Privacy Policy
- Version
- 1.0
- Effective
- 30 July 2026
- Last updated
- 30 July 2026
Contents
- 1. Who this policy covers
- 2. Privacy at a glance
- 3. Information we collect and where it comes from
- 4. Google Drive, Google Sheets and local storage
- 5. Information held by Common Things
- 6. How we use personal information
- 7. Optional features and sensitive processing
- 8. Disclosures and service providers
- 9. Overseas disclosures
- 10. Cookies, analytics and similar technologies
- 11. Legal bases for users in the EEA or UK
- 12. Security
- 13. Data breaches
- 14. Your choices and rights
- 15. Account deletion
- 16. Children
- 17. Automated features and financial decisions
- 18. Changes to this policy
- 19. Contact and complaints
1. Who this policy covers
This Privacy Policy explains how Common Things collects, uses, discloses, stores and protects personal information when you use commonthings.app, the Common Things web application, and the Common Things mobile applications (together, the “Service”).
The Service is operated by an individual developer based in Australia (“Common Things”, “we”, “us” or “our”). Contact: support@commonthings.app.
We aim to handle personal information consistently with the Australian Privacy Principles, whether or not every provision of the Privacy Act 1988 (Cth) applies to us in a particular circumstance. Additional local privacy rights may apply depending on where you live.
2. Privacy at a glance
- Your core financial records are designed to be stored in Google Sheets files in your Google Drive, rather than in a Common Things financial-data database.
- We keep limited account and operational information needed to authenticate users, manage access, send requested communications, support collaboration, prevent abuse and operate the Service.
- We do not sell personal information or use Google user data for advertising.
- Optional features — such as shared lists or a third-party import — may send specific data to the providers identified in this policy.
- You can export your data, disconnect Google access, and request or perform account deletion.
3. Information we collect and where it comes from
| Category | Examples | Source |
|---|---|---|
| Google account information | Name, email address, profile image, Google account identifier and authentication information. | From Google when you choose Google sign-in. |
| Account and membership information | Membership tier, trial status, subscription or store transaction reference, preferences and account status. | From you, the app, and applicable app stores. |
| Financial and household content | Expenses, income, budgets, categories, bills, saving goals, debts, group or Circle data, notes, receipts and shopping-list content. | Entered or uploaded by you or collaborators. Core records are intended to remain in your Google Drive; limited temporary copies may be processed as described below. |
| Collaboration information | Inviter/invitee details, group names, join codes, workbook identifiers, roles and invitation status. | From you and invited users. |
| Device and technical information | App version, platform, browser type, device identifiers, IP address, timestamps, route, sync state, crash information and diagnostic logs. | Collected automatically when needed to secure, troubleshoot and operate the Service. |
| Communications | Support messages, feedback, survey responses and optional contact details. | From you when you contact us. |
| Marketing preferences | Email address, name, consent status and unsubscribe history. | From you when you subscribe or manage preferences. |
| Import information | Data you authorise us to retrieve from supported third-party services, such as Splitwise. | From the third party at your direction. |
4. Google Drive, Google Sheets and local storage
Common Things requests Google permissions needed to create, open and update Common Things workbooks. The drive.file scope generally allows access to files the app creates or that you explicitly open with it. The spreadsheets scope allows spreadsheet reads and writes and is used only for Common Things workbook identifiers required for personal, Circle and Group functionality.
Your core financial content is written to Common Things workbooks in your Google Drive. The app may also keep an offline copy on your device (for example, in browser or app storage) so it can work without a connection. Offline data may remain until you clear app data, delete it through the Service, uninstall the app, or the operating system removes it.
The permissions actually requested at sign-in are openid, email, profile, drive.file and spreadsheets. A plain-language breakdown of each, including what it is and is not used for, is published at Permissions & data access.
5. Information held by Common Things
| Record | Purpose | Typical retention |
|---|---|---|
| Account record | Authentication, profile, preferences, tier and account administration. | Until account deletion, plus a limited period where required for security, dispute or legal purposes. |
| Encrypted Google credential or refresh token | To maintain authorised syncing across devices. | Until revoked, expired or account deletion. |
| Invitations and sharing metadata | To send, accept and manage Circle or Group invitations. | Until resolved, expired or deleted. |
| Support and feedback records | To respond, investigate and improve the Service. | Usually up to 24 months, unless a longer period is reasonably needed. |
| Error and diagnostic records | Security, reliability and troubleshooting. | Usually 90 days; longer only for active investigations or aggregated/de-identified records. |
| Temporary shared-list data | To provide real-time list sharing. | Up to 48 hours after the sharing session ends, unless saved by a user. |
| Newsletter records | To send opted-in product updates and maintain suppression records. | Until unsubscribe; minimal suppression data may be retained to honour the opt-out. |
| Transaction records | Subscription administration, fraud prevention, accounting and legal compliance. | As required by applicable tax, accounting, consumer and app-store rules. |
Where you attach a file to a support request, the file is forwarded to our support mailbox with the request and is not stored in the support record itself; only its filename is recorded.
6. How we use personal information
- Provide sign-in, syncing, offline functionality, budgets, bill splitting, groups, Circles, invitations, exports and other requested features.
- Administer Free and Gold access, trials and subscriptions.
- Authenticate users, secure the Service, prevent abuse and investigate incidents.
- Respond to support requests and troubleshoot errors.
- Send service messages and optional notifications selected by you.
- Improve the Service using aggregated or de-identified information where practicable.
- Comply with law, enforce our Terms, and establish or defend legal claims.
7. Optional features and sensitive processing
Receipts
Receipt images you attach to an expense are stored on your device and backed up to your own Google Drive alongside your workbook. They are not sent to us, and they are not sent to any artificial-intelligence or text-extraction service: Common Things does not integrate one. Expense details are entered by you.
Diagnostics
Common Things does not use a third-party error-monitoring, analytics or session-replay service. There is no session recording of any kind. When something goes wrong, technical details of the error may be recorded in our own error log — see the retention table in section 5 — and that log holds error metadata only.
Where you submit a support request, technical diagnostics are only included if you tick the optional consent box, and are limited to the items described next to it.
Imports
When you authorise an import from a third-party service, we access only the data needed to complete that import. The third party's privacy policy also applies. Access tokens are intended to be short-lived or deleted promptly after import unless ongoing access is expressly requested.
8. Disclosures and service providers
We may disclose personal information to providers that process it for us, subject to contractual, security and confidentiality controls. Current categories include:
- Google: authentication, and Drive and Sheets storage of your own workbooks. Google Play also processes billing for Android subscriptions.
- Apple: App Store distribution and billing.
- Vercel: website and application hosting.
- Neon: operational database hosting.
- Resend: transactional and opted-in email delivery.
- Splitwise: user-directed import.
- Frankfurter or another exchange-rate provider: currency-rate lookup.
- Professional advisers, insurers, regulators, courts or law-enforcement bodies where reasonably necessary or legally required.
- A purchaser or successor in a genuine business reorganisation, subject to appropriate confidentiality and notice.
We do not use an advertising network, an analytics provider, an error-monitoring service or an artificial-intelligence provider. The categories above are the current list, and this policy is updated before a provider is added that materially changes how information is handled.
9. Overseas disclosures
Our providers may process information in Australia, the United States, the European Union and other locations in which they or their subprocessors operate. We take reasonable steps to assess providers and protect information transferred overseas, subject to applicable law.
11. Legal bases for users in the EEA or UK
Where GDPR or UK GDPR applies, we rely on: performance of a contract to provide requested features; legitimate interests in security, support and service improvement; consent for optional marketing and certain optional processing; and legal obligation where applicable. You may withdraw consent without affecting earlier lawful processing.
12. Security
We use reasonable administrative, technical and organisational safeguards appropriate to the information and risks involved. These include encryption in transit, encryption of the stored Google refresh token at rest, restricted production access, logging, dependency management, backups and incident response. No online service can guarantee absolute security.
13. Data breaches
We investigate suspected breaches and, where the Australian Notifiable Data Breaches scheme or another applicable law requires it, notify affected individuals and the relevant regulator. Please report suspected security issues to support@commonthings.app.
14. Your choices and rights
- Access and export your financial records through Google Sheets and available export tools.
- Correct information in your account or contact us for assistance.
- Change notification and marketing preferences and unsubscribe from optional email.
- Revoke Google access through your Google account.
- Delete local data, Common Things Drive files and your Common Things server account using the in-app controls, subject to any information we must retain.
- Request access, correction, deletion, restriction, objection or portability where applicable.
- Complain to us and, where applicable, to the Office of the Australian Information Commissioner or your local authority.
We may need to verify your identity before actioning a request. We aim to respond within 30 days, but the legally applicable period may differ. We will explain any lawful refusal.
15. Account deletion
- 1Use Settings → Danger zone → Delete everything from Drive & device to remove Common Things workbooks, receipt folders and local app data, where available.
- 2Use Settings → Danger zone → Delete account & server data to remove the operational account record and sign out.
- 3Revoke Common Things access in your Google account permissions if desired.
- 4When you cannot sign in, contact support@commonthings.app from the account email address, or use the support form. We may request verification.
Deletion may not remove copies already shared with other users, records another user independently controls, app-store transaction records, backups pending normal rotation, or information we must retain by law or for security and dispute handling.
16. Children
The Service is not directed to children under 16. Users under 18 should use it only with parent or guardian consent where required. If we learn that we collected personal information from a child contrary to applicable law, we will take reasonable steps to delete it.
17. Automated features and financial decisions
Smart Coach, categorisation, receipt extraction and similar features provide organisational suggestions only. They do not make eligibility, credit, insurance, employment or other decisions producing legal or similarly significant effects. Outputs may be incomplete or inaccurate and should be reviewed by the user.
18. Changes to this policy
We may update this policy to reflect product, legal or provider changes. We will publish the updated version and effective date. For material changes, we will provide reasonable notice in the Service or by email before the change takes effect where practicable or required.
19. Contact and complaints
- Email: support@commonthings.app
- Website: commonthings.app
Email is the fastest way to reach us, and the support form has a Privacy enquiry topic that routes the request the same way. Please describe your concern and the account email involved. We will acknowledge and investigate complaints within a reasonable period. If you are not satisfied, you may be able to complain to the Office of the Australian Information Commissioner or another competent regulator.
Questions about this document? Use the support form and choose the Privacy enquiry topic, or write to support@commonthings.app.