Spenlow

Privacy Policy

Last updated: 10 September 2026

Spenlow is privacy-first. Spenlow ("the app") is a personal expense tracker for Android. Your financial data belongs to you and stays on your device. This policy explains what data the app handles and why.

1. Your financial data stays on your device

Everything you record — transactions, amounts, merchant names, categories, budgets, and accounts — is stored in an encrypted database on your device only. It is never uploaded, to us or to anyone else. There is no account to create, no server that holds your records, and no sync.

One thing can send your records off your phone, and only when you switch it on yourself: Web Access (§5), which serves them to a browser on your own Wi-Fi. Nothing about that reaches us — see §5 for exactly what it does and what it does not protect against.

One thing can make some of them visible without opening the app, and again only if you set it up: a home screen widget (§6). It still never leaves your device — but it is on your home screen, so §6 spells out exactly what it does and does not show.

One more thing can send a full copy of your records off your phone, and only if you turn it on yourself: Google Drive backup (§7), which uploads an encrypted copy to your own Google Drive. Nothing about it reaches us — see §7 for exactly what is protected and how to turn it off.

The app does not sell, rent, or share your financial data with anyone, because we never receive it in the first place.

2. Optional diagnostics (off by default)

The app can send anonymous diagnostics to help us find crashes and slow screens. This is off unless you turn it on, and you are asked once, after setup, in a prompt you can decline.

If you turn it on, the following is collected:

The following is never collected, whether diagnostics are on or off:

The one identifier that does exist. So that a handful of crash reports can be recognised as coming from the same phone rather than from many, Firebase assigns a random per-install ID. It is generated on your device, is specific to Spenlow, cannot be linked to you or to any other app, and is discarded when you uninstall the app or clear its data. Turning diagnostics off deletes it along with everything else (§3). We call the diagnostics "anonymous" in that sense — not tied to you — rather than in the sense that no identifier of any kind exists.

We use two third-party services to receive this diagnostic data: Kotzilla (app performance) and Google Firebase — Crashlytics and Analytics (crash reporting and usage analytics). They act as processors on our behalf and receive only the categories listed above. Neither is permitted to use the data for advertising, and neither receives an advertising identifier from this app.

3. Turning diagnostics off, and what that does

You can turn diagnostics off at any time in Settings → Privacy → Share Diagnostics. Doing so, immediately and without asking again:

Reports that were already sent before you turned it off cannot be recalled by the app. Those are held by the services named in §2 and age out on their retention schedules (crash reports are retained for approximately 90 days). To request earlier deletion of already-sent diagnostics, email the address in §12 and we will action it with those providers.

4. Network access

The app declares the INTERNET permission for three things and nothing else: the optional diagnostics in §2, the Web Access server in §5, and the optional Google Drive backup in §7. It is never used to send your financial data — unencrypted — to us or to any third party, and the app has no ads and no remote configuration of your records. Backup is not sync: it copies one direction, phone to your own Drive, with no merge and no reconciliation between two devices.

No advertising or tracking permissions. Spenlow requests no advertising permission of any kind. The advertising and attribution permissions that the Google analytics library would otherwise add on its own — AD_ID, ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, and the Play install-referrer permission — are all removed from the app deliberately. You can check this yourself: the app's full permission list on its Play listing contains none of them.

The app makes no outbound network request carrying your unencrypted financial data. Web Access is a server — it answers requests from your own devices; it does not call out. Google Drive backup does call out, but only to upload files that were already encrypted, on your phone, before the request was made — see §7.

5. Web Access (off by default)

Web Access lets you open your Spenlow data in a browser on the same Wi-Fi as your phone — useful for reviewing a month or cleaning things up on a laptop keyboard. It is off unless you turn it on, and it is not downloaded at all unless you ask for it.

What it does

What it does not do

What you should know before you use it

Traffic on your local network is not encrypted. On a network you control — your home Wi-Fi, or your phone's own hotspot — that is a reasonable trade-off. On a network you do not control, such as a café or an office, someone able to monitor that network could read what is being served. We recommend using Web Access only on networks you trust.

Anyone you pair has full access to your data until you remove them, or until you turn Web Access off.

6. Home screen widgets and launcher shortcuts (off until you add one)

Spenlow offers two home-screen widgets, plus a set of launcher shortcuts.

Quick Add is a small grid of one-tap tiles for the cash spends you repeat, like a daily chai or an auto fare, plus a plain 1×1 button that just opens the Add screen.

Budget Glance shows how one of your budgets is going, as a percentage and a progress bar — for example "68% used" with "12 days left". Budget figures are hidden by default: no rupee amount appears anywhere on this widget until you turn that on yourself, in Settings → Privacy → "Show amounts on widgets". Turn it on and the widget shows the actual figures (for example "₹13,600 of ₹20,000"); turn it off and every placed widget goes back to percentage-and-bar only, the next time it refreshes — no reinstall or replacement needed. Like Quick Add, everything Budget Glance shows is read from the encrypted database on your device at the moment it draws, and nothing is copied anywhere else to make that happen.

Launcher shortcuts — what you see when you long-press the Spenlow icon — jump straight to Add Expense, Analytics, and Search, plus, only when something is waiting for you, a "needs review" entry. None of them show an amount, a balance, or a budget position: each is a plain label that opens a screen, nothing more.

Worth knowing, because it is the one thing that changes: a placed widget is visible to anyone who can see your home screen, without opening the app. If you use the app lock, a widget shows "Open Spenlow to load your tiles" (or, for Budget Glance, "Open Spenlow to load your budget") until you unlock, rather than showing your data.

7. Google Drive backup (off by default)

You can choose to back up Spenlow to your own Google Drive. This is off until you turn it on in Settings → Data → Backup, and turning it on requires two things: choosing a Google account, and creating a passphrase.

What is backed up. Your whole Spenlow database (transactions, accounts, budgets, categories, credit cards and statements, recurring rules, quick-add tiles) and your app settings. Receipt images are a separate switch, off unless you turn it on.

How it is protected. Everything is encrypted on your phone, with a key derived from your passphrase, before it is uploaded. The encrypted files are stored in the hidden application-data folder of your Google Drive, which only Spenlow can access — you will not see them if you browse your own Drive yourself. Google receives ciphertext only. Spenlow has no server and never sees your passphrase or your data. If you forget the passphrase, the backup cannot be restored by anyone, including us.

What leaves the device. Only the encrypted files, over HTTPS, to Google Drive. Nothing about their contents — no amounts, names, counts or file names — is included in diagnostics (§2).

This is backup, not sync. Each backup replaces the one before it; there is no merge and no reconciliation between two phones. Restoring puts one device's data onto another — it does not keep two devices in step with each other.

Turning it off. Settings → Data → Backup → Turn off backup. You can keep the encrypted files in Drive for a later restore, or delete them all at the same time. You can also revoke Spenlow's access to your Drive at myaccount.google.com/permissions, or remove the files yourself from Drive → Settings → Manage apps.

Restoring. On a new phone, choose "Restore from Google Drive" during setup, sign in to the same account and enter your passphrase. Settings that need an Android permission — notifications and SMS detection — are turned back on only if you grant that permission again during the restore.

Google user data: what Spenlow requests, and what it does with it

The scope requested. Spenlow requests one Google OAuth scope and no other: https://www.googleapis.com/auth/drive.appdata. This grants access to the hidden application-data folder that Spenlow creates for itself in your Drive. It does not grant access to any other file in your Drive — Spenlow cannot list, open, modify or delete your own documents, photos or anything else stored there, and it never asks for a scope that would let it.

Why it is needed. Without it there is nowhere to put the backup. Spenlow runs no server of its own, so the only place an encrypted copy of your ledger can live is storage that already belongs to you. The application-data folder is the narrowest such place Google offers.

How it is accessed. Only to write, read, list and delete Spenlow's own backup files, and only when a backup or a restore that you configured is running. Spenlow does not access your Drive at any other time.

How it is stored. The files Spenlow writes are encrypted on your phone before upload and are stored in your Drive, under your Google account, subject to Google's own terms. The OAuth token that authorises the upload is held on your device by Google Play services; it is never transmitted to us, because there is no service of ours to transmit it to. We store no copy of your Google account details, your files, or their contents.

How it is shared. It is not. Google user data obtained through this scope is never sold, rented, or transferred to anyone, is never used for advertising or for building a profile, is never used to train artificial-intelligence or machine-learning models, and is never read by a human — the files are ciphertext, so there is nothing readable to read.

Limited Use. Spenlow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access. You can withdraw Spenlow's access to your Drive at any time at myaccount.google.com/permissions, independently of anything in the app. Doing so stops all further backups. Files already in your Drive stay there until you delete them; see §9.

8. SMS permission (on-device parsing)

If — and only if — you explicitly enable it, the app requests the RECEIVE_SMS permission so it can detect incoming bank and financial transaction messages and automatically create expense or income entries for you.

9. Data retention and deletion

Your financial data remains on your device for as long as the app is installed. Uninstalling the app removes it from the device. You may also delete individual transactions, budgets, and accounts within the app at any time. If you have turned on Google Drive backup (§7), your encrypted backup files remain in your Drive until you delete them — either by turning backup off and choosing to delete them, or directly in your own Google Drive. Uninstalling Spenlow does not delete them for you. Diagnostic data is covered separately in §3.

10. Children

The app is not directed at children under 13 and we do not knowingly collect data from them.

11. Changes to this policy

If this policy changes, we will update the "Last updated" date above and post the revised policy at the same URL.

12. Contact

Questions about this policy, or a request to delete already-sent diagnostics? Email seenivasant.dev+spenlow@gmail.com.