Rrow

CDM Nexus LLC

RROW Privacy Policy

Effective date: 25 August 2026Version 2026-08-25

This Policy explains how CDM Nexus LLC, registration number 999.110.1559924, registered on 13 February 2026 at 26/3 Vazgen Sargsyan Street, Yerevan, Republic of Armenia (the “Company”, “we”, or “controller”), collects, uses, stores and protects personal data of RROW users.

It applies to the RROW mobile and web application. We process data in accordance with the Republic of Armenia Law on Protection of Personal Data and other applicable requirements, including the GDPR where it applies to a user or processing activity.

1. Data we process

Account data: name, email, Apple or Google identifier, sign‑in records, language, consent dates and versions, security settings and two‑factor authentication status. Passwords are handled in protected form by our authentication provider; we do not see their plain text value.

Profile and preferences: avatar, selected currencies, analytics currency, theme, notification preferences, carry‑forward settings and other choices.

Financial content: amounts, currencies, dates, titles, categories, status and frequency of income and expenses; net worth; savings and goals; investment positions and trades; notes; exchange‑rate snapshots; and receipt fields that you confirm after recognition.

Technical data: IP address and security logs, device and app type, session identifiers, push token, error and activity data needed for security, diagnostics and service delivery. We do not use advertising identifiers for cross‑service tracking and do not sell personal data.

2. Sources of data

You provide most data directly when registering, editing your profile, or adding transactions, goals, investments, an avatar or a receipt. Apple or Google may provide sign‑in data at your choice. Technical data is created automatically when you use the service. Rates and quotes come from external market‑data providers.

3. Purposes and legal bases

We process data to create and secure accounts; synchronise devices; provide calendars and financial records; perform calculations, conversion, analytics, export and reminders; scan receipts and generate AI reports; provide support; prevent abuse; fix errors; comply with law; and protect rights.

Legal bases may include performing our contract with you, your consent (including for optional AI features and device permissions), our legitimate interests in security and service improvement, and compliance with legal obligations. Where processing relies on consent, you may withdraw it for the future without affecting prior lawful processing.

4. Receipt scans and AI reports

When you start a scan, the selected receipt image is sent through our protected server to an AI provider to extract the amount, date, currency, merchant and suggested category. RROW does not save the source image in its database or cloud storage; it is released from request memory after a result is returned. If you save the transaction, only the fields you review and confirm remain in your account.

For financial reports, the provider receives aggregate metrics for the selected period—amounts, currencies, categories and comparisons. Your name, email, avatar and receipt images are not included in the report request. We use the OpenAI API with application‑state storage disabled. API data is not used to train OpenAI models by default, but the provider may retain abuse‑monitoring logs for up to 30 days unless Zero Data Retention applies, or longer when legally necessary.

You may disable AI features in Settings. Withdrawing consent deletes saved AI reports; financial transactions remain until you delete them separately.

5. Recipients

We use providers only as needed to operate RROW: Supabase for authentication, databases, cloud storage and server functions; Apple and Google for the sign‑in method you choose; OpenAI for receipt scanning and report generation; Expo and Apple/Google platform services for push delivery; and market‑data providers including ExchangeRate‑API, CoinGecko and Nasdaq.

Providers process data on our instructions or as independent controllers within their own services. We may also disclose data where required by law, a competent authority or protection of rights and safety. In a business reorganisation, data may transfer to a successor subject to applicable obligations. We do not sell or rent personal data.

6. International transfers

Providers may process data in Armenia, the European Economic Area, the United States and other countries where protections may differ. Where required, we use contractual and organisational safeguards for lawful transfers, including processing agreements, standard contractual clauses or another recognised mechanism.

7. Retention

Account data, financial records, investments and goals are generally kept while the account exists or until you delete the relevant item. RROW does not store source receipt images. A push token is kept while notifications are enabled or the account is active. AI reports remain until deletion, withdrawal of AI consent or account deletion.

After account deletion we delete or anonymise active data without undue delay, except information we must retain for law, disputes, fraud prevention or proof of consent. Residual copies may remain for a limited period in protected backups until scheduled overwrite and are not used for ordinary operations.

8. Security

We use access controls, authentication, protected transmission, server access rules, logging, backups and other reasonable technical and organisational measures. Some local data is kept in protected device storage. No method is absolutely secure, so protect your device, password and 2FA codes and report suspicious activity.

9. Your rights

Depending on applicable law, you may request access, a copy, correction, updating, deletion or restriction; object to certain processing; obtain a portable copy of data you provided; withdraw consent; and complain to a competent data‑protection authority.

Many controls are available in the app: editing profile and preferences, export, disabling AI, deleting individual records and full account deletion. For other requests, contact support or write to the Company. We may verify identity and will respond within the period required by applicable law.

10. Device permissions

Camera and selected photo access is used only for avatars and receipt scanning; notifications for reminders; and Face ID, Touch ID or biometrics for local access protection. The biometric template remains with the operating system and is not sent to the Company. You may change permissions in device settings, but the relevant feature may stop working.

11. Local storage and web technologies

The app uses protected local storage, application memory and necessary session technologies for sign‑in, synchronisation and preferences. The web version may use strictly necessary cookies or similar local storage. RROW does not use them for third‑party behavioural advertising.

12. Minors

RROW is not intended for independent use by anyone who cannot validly consent or enter an agreement under applicable law. If you believe a child submitted data without required representative permission, contact us so we can investigate and take legally required action.

13. Changes to this Policy

We may update this Policy when RROW, our providers or the law changes. The current version and effective date will be available in the app. We will give prominent notice of material changes and obtain renewed consent where required.

14. Controller and contact

Controller: CDM Nexus LLC, registration number 999.110.1559924, registered on 13 February 2026. Address: 26/3 Vazgen Sargsyan Street, Yerevan, Republic of Armenia.

Privacy questions and rights requests may be sent through RROW support or by post to the address above. Never include a password, full 2FA code or other access secret in a request.

← Rrow© 2026 CDM Nexus LLC