ShuvLu Studio / Slyva Privacy Policy
Updated 24 July 2026

Slyva Privacy Policy

This policy explains what stays on the device, what ShuvLu Studio may receive, how third-party services operate, and what rights users have.

1. Overview

Core principle: Slyva's main financial database is stored locally on the device. ShuvLu Studio does not operate a server containing user accounts, transactions, budgets, goals, or investment records.
Local storageFinancial records are not sent to ShuvLu Studio.
No advertising profilingNo AdMob, advertising SDKs, or sale of data.
Support only on requestWe receive only what a user voluntarily sends by email.
Third parties have separate rulesGoogle Play, hosting, and any future AI service operate under their own terms.

2. App owner and data controller

Owner and operator: ФОП Шилінська Уляна Василівна. Full legal details are available on the Owner information page.

3. Scope

This policy applies to the Slyva mobile app, Slyva pages on the ShuvLu Studio website, support correspondence, and related data-deletion pages. It does not replace the privacy policies of Google Play, Gemini API, Android, the device manufacturer, email provider, or hosting provider.

4. Local registration and profile

The current “registration” and “sign-in” screens create and open a local profile on the device. They do not create an online account on ShuvLu Studio servers, send credentials or the financial database to us, or provide cloud sync.

If server authentication, cloud sync, family profiles, server backup, or remote recovery are added later, this policy and the Google Play Data safety form will be updated before launch.

5. Data categories

CategoryStorageAccess
Name or nickname, profile image, theme, currency, settingsOn the deviceUser and Android system components
Accounts, balances, income, expenses, transfers, categories, budgets, limits, goals, savings, investments, notes, dates, and scheduled transactionsOn the deviceUser; ShuvLu Studio does not receive these records
Reminders, notification time, daily check-ins, and local statisticsOn the deviceUser and local Android components
Subscription status, product, purchase identifier, date, and technical transaction statusGoogle Play and local entitlement stateGoogle; the app receives the minimum needed to provide paid functionality
Email, support message, technical description, and voluntarily attached filesEmail systemOwner or authorised support handler
IP address, time, URL, browser, response code, and technical logsHosting provider, if enabledProvider and administrator for security and reliability
Gemini API key, image/text selected for scanning, prompt, and responseNot included in the first release. If later enabled: key locally; requests at GoogleUser and Google; ShuvLu Studio receives no server copy

“Analytics” inside Slyva means local charts, summaries, and calculations. It does not mean Firebase Analytics, advertising profiling, behaviour tracking, or hidden telemetry.

6. Data sources

  • users enter or add local data themselves;
  • Google Play supplies technical purchase status;
  • support receives data only through voluntary messages;
  • hosting may automatically generate technical logs;
  • ShuvLu Studio does not buy data from brokers or enrich profiles from external databases.

7. Purposes and legal bases

  • contract providing core and paid functionality and verifying subscription status;
  • request handling responding to support;
  • legitimate interests website security, abuse prevention, diagnostics, and legal defence;
  • legal obligation retention required by law, tax, or accounting rules;
  • consent / explicit action optional device permissions and any future submission to a third-party AI service.

Local financial records are not used for advertising, scoring, sale, profiling, or decisions about the user.

8. Device permissions

AccessPurposeCondition
NotificationsDaily reminders and scheduled eventsOnly after system permission
Camera / photos / filesProfile image, import, or future receipt scanningOnly after an explicit user action
InternetGoogle Play Billing, support pages, and any future AI serviceOnly for the relevant function

9. Google Play Billing

Google Play processes payment credentials, taxes, refunds, and purchase history. ShuvLu Studio does not receive full card numbers, CVV, bank logins, or passwords. Google may provide subscription status, product, purchase identifier, and other minimum technical information. Payment, renewal, cancellation, and refund rules are governed by Google Play and mandatory consumer law.

10. AI scanner and Google Gemini API

Feature status: the AI scanner is excluded from the first public Slyva release. A consent screen alone is not enough; compliance with current Google terms, audience, region, and use model must be confirmed first.

If the feature is lawfully enabled later:

  • the user must be at least 18;
  • the user manually selects content sent to Google;
  • a prominent disclosure and two mandatory confirmations are shown before first use;
  • the user accepts Google's current terms and privacy policy;
  • confidential, sensitive, unnecessary, or third-party personal data must not be submitted;
  • results may be inaccurate and must be reviewed before saving;
  • Google controls models, quotas, pricing, regions, blocking, and API suspension;
  • ShuvLu Studio may immediately disable or remove the AI feature where required by law, Google terms, safety, technical issues, or user protection.

For unpaid services, Google may use inputs and outputs to improve products and may use human reviewers. Paid services use a different data regime, but Google still keeps limited logs for security, policy enforcement, and required legal disclosure. Current abuse-monitoring rules state that prompts, context, and output are retained for 55 days and flagged material may be reviewed by authorised Google personnel.

Self-declared age does not override other Google restrictions or prove that a consumer integration is permitted. The feature remains disabled until legal and technical review is complete.

11. Sale, sharing, and recipients

ShuvLu Studio does not sell, rent, or provide the local financial database to advertisers, data brokers, or analytics platforms. Recipients of separate data may include Google Play, the email provider, hosting provider, and, only if lawfully enabled, Gemini API. Contractors receive only necessary access and appropriate confidentiality obligations.

12. International processing

Google, email, and hosting providers may use infrastructure outside Ukraine or the EEA. Each provider is responsible for its transfer mechanisms. Hosting details, processing location, and log retention will be added after a provider is selected.

13. Retention

  • local database: until deletion, storage clearing, or app removal;
  • Android backups: under Google/Android and device settings;
  • support: generally up to 24 months after closure, unless longer retention is needed for security, legal defence, or law;
  • website logs: under the future host's settings;
  • Google Play: under Google and mandatory payment/tax rules;
  • Gemini API: under current Google terms; abuse-monitoring data for 55 days.

14. Data deletion

Users may delete local records in Slyva, clear app data in Android, or uninstall the app. ShuvLu Studio cannot remotely erase a database it does not possess. Instructions are available on the profile and data deletion page. Support correspondence can be requested for deletion from the same email address, subject to legal and security retention.

15. Security and limitations

We minimise data transfer and do not create a server copy of the financial database. App data is isolated by the Android sandbox and depends on device security. We do not claim separate encryption of the local database or API key until verified by final-code audit. No system can guarantee absolute security.

16. User rights

Depending on applicable law, users may have rights of access, correction, erasure, restriction, objection, portability, and withdrawal of consent for data actually controlled by ShuvLu Studio. Requests may be sent to shuvlustudio@gmail.com. Users may also contact the competent data protection authority.

17. Automated decision-making

Slyva does not make legally or similarly significant decisions. Local charts are informational. Any future AI recognition may only propose a draft; the user decides whether to save the amount, category, and date.

18. Age requirements

Slyva is not directed to children. The first release without AI may receive a separate Google Play age rating. If Gemini API is integrated, the feature must not be available to users under 18 and the entire access model must comply with current Google terms. A simple “I am 18” checkbox is not sufficient where the app or feature is likely to be accessed by minors.

19. Legal disclosure and business transfer

Data actually controlled by ShuvLu Studio may be disclosed where lawfully required by a court or authorised authority. If the product is reorganised or transferred, support data and contracts may transfer to a successor in compliance with applicable law and notice requirements.

20. Changes

This policy may change when functionality, SDKs, permissions, contractors, hosting, or law changes. Material changes may be shown in the app. Continued use does not replace separate consent where consent is legally required.

21. Governing language

The Ukrainian version is the primary version. The English translation is provided for convenience. In case of inconsistency, the Ukrainian text applies to the extent permitted by mandatory law in the user's country.

22. Contact

For privacy questions, data-subject requests, or questions about support correspondence, contact:

ФОП Шилінська Уляна Василівна
Email: shuvlustudio@gmail.com
Full legal details: Owner information.

Please describe the request and use the same email address previously used for support when the request concerns correspondence. Do not send passwords, API keys, or a complete Slyva financial database.