ExpenseFlow Privacy Policy

Clear information about how ExpenseFlow handles your data

We built ExpenseFlow to help people understand their money without making privacy harder than it needs to be. This Privacy Policy explains, in straightforward language, what information the app handles, when it stays on your device, when it is sent to another service, and the choices available to you.

ExpenseFlow is an independent project operated by Siam Mahmud Khan (“ExpenseFlow,” “we,” “us,” or “our”) through an individual Apple Developer account. This policy applies to the ExpenseFlow iOS app, its widget, cloud sync and backup, premium features, receipt scanning, reminders, exports, and optional artificial-intelligence features (together, the “Service”).

1. The short version

2. Information ExpenseFlow handles

2.1 Financial and app information you enter

ExpenseFlow handles the information you choose to record, including expenses, income, budgets, savings goals, debts, lending records, recurring entries, categories, templates, shared-event or group records, receipt details, notes, names, labels, and similar information. It also stores settings such as your currency, reminder preferences, accessibility choices, onboarding selections, and dashboard preferences.

Because notes and labels are free-text fields, please avoid entering information you do not need the app to hold, especially another person’s sensitive information.

2.2 Account and sign-in information

If you sign in with email, Apple, or Google, we may receive and process your name, email address, authentication provider, provider-issued identifier, Firebase user identifier, and authentication or security information needed to keep you signed in. Google and Apple may separately process information under their own privacy policies.

If you continue as a guest, ExpenseFlow does not create a Firebase Authentication account for you.

2.3 Receipts, camera, and photos

When you scan or import a receipt, the app may access the camera or photo library with your permission. A receipt can contain a merchant name, date, amount, taxes, discounts, line items, payment clues, and other visible text. Text recognition is performed on-device with Apple’s Vision and VisionKit technologies. The resulting image and extracted information may be saved with your local records and may be included in a backup or sync operation when that feature supports the record.

2.4 Location and currency suggestions

ExpenseFlow requests location only after you choose a feature that needs it, such as quickly filling a location during onboarding or suggesting an appropriate currency. The app asks iOS for a kilometer-level location reading and uses Apple’s geocoding service to turn it into a place or country. Actual precision is controlled by iOS and your permission settings.

We do not use location for continuous tracking, advertising, or background movement history. You can deny or revoke location access in iOS Settings and choose a currency manually.

2.5 Purchases and entitlements

Apple processes purchases made through the App Store. We may receive a product identifier, purchase or renewal state, transaction verification result, and entitlement status so that ExpenseFlow can unlock or restore premium access. We do not receive your complete payment-card or bank-account information.

2.6 Technical, security, and diagnostic information

The app and its service providers may process technical information such as app version, device and operating-system details, app-instance identifiers, IP address, authentication events, integrity signals, performance measurements, crash reports, error logs, and limited interaction data. We use this information to deliver configuration, prevent abuse, diagnose failures, and improve reliability.

ExpenseFlow uses Firebase services that may include Authentication, Cloud Firestore, Remote Config, Crashlytics, Performance Monitoring, and App Check. Firebase Analytics event collection is currently disabled. If we enable it in a future release, we will update this policy and the App Store privacy disclosures before collecting analytics events. We do not use Firebase services to create advertising profiles from your financial records.

2.7 AI information

If you choose to use an AI feature and give permission, ExpenseFlow may process your prompt, recent chat context, the financial information needed to answer the request, the AI model used, and usage information such as request counts, token counts, and the last request time. If you decline or later turn off AI data sharing, ExpenseFlow will not send AI coach requests to Google Gemini through Firebase AI Logic until you grant permission again.

3. Where information is stored

3.1 Local and guest use

Core records are designed to work locally. Guest records, preferences, receipt-processing data, locally created exports, and custom AI credentials generally remain on your device unless you deliberately use cloud sync, sharing, remote AI, support, or another connected feature. Uninstalling the app may remove local-only data, subject to normal iOS backup behavior.

Even in guest mode, the app may contact Firebase or Apple for configuration, integrity checks, diagnostics, performance, purchase verification, or other operational functions. Guest mode therefore does not mean that no technical data ever leaves the device.

3.2 Signed-in cloud sync and backup

When you sign in and use cloud features, ExpenseFlow may upload records associated with your account to Cloud Firestore. This can include your financial entries, recurring items, budgets, savings information, debts and lending information, categories, templates, group or event records, related notes, deletion markers, and other data necessary to keep devices consistent.

Cloud data is separated by account identifiers and protected through authentication and application security rules. No internet service is risk-free, so you should also protect your device and sign-in credentials.

4. AI processing deserves a clear explanation

Before ExpenseFlow sends your first AI coach request, the app asks for your permission and explains that your prompt, recent conversation, and the financial context needed to answer may be sent to Google Gemini through Firebase AI Logic. Google processes the request under its own terms and privacy policy. ExpenseFlow does not currently send AI requests to another AI provider.

Financial context can include totals, balances, budgets, recurring commitments, goal information, debt or lending information, and user-entered names or labels if they are relevant to the answer. You can decline AI data sharing, turn it off in app settings when available, or avoid using remote AI with information you do not want sent to that provider. AI responses may be inaccurate and should not be treated as professional financial advice.

For signed-in users, limited AI usage metadata may be stored in Firebase to enforce quotas and protect the Service. Guest quota information is generally stored locally.

5. How we use information

We use information only as reasonably necessary to:

6. When information is shared

We do not sell or rent personal information. We do not share financial records with data brokers or use them for targeted advertising.

Information may be made available to the following recipients only when needed for the purposes described in this policy:

Provider information is available at:

If a future version introduces another AI provider, we will update this policy before that provider begins receiving user information.

7. Notifications, widgets, and exports

Most ExpenseFlow reminders are scheduled locally through iOS. Notification previews may appear on a lock screen depending on your device settings. The current widget provides quick actions and feature availability rather than displaying ledger amounts, but tapping it may open a relevant part of the app. You can control notifications, lock-screen previews, and widgets through iOS.

Exports may contain highly sensitive financial information. Exported CSV, JSON, or PDF files are controlled by the destination you choose through the iOS share sheet. Delete copies you no longer need and take care when sending them to another person or service.

8. Retention and deletion

Local records remain until you delete them, reset the app, uninstall it, or iOS removes them. Cloud records generally remain while your account is active or until you delete the relevant records or account. Backups, security logs, diagnostic records, and processor records may remain for a limited period where reasonably needed for recovery, fraud prevention, legal compliance, or service integrity.

You can request account deletion in Settings > Account > Delete Account. The app will attempt to delete the Firebase Authentication account and associated ExpenseFlow cloud records, then remove local app data on that device. A recent sign-in may be required for security. If deletion cannot be completed, the app will tell you so that you can re-authenticate or contact support.

Deleting your ExpenseFlow account does not cancel an App Store subscription. Apple controls subscriptions, and you must cancel or manage an active subscription separately in your Apple Account or App Store subscription settings.

9. Your choices and privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection, and to withdraw consent where consent is the basis for processing. You may also have the right to complain to a local data-protection authority.

You can exercise many choices directly by editing or deleting records, using guest mode, turning off cloud features, changing permissions in iOS Settings, disabling notifications, or deleting your account. For a request we cannot complete in the app, email expenseflow.feedback@gmail.com. We may need to verify your identity and may retain information where law permits or requires it.

ExpenseFlow does not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising a privacy right.

10. Legal bases

Where a legal basis is required, we process information as necessary to perform our agreement with you, based on your consent, for our legitimate interests in operating and securing the Service, and to comply with legal obligations. The basis depends on the feature and your location. You may withdraw consent through the relevant device or app control, although this does not affect earlier lawful processing.

11. International processing

Our providers may process information in countries other than your own. Firebase Authentication is operated from the United States, while other Firebase and provider services may use global infrastructure. Where required, we rely on appropriate contractual or legal safeguards. Different countries may have different data-protection rules.

12. Children

ExpenseFlow is a general-audience personal-finance app and is not directed to children under 13. We do not knowingly collect personal information online from a child under 13 without legally required permission. If you believe a child has provided personal information improperly, contact us so we can investigate and delete it where appropriate. A country may require a higher minimum age for a child to consent to online data processing; local law will apply.

13. Security

We use reasonable technical and organizational safeguards, including authenticated cloud access, application security rules, platform integrity checks, encrypted network connections where supported, and Keychain storage for user-entered provider credentials. Security also depends on your device, passcode, Apple or Google account, network, and chosen third-party providers. No storage or transmission system can be guaranteed completely secure.

If you believe your account or data may have been compromised, contact us promptly and secure the affected sign-in account.

14. Changes to this policy

We may update this policy when the app, service providers, or legal requirements change. We will revise the date at the top and provide additional notice in the app or by another appropriate method when a change is material. Your continued use after an update means the revised policy applies from its effective date, subject to any consent required by law.

15. Contact us

Questions, requests, or concerns about privacy can be sent to:

Siam Mahmud Khan
Independent developer
Email: expenseflow.feedback@gmail.com
Privacy page: https://siam300.github.io/ExpenseFlow-Budget-Tracker-Legal/expenseflow-privacy-policy.html

We will make a reasonable effort to respond within the period required by applicable law.