Privacy Policy

ExpenseFlow · Last updated: 13 August 2026

ExpenseFlow (“ExpenseFlow,” “we,” “us”) is a personal finance tracker that helps you log expenses, track budgets, and get AI-powered coaching. This policy explains what we collect, how we use it, and the choices you have. It applies to the ExpenseFlow mobile app (Android and iOS) and the companion web app at expenseflow-mobile-app-web.web.app.

Short version: your expenses are stored primarily on your device and (if you sign in) synced to your private Supabase account. Free plan users may see Google AdMob ads, Premium users get an ad-free experience, and Google Gemini is used for AI features. We do not sell your personal data or share your financial entries with ad networks.

1. Information we collect

1.1 Information you provide

1.2 Information collected automatically

1.3 Permissions we request on your device

1.4 We never read your SMS or email

Many expense apps ask for permission to read your text messages or email inbox to log transactions automatically. ExpenseFlow deliberately does not do this and never will. Your bank alerts, OTPs, personal messages, and email stay entirely on your device — the app does not request SMS or email permissions at all. Nor does ExpenseFlow read notifications from your other apps. Faster logging is offered only through means you explicitly hand us, one item at a time: typing a quick line, speaking a voice note, scanning a receipt you choose to photograph, or importing a statement file or a payment screenshot you pick yourself (or share to ExpenseFlow). Nothing is read in the background, and nothing is added to your expenses until you review it and tap save.

2. How we use your information

3. Where your data is stored

4. Third-party services we use

5. Advertising & consent

ExpenseFlow may show ads to Free plan users through Google AdMob. Premium subscribers receive an ad-free experience. AdMob and related Google SDKs may collect or receive the Android Advertising ID, app set ID, IP address, device and account identifiers, app interactions, ad interactions, diagnostics, and approximate location inferred from IP address. These data types are used to serve ads, limit repeated ads, measure ad performance, detect invalid activity, prevent fraud, and comply with legal obligations.

We do not send your expense amounts, income, savings goals, transaction descriptions, budget details, coach messages, or imported statement files to AdMob for advertising.

In the EEA, UK, and Switzerland, Google UMP may show a consent form before personalized ads are requested. If you decline consent, the app can request non-personalized ads where available. You can revisit ad privacy choices from Settings → Privacy options when that option is shown. You can also reset or delete the Android Advertising ID in Android settings. On iOS 14.5+, IDFA-backed advertising is controlled by the system App Tracking Transparency prompt and iOS tracking settings.

6. Your choices & rights

7. Data retention

We retain your data for as long as your account is active. When you delete your account, financial data and the account record are removed within 30 days. Backups are overwritten on a rolling 30-day cycle. Aggregated, non-identifying logs may be retained longer for security and debugging.

8. Children

ExpenseFlow is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children. If you believe a child has used the app, contact us and we will delete the data.

9. Security

On-device settings are stored in an AES-encrypted Hive box. Traffic between the app and our backend is sent over HTTPS. Supabase enforces row-level security so one user cannot read another user’s rows. No system is perfectly secure; if you discover a vulnerability, please report it to the contact address below.

10. International transfers

Some of our processors (Gemini, Firebase, Supabase, RevenueCat, and Resend) operate globally and may process your data outside your country of residence, including in the United States. Where required, we rely on the standard contractual clauses published by the European Commission and, for UAE users, on these same contractual safeguards with our processors, consistent with the UAE Personal Data Protection Law’s cross-border provisions.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced in-app before they take effect. The “Last updated” date at the top reflects the most recent revision.

12. Contact

For privacy questions or to exercise your rights, email Quantumcreations.in@gmail.com.

Data controller: QuantumCreations (Jaya Pankaj Jambhulkar)
Postal address: FL-C/801, Pristine Prolife 170, Nr. Sayaji Hotel, Maharashtra 411057, India