1. Who is responsible
The controller responsible for this website and the Glowbug app is Jan Lennartz. You can contact us at brubyte.labs@gmail.com.
2. Scope of this policy
This policy explains how data is handled when you visit glowbug.eu, contact support, or use the Glowbug app. Glowbug is an independent client for Firefly III. Your own Firefly III operator may have separate privacy obligations and policies.
3. Website delivery and server logs
When you open this website, the hosting system must process technical request data such as your IP address, the requested page, date and time, browser information, and referring page. This is necessary to deliver the website, maintain security, and diagnose technical problems.
The legal basis is our legitimate interest in providing a secure and reliable website. Technical logs are not used to create advertising profiles.
4. Privacy-friendly website analytics
We use a self-hosted installation of Umami to understand aggregate website usage. Umami does not use cookies, does not track visitors across websites, and does not store personally identifiable information. Analytics data remains on infrastructure controlled by us.
The tracker records anonymous page views and technical context such as the referrer, browser, operating system, device type, and approximate country. Search parameters and URL fragments are excluded. The tracker also respects your browser's Do Not Track setting.
The legal basis is our legitimate interest in improving the website while minimizing personal data processing. Because Umami uses no cookies, no analytics cookie is placed on your device.
5. Support messages
If you email support, we process the information you provide to answer your request and investigate the problem. Email is handled through Gmail, a service provided by Google. Never include access tokens, passwords, server addresses, or financial records in a support message.
We retain support correspondence for as long as needed to resolve the request and to document recurring technical issues, unless legal obligations require a longer period.
6. Data handled by the Glowbug app
Glowbug does not require a Glowbug account and does not send your financial data to a Glowbug service. The app connects directly to the Firefly III instance you configure.
Instance details, cached Firefly III data, offline transactions, settings, and optional receipt files are stored locally on your device. Access tokens are stored in the iOS Keychain with device-only protection. Receipt files waiting for upload use iOS file protection.
- Camera access is requested only when you choose to photograph a receipt.
- Face ID or device passcode access is used only when you enable app or credential protection.
- The app declares no tracking and no data collection by the developer.
- Data sent to your Firefly III server is governed by your server configuration and operator.
7. Deleting app data
You can remove configured instances and their local data from within Glowbug. Uninstalling the app removes its local app container. Data already uploaded to your Firefly III server must be managed on that server.
8. Your rights
Depending on applicable data protection law, you may have rights to access, correct, delete, restrict, or receive a copy of personal data we process, and to object to certain processing. You may also lodge a complaint with your competent supervisory authority.
To exercise a right, contact brubyte.labs@gmail.com. We may need enough information to verify and handle the request, but we will not ask for your Firefly III credentials.
9. Changes
We may update this policy when Glowbug, the website, or legal requirements change. The date at the top of this page shows the latest revision.