This Privacy Policy explains what data ExpensO handles, where it lives, and the choices you have. ExpensO is an offline-first, end-to-end-encrypted personal finance app: your financial data stays on your device. The free version is ad-supported (Google AdMob); a one-time "ExpensO Full" purchase removes all ads. Ads only run after you agree through the Google consent prompt, and the ad software is never even started for ExpensO Full owners.
For data that stays on your device, the individual developer identified above is the nominal data controller / data fiduciary, but because ExpensO has no backend, you are effectively in sole control and the developer cannot access, restore, or delete it.
For advertising data processed through AdMob, Google Ireland Limited / Google LLC acts as an independent controller (and, in some regions, as the developer's processor) under Google's own privacy policy (policies.google.com/privacy) and the AdMob/Google Ads data terms. A list of Google's advertising technology providers is at support.google.com/admob/answer/9012903.
Transactions, amounts, dates, payees, notes, categories, tags, accounts and the last four digits of an account label (full card/account numbers are rejected on entry), budgets, savings goals, recurring rules, bill reminders, attached receipt images, and app settings.
When you are not an ExpensO Full owner, ads are shown by the Google Mobile Ads (AdMob) SDK. Subject to your consent (section 3.3):
Legal bases: consent (GDPR Art. 6(1)(a); ePrivacy) where the UMP form asks for it; a US-state "Do Not Sell or Share / opt out of targeted advertising" signal is offered where applicable; DPDP Act 2023 — consent for a lawful purpose. Ads may be personalised (if you consent) or non-personalised / contextual (if you decline where a decline option is offered).
ExpensO Full owners: the ad SDK is not initialised at all. No advertising ID is accessed, no ad request is made, and nothing ad-related leaves the device.
Before any ad loads, ExpensO runs the Google User Messaging Platform (UMP) consent flow:
Your choices are stored on your device by the UMP SDK. You can reopen the form any time from Settings → "Ad privacy choices" (shown where UMP requires it). On iOS 14.5+, after the UMP step ExpensO also shows Apple's App Tracking Transparency prompt; if you deny it, the advertising identifier is not used and ads are non-personalised.
"ExpensO Full" is a one-time, non-consumable purchase processed by Google Play Billing or the Apple App Store. The store handles your payment, billing address and taxes under its own privacy policy and terms; ExpensO never sees or stores your card or payment details. ExpensO stores a single local flag ("purchased: yes/no"), on-device only, not synced. The developer receives only the store's standard aggregated sales, payout and tax reports. Restore-purchases re-checks your entitlement with the store.
If — and only if — you sign in with Google and grant the in-app cloud-sync consent:
drive.appdata only — a private app-data folder in your
Drive that other apps cannot see. ExpensO cannot see the rest of your Drive.ExpensO advertises the device over mDNS on your local network and exchanges encrypted change records over a direct socket with devices you paired by QR code. Payload is ciphertext; an on-network observer sees only timing, size and mDNS presence. Nothing is sent to the internet.
If you enable online exchange-rate refresh and grant the fx_fetch consent,
ExpensO requests public, non-personal currency rates over HTTPS. The request
contains no account data and no identifiers beyond the IP address any HTTPS
request exposes.
Bill and recurring-transaction reminders are scheduled on the device by the operating system. No notification content is sent anywhere.
| Permission | Why |
|---|---|
| Internet / network state | Ads (free tier); cloud sync to your Drive; optional exchange rates; store billing. |
AD_ID (Android advertising ID) | Serve and frequency-cap ads and measure ad performance on the free tier. Not accessed for ExpensO Full. |
| Local network / multicast (Wi-Fi) | Discover your other devices for peer-to-peer sync. |
| Camera | Scan the pairing QR code and capture receipt images (encrypted immediately; nothing uploaded). |
| Biometric / device credential | Unlock the app and confirm high-value actions (export, erase). |
| Notifications | Show bill and recurring-transaction reminders. |
| Schedule alarms / run at boot | Fire reminders on time and re-register them after a restart. |
| Billing | Process the one-time "ExpensO Full" purchase. |
The developer does not sell or share your ledger data with anyone.
ExpensO is a general-audience finance tool, not directed to children. AdMob
is configured with tagForChildDirectedTreatment not set to child-directed
and a maximum ad content rating of "G". The app does not knowingly process
data of children under 13 (or the minimum digital-consent age in your
jurisdiction). If you believe a child has used the app, erase the data from
Settings and contact the developer.
FLAG_SECURE / resign blur).Lawful bases: contract/legitimate interests for on-device app functionality; consent for advertising and for cloud sync/FX. You have the rights of access, rectification, erasure, restriction, portability, and objection (including objection to direct marketing / profiling), and the right to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your supervisory authority. As a sole developer established in India with EEA/UK users, the developer relies on Google's advertising SCCs for transfers; contact the developer for any Art. 27 representative query.
The developer does not sell personal information for money. Behavioural advertising via AdMob may be treated as "sharing" / "targeted advertising"; you can opt out through the UMP "Do Not Sell or Share" message, the iOS ATT prompt, or by buying ExpensO Full. You may request to know, delete, and correct; you will not be discriminated against for exercising a right. Global Privacy Control signals, where the platform surfaces them, are honoured by the UMP framework.
Processing is on the basis of your consent for a lawful purpose (advertising, cloud sync, FX) or as necessary to provide the app. You may withdraw consent, seek correction/erasure, and nominate a person to exercise rights on your behalf. Grievances: contact the developer (details in Settings → Legal); if unresolved, you may approach the Data Protection Board of India.
Brazil (LGPD): rights of confirmation, access, correction, anonymisation, portability, deletion, and information about sharing; legal basis is consent for advertising. Canada (PIPEDA / Québec Law 25): consent-based; access and correction rights; the developer is accountable for transfers to Google. Australia (Privacy Act / APPs): access and correction; APP 7 direct-marketing opt-out via the UMP form. South Korea (PIPA): consent for advertising data; withdrawal and access rights. Residents of any other jurisdiction retain whatever rights local law grants and may contact the developer to exercise them.
On-device data: until you delete it or uninstall. Ad-consent choices: until you change them or clear app data. Purchase entitlement flag: until you erase app data (your store account retains the purchase). Advertising data held by Google is retained under Google's retention policies.
Developer contact details are in the app under Settings → Legal. For advertising data held by Google, use Google's privacy tools and the links in section 2.
If this policy changes materially, the in-app version number is incremented and the acceptance screen is shown again so you can review it before continuing. The current text is always available under Settings → Legal, and this page is updated to match.