Privacy Policy

Last updated: 23 July 2026

1. Introduction

555 Notebook is operated from Malaysia by 0x_wzhenkai, the developer identified on our Google Play listing ("we", "our", "us"). We are the data controller for the 555 Notebook mobile application and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, store, share, and protect your personal information.

This policy provides notice of our data practices. Where applicable law requires consent for a particular activity, we will request it through the relevant feature.

2. Information We Collect

2.1 Account Information

When you register, we collect:

If you register with an email address and password, we send a one-time verification code to that address and you must confirm it before your first sign-in, so we can confirm the email belongs to you. If you sign in with Google, we receive your name, email address, and profile picture from Google (your email is treated as already verified), and we do not receive or store your Google password.

2.2 Trip and Financial Data

When you use the Service, we collect:

2.3 Device Information

We collect device tokens for push notifications (Firebase Cloud Messaging) and a coarse timezone offset (used only for "quiet hours" notification scheduling). We do not collect persistent device identifiers, advertising IDs, or location data, and we do not use third-party analytics or ad-tracking platforms (such as Google Analytics or Mixpanel). The only usage data we record is the limited product-usage events described in Section 2.2.

2.4 Purchase Information

Credit purchases are processed through Google Play Billing. We receive the purchase token to verify the purchase, then retain only a one-way SHA-256 fingerprint in the credit transaction history and a separate replay-prevention registry. The fingerprint cannot be used to recover the token. When you delete your account, we delete your credit transaction history and any raw legacy token; the registry keeps only the fingerprint, with no user or account identifier, solely to prevent the same purchase from granting credits again. We do not receive or store your payment-card or bank-account details; Google handles those details and retains its own transaction records under its policies.

2.5 Technical Information

When you use the Service, our servers automatically receive:

2.6 Required and Optional Information

Your email address and display name are required to create and identify an account; without them, we cannot provide a signed-in account. An avatar is optional. Trip, receipt, expense, and settlement information is provided only when you choose to use the corresponding feature. Receipt scanning is optional — you may enter receipts and expenses manually instead. Push notifications are optional and can be disabled in the app or your device settings.

3. How We Use Your Information

We use your information to:

4. Receipt Image Processing

When you upload a receipt image, it is:

  1. Compressed and stored in our cloud storage (Cloudflare R2)
  2. Processed by an AI vision model to extract text, items, and prices
  3. Optionally translated to English if the receipt is in another language

Receipt images are accessible only to members of the trip they belong to, via time-limited signed URLs. Images are permanently deleted when the associated trip is deleted.

5. Data Storage and Security

We take the security of your data seriously:

Your data is stored on servers that employ industry-standard security practices.

The Service is operated from Malaysia, but our service providers may process or store data in the United States and other countries where they or their infrastructure operate. Those transfers are limited to operating the Service and are subject to the providers' data-protection terms and applicable transfer safeguards.

6. Data Sharing

We do not sell, rent, or trade your personal information to third parties.

Your trip data (receipts, expenses, balances) is shared only with other approved members of the same trip. We use the following third-party processors strictly to operate the Service:

Each processor only receives the data it needs to perform its function and is bound by its own privacy and data-protection terms.

7. Data Retention

Database backups

We retain encrypted database backups (operated by our hosting provider) for up to 30 days as part of our standard disaster-recovery practice. Backups are not used for any business purpose other than restoring service after data loss. When you delete your account, your identifying account data is removed from production immediately; any backup copy expires within 30 days. Anonymized financial records in shared trips remain as described below and are not restored with your former identity.

8. Your Rights

You have the right to:

9. Children's Privacy

The Service is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us so we can delete it.

10. Offline Data

The app caches trip data locally on your device for offline access. This cached data is cleared when you log out. No offline data is sent to external parties.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Where required, we will provide additional notice or request consent before a material change takes effect.

12. Contact Us

If you have questions about this Privacy Policy or your personal data, please contact us at:

Operator: 0x_wzhenkai, Malaysia
Email: contact@notebook555.com