses and income with their amount, date, optional category and optional description, settlements, and an activity log of who changed what.
Participants are names, not accounts. If you add a flatmate as a name, that name is data you entered about another person — you are responsible for what you type there. Cosum needs nothing else about them: no email, no phone number, no contacts access.
4.Usage analytics
The app uses Google Firebase Analytics to understand which features are used and where people get stuck. Events record things like which category an expense had, how many participants a ledger has, and whether a limit was hit.
Analytics events deliberately carry no ledger content and no account identifier: no participant names, no descriptions, no email addresses, and nothing that ties an event back to who you are. Firebase counts app installations, not people. You can turn analytics off in the app.
5.Crash reports
When the app crashes, Google Firebase Crashlytics records the error, the stack trace, the device model and the operating system version so the fault can be fixed. Crash reports are not used for advertising or profiling.
6.Advertising
The free tier shows a single banner from Google AdMob on the summary screen. Premium removes it entirely. No advertising appears in any screen where you enter money or settle up.
On Android the app removes the advertising-identifier permission outright, so ads there are never personalised — there is no identifier for an advertiser to profile you with. On iOS the system App Tracking Transparency prompt decides whether your advertising identifier may be used; decline it and you see non-personalised ads instead.
In the EEA and the UK a Google-certified consent form still appears before any ad is served, on both platforms, because showing one requires storing and reading information on your device. You can reopen that form at any time from the privacy page inside the app.
7.Purchases
Premium subscriptions are billed by Apple and Google. Cosum never receives your card details. What reaches us is the subscription’s status and the date it runs until, so the account can be marked as premium and set back when it lapses.
8.This website
cosum.app is mostly a set of static pages. With your permission, it uses Firebase Analytics (a Google product) to see how the site is used — which pages are visited and a handful of key actions, like signing up or creating a ledger. This only runs if you accept it in the cookie banner, is never used for ads or to track you across other sites, and you can change your mind at any time from the Cookie preferences link in the footer.
Your light or dark theme choice, and your cookie choice, are both stored in your browser only. If you start writing feedback and leave the page before sending it, the draft is kept in your browser the same way, so it's there if you come back — it is never sent anywhere until you press send.
Fonts are served from our own domain. The one page that sends anything else is the feedback form, described below.
9.Feedback you send us
The form at cosum.app/feedback — the same page the app opens from Profile — sends us your message, the topic you picked, the language you wrote in and, when it is opened from the app, the platform and app version.
An email address is optional and is there only so we can reply. Leave it out and the message still reaches us; we simply have no way back to you.
The form does not carry your login. The app opens it in a browser view that does not share your session, so feedback arrives with no account identifier attached to it.
To stop automated abuse without putting a puzzle in front of you, the server counts recent submissions against a salted, one-way hash derived from the network address the request came from. That counter is stored apart from the messages, cannot be traced back to one, and is deleted five minutes after the last submission.
10.Why we are allowed to process this
- To provide the service you asked for — performing the contract between us
- To keep the service working and secure, and to fix crashes — our legitimate interest
- To read and answer the feedback you send, and to keep the form from being abused — our legitimate interest
- For analytics and personalised advertising — your consent, which you can withdraw at any time
- To keep records the law requires us to keep — legal obligation
11.Who else processes your data
These providers act on our instructions. We never sell your data for money and we do not share it with data brokers. Personalised advertising does involve sharing an advertising identifier with Google, which some laws — California’s among them — classify as a “sale” or “share”; declining the consent prompt, or Ask App Not to Track on iOS, stops it.
- Supabase — database, authentication and the app backend
- Hostinger — hosting for this website
- Google (Firebase, AdMob) — analytics, crash reporting and advertising
- Apple and Google — app distribution and subscription billing
- RevenueCat — subscription state, once premium launches
12.Where your data is held
Our providers operate servers outside your country, including in the European Union and the United States. Transfers rely on the safeguards those providers offer, such as the European Commission’s standard contractual clauses.
13.How long we keep it
Account data is kept while the account exists. Deleting your account removes your account, your display name and your email address from our live systems immediately. Encrypted backups are overwritten on their normal cycle, within 30 days.
Expenses in ledgers you shared with other people stay with them, because those records are also theirs — a shared ledger cannot be made correct for one person by erasing it for everyone else. Your name remains visible on entries you created, as the record of who entered them.
Feedback is kept for as long as it is useful for improving the app, and no longer than 24 months. The anti-abuse counter that goes with it is deleted within five minutes.
14.Your rights
Under the GDPR and Turkey’s KVKK you can ask for access to your data, correction of it, deletion of it, a copy of it in a portable form, and you can object to processing based on legitimate interest or withdraw a consent you gave.
Most of this is available in the app under Profile → Account details. For anything else, write to support@cosum.app and we will answer within 30 days. You may also complain to your national data protection authority.
15.Children
Cosum is not intended for children under 13, or under the minimum age set by local law where that is higher. We do not knowingly create accounts for them. If you believe a child has an account, write to us and it will be removed.
16.Changes to this policy
When this policy changes materially, the app asks you to accept the new version, and the date at the top of this page changes. Past versions are available on request.
17.Contact
Questions about this policy: support@cosum.app