The short version: RefundHound collects nothing.
There is no account, no server and no analytics. Every refund, note and receipt photo you enter stays in a database on your own device. I have no way to see it, and the app transmits none of it anywhere.
This policy explains that in full, and is honest about the few edges where another company is unavoidably involved. RefundHound is made by Nilbyte Studio ("I", "me").
What the app stores on your device
Everything you enter is written to local storage on your phone or tablet:
- Refund details — merchant name, amount, currency, refund method, the date promised, and your notes
- Receipt photos you attach, kept in the app's own private storage
- Reminder schedules, so the app knows when to notify you
- Small settings, such as whether you've bought the unlock and whether you've been asked about notifications
None of it is transmitted, uploaded, synced or shared. It is readable only by RefundHound on your device, and it is removed when you delete a refund or uninstall the app.
What RefundHound does not do
- No user accounts, sign-up or login
- No servers or cloud storage operated by me
- No analytics, usage tracking, event logging or session recording
- No advertising, ad networks or advertising identifiers
- No cookies, pixels, SDK trackers or fingerprinting
- No remote crash reporting
- No sale or sharing of personal information — there is none to sell
- No location, contacts, calendar or microphone access
Error logs
If something goes wrong, the app appends the technical error to a small local file, capped in size, so a problem can be diagnosed if you choose to report it. It records errors only — never merchant names, amounts, notes or photos. It is not sent anywhere on its own, there is no remote crash reporting, and it is deleted with the app.
The one way it can leave your device is if you send it. When you use Contact support on the About screen and there is something logged, the app asks whether to attach a recent extract to the email — every time, never remembered, and Send without it is always an option. If you agree, the extract is pasted into the draft in your own mail app, where you can read it, edit it or delete it before sending, and the log is cleared so an old error doesn't ride along on later mail.
One honest caveat: an error message describes what failed, so it can contain a file path from your device, and the technical trace can name internal parts of the app. Neither carries your refund data, but "errors only" is not the same as "no personal information whatsoever" — which is exactly why attaching it is your decision, shown to you first, and asked fresh each time.
Backups
RefundHound deliberately excludes its database and receipt photos from Android's cloud backup and device-transfer, and from iCloud and encrypted device backups on iOS. Receipt photos are personal, and the app promises the data stays on your device — that promise and automatic cloud backup cannot both be true.
The consequence is that your data does not follow you to a new phone on its own. The CSV export on the Stats screen is the migration path, and you control the exported file entirely — including where it is stored and who can read it.
Permissions
- Camera — only when you choose to photograph a receipt. The photo is saved into the app's private storage and nowhere else.
- Photo library — only when you choose to attach an existing photo. The app reads the single image you pick; it does not browse or index your library.
- Notifications — to deliver refund reminders. You are only asked once you have an active refund, and declining is respected permanently: the app will not ask a second time. If you change your mind, turn notifications on for RefundHound in your system Settings.
All three are optional. The app works without any of them, with the obvious features missing.
Two further permissions appear on the Android listing and are worth explaining, because neither does what its name suggests here. Network access is required by Google Play Billing to sell and verify the one-time unlock; the app itself makes no network calls, and your refund data is never sent over it. Run at startup lets the app re-register your pending reminders after a reboot, which would otherwise silently clear them.
Where other companies are unavoidably involved
These are the only points at which anything reaches a third party, and each happens because you took an action:
- Buying the unlock. Purchases are processed entirely by Apple or Google. They handle the payment and tell the app whether you own the unlock; I never see your name, payment details or address. Their handling of the transaction is covered by Apple's privacy policy and Google's privacy policy.
- Emailing support. If you use the contact button, the app opens your own mail app with a draft that pre-fills the app version and build, your device make and model, and your OS version — this helps diagnose problems. If anything has been logged, it also offers to attach a recent error extract, and you can decline. You can see and edit all of it before sending, and nothing is sent unless you send it. If you email me, I have your email address and whatever you wrote, kept only as long as needed to answer you.
- Opening a link. Tapping the privacy policy, or rating the app, hands off to your browser or app store in the normal way.
- Exporting CSV. You choose where the file goes. Once it leaves the app it is an ordinary file under your control, and if you save it to cloud storage that provider's terms apply to it.
Children
RefundHound is a general-purpose utility, not directed at children, and it collects no personal information from anyone regardless of age.
Retention and deletion
Your data is retained on your device for exactly as long as you keep it. Delete a refund and it is gone; uninstall the app and the database and every receipt photo go with it. Because I hold no copy, there is no retention period on my side and no deletion request to make.
Your rights
Data-protection laws including the GDPR and the California Consumer Privacy Act give you rights to access, correct, delete and port your personal information, and to opt out of its sale or sharing.
RefundHound satisfies these by design rather than by process. I am not a controller or processor of your refund data because I never receive it: access and correction happen directly in the app, deletion is immediate and permanent, portability is the CSV export, and there is no sale or sharing to opt out of. If you email me about a support question, that correspondence is the only personal information I ever hold, and you can ask me to delete it at any time.
Who is responsible for your data
For your refund data, nobody but me needs naming — it never reaches me, so there is no controller of it in the legal sense. Support correspondence is the one exception. If you email me, Nilbyte Studio is the data controller for your address and whatever you wrote:
You also have the right to complain to a data protection authority. Nilbyte Studio is established in Sweden, so the lead authority is Integritetsskyddsmyndigheten (IMY). If you live or work elsewhere in the EEA or the UK, you may complain to your own country's supervisory authority instead — you do not need to raise it with me first. Though if something here concerns you, I would rather hear about it and fix it.
Changes to this policy
If the app ever changes in a way that affects this policy, I will update this page and change the date at the top before the change ships. Material changes will also be noted in the app's release notes.
Contact
Questions about this policy or the app: refundhound@nilbytestudio.com