Privacy Policy
Last updated: 10 September 2026
Spenlow is privacy-first. Spenlow ("the app") is a personal expense tracker for Android. Your financial data belongs to you and stays on your device. This policy explains what data the app handles and why.
1. Your financial data stays on your device
Everything you record — transactions, amounts, merchant names, categories, budgets, and accounts — is stored in an encrypted database on your device only. It is never uploaded, to us or to anyone else. There is no account to create, no server that holds your records, and no sync.
One thing can send your records off your phone, and only when you switch it on yourself: Web Access (§5), which serves them to a browser on your own Wi-Fi. Nothing about that reaches us — see §5 for exactly what it does and what it does not protect against.
One thing can make some of them visible without opening the app, and again only if you set it up: a home screen widget (§6). It still never leaves your device — but it is on your home screen, so §6 spells out exactly what it does and does not show.
One more thing can send a full copy of your records off your phone, and only if you turn it on yourself: Google Drive backup (§7), which uploads an encrypted copy to your own Google Drive. Nothing about it reaches us — see §7 for exactly what is protected and how to turn it off.
The app does not sell, rent, or share your financial data with anyone, because we never receive it in the first place.
2. Optional diagnostics (off by default)
The app can send anonymous diagnostics to help us find crashes and slow screens. This is off unless you turn it on, and you are asked once, after setup, in a prompt you can decline.
If you turn it on, the following is collected:
- Crash and freeze reports — the technical stack trace, your device model, Android version, and app version.
- Performance data — screen load times and internal timings.
- Feature usage — which screens and features are opened.
- which app settings you have chosen — for example theme, week start day, and whether notifications or SMS parsing are on — as on/off or named values, never anything you typed.
The following is never collected, whether diagnostics are on or off:
- transaction amounts, merchant names, categories, notes or account balances
- account names or numbers
- SMS content of any kind
- your name, email address, phone number or contacts
- your Android Advertising ID, or any other identifier that could follow you
across apps. The app requests no advertising permissions at all — the
AD_ID,ACCESS_ADSERVICES_AD_ID,ACCESS_ADSERVICES_ATTRIBUTIONand install-referrer permissions are explicitly removed from the app, and advertising-ID collection is switched off in the analytics SDK. There are no ads in Spenlow, no ad networks, no install-campaign attribution, and no profile of you anywhere.
The one identifier that does exist. So that a handful of crash reports can be recognised as coming from the same phone rather than from many, Firebase assigns a random per-install ID. It is generated on your device, is specific to Spenlow, cannot be linked to you or to any other app, and is discarded when you uninstall the app or clear its data. Turning diagnostics off deletes it along with everything else (§3). We call the diagnostics "anonymous" in that sense — not tied to you — rather than in the sense that no identifier of any kind exists.
We use two third-party services to receive this diagnostic data: Kotzilla (app performance) and Google Firebase — Crashlytics and Analytics (crash reporting and usage analytics). They act as processors on our behalf and receive only the categories listed above. Neither is permitted to use the data for advertising, and neither receives an advertising identifier from this app.
3. Turning diagnostics off, and what that does
You can turn diagnostics off at any time in Settings → Privacy → Share Diagnostics. Doing so, immediately and without asking again:
- stops all collection,
- cancels anything queued for upload,
- deletes diagnostic data still stored on your device.
Reports that were already sent before you turned it off cannot be recalled by the app. Those are held by the services named in §2 and age out on their retention schedules (crash reports are retained for approximately 90 days). To request earlier deletion of already-sent diagnostics, email the address in §12 and we will action it with those providers.
4. Network access
The app declares the INTERNET permission for three things and nothing else: the
optional diagnostics in §2, the Web Access server in §5, and the optional Google Drive backup
in §7. It is never used to send your financial data — unencrypted — to us or to any third
party, and the app has no ads and no remote configuration of your records. Backup is not
sync: it copies one direction, phone to your own Drive, with no merge and no reconciliation
between two devices.
No advertising or tracking permissions. Spenlow requests no advertising
permission of any kind. The advertising and attribution permissions that the Google analytics
library would otherwise add on its own — AD_ID,
ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, and the
Play install-referrer permission — are all removed from the app deliberately. You can check
this yourself: the app's full permission list on its Play listing contains none of them.
The app makes no outbound network request carrying your unencrypted financial data. Web Access is a server — it answers requests from your own devices; it does not call out. Google Drive backup does call out, but only to upload files that were already encrypted, on your phone, before the request was made — see §7.
5. Web Access (off by default)
Web Access lets you open your Spenlow data in a browser on the same Wi-Fi as your phone — useful for reviewing a month or cleaning things up on a laptop keyboard. It is off unless you turn it on, and it is not downloaded at all unless you ask for it.
What it does
- While you have it switched on, your phone runs a small web server on your local network.
- A browser can reach it only after you pair that browser, by scanning a QR code shown on your phone or typing a 6-digit PIN from it. A code is created only when you open the Web Access screen, and it stops working five minutes later or as soon as it is used — whichever comes first. Nobody on your network can pair with a phone that has never displayed a code.
- A paired browser can read and change your financial data, exactly as the app can.
- You can see every paired device and remove any of them at any time, from your phone or from a paired browser. Removal takes effect on that device's next request.
- Turning the toggle off stops the server and disconnects every paired browser. Pairings are kept in memory only and are never saved, so they last only as long as that session — the next time you turn Web Access on, you pair again. It also stops itself if the Wi-Fi drops.
What it does not do
- It never sends anything to us or to any third party. We do not receive your data, and there is no server of ours involved at any point.
- It does not work over mobile data. If your phone has no Wi-Fi and no hotspot, the server refuses to start.
- It is not reachable from the internet. There is no port forwarding, no tunnel, and no relay.
- Nothing is stored outside your phone. The browser keeps only a key that lets it connect.
- Nothing is stored about your pairings, on the phone either. Which devices you paired, and when, is not written to the database or to any file — it exists only while Web Access is running and is gone the moment you switch it off.
What you should know before you use it
Traffic on your local network is not encrypted. On a network you control — your home Wi-Fi, or your phone's own hotspot — that is a reasonable trade-off. On a network you do not control, such as a café or an office, someone able to monitor that network could read what is being served. We recommend using Web Access only on networks you trust.
Anyone you pair has full access to your data until you remove them, or until you turn Web Access off.
6. Home screen widgets and launcher shortcuts (off until you add one)
Spenlow offers two home-screen widgets, plus a set of launcher shortcuts.
Quick Add is a small grid of one-tap tiles for the cash spends you repeat, like a daily chai or an auto fare, plus a plain 1×1 button that just opens the Add screen.
- Nothing appears until you place a widget yourself. A fresh install has no widget and never adds one for you.
- The tiles show a label and a fixed price — the things you buy repeatedly. They do not show your balance, your total spending, or how much of a budget you have used.
- The 1×1 button widget shows no data at all — no label, no amount, nothing read from your data. It only opens the Add screen when tapped.
- Everything a widget displays is read from the encrypted database on your device. Nothing about it is transmitted, and nothing is copied into unencrypted storage to make it render.
- Tapping a tile records the expense and posts a short confirmation you can undo. That confirmation shows the tile's name only, never an amount, so no figure appears in your notification shade or on your lock screen.
- Removing a widget removes all of it. There is nothing left behind.
Budget Glance shows how one of your budgets is going, as a percentage and a progress bar — for example "68% used" with "12 days left". Budget figures are hidden by default: no rupee amount appears anywhere on this widget until you turn that on yourself, in Settings → Privacy → "Show amounts on widgets". Turn it on and the widget shows the actual figures (for example "₹13,600 of ₹20,000"); turn it off and every placed widget goes back to percentage-and-bar only, the next time it refreshes — no reinstall or replacement needed. Like Quick Add, everything Budget Glance shows is read from the encrypted database on your device at the moment it draws, and nothing is copied anywhere else to make that happen.
Launcher shortcuts — what you see when you long-press the Spenlow icon — jump straight to Add Expense, Analytics, and Search, plus, only when something is waiting for you, a "needs review" entry. None of them show an amount, a balance, or a budget position: each is a plain label that opens a screen, nothing more.
Worth knowing, because it is the one thing that changes: a placed widget is visible to anyone who can see your home screen, without opening the app. If you use the app lock, a widget shows "Open Spenlow to load your tiles" (or, for Budget Glance, "Open Spenlow to load your budget") until you unlock, rather than showing your data.
7. Google Drive backup (off by default)
You can choose to back up Spenlow to your own Google Drive. This is off until you turn it on in Settings → Data → Backup, and turning it on requires two things: choosing a Google account, and creating a passphrase.
What is backed up. Your whole Spenlow database (transactions, accounts, budgets, categories, credit cards and statements, recurring rules, quick-add tiles) and your app settings. Receipt images are a separate switch, off unless you turn it on.
How it is protected. Everything is encrypted on your phone, with a key derived from your passphrase, before it is uploaded. The encrypted files are stored in the hidden application-data folder of your Google Drive, which only Spenlow can access — you will not see them if you browse your own Drive yourself. Google receives ciphertext only. Spenlow has no server and never sees your passphrase or your data. If you forget the passphrase, the backup cannot be restored by anyone, including us.
What leaves the device. Only the encrypted files, over HTTPS, to Google Drive. Nothing about their contents — no amounts, names, counts or file names — is included in diagnostics (§2).
This is backup, not sync. Each backup replaces the one before it; there is no merge and no reconciliation between two phones. Restoring puts one device's data onto another — it does not keep two devices in step with each other.
Turning it off. Settings → Data → Backup → Turn off backup. You can keep the encrypted files in Drive for a later restore, or delete them all at the same time. You can also revoke Spenlow's access to your Drive at myaccount.google.com/permissions, or remove the files yourself from Drive → Settings → Manage apps.
Restoring. On a new phone, choose "Restore from Google Drive" during setup, sign in to the same account and enter your passphrase. Settings that need an Android permission — notifications and SMS detection — are turned back on only if you grant that permission again during the restore.
Google user data: what Spenlow requests, and what it does with it
The scope requested. Spenlow requests one Google OAuth scope and no other:
https://www.googleapis.com/auth/drive.appdata. This grants access to the hidden
application-data folder that Spenlow creates for itself in your Drive. It does not grant
access to any other file in your Drive — Spenlow cannot list, open, modify or delete your own
documents, photos or anything else stored there, and it never asks for a scope that would let
it.
Why it is needed. Without it there is nowhere to put the backup. Spenlow runs no server of its own, so the only place an encrypted copy of your ledger can live is storage that already belongs to you. The application-data folder is the narrowest such place Google offers.
How it is accessed. Only to write, read, list and delete Spenlow's own backup files, and only when a backup or a restore that you configured is running. Spenlow does not access your Drive at any other time.
How it is stored. The files Spenlow writes are encrypted on your phone before upload and are stored in your Drive, under your Google account, subject to Google's own terms. The OAuth token that authorises the upload is held on your device by Google Play services; it is never transmitted to us, because there is no service of ours to transmit it to. We store no copy of your Google account details, your files, or their contents.
How it is shared. It is not. Google user data obtained through this scope is never sold, rented, or transferred to anyone, is never used for advertising or for building a profile, is never used to train artificial-intelligence or machine-learning models, and is never read by a human — the files are ciphertext, so there is nothing readable to read.
Limited Use. Spenlow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access. You can withdraw Spenlow's access to your Drive at any time at myaccount.google.com/permissions, independently of anything in the app. Doing so stops all further backups. Files already in your Drive stay there until you delete them; see §9.
8. SMS permission (on-device parsing)
If — and only if — you explicitly enable it, the app requests the RECEIVE_SMS
permission so it can detect incoming bank and financial transaction messages and
automatically create expense or income entries for you.
- Access is limited to financial transaction SMS. The app does not parse personal messages.
- All parsing happens entirely on your device.
- The raw SMS message text is never stored and is never sent anywhere.
- SMS access is optional. You may decline it and enter transactions manually; the app works fully without it. You can revoke the permission at any time in Android Settings.
9. Data retention and deletion
Your financial data remains on your device for as long as the app is installed. Uninstalling the app removes it from the device. You may also delete individual transactions, budgets, and accounts within the app at any time. If you have turned on Google Drive backup (§7), your encrypted backup files remain in your Drive until you delete them — either by turning backup off and choosing to delete them, or directly in your own Google Drive. Uninstalling Spenlow does not delete them for you. Diagnostic data is covered separately in §3.
10. Children
The app is not directed at children under 13 and we do not knowingly collect data from them.
11. Changes to this policy
If this policy changes, we will update the "Last updated" date above and post the revised policy at the same URL.
12. Contact
Questions about this policy, or a request to delete already-sent diagnostics? Email seenivasant.dev+spenlow@gmail.com.