SUM100 household budget
Privacy Policy
Last updated: 25 September 2026
This policy explains how personal information is processed when you use SUM100. It covers the demo budget, your own local budget, and optional cloud accounts.
Controller and contact
SUM100 is operated as a private hobby project by Peter Ekmark, who is the controller for the processing described here. Questions can be sent to peter@sum100.app.
Information processed
- Account information, such as email address, display name, technical user ID, and selected language.
- Budget content that you enter, such as people, categories, amounts, loans, credit card invoices, notes, and web addresses.
- Sharing information, such as a recipient's email address, role, membership, and invitation status.
- Technical information needed for connectivity, authentication, security, and troubleshooting, such as IP address, browser information, and technical logs.
- Information that you provide when contacting support.
Most information is provided directly by you. A recipient's email address is provided by the budget owner when sending an invitation. Technical connection information is collected automatically when the service is used.
Google sign-in and Google user data
If you choose Sign in with Google, SUM100 uses Google OAuth through Firebase Authentication.
- Access: SUM100 may receive the Google account's unique identifier, email address, email verification status, display name, and profile photo URL if Google provides it.
- Use: The information is used to sign you in, identify and display your SUM100 account, protect access to your budgets, match budget invitations, and confirm your identity for actions such as account deletion. The profile photo is not displayed in SUM100.
- Limited permission: SUM100 requests only basic profile and email information for sign-in. It does not request access to Gmail, Google Drive, Google Calendar, Google Contacts, payment information, or other Google services.
- Sharing: Google user data is processed by Google Firebase for authentication. The email address may also be stored for memberships and invitations and shown to people who administer or participate in a budget that you choose to share. The information is not sold or used for advertising, credit assessment, or training AI models.
- Retention and deletion: Google account information is stored in Firebase Authentication while the SUM100 account exists. You can delete your account in the app. The authentication account and related information are then removed according to the retention periods below.
Demo and your own budget without an account
The demo can be used without an account and is stored temporarily for the browser session. Your own budget without an account is stored in the current browser and may be lost if site data is cleared. Language, theme, text size, and the last selected cloud view may also be stored locally. SUM100 does not use analytics or advertising cookies.
Purposes and legal bases
- Creating accounts, storing and displaying budgets, synchronising changes, and administering sharing: necessary to provide the service you request (contract).
- Security, error handling, abuse prevention, and support: the legitimate interest in operating a safe and functioning service.
- Complying with legal requirements or managing legal claims where applicable: legal obligation or legitimate interest.
SUM100 does not make automated decisions or use profiling that produces legal or similarly significant effects.
Information the service is not intended for
SUM100 is not intended for special categories of personal data. Avoid entering information that reveals health, religion, political opinions, trade union membership, sex life, or sexual orientation in categories or notes.
Recipients, cloud services, and transfers
Cloud accounts, authentication, and budget data are handled using Google Firebase. When you share a budget, its contents become available to the participants and roles that you select. The browser also downloads interface resources from Google, jsDelivr, and cdnjs, which means that these providers may receive technical connection information. For customer data processed through Firebase, Google generally acts as a processor under the applicable data protection terms. Read Google's information about privacy and security in Firebase.
Google and other providers may process information outside the EU/EEA. Where required, transfers are supported by an adequacy decision, such as the EU–US Data Privacy Framework, or by the European Commission's Standard Contractual Clauses and supplementary safeguards.
Retention and deletion
The demo is stored for the browser session. A local budget and local preferences remain until site data is cleared. Cloud accounts and budgets are retained while needed for the service. When you delete your account, budgets that you own are deleted and you leave budgets owned by others. Invitations are valid for seven days and are deleted when accepted or revoked; an expired invitation is deleted the next time the budget owner or verified recipient opens invitation management. Google states that Firebase Authentication IP logs are retained for a few weeks and Firebase Hosting IP logs for a few months. After deletion is initiated, authentication information may remain in live systems and backups for up to 180 days.
Security
Cloud budgets are transferred over an encrypted HTTPS connection, and Google encrypts data stored in Firebase. Authentication and Firestore rules restrict access to the budget owner and the participants selected by the owner. Budgets are not end-to-end encrypted. SUM100 has no administrator view for reading users' budgets. As the person responsible for the Firebase project, Peter Ekmark can still retrieve stored information using administrative tools. Peter does not routinely review users' budgets.
Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, and data portability, and object to processing based on legitimate interests. Contact SUM100 at the address above. Information needed to verify your identity may be requested, and you will normally receive a response within one month. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection.
Changes
The policy is updated if the service or processing changes. The date above shows the current version. Users are informed in the service about material changes.