Privacy Policy

Last updated: October 3, 2026

This policy applies from the release of Alcoin 2.0.0. This English version is a translation for reference; the Japanese version is the governing text.

Your personal book stays on your iPhone

Personal book and solo period book data is stored only on your device and is never sent to our server (when you use a transfer code, we briefly hold data encrypted on your device, which we cannot read). Only when you use shared books do we handle the information needed to share them on our server. We use no ads, no analytics and no tracking, and we never sell your data.

This Privacy Policy explains how Bluedog ("we", "us") handles information in the iOS app "Alcoin" (formerly "Coinly") (the "App") and on the shared book invite page.

1. Personal book (on your device only)

Your personal book data, including expenses, budgets, categories, monthly summaries and savings, is stored on your device using Apple's SwiftData. So are solo period books such as trips (their period, budget and records) and each book's currency and conversion details (the original amount, currency and the rate you entered). Settings such as language and the day your month starts are also stored on your device (UserDefaults). Information shown or recorded through widgets and Siri (Shortcuts) is also handled on your device. The Apple Watch app receives a summary of your books from your iPhone and sends its records back to your iPhone (device-to-device via Apple's WatchConnectivity, never through our server). The Apple Watch stores a summary of the book you are viewing (book and category names, budget, amount spent) and records not yet delivered to your iPhone (for up to 45 days). Your iPhone keeps the IDs of records received from the Apple Watch for 60 days so they are never saved twice.

If you use the Shortcuts action "Record a payment in Alcoin" (for example in an automation after an Apple Pay payment), the payment amount is kept temporarily on your iPhone and Apple Watch only, as a suggestion for your next record. It is deleted when used, or the next time Alcoin runs after an hour (it is no longer shown after an hour), and is never sent anywhere. The merchant name and the card are not received.

This data is never sent to our server (if you use a transfer code, we hold it only in encrypted form for a short time, as described in "2. Information we handle when you use shared books or transfer codes"). The App does not fetch exchange rates from anywhere. If you only use the personal book and do not use transfer codes, the App never contacts our server, and every feature works without an internet connection.

Depending on your settings, data on your device may be included in device backups such as iCloud Backup. Information Apple handles when you use Siri is subject to Apple's privacy policy.

2. Information we handle when you use shared books or transfer codes

The first time you create or join a shared book, or when you issue a transfer code, a random user ID is created on your device and stored in the iOS Keychain. There is no sign-in, and you never register a name, email address or phone number. Only when you use shared books or transfer codes, the information below that is needed is sent to and stored on our server:

  • your user ID and the display names you enter (including your display name in each book);
  • an authentication token (our server stores only its hash, never the token itself);
  • the App's language (used to write record notifications in the recipient's language);
  • the content of your shared books: book name, icon and currency, a period book's period and budget, members' display names, the creator and the payer, expenses (amount, category, date, the member who recorded them and, if converted, the original amount, currency and rate), categories, budgets, copies of the details of merged period books (dates, categories, amounts, notes, the display names of those who recorded them, etc.) and invite codes;
  • whether record notifications are on or off for each shared book;
  • your device's push notification token (APNs), used for silent notifications (which are not shown on screen) that bring other members' changes to your device, and for record notifications;
  • Alcoin Plus purchase information: subscription status, App Store transaction identifiers (originalTransactionId), expiry date, whether it renews automatically, product and environment (production or test);
  • technical information that comes with each request, such as IP address, time and app version (used in server logs and to limit request rates).

What members of a shared book can see

The content of a shared book and members' display names are visible to every member of that book. Copies of the details of merged period books are visible to members who were not in that period book too. So that members can be told before a shared book stops being recordable, whether the payer's Alcoin Plus has auto-renew turned off, and the date until which a shared period book can be recorded, may be shown to its members (the payer's expiry date itself is not shown).

When you use a transfer code

When you issue a transfer code, your personal book and solo period books (such as trips) — records, categories, budgets, periods, monthly summaries, etc. — and settings are encrypted on your device with a key derived from the code, and the ciphertext and a hash derived from the code are sent to our server. The server stores the ciphertext in cloud storage, and a hash of that hash in its database. The code and the key are never sent to our server or stored by the App, so we cannot read the content.

What we do not collect

  • your name, email address, phone number or postal address;
  • your location, contacts or photos;
  • the advertising identifier (IDFA);
  • payment details such as card numbers (payments are processed by Apple);
  • your personal book and solo period book data (except that, when you use a transfer code, we briefly hold it encrypted in a form we cannot read).

The App may use the camera to scan an invite QR code. The camera image is used on your device only to read the code, and is never saved or sent.

3. How we use information

We use this information only to:

  • provide shared books (storage, syncing between members and invitations);
  • send silent notifications that bring other members' changes to your device;
  • send record notifications that tell you another member added a record;
  • move your data to a new device with a transfer code;
  • verify Alcoin Plus purchases, decide whether you can create shared books and whether shared books can be recorded in, and process App Store notifications (renewals, cancellations, refunds, etc.);
  • prevent abuse and excessive requests, handle incidents and keep the Service secure; and
  • respond to your inquiries.

We do not use it for advertising, behavioral analysis or profiling.

4. Sharing and service providers

We do not share your information with third parties without your consent, except where required by law, and we never sell it. We use the following services to run the Service:

  • Amazon Web Services (AWS): the server infrastructure for shared books. Data is processed and stored in the Tokyo region (Japan) using API Gateway, AWS Lambda and Amazon DynamoDB, and logs are stored in Amazon CloudWatch Logs. Data encrypted for a transfer code is stored temporarily in Amazon S3, also in the Tokyo region. The invite page is also served from AWS.
  • Apple: the App Store (purchases, payments and subscription management) and the Apple Push Notification service (delivery of silent notifications and record notifications). The content of record notifications (book name, display name, category and amount) reaches your device through the Apple Push Notification service. Apple's handling of information is subject to Apple's privacy policy.
  • Google Fonts: only the web page shown when you open an invite link (https://coinly.bluedoghub.com/join/…) loads fonts from Google Fonts. When it does, your browser sends information such as your IP address and user agent to Google. The App itself does not use Google Fonts.

5. Retention

  • Shared book content (including copies of the details of merged period books): kept while the book has members, and deleted from our server when the last member leaves. After a member leaves or is removed, the expenses they recorded and their display name remain until the book is deleted.
  • Data encrypted for a transfer code and its hash: deleted when the new device confirms the transfer, or when a new code is issued. Otherwise they stop working 24 hours after the code is issued and are then deleted automatically.
  • Invite codes: expire 48 hours after they are issued and are then deleted automatically.
  • Rate-limit counters (which may include IP addresses): expire after about 2 hours and are deleted automatically.
  • Server logs (which include IP addresses): deleted after 30 days.
  • User ID, display name, language, token hash, device token and Alcoin Plus purchase information: kept as long as needed to provide shared books, and deleted on request.
  • For recovery from failures, we keep database backups for up to 35 days. Deleted data may remain in these backups during that period.

6. Security

  • Communication between the App and our server is encrypted with TLS.
  • Authentication tokens are stored only as hashes.
  • Data held for a transfer code is encrypted on your device, and we have neither the key to decrypt it nor the transfer code.
  • Data stored on our server is encrypted at rest.
  • Each part of our server has only the minimum permissions it needs, and access is restricted.
  • Rate limits and similar measures protect against unauthorized access and guessing of invite codes and transfer codes.

No method of transmission or storage over the internet is completely secure, however.

7. Your choices and rights

  • If you don't use shared books or transfer codes, no information is sent to our server.
  • You can leave a shared book at any time in the App.
  • You can turn record notifications off for each shared book in the App, or turn off the App's notifications in iOS Settings.
  • Issue a transfer code only when you use it, and do not show it to anyone: anyone who has the code can take over your data. After a transfer, you can delete the personal book and solo period book data left on the old device in the App on that device.
  • You can cancel Alcoin Plus in iOS Settings. Your purchase history is managed by Apple.
  • To request access to, correction of, suspension of use of, or deletion of your information that we hold, contact us below. Because there are no accounts, we may ask for details such as the names of your shared books and your display name to identify you and your data.

8. No tracking or advertising

The App does not use any:

  • analytics services;
  • tracking technologies;
  • advertising networks.

9. Children's privacy

The App is not directed to children under the age of 13. Children under 13 should use shared books only under a parent's or guardian's supervision. If we learn that we handle information of a child under 13 without parental consent, we will delete it promptly.

10. Changes to this policy

We may update this Privacy Policy as needed. We will post the new policy on this page and update the "Last updated" date at the top. We will also announce significant changes in the App or on this website.

11. Contact us

If you have any questions or requests about this Privacy Policy, please contact us:

Email

support@bluedoghub.com

App

Alcoin - Smart Budget Tracker

See also: Terms of Use