Privacy Policy
SpendPulse · Last updated 23 August 2026
The short version: your financial data never leaves your phone.
SpendPulse has no accounts, no sign-in, and no server that stores your records. The limited network traffic it does make is described in section 4, and none of it carries a transaction, a balance, or a category.
1. Offline-first data storage
All transactions, categories, budgets, exchange rates, and settings are stored locally on your device in an embedded database (ObjectBox).
We do not collect, store, transmit, or share your financial records. There is no account to create and no copy of your ledger on any server we operate.
Backups and exports are files written to storage you choose. Where they go afterwards is entirely up to you.
2. Bank statements and document parsing
When you import a bank statement (PDF or CSV), all parsing, text extraction, and transaction classification happen entirely on your device.
No statement file, and no data extracted from one, is uploaded anywhere.
Categorisation rules learned from your past imports are stored only in local app storage.
3. Biometric and passphrase security
Biometrics (fingerprint or face) are handled entirely by your device’s operating system. The app receives only a yes-or-no answer; raw biometric data is never accessible to it.
Encrypted backups use AES-256-GCM. Your passphrase derives the encryption key on-device and is never transmitted or stored in plaintext. If you lose it, the backup cannot be recovered — by you or by us.
4. Network services
These are the only reasons the app contacts a network. None of them sends your financial data.
Firebase Cloud Messaging (push notifications)
Used to send occasional announcements, such as news of an update. The app subscribes to broadcast topics — it does not register a per-device token with us, and we hold no database of installations or device identifiers.
Firebase Remote Config (feature flags and release control)
The app fetches a small configuration file that says which features are switched on, what the minimum supported version is, and whether the app is temporarily unavailable. The request carries no personal or financial data from the app.
Google Mobile Ads (only if advertising is enabled)
Advertising is switched off unless it is explicitly enabled for a release. When it is on, Google Mobile Ads may collect and process device and usage information — including your device’s advertising identifier — to select and measure ads. Your transactions, amounts, categories, notes, and budgets are never shared with the advertising SDK or used for ad targeting. Where consent rules apply, you are asked first and can change your answer at any time under Settings → Ad privacy choices.
Google Play (updates and reviews)
Tapping an update or review prompt hands you to the Play Store app, which operates under Google’s own terms.
5. What we never do
- We do not sell, rent, or share your data with anyone.
- We do not use your financial records for advertising, profiling, or model training.
- We do not track your usage of the app with analytics.
- We do not require an account, an email address, or a phone number.
6. Device permissions
Each permission exists for one named feature.
- Storage / file access — to read the statements you pick and to save exports and backups.
- Notifications — for daily reminders, budget alerts, quick-add, and announcements.
- Biometric / device lock — to unlock the app when App Lock is enabled.
- Exact alarms — so scheduled reminders arrive at the time you set.
7. Children
SpendPulse is not directed at children under 13, and we do not knowingly collect any data from them.
8. Data retention and erasure
You hold all of it.
Because we hold no copy of your data, there is nothing for you to request from us and nothing for us to delete on your behalf.
- Export to CSV or an encrypted backup at any time.
- Erase every transaction, category, learned rule, and setting under Settings → Erase everything.
- Uninstalling the app removes all local app data from your device.
9. Changes to this policy
Material changes will be noted here with a new “last updated” date, and significant ones will be called out in the app’s release notes.
10. Contact
Questions about this policy or your data — email hayatflutter@gmail.com, or use Settings → Developer details in the app.
SpendPulse is published by Hexmorio Technologies.