Worth Privacy Policy
This policy explains how CoreLabs processes information in Worth: Subscription Tracker for Android. Worth is designed as a local-first subscription organizer. Core tracking does not require an account.
Information you add
Worth may store subscription names, prices, currencies, billing cycles and dates, categories, notes, reminders, usage history, cancellation progress, list and family metadata, price history and confirmed savings. This primary state is encrypted locally using AES-GCM with a key held by Android Keystore.
On-device usage analysis
Only after you grant Android Usage Access and use the Pro analysis feature, Worth reads package names for supported apps, foreground duration, launch counts and active dates from the previous 30 days. It does not read app content, messages, entered text or browsing history. Derived summaries remain local unless you explicitly sync your Worth state.
OCR and image imports
You choose receipt or subscription screenshots through the Android picker. The bundled Google ML Kit text recognizer processes the image on device. Worth does not upload the image or recognized text to a CoreLabs server. Google’s SDK may process limited technical app, device, performance and installation information for diagnostics.
Notifications
If enabled, Worth uses notification permission and locally scheduled work for renewal, trial, grouped-payment and audit reminders. You can disable reminders in Worth or revoke permission in Android settings.
Purchases
Google Play Billing provides product information and purchase status for Plus and Pro. Worth caches entitlement state but does not receive or store payment-card details. Purchases, renewals, cancellation and refunds are governed by Google Play and applicable law.
Optional Google account, sync and family spaces
If you choose Google sign-in, Firebase Authentication processes your Google identity, email and UID. If you explicitly sync, Worth stores your state in Firebase Firestore under your UID. In a family space, family-list records and membership/role information are stored in that family’s Firestore area and made available to authenticated members according to the configured rules. Join codes are shared by you; Worth does not promise a public deep-link flow.
Catalog updates and diagnostics
Firebase Remote Config can deliver non-personal reference prices for the service catalog. It does not receive subscriptions you saved. Worth’s product-event counters are stored only in private local preferences and are not sent to CoreLabs. Worth contains no advertising, Firebase Analytics or Crashlytics SDK.
Backups, imports and exports
Worth keeps an encrypted automatic backup in app-private storage. Android cloud backup and device transfer are disabled. When you export JSON or CSV or import a document, Android lets you choose the file or destination; files outside Worth are controlled by you and the selected storage provider.
Biometric lock
The optional lock uses Android BiometricPrompt or device credentials. Android performs the match. Worth receives only the authentication result and never receives your biometric template.
Third-party processors
Worth uses Google Play Billing, Google ML Kit, Google Identity, Firebase Authentication, Firebase Firestore and Firebase Remote Config for the purposes described above. Their processing is governed by Google’s applicable terms and privacy documentation.
Retention and deletion
Local data remains until you delete it in Worth, clear app storage or uninstall. A separate confirmed action deletes your signed-in personal Firestore copy. Signing out does not by itself delete remote data. Google retains purchase records under your Google account. Exported files remain wherever you saved them. Family-space deletion and membership requests may require support and verification.
Security
Worth encrypts primary local state and entitlement caches using Android Keystore and disables cleartext network traffic. Google/Firebase traffic uses transport encryption. No system can guarantee absolute security; keep your device and Google account protected.
Children
Worth is a general-audience finance utility and is not directed to children. CoreLabs does not knowingly design Worth to collect children’s personal information.
International processing
Google and Firebase may process data in countries other than yours under their infrastructure and contractual safeguards. Local law may provide additional rights.
Your choices and rights
You can use core tracking without an account, decline notifications and Usage Access, avoid OCR or cloud sync, edit or delete subscriptions, export data, delete local data, and delete your personal cloud copy. For a verified privacy request, use the contact route below.
Changes
We may update this policy when Worth, service providers or legal requirements change. The updated date will change and material changes will be communicated where required.
Contact
Developer: CoreLabs. Email worth@corelabs.app or use the Worth support page.