Legal
Privacy Policy
NoBuyBox is built to keep your urges your business. This policy explains, in plain language, exactly what data we process and the rights you have.
01Who we are#
NoBuyBox (the Android and iOS app and the website nobuybox.monryte.com) is provided by MONRYTE S.R.L., a Romanian limited liability company with its registered office at Str. Baia nr. 10, Sector 1, 013496 București, Romania, Trade Register no. J2026032634002, fiscal code (CUI) 54716131, VAT no. RO54953006 (“Monryte”, “we”, “us”). We are the controller of the personal data described in this policy.
For anything about your data, write to nobuybox@monryte.com. We have not appointed a Data Protection Officer because the law does not require one for our activities; this address reaches the people responsible for privacy at Monryte.
02What this policy covers#
This policy explains what personal data we process when you use the NoBuyBox app, the Buddy pages (links that start with nobuybox.monryte.com/b/ or /r/), the Wishlist pages (links that start with nobuybox.monryte.com/w/) and this website, why we do it, and the rights you have under the EU General Data Protection Regulation (“GDPR”) and other privacy laws.
NoBuyBox is built local-first: it works without an account, and most of what you type stays on your phone. Several features are optional and only send data when you turn them on. The sections below say exactly what leaves your phone and when.
03The data we process, and why#
1. What stays on your phone (not collected by us)
- What: your boxes (item name, price, category, note, product link, photo), timers, decisions and history, goals and money kept, Pro tools you set up (challenges, return reminders with item name, price and return date, rules, treat allowance, payday buffer, gift budget with the people you buy for, their budgets and what you spent), and settings.
- Why: so the app works. This data is stored only in the app’s storage on your device. We do not receive it unless you turn on backup (see 3), send a Buddy request (see 4) or use Wishlist (see 5).
- Legal basis: not applicable — we do not process this data. Photos are only read from your library or camera after you grant the operating system permission, and stay on the device.
- How long: until you delete it (Me → Delete everything on this phone) or uninstall the app.
2. Your account (optional)
- What: email address, the sign-in method you chose (Sign in with Apple, Google, or a one-time email link), a random account ID, and technical sign-in records kept by our authentication service (such as time of sign-in and the IP address used), for security. If you use Sign in with Apple you can hide your real email; we then only see Apple’s relay address. We never receive your Apple or Google password.
- Why: to create and secure your account, send you sign-in and account emails, back up and restore your boxes, and let you use features that need an account (Buddy, Wishlist).
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR); security logs — our legitimate interest in keeping accounts safe (Art. 6(1)(f)).
- How long: while your account exists. When you delete your account, it is erased within 30 days (see Delete your account).
Sign-in and account emails (such as the one-time sign-in link) are sent from nobuybox.monryte.com through our email provider Resend, using its EU sending region. If Resend is unavailable, the same email is sent through the mail server of our hosting provider in Romania (nxtHost). For this they receive your email address and the content of the email (including the sign-in link).
3. Cloud backup (optional, only when signed in)
- What: a copy of your boxes, history, goals, Pro tool settings (challenges, return reminders, rules, treat allowance, gift budget) and settings — including the names, prices, notes and links you typed. Photos themselves are not uploaded; the backup only keeps a reference to the file on your phone.
- Why: so you don’t lose your boxes and can move them to a new phone.
- Legal basis: performance of our contract with you (Art. 6(1)(b)).
- How long: while your account exists; erased with your account within 30 days of a deletion request. “Delete everything on this phone” does not delete the backup — deleting your account does.
The backup is stored in the European Union (Frankfurt, Germany) by our hosting provider Supabase. It is encrypted in transit (TLS) and at rest, and database rules only let your own account read or change it. It is not end-to-end encrypted: our staff can technically access it, but only do so when needed to help you at your request, to keep the service secure, or when the law requires it.
4. Buddy unlock (optional, Pro)
- What: for the invite: your display name (if you set one), the first name you give your buddy, a random invite code, its status and dates. For an early-open request: the box name, your optional note (up to 140 characters), when the box unlocks, a random request code, and the answer with its time. If your buddy accepts inside the app while signed in, their account ID is linked to the invite.
- Why: to let a friend you choose approve or refuse opening a strict box early. Your buddy sees your name, the box name, your note and the time left — not the price.
- Legal basis: performance of our contract with you (Art. 6(1)(b)); for your buddy, our legitimate interest in running the feature they agreed to take part in (Art. 6(1)(f)). Your buddy can use the web page without an account.
- How long: invite links expire after 7 days and requests after 24 hours; the records are kept while your account exists and are erased with it. Removing your buddy ends their access.
5. Wishlist (optional, only when signed in)
- What: for you, the owner: your occasions (title, kind, date, message, the surprise and exact-price settings, the first name you choose to show friends, currency) and their items (name, price, optional store link, category, priority, the date you marked it received). When you share an occasion, a long random link code. For friends who open the link: if they reserve (“claim”) an item, we store the item, a random token kept in their browser’s local storage and the time — no name, no account, no email. To protect the pages from abuse, we briefly record the friend’s token and IP address with a timestamp for rate limiting.
- Why: so you can keep gift wishlists and share them with people you choose, and so friends can see what you would like and reserve an item without doubling up. Anyone with the link (nobuybox.monryte.com/w/…) can view the list without an account. They see the first name you chose (never your email), the occasion, your message, the items with a price range (the exact price only if you turn it on) and store links. You only see whether an item is claimed — and only if you turn “surprise” off — never who claimed it.
- Legal basis: performance of our contract with you (Art. 6(1)(b)); for friends’ claims, our legitimate interest in running the feature they chose to use, and for rate limiting, our legitimate interest in keeping the pages secure and available (Art. 6(1)(f)). Friends can use the page without an account.
- How long: occasions and items while your account exists, or until you delete the occasion, which also deletes its items and claims. If you turn a link off, the page shows “no longer available”. A claim is kept until the friend or you remove it, or until the occasion or your account is deleted. Rate-limit records are deleted within 1 hour (a job removes older ones every 15 minutes). Deleting your account deletes all your wishlist data.
Wishlist data is stored in the European Union (Frankfurt, Germany) by Supabase, like the backup, and database rules only let your own account read or change your lists. The friend page loads no third-party scripts, sets no cookies and runs no analytics; it only contacts our database to show the list and record claims.
6. Notifications
- What: “Ready” alerts, the weekly recap, the evening check-in, return reminders and the trial reminder are scheduled locally on your phone and never pass through our servers. For Buddy only, we store a push token for your device (with your account ID and platform) to deliver Buddy messages, which contain your buddy’s name and the box name.
- Why: to tell you when a box is ready and to deliver Buddy invitations, requests and answers.
- Legal basis: your consent to notifications, given in the operating system (Art. 6(1)(a)), and performance of our contract (Art. 6(1)(b)). You can turn notifications off in your phone’s settings at any time.
- How long: push tokens are deleted when you sign out, when the device stops accepting notifications, or with your account.
7. Purchases and Pro status
- What: a purchase user ID (random, or your account ID if you are signed in), the product you bought, transaction identifiers and receipts, subscription and trial status, store country and currency. Payments are handled by Google Play or the App Store — we never see your card or bank details.
- Why: to unlock Pro, restore purchases on your devices, handle trials and renewals, and meet our accounting duties.
- Legal basis: performance of our contract (Art. 6(1)(b)); legal obligation for tax and accounting records (Art. 6(1)(c)).
- How long: for as long as your purchase gives you Pro, and afterwards as long as required by tax and accounting law.
8. Anonymous usage events (you can switch this off)
- What: events such as “box sealed”, “decided: let go”, “paywall viewed” or “settings changed”, with small technical details (for example the timer length, a money amount when you let something go, the plan viewed), a random install ID that is not linked to your account, app version, platform, language and time. Never the names, notes, links or photos you add, and never your email.
- Why: to understand which parts of NoBuyBox help people and to fix what doesn’t.
- Legal basis: our legitimate interest in improving the app (Art. 6(1)(f)). You can object at any time with one switch: Me → Terms & Privacy → Anonymous usage events. When it is off, nothing more is sent.
- How long: up to 24 months, after which events are deleted or aggregated so that no install can be singled out.
9. Crash reports (covered by the same switch)
- What: if the app crashes or hits an error: the error and where in the code it happened, app version, device model and operating system, and the random install ID. Before sending, the app removes emails, money amounts, the names you typed and web-address details. Sending your IP address as personal data is disabled.
- Why: to find and fix bugs and keep the app stable and secure.
- Legal basis: our legitimate interest in a working, secure app (Art. 6(1)(f)). The “Anonymous usage events” switch turns crash reports off too.
- How long: up to 90 days in our crash-reporting service (Sentry, EU data region in Germany).
10. Support and privacy requests
- What: your email address, what you write to us and any details you choose to share.
- Why: to answer you and, for rights requests, to show we handled them correctly.
- Legal basis: our legitimate interest in helping our users (Art. 6(1)(f)); legal obligation for GDPR requests (Art. 6(1)(c)).
- How long: up to 3 years after the conversation ends (the general limitation period for claims in Romania), unless we need it longer to defend a legal claim.
11. Price Watch (coming soon)
- What: Price Watch is not live yet. Joining the waitlist is recorded only as an anonymous usage event (see 8).
- Why: to know who asked to be told when it launches, inside the app.
- Legal basis: as for usage events.
- How long: as for usage events. Before Price Watch launches we will update this policy to describe how it checks the product links you save.
04Legal bases in short#
- Contract (Art. 6(1)(b) GDPR): account and sign-in emails, backup, Buddy, Wishlist (for the owner), Pro purchases, Buddy notifications.
- Legitimate interests (Art. 6(1)(f)): anonymous usage events, crash reports, security logs, support, friends’ Wishlist claims and Wishlist rate limiting. We have weighed these interests against your rights: the data is minimal and pseudonymous, never used for advertising, and you can object at any time.
- Consent (Art. 6(1)(a)): notification and photo permissions, which you grant and can withdraw in your phone’s settings.
- Legal obligation (Art. 6(1)(c)): accounting and tax records, answering authorities and rights requests.
We do not use your data for advertising, we do not build advertising profiles, and we do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
05Who receives data#
We never sell your personal data and never share it with advertisers or data brokers. We use a small number of service providers (“processors”) who act only on our instructions under data-processing agreements, and some independent controllers you choose to use:
| Provider | Role | Data | Location |
|---|---|---|---|
| Supabase, Inc. | Processor — database, authentication, server functions (including the one that prepares sign-in emails) | Account, backup, Buddy records, Wishlist records and rate-limit records, push tokens, usage events | EU — Frankfurt, Germany (AWS eu-central-1); support access from the USA possible |
| Resend, Inc. | Processor — sends sign-in and account emails (from nobuybox.monryte.com) | Email address, email content (sign-in link) | EU sending region; company in the USA — Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Processor — crash reporting | Crash reports (see 9) | EU data region (Germany); company in the USA |
| RevenueCat, Inc. | Processor — purchase validation and Pro status | Purchase data (see 7) | USA |
| 650 Industries, Inc. (Expo) | Processor — push notification delivery | Push token, Buddy notification text | USA |
| Google (Firebase Cloud Messaging) | Processor — delivers push notifications to Android | Push token, notification text | EU / USA |
| Frankfurter (frankfurter.dev) | Public exchange-rate service (European Central Bank reference rates), used when you pick a currency | No account or app data — only the technical request (IP address) | EU |
| Google Play, Apple App Store | Independent controllers — payments, refunds, subscriptions | Your store account and payment | Under their own privacy policies |
| Apple (Sign in with Apple, push service), Google (Sign-In) | Independent controllers for your Apple / Google account | Sign-in and notification delivery | Under their own privacy policies |
| Our web and email host (NXTSERVERS SRL (nxtHost), Romania) | Processor — hosts this website and our mailbox; backup sender for sign-in emails when Resend is unavailable | Website server logs, emails you send us, sign-in emails (email address and content) sent through it | Romania |
Your buddy sees what is described in section 4. People you share a wishlist link with see what is described in section 5. We may also disclose data if required by law or a binding order of an authority, to protect our rights in a legal claim, or to a successor if Monryte’s business is transferred — in which case this policy continues to protect your data.
06International transfers#
We keep your account, backup and usage data in the EU. Some providers above are based in the United States or may access data from there. When personal data is transferred outside the European Economic Area, we rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework (for certified recipients) and/or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, together with additional safeguards where needed (such as encryption in transit and data minimisation). You can ask us for a copy of the relevant safeguards at nobuybox@monryte.com.
07How long we keep data#
| Data | Kept |
|---|---|
| Data on your phone | Until you delete it or uninstall the app |
| Account and cloud backup | While the account exists; erased within 30 days after you delete it (a daily job removes accounts whose deletion date has passed) |
| Buddy invites and requests | While your account exists; erased with it |
| Wishlist occasions, items and claims | Until you delete the occasion (items and claims go with it) or your account; a claim also ends when the friend or you remove it |
| Wishlist rate-limit records (token, IP address, time) | Deleted within 1 hour |
| Push tokens | Until sign-out, until the token becomes invalid, or until account deletion |
| Purchase records | While they give you Pro, then as required by tax and accounting law |
| Anonymous usage events | Up to 24 months, then deleted or aggregated |
| Crash reports | Up to 90 days |
| Support emails | Up to 3 years after the conversation ends |
| Website server logs | A short period for security, normally no more than 30 days |
Deleted data may remain for a short time in our providers’ encrypted backups until those are overwritten in their normal cycle; it is not used in the meantime.
08Your rights#
Under the GDPR you have the right to:
- access your data and receive a copy (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure (“right to be forgotten”, Art. 17);
- restriction of processing (Art. 18);
- data portability — receive your data in a structured, machine-readable format (Art. 20). In the app you can export your boxes and history as CSV any time;
- object to processing based on legitimate interests (Art. 21) — for usage events and crash reports, just switch them off;
- withdraw consent at any time, without affecting what was done before (Art. 7(3));
- not be subject to solely automated decisions with legal or similarly significant effects (Art. 22) — we make none.
More detail and a step-by-step guide: Your GDPR rights.
09How to exercise your rights#
- In the app, instantly: export (Me → Export as CSV), delete local data (Me → Delete everything on this phone), delete your account and backup (Me → Account → Delete account), stop usage events and crash reports (Me → Terms & Privacy).
- By email: write to nobuybox@monryte.com from the email address of your account, if you have one, and tell us what you would like. If we cannot confirm who you are, we may ask for more information — only as much as needed.
We answer without undue delay and within one month. For complex or numerous requests we may extend this by two more months and will tell you why. Requests are free unless they are manifestly unfounded or excessive.
10Complaints#
If you think we have not respected your rights, please tell us first — we will try to fix it. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live, work or where the issue happened. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, www.dataprotection.ro, anspdcp@dataprotection.ro. You may also go to court.
11Children#
NoBuyBox is not directed at children under 16, and you must be at least 16 to create an account. We do not knowingly collect personal data from children under 16. If you believe a child has given us personal data, contact us and we will delete it.
12Security#
We protect data with encryption in transit (TLS) and at rest, database rules that let each account reach only its own data, server functions that can only be called with a secret, random unguessable codes for Buddy links that expire (7 days for invites, 24 hours for requests), long random Wishlist links that you can turn off at any time, rate limits on the Wishlist pages, minimal access for our staff, and privacy scrubbing of crash reports. No system is perfectly secure; if a personal data breach is likely to put you at risk, we will tell you and the authority as the GDPR requires.
13This website and cookies#
This website does not use advertising or analytics cookies, tracking pixels or third-party trackers, and it loads its fonts from our own server. Our web host keeps standard server logs (IP address, time, page requested, browser type) for security and to keep the site running — our legitimate interest (Art. 6(1)(f)). The Buddy pages contact our database (Supabase, EU) only to show and answer the invite or request in the link. The Wishlist pages contact it only to show the list and record claims; they keep a random claim token in your browser’s local storage so you can see and undo your own claims, and set no cookies. See the Cookie notice.
14Notice for US residents (CCPA / CPRA and other state laws)#
In the last 12 months we collected these categories of personal information, only for the purposes explained above: identifiers (email, account ID, random install ID, push token), commercial information (purchases and subscription status), internet or other electronic network activity (in-app usage events and crash diagnostics), and user content you back up, send to a buddy or share in a wishlist. Sources: you, your device, and Google Play / the App Store.
- We do not sell personal information and do not share it for cross-context behavioral advertising. We have not done so in the last 12 months.
- We do not use or disclose sensitive personal information to infer characteristics about you.
- You have the right to know, access, correct and delete your personal information, and not to be discriminated against for using these rights. Residents of other US states with privacy laws (such as Virginia, Colorado, Connecticut, Utah and Texas) have similar rights, including to appeal a refusal.
- To make a request, email nobuybox@monryte.com. You may use an authorized agent; we may ask for proof of the authorization and to verify your identity.
15Summary for Google Play “Data safety”#
This matches what we declare on Google Play. “Shared” means transferred to a third party other than our service providers.
| Data type | Collected | Shared | Purpose | Optional |
|---|---|---|---|---|
| Email address | Yes, if you create an account | No | Account management, app functionality (backup) | Yes |
| Name (your display name, your buddy’s first name, the first name you show on a wishlist) | Yes, if you use Buddy or Wishlist | No | App functionality | Yes |
| Other user-generated content (backup; box name and note in Buddy requests; wishlist occasions and items) | Yes, if you back up, use Buddy or use Wishlist | No | App functionality | Yes |
| Purchase history | Yes, if you buy Pro | No | App functionality (unlock Pro) | Yes |
| App interactions | Yes | No | Analytics | Yes — can be switched off |
| Crash logs and diagnostics | Yes | No | App stability | Yes — can be switched off |
| Device or other IDs (install ID, push token, purchase user ID) | Yes | No | Analytics, app functionality | Partly |
| Photos, location, contacts, financial accounts, messages, web history | No | No | — | — |
Data is encrypted in transit. You can ask us to delete your data — in the app or at nobuybox.monryte.com/delete-account.
16Changes to this policy#
We will update this policy when NoBuyBox or the law changes. The date at the top shows the latest version. If a change is significant, we will tell you in the app or by email before it takes effect.
17Contact#
MONRYTE S.R.L., a Romanian limited liability company with its registered office at Str. Baia nr. 10, Sector 1, 013496 București, Romania, Trade Register no. J2026032634002, fiscal code (CUI) 54716131, VAT no. RO54953006.
Email: nobuybox@monryte.com
This policy is available in English and Romanian; both versions are equally valid.