Privacy Policy
Last updated: 2 September 2026
Expensio ("we", "our", "the app") is built privacy-first. This policy explains exactly what the app does and does not collect. In short: your financial data stays on your device, and we run no ads, no trackers and no analytics SDKs. The one thing we do store on our side is a small account record — described in section 1 — which contains none of your finances. Some features differ by platform, and those differences are marked below.
1. Information We Collect
Everything you enter stays in a local database on your device:
- What you enter — your name, transactions (amount, category, notes, brand), account & card metadata (name, type, last 4 digits, limit, bill date), budgets and preferences.
- Google account (only if you sign in) — your email, name and profile photo, plus access to an app-specific Expensio folder on your own Google Drive (
drive.filescope) for optional backups. - Bank notifications (Android only, and only if you enable Auto-Capture) — read on-device to detect transactions; they are parsed locally and never uploaded. iOS and iPadOS have no equivalent: Apple provides no way for an app to read another app's notifications or your SMS, so Expensio on iPhone, iPad and Mac never does.
- An account record (only if you sign in) — when you sign in with Google or with Apple we store a small record in our Firebase project so we know how many people use Expensio and on which platforms. It holds an account identifier, whether the account is Google or Apple, the app version, the platforms you have used, when you were last active, and your email and name where the sign-in method provides them. It contains no transactions, amounts, balances, accounts, cards or budgets. If you continue as a Guest, none of this happens — no account is created and nothing about you reaches our Firebase project.
- What we never collect — full card numbers, CVV, bank login credentials, Aadhaar, PAN, your location, or your contacts.
2. How We Use Your Information
- To show your spending analytics, budgets and insights.
- To create optional backups to your own Google Drive.
- To power home-screen widgets and app-icon shortcuts (Android), and Siri quick add (iPhone).
- We never use your data for advertising, profiling or resale.
3. Data Storage & Security
- All financial data is stored in a local SQLite database on your device.
- Optional backups are stored as a single file in your own Google Drive.
- Backups are encrypted. The file is encrypted with AES-256-GCM before it leaves your device, so it is not readable or editable as plain text in Drive, and a file that has been edited is rejected when you restore it. Because the app has to restore your data on any of your devices without a password, the key is built into the app — this protects the file from being read or altered casually, but it is not end-to-end encryption with a key that only you hold.
- You can protect the app with biometric App Lock, handled entirely by your device's own secure APIs (Android biometrics, or Face ID / Touch ID on Apple devices). We never see your biometric data.
- We recommend securing your device with a screen lock.
4. Permissions (all optional)
- Notification access (Android only) — for Auto-Capture.
- Camera — to scan a credit card. The image is read on your device and discarded.
- Microphone & speech recognition — for Voice Quick Add, so you can say a transaction instead of typing it.
- Storage (Android only) — to save an exported file. On Apple devices you choose where an export goes through the system Files sheet, so no storage permission is needed.
- Siri & Shortcuts (iPhone) — if you ask Siri to log an expense, Apple processes the phrase on its side and hands Expensio only the finished result, which is written to your local database like any other entry. We never receive the audio, and Apple's handling of the request is governed by Apple's own privacy policy.
- Biometrics — for App Lock.
- Google Sign-In — for Drive backup.
5. Platform Differences
Expensio is on Android today; the iPhone app arrives in September 2026. Everything that touches your data behaves identically on both — local storage, encryption, Drive backup, App Lock and the "we never collect" list above all apply everywhere. Only these differ:
- Auto-Capture from bank notifications — Android only, and permanently so. Apple provides no way for an app to read another app's notifications or your SMS.
- Home-screen widgets and app-icon shortcuts — Android only for now; planned for a later iPhone release.
- Siri quick add — iPhone only, since Siri is an Apple service.
- Voice Quick Add, camera card scan and everything else — both platforms.
Where a permission or data flow exists on only one platform, it simply never runs on the other. Nothing in this policy grants us access on a platform where the feature is unavailable.
6. Data Sharing
We do not sell or share your financial data with anyone, and there are no ad networks or tracking SDKs. Your financial data goes only where you send it — an exported file, or your own Google Drive backup. Separately, the account record described in section 1 is stored in our Firebase project. Firebase is operated by Google as our processor; it is never used for advertising and is never sold or passed on.
7. Data Retention & Deletion
- You control all data — clear or reset it any time from Profile → Clear Data.
- Uninstalling the app removes all local data.
- You can delete your Drive backup from Google Drive at any time.
- To have the account record described in section 1 deleted, email us and we will remove it.
8. Children's Privacy
Expensio is not intended for children under 13, and we do not knowingly collect data from them.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected here with a new "last updated" date.
10. Contact
Questions about your privacy? Email us at support.expensio@gmail.com.
