Privacy Policy
AutoExpenseTracker (“the app”, “we”, “us”) reads transaction notifications on your phone and turns them into an expense log. This policy explains exactly what the app collects, what leaves your device, who processes it, and how long it is kept. It describes the app's real behaviour rather than generic boilerplate.
The short version
- Your expense log lives on your device. We do not run an account system and we hold no copy of your ledger.
- To read a transaction notification, its text is sent to our server and to an AI model for extraction. This is the core of how the app works, and it is described in full in section 2.1.
- Backups go to your own Google Drive, in a private app folder we cannot browse.
- The free version shows ads through Google AdMob, which uses your device's advertising ID.
- We do not sell your data, and we run no analytics or tracking SDK.
1. Data stored on your device
Expenses, categories, accounts, rules, settings and your local diagnostic log are stored in the app's private storage on your phone. This is the authoritative copy of your data. Uninstalling the app deletes it.
You can require your fingerprint, face or device screen lock before the app opens (Settings → System → App lock). Authentication is handled by Android; the app never receives your biometric data.
2. Data that leaves your device
2.1 Notification content sent for AI extraction
If you grant notification access, the app reads notifications from apps
you have not excluded. To turn a notification into an expense, the app
sends the following over HTTPS to a server we operate on Cloudflare
Workers, which passes it to
Cloudflare Workers AI (model
@cf/openai/gpt-oss-120b):
- The notification text — its title and body, combined. It is sent unmasked: the app does not redact names, reference numbers or any other content before sending.
- The name and package ID of the app that posted the notification.
- Your category list, your default currency, and your account names, types and currencies.
- Up to 100 of your most recent expense records — merchant/party names, amounts, currencies, descriptions, categories, direction and timestamps. These give the model context so it can match a transaction to the right account and avoid duplicates.
Please read this if you use the AI features. Because the notification text is sent unredacted, anything your bank puts in a notification goes with it — which can include partial card numbers, reference codes, balances or a counterparty's name. If you would rather this never happen, turn off “Use AI” in Settings → Intelligence, or revoke notification access in Android settings. You can also exclude individual apps under Settings → Apps.
We do not write these requests to a database, and we do not use your data to train any model. Requests may appear transiently in Cloudflare's operational logs, which exist for reliability and abuse monitoring. Cloudflare processes this data as our infrastructure provider — see the Cloudflare Privacy Policy.
2.2 Weekly Wrap
If you switch on Weekly Wrap, the app sends aggregates only — totals, category sums and merchant names for the week — to generate the recap. Raw notification text is not sent for this feature.
2.3 Device identifier
The app generates a random identifier when it is first installed and sends it with requests to our server. It is used to apply the daily AI allowance per device and to group crash reports. It is not derived from your hardware, contains no personal information, and a reinstall produces a new one.
2.4 Crash reports
If the app crashes, a report is uploaded the next time it launches containing the stack trace, your device manufacturer and model, Android version, the app version, and the random device identifier above. It contains no expense data and no notification text.
2.5 Currency rates
The app fetches exchange rates through our server. These requests carry no personal data.
3. Google services
3.1 Sign-in and Google Drive backup
Backup is optional. If you enable it, you sign in with Google and the
app requests only the
drive.appdata scope. That scope grants access to a private
application folder in your own Google Drive and
nothing else — the app cannot see, list or open your
other files.
Backups are written to your Drive, not to our servers. They are protected by your Google account and by Google's encryption at rest; the app does not apply its own additional encryption layer on top. You can delete backups at any time from the app or from your Google account.
3.2 Advertising (Google AdMob)
The free version displays a banner ad and an optional rewarded video ad that grants extra AI scans. These are served by Google AdMob, which may collect your device's advertising ID, coarse location derived from IP, and ad interaction data in order to serve and measure ads. This is governed by Google's policy on how it uses data from partner sites and apps.
Your expense data is never shared with AdMob or used for ad targeting. You can reset or delete your advertising ID under Android Settings → Privacy → Ads. Subscribing removes ads from the app entirely.
3.3 Subscriptions
Subscriptions are processed by Google Play Billing. Payment details go to Google, never to us; we only receive whether an entitlement is active.
4. Permissions and why they are needed
| Permission | Why |
|---|---|
| Notification access | The core feature — reading transaction notifications to capture expenses. Optional; the app works as a manual tracker without it. |
| Installed apps list | To show you which apps are sending notifications so you can exclude the ones you do not want read. |
| Internet & network state | AI extraction, exchange rates, Drive backup, ads. |
| Post notifications | Backup results and review reminders. |
| Run at startup | To re-arm scheduled backups after a reboot or app update. |
| Foreground service / battery exemption | To keep capturing notifications reliably instead of being killed in the background. Optional. |
5. How long data is kept
| Data | Retention |
|---|---|
| Your expense log on the device | Until you delete it or uninstall the app |
| AI extraction requests | Not stored by us; used only to answer the request |
| Crash reports | Up to 30 days, then deleted automatically |
| Daily AI usage counters | Up to 2 days |
| Cached exchange rates | Up to 7 days (no personal data) |
| Google Drive backups | In your own Drive until you delete them |
6. What we never do
- We do not sell or rent your data.
- We do not use your expenses or notifications to target ads.
- We do not use your data to train AI models.
- We run no analytics, attribution or tracking SDK in the app.
- We keep no server-side copy of your expense log.
- We cannot read your Google Drive outside the app's own folder.
7. Your choices and rights
- Turn off AI processing — Settings → Intelligence. The app still records expenses you enter by hand.
- Revoke notification access — Android Settings → Notifications → Device & app notifications.
- Exclude specific apps — Settings → Apps.
- Export your data from the app at any time.
- Delete your data by deleting records in the app, deleting Drive backups, or uninstalling, which removes everything held locally.
- Opt out of personalised ads — Android Settings → Privacy → Ads, or subscribe to remove ads.
Depending on where you live, you may have rights to access, correct, delete or port your personal data, or to object to its processing (including under the GDPR and the CCPA). Because your ledger is held on your own device and in your own Google Drive, you can exercise most of these yourself. For anything we hold — crash reports and usage counters tied to the random device identifier — email us and we will action it.
8. Children
The app is not directed at children under 13, or under the applicable age of digital consent where you live. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
9. International transfers
Our server runs on Cloudflare's global network and requests are handled at a location near you. Google services (Drive, Play, AdMob) operate globally. Your data may therefore be processed in countries other than your own, whose data protection laws may differ.
10. Changes to this policy
We may update this policy as the app changes. Material changes will be reflected in the “Last updated” date above, and where appropriate announced in the app.
11. Contact
Questions, requests or privacy concerns: wizmao@gmail.com