Last updated: September 16, 2026
Auto Expense Tracker ("the app") is an Android app that helps you track your spending automatically. This page explains what information the app accesses, what it does with it, and what it never does. We wrote this to be accurate and specific to how the app actually works, not generic boilerplate. This policy is kept in sync with the Data Safety declarations we file in Google Play Console — the two describe the same facts, so nothing here should contradict what's declared there.
Your financial transaction data is processed and stored only on your device, encrypted. We do not operate a server, and your transaction history is never uploaded anywhere, ever. The only network activity the app performs is talking to Google's own services — for optional ads, optional subscriptions, and update checks — none of which involve your financial data.
With your permission (Android's "Notification Access" setting, which you must explicitly grant and can revoke at any time), the app reads the text of notifications from your banking, UPI, and default messaging apps, specifically to detect transaction alerts (e.g. "Rs.500 debited...", "You received Rs.1200...").
Banks send these alerts from a registered sender code (e.g. "HDFCBK"), not a normal app or contact name. To detect alerts from banks that aren't on our known-app list, the app also checks the sender name of notifications from apps outside that list against the pattern used by these registered bank codes. Only the sender name is checked for such apps — the message text itself is not read unless the sender name matches this bank-code pattern. If it doesn't match, nothing about that notification is stored, logged, or leaves your device. The app does not read notification content from social media, chat apps, or anything unrelated to financial transaction alerts.
From a matching notification, the app extracts only:
The original notification text itself is discarded immediately after these details are extracted. It is never saved to disk, never logged, and never leaves your device.
The app does not use SMS permissions of any kind. It
never requests READ_SMS or RECEIVE_SMS.
Notification Access is the only mechanism used to detect transactions.
The structured details above (amount, direction, date, counterparty, category, your own notes/tags) are stored in an encrypted database on your device, using industry-standard encryption (SQLCipher) with a key held in your device's own secure hardware (Android Keystore) where available. This data is never transmitted off your device — there is no backend server for this app to send it to.
You can export your data at any time (JSON backup, or CSV for spreadsheet use) directly to a location you choose on your own device or cloud storage — this is an action you take deliberately; the app does not do this automatically or without your action.
You can permanently delete all app data at any time from Settings.
The app uses a small number of Google services, which is the only network access the app has. This is separate from, and does not involve, your financial transaction data:
See Google's own Privacy Policy for how these Google services handle data: https://policies.google.com/privacy
This app is a personal finance utility intended for general adult use and is not directed at children. We do not knowingly collect information from children.
If this policy changes, we'll update the "Last updated" date above. Continued use of the app after a change means you accept the updated policy.
Questions about this policy or the app's data practices can be sent to: gaurav954624@gmail.com