Privacy Policy
Last updated: 20 July 2026
Who this policy covers
This policy applies to the Expense Manager mobile application (“the app”) for Android and iOS, published by srjn45 (“we”, “us”). It explains what the app stores, what it does not collect, and the choices you have.
Data the app stores on your device
To do its job, the app saves the following only on your device, in on-device storage:
- Your expense and income entries — titles, amounts, currencies, dates, categories, tags, and notes.
- Categories and tag suggestions you create.
- App settings, such as your default currency.
- If you enable the app lock, a salted cryptographic hash of your PIN — never the PIN itself — kept in the device’s secure keystore (Android Keystore / iOS Keychain).
This data lives in a local SQLite database on the device and, on Android, is excluded from cloud auto-backup. It is not uploaded anywhere.
Data we collect: none
The app has no server and no account system. We do not collect, receive, store, sell, or share any personal information. Specifically, the app contains:
- No analytics, telemetry, or usage tracking.
- No advertising or ad networks.
- No third-party trackers or cookies.
- No login, sign-up, or cloud sync.
Device permissions
The app requests only what a feature needs, when you use it:
- Files / storage — only when you choose to export or import a CSV or backup file. The app reads and writes the file you pick; it does not scan or upload your files.
- Biometrics (optional) — if you enable biometric unlock, the app asks the operating system to verify your fingerprint or face. The biometric check happens entirely on-device; the app never receives your biometric data.
Sharing your data
You are the only one who can move your data off the device, and only by an explicit action you take — for example, exporting a CSV or backup file and choosing where to send it. Once you export a file, whatever you do with it (share it, email it, save it to cloud storage) is outside the app and governed by the service you choose. The app itself shares nothing.
Third-party services
The app has no third-party SDKs that collect data at runtime. It is built with Expo / React Native, which are development tools only and are not embedded as data-collecting services in the shipped app. If you install the app from Google Play or the App Store, that store’s own privacy policy governs the download and any diagnostics the store platform itself collects — not the app.
Children’s privacy
Because the app collects no personal data at all, it collects none from children. It is a general-audience utility and is safe in that regard.
Deleting your data
Your data is entirely under your control:
- Use the in-app “wipe and start over” option to erase all entries and remove the stored PIN.
- Or uninstall the app — this deletes the local database and secure-storage entries from your device.
Because nothing is stored on any server, there is no remote copy for us to delete or for you to request.
Security
Data is stored locally and, on Android, excluded from cloud auto-backup. The optional PIN is stored only as a salted hash in the OS secure keystore, and repeated wrong PIN attempts are rate-limited to resist guessing. That said, no method of on-device storage is perfectly secure, and the security of your data ultimately depends on the security of your device (screen lock, OS updates, physical access).
Changes to this policy
If this policy changes, we will update this page and revise the “Last updated” date above. Material changes will be reflected here before a new version of the app that depends on them is released.
Contact
Questions about this policy? Reach out at srajanpathak45@gmail.com or open an issue on GitHub.