BorroBorro.
Legal — Borro

Privacy Policy.

Last updated: 20 July 2026 Applies to: the Borro app & borro.aroralabs.org
In plain English. Borro is offline-first. If you never sign in, everything you enter stays on your device and we never see it. When you choose to sign in, you turn on optional cloud backup & sync — only then is your ledger (and any receipt photos you back up) stored on our cloud so it can back up, sync across your devices, and reach the specific people you share expenses with. Borro is about money between people, so it also stores the names, and any phone numbers or emails you add, for the people you track — please only add people whose details you’re entitled to record. We don’t sell your data, we don’t show ads, we don’t use your ledger to train models, and you can export or delete everything at any time.
1

Overview & who we are

This Privacy Policy explains what data the Borro mobile app (“Borro”, the “app”) and the website at borro.aroralabs.org collect, how it is used, the third parties involved, and the choices and rights you have. Borro is provided by AroraLabs (“we”, “us”, “our”), a studio based in Australia. For the purposes of the EU/UK GDPR we are the data controller for the personal data described here; for the purposes of the Australian Privacy Act we are the entity responsible under the Australian Privacy Principles (APPs).

Our guiding principle is data minimisation: the app is designed to work entirely on your device, and any data leaves your device only to deliver a feature you have explicitly turned on — signing in for cloud backup, sending an entry to someone, settling up, or asking us for help. By using Borro you agree to the handling of data as described in this policy. If you do not agree, please do not use the cloud features (or, for the offline-only app, simply do not sign in).

Contact: for any privacy question or request, email support@aroralabs.org. (Our system emails are sent from contact@aroralabs.org; the address to reach a human is support@aroralabs.org.)

2

Key terms used in this policy

  • Ledger: the people, transactions, amounts, balances, groups, splits, notes, categories and receipts you record in Borro.
  • Personal data / personal information: information that identifies, or can reasonably be linked to, an identifiable individual — including you and the people you add.
  • Processing: any operation performed on personal data (collecting, storing, using, sharing, deleting).
  • Processor / sub-processor / service provider: a third party that processes data on our behalf and under our instructions (for example, Google Firebase). We name them in Section 8.
  • Guest account: an anonymous, on-device account created without email or social sign-in. A real account is one created with Apple, Google or email.
  • Pro: the optional paid tier (see our Terms of Service) that unlocks cloud backup, multi-device sync, receipt cloud storage and other features.
3

Data stored on your device

By default, your information lives only in a local database on your phone. This includes the people you track, your transactions and balances, groups and splits, notes, categories, receipt photos, currency settings, home-screen widget summary and app preferences. This local database is the app’s primary store — the cloud, when enabled, is a mirror and backup of it.

The following also stay purely on your device and are never transmitted to us:

  • Receipt text recognition (OCR). When you scan a printed receipt, text is recognised entirely on-device using Apple/Google’s on-device machine-learning libraries. The image is not sent to any server for recognition.
  • App Lock (Face ID / Touch ID / passcode). Biometric checks are performed by your operating system. Borro never receives or stores your biometric data — it only receives a “pass/fail” result.
  • Camera use for QR settle-up. Camera frames are processed on-device to read a settle QR code; only the decoded payload is used.
  • The home-screen widget summary (a locked/unlocked balance snapshot) is written to your device’s local widget storage only.

If you never sign in and never share an entry, none of your data is transmitted to us or anyone else, and we have no ability to access it.

4

Data stored in the cloud (only when you sign in)

Signing in — with Apple, Google, or an email address (password or one-time code) — enables cloud backup & sync. From that point, the following is stored on our cloud infrastructure (Google Firebase; see Section 8) so your data is backed up and can sync between your devices and to the people you transact with:

  • Account & identity: your display name, a unique @username (a handle you choose once at sign-up), email address (stored in lowercase), the sign-in provider used (Apple, Google, email or guest), whether your email is verified, your profile photo or chosen avatar, and an opaque account identifier (your “uid”).
  • Email directory entry: when your email is verified, a lookup record keyed to your email address (containing your uid, display name and avatar) is stored so that people who already have your email can connect with you on Borro. You can remove this by deleting your account.
  • Your ledger: people, transactions, amounts, currencies, dates, due dates, free-text notes, categories, groups, splits, recurring-entry settings, and computed balances and statistics.
  • Receipt & profile images (see Section 8 for storage paths): your profile/avatar image; receipts you attach to entries; and receipts on shared group expenses.
  • Sharing & settlement records: when you send an entry for approval, invite someone, request a payment, settle up, forgive a balance, or add someone to a group, the information required for that action (amount, currency, your name and email, the counterparty’s name/email, any note, category or receipt you attach, and a change history for shared entries) is stored so the other person can receive and confirm it.
  • Subscription & entitlements: your Pro tier and its source, and — when you purchase — the store purchase receipt / token (Apple’s receipt data or Google’s purchase token) needed to verify and maintain your subscription, plus a one-way hashed binding that locks a purchase to a single account.
  • Preferences that sync: home currency, notification channel/type toggles, receipt-retention preference, and similar settings.
Receipt photos & your plan. Cloud backup of your personal receipt images is part of Borro Pro; on the free tier, personal receipts stay local to the device that created them. Receipts attached to a shared 1:1 entry or a group expense are always uploaded regardless of plan, because the other person needs to see them. We may apply reasonable fair-use limits to receipt-image cloud storage; any such limits are described in the app.
5

Information about the people you add

Because Borro tracks money between people, when you add someone to your ledger you may record their name, and optionally a phone number, email address or photo. If you later back up or share that entry, this information about them is stored in the cloud alongside your own data, and — for shared or settled entries — is transmitted to that person so they can confirm it.

Many of these people may not be Borro users and have not themselves agreed to this policy. You are responsible for only adding details you are entitled to record, and for having a lawful basis (such as your legitimate personal interest in tracking a debt) to include another person’s information. If you are in the EEA/UK and add someone’s data, you act as an independent controller for the purposes of your own record-keeping. If someone you have added asks us to remove their information, we will act on reasonable requests where we can identify the data — contact us at support@aroralabs.org.

6

Device, session & technical data

When you use cloud features, we also process technical data needed to run and secure the service:

  • Device & install information: a random per-install device identifier, your device model and device name (which, depending on how you named your phone, may include your own name — e.g. “Alex’s iPhone”), operating-system version, app version, build type, language/locale, timezone, and session counts.
  • Session & single-device lock: the identifier of the currently active device, its platform, and a timestamp — used to keep a free account limited to one active device at a time, and to let Pro sync across several.
  • Push tokens: your Firebase Cloud Messaging token and, on iOS, your Apple Push Notification token — required to deliver notifications. These are cleared when you sign out.
  • Approximate location (country only): to localise pricing and content and to help prevent abuse, the app determines your country from your device’s IP address. Your IP address is sent to third-party geolocation services (ipapi.co and ipwho.is) which return a country; we store only the resulting country and country code, not your IP address. As with any internet service, our infrastructure providers also process your IP address transiently to deliver and secure requests.
  • Device-integrity attestation (App Check): to protect our backend from abuse, the app may generate a device-attestation token via Apple’s App Attest or Google’s Play Integrity and send it with requests to our servers. This token attests that the request comes from a genuine app instance; it is not used to identify you personally.
  • Diagnostics you send: if you submit feedback or a bug report, we receive your uid, email, the app version, device model, OS version, whether the device is physical, your country, and whatever text you write.
  • Crash & usage diagnostics: see Section 11.
7

How we use your data — and our legal bases

We use your data solely to provide and operate the features you ask for: storing your ledger, backing it up, syncing it across your devices, delivering shared entries and settlements to the right people, sending the notifications and emails you have enabled, verifying and maintaining purchases, providing support, keeping the service secure, and improving reliability. We do not use your data for third-party advertising, cross-context behavioural advertising, profiling, or training AI/ML models, and we never sell or rent it.

Where the EU/UK GDPR (or a similar “legal basis” regime) applies, we rely on the following bases per purpose:

PurposeLegal basis (GDPR)
Providing your account, cloud backup, sync, sharing & settlementPerformance of a contract (Art. 6(1)(b))
Recording details of people you add to your ledgerOur and your legitimate interests in tracking debts (Art. 6(1)(f)); you are responsible for your own basis
Push tokens & sending notifications you enabledConsent via your device permission, plus contract (Art. 6(1)(a)/(b))
Verification, one-time-code, password-reset & transactional emailContract and legitimate interests (Art. 6(1)(b)/(f))
Single-device lock, App Check, abuse/rate-limit preventionLegitimate interests in security & fair use (Art. 6(1)(f))
Country-from-IP for localisation & fraud preventionLegitimate interests (Art. 6(1)(f))
Analytics & crash diagnostics (aggregate, opaque-id only)Legitimate interests in improving & stabilising the app (Art. 6(1)(f)) — you may object
Verifying purchases & keeping tax/transaction recordsContract and legal obligation (Art. 6(1)(b)/(c))
Handling support requests and complying with lawLegitimate interests and legal obligation (Art. 6(1)(f)/(c))
8

Service providers & sub-processors

We rely on trusted providers to run Borro’s cloud features. Your cloud data is stored on their infrastructure under our project and is processed only to deliver the service, under each provider’s own security and privacy commitments.

PurposeProviderData involved
Sign-in & account identityApple, Google, Google Firebase AuthenticationEmail, name, provider id, uid
Cloud backup & sync of your ledgerGoogle Cloud FirestoreYour ledger, sharing & settlement records
Image storage (avatars & receipts)Google Firebase Cloud StorageProfile images at userAvatars/, 1:1 receipts at txnReceipts/, group receipts at groupReceipts/
Server-side logic (sharing, settlements, entitlements, deletion)Google Cloud FunctionsLedger & account data as needed per action
Push notificationsFirebase Cloud Messaging, Apple Push Notification servicePush tokens; notification title/body/data (names, amounts, notes, receipt links)
Verification, one-time-code, reset & transactional emailZoho Mail (SMTP, via an Australian endpoint)Recipient email; message content (names, amounts, notes for shared entries)
Device-integrity attestationFirebase App Check (Apple App Attest / Google Play Integrity)Attestation token (not personal)
Translating in-app announcementsGoogle Cloud TranslationOnly our admin-authored announcement text — no user data
Approximate country from IPipapi.co, ipwho.isYour IP address (we keep only the returned country)
Currency conversion ratesExchangeRate-API (open.er-api.com)A three-letter currency code only — no personal data
Product analytics (aggregate)Google Firebase AnalyticsOpaque uid + product events (no name/email)
Crash & error diagnosticsGoogle Firebase CrashlyticsOpaque uid + crash traces (release builds only)
In-app purchases & subscriptionsApple App Store, Google PlayPurchase receipts/tokens (verified server-side)

Purchases are handled entirely by Apple or Google; we never receive your full payment-card details. We also operate an internal administrative console (“Atlas”) used by our team to run the service; a limited signal — such as a new user’s name and email at first join — may be relayed to that console so we can support and monitor the app. Purchases are validated by sending the store’s receipt or token to Apple and Google’s verification endpoints.

9

Sharing with other people

Borro is about money between people, so some information is shared by design — but only what is necessary, and only with the specific people involved. When you send an entry for approval, request a payment, settle up, forgive a balance, invite someone, or add a member to a group, that person receives the relevant amount, currency, your name and email, and any note or receipt you chose to attach — by push notification, in-app inbox, and/or email. In a shared group, group members can see group expenses, splits and any receipts attached to them. People you have never shared anything with never see your data.

Because each side keeps its own copy of a shared 1:1 entry, information the other person recorded about a transaction with you remains in their ledger even after you delete yours. We do not otherwise disclose your personal data to third parties, except: to our service providers (Section 8); to comply with law, legal process, or a lawful government request; to protect the rights, safety and property of AroraLabs, our users or the public; or in connection with a business transfer (merger, acquisition or sale of assets), in which case we will require the recipient to honour this policy or notify you of any change.

10

Notifications & email

With your permission, Borro sends push and local notifications (for approvals, confirmations, settlements, reminders, milestones and occasional announcements). Push delivery uses Firebase Cloud Messaging and Apple’s push service and requires a device push token. You can turn notifications off at any time in the app (per channel and type) or in your device settings.

We also send email for: address verification, sign-in one-time codes, password resets, and — where you or the counterparty has opted in, or where an invited person is not yet on Borro — notifications about shared entries, settlement requests, reminders and group invites, plus an occasional “restore your account” nudge if you have scheduled deletion. Transactional emails (verification, codes, resets) are necessary to operate your account and are not marketing. We do not send unrelated marketing email.

11

Analytics, crash reporting & advertising

The app uses Google Firebase Analytics to understand aggregate, product-level usage (for example, how many people complete sign-up or view the paywall) and Google Firebase Crashlytics to diagnose crashes and errors. These are tied to an opaque account identifier — not your name or email — and event parameters contain product metadata only (such as a screen name or product id), never the contents of your ledger. Both are turned off entirely in debug builds and run only in released builds.

The app contains no third-party advertising SDKs, we do not show ads, and none of this data is used for advertising, cross-context behavioural advertising, or profiling. We do not use motion sensors or track your precise location.

We currently rely on legitimate interests for this limited diagnostic processing and do not offer a separate in-app analytics toggle; if you are in a region where you may object to such processing, or you would prefer we exclude your diagnostics, email support@aroralabs.org and we will honour reasonable requests.

12

Website, cookies & local storage

The Borro website (borro.aroralabs.org) is a marketing and support site and does not require an account. It uses privacy-respecting, aggregate analytics to understand traffic, with advertising and ad-personalisation signals disabled by default. The legal pages use your browser’s local storage only to remember your light/dark theme preference — this is a functional preference stored on your device, not a tracking cookie, and no personal data is collected by that mechanism.

13

International data transfers

We operate globally and our providers process data in several countries. In particular, our cloud backend (Google Cloud Functions and Cloud Storage) runs primarily in the United States, our email is sent through Zoho Mail’s Australian endpoint, and Apple and Google process purchase and push data in their own global infrastructure. This means your personal data may be processed in a country other than your own, including the United States.

Where we transfer personal data out of the EEA, the UK, Australia or another regulated region, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and the equivalent contractual protections offered by our providers — and, where required, we assess that the destination provides adequate protection. You may request more detail on these safeguards using the contact details below.

14

Data retention

We keep personal data only as long as needed for the purposes above:

  • Account & ledger: retained while your account is active so backup and sync keep working.
  • Account deletion: when you delete a real account, it enters a 30-day recovery window during which you can restore it by signing back in; after 30 days your cloud data is permanently purged. This includes your profile, username, email-directory entry, ledger, shared and pending records, receipt images, and any custom profile photo you uploaded, and it releases the purchase lock tied to your account. Guest (anonymous) accounts are deleted immediately, with no recovery window. Feedback and bug reports are the one exception, noted below. See our account deletion guide and Section 15.
  • Cloud receipt images: automatically removed after 24 months, unless you turn off receipt auto-cleanup in the app, in which case they are kept until you delete them.
  • In-app inbox notifications & abuse/rate-limit counters: automatically expire after about 60 days.
  • One-time codes: deleted on use, expiry, or after too many attempts.
  • Feedback & bug reports you send us (which include your email, message and device details) are retained so we can investigate and improve; they are not automatically removed when you delete your account. Ask us and we will delete them.
  • Diagnostic logs held by our providers are typically retained for a short period (on the order of 30 days) before being purged.

We may retain limited information longer where necessary to comply with legal, tax or accounting obligations, resolve disputes, or enforce our agreements.

15

Your rights & choices

You are in control of your data. Directly in the app you can:

  • Access & export: view all of your ledger, and export it as CSV or PDF at any time.
  • Correct: edit any person, transaction, group or profile detail.
  • Delete: remove individual entries, people and groups, or permanently delete your whole account and its cloud data (Settings → Account & Sync → Delete account), or email us to do it for you.
  • Stay local: sign out at any time — your local data remains on your device and simply stops syncing.
  • Control notifications: per channel and type, in the app or your device settings.

Depending on where you live, you may also have statutory rights to access, correct, delete, port, restrict or object to the processing of your personal data, and to withdraw consent. To exercise a right that the app does not already provide, email support@aroralabs.org. We will verify your identity (usually by confirming control of your account email) and respond within the timeframe required by your local law. Exercising your rights is free unless a request is manifestly unfounded or excessive, and we will not discriminate against you for exercising them.

16

Region-specific rights

EEA & UK (GDPR / UK GDPR). You have the rights of access, rectification, erasure, restriction, data portability, and objection (including to processing based on legitimate interests), and the right not to be subject to solely automated decisions with legal effect (we do not carry out such decision-making). Where we rely on consent, you may withdraw it at any time without affecting prior processing. You may lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office).

California (CCPA / CPRA). You have the right to know, access, correct and delete your personal information, and to limit the use of sensitive personal information. We do not “sell” or “share” your personal information as those terms are defined under California law, and we do not use it for cross-context behavioural advertising, so there is nothing to opt out of on that front. You may use an authorised agent to make a request, and you will not be discriminated against for exercising your rights.

Australia (Privacy Act & APPs). You may request access to, and correction of, the personal information we hold about you. If you believe we have breached the Australian Privacy Principles, you can complain to us first at support@aroralabs.org; if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).

Canada (PIPEDA). You may request access to your personal information and challenge its accuracy, and you may withdraw consent subject to legal or contractual limits. Complaints may be directed to the Office of the Privacy Commissioner of Canada.

India (DPDP Act 2023). As a Data Principal you may request access to, correction and erasure of your personal data, nominate another person to exercise your rights in the event of death or incapacity, and raise a grievance with us. Unresolved grievances may be escalated to the Data Protection Board of India. Contact us at support@aroralabs.org to begin.

Wherever you are, if a right listed here is available to you under your local law, we will honour it even if your country is not named above.

17

Security

Data in transit is encrypted (HTTPS/TLS), and cloud data is protected by server-side access rules that restrict each record to its owner and the specific people it is shared with. Group receipt photos are readable only by members of that group; a purchase can be bound to a single account to prevent abuse; and our backend uses rate limiting and device-integrity attestation to resist automated abuse. Passwords are handled by Firebase Authentication and are not stored by us in readable form. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information, and if a data breach occurs that is likely to put you at risk we will notify you and the relevant regulator as required by law.

18

Children

Borro is a general-audience personal-finance tool and is not directed to children under 13 (or the higher minimum age required in your country). We do not knowingly collect personal data from children under that age. If you believe a child has provided us personal data, contact us and we will delete it promptly.

19

Changes to this policy

We may update this policy as Borro evolves. We will revise the “last updated” date above, and for material changes we will provide notice in the app and/or by email before they take effect. Continuing to use Borro after changes take effect means you accept the updated policy.

20

Contact & complaints

Questions, requests or complaints about your privacy? Email support@aroralabs.org and we will respond. You may also contact your local data-protection authority (see Section 16) if you are not satisfied with our response. See also our Terms of Service.