Spendlo — Privacy Policy
Last updated: 22 August 2026
Spendlo ("the app") is a personal finance / money-manager application.
Your privacy is simple to explain: all your data stays on your own
device, and nothing is uploaded anywhere unless you personally choose to back
it up.
Data we collect
Spendlo does not collect, transmit, or sell any personal
data to us. We do not operate any servers that receive your information, and
there is no account sign-up.
The following data is created and stored locally on your device
only:
- Financial records you enter — accounts, categories,
journal entries (transactions), budgets, recurring-transaction rules, loan
schedules, credit-card settings, tags, and transaction templates. Stored in
a local SQLite database on the device.
- Receipt / photo attachments (optional) — if you attach
an image to a transaction, the image file is copied into the app's private
storage on your device. It is not uploaded to us.
- App lock credentials (optional) — if you enable the app
PIN, a hashed PIN and salt are stored in the device's secure storage
(Android Keystore via expo-secure-store). The PIN itself is never stored in
plain text and never leaves the device.
Optional cloud backup (Google Drive)
Spendlo includes an optional backup feature that lets you
save a copy of your data to your own Google Drive account:
- This runs only when you choose to sign in and back up.
It is off by default.
- When you use it, the app authenticates directly with Google (OAuth,
using PKCE — no data passes through any server of ours) and uploads a backup
file to your own Drive. We never receive, see, or store
this data.
- You can revoke the app's Google access at any time from your Google
Account settings, and delete the backup file from your Drive yourself.
- Your use of Google Drive is governed by
Google's Privacy Policy.
Optional AI-assisted SMS import (Groq)
Spendlo includes an optional feature that lets you paste
or share bank/wallet SMS text so the app can auto-create transactions:
- This runs only if you add your own Groq API key in
Settings → Bulk SMS Import → AI Settings. It is off by default, and the
rest of the app (manual entry, budgets, reports, backup) works fully
without it.
- When you use it, the text of the SMS you paste or share
— which may include a merchant name, amount, and sometimes a phone number
(e.g. mobile wallet transfers) — plus your own category and account
names (not your full transaction history or balances) are
sent to Groq, Inc., a third-party AI provider, to classify
the transaction.
- Spendlo does not operate this AI service and does not receive or store
a copy of what Groq does with the request; your use of it is also governed
by Groq's own privacy policy.
We recommend reviewing Groq's data-sharing settings for your account if you
want to opt out of your requests being used to improve their models.
- The app does not request Android's SMS-read
permission. It only ever sees text you explicitly shared via the system
share sheet or manually pasted — never your SMS inbox directly.
- Any category the app learns from this (which merchant maps to which
category) is stored only in your local database — Groq
itself has no memory of past requests; each request is independent.
Data sharing
Other than the optional Google Drive backup and the optional Groq AI
classification described above, we do not share your data
with any third party. The app contains no third-party
analytics, no advertising SDKs, and no
trackers. The only outbound network activity is (a) the optional
Google Drive backup you initiate yourself, (b) the optional Groq AI
classification described above, which only runs when you've added your own
API key and are actively using Bulk SMS Import, and (c) exports you
explicitly share.
Exports
When you use Export JSON / CSV, the app creates a file
containing your data and lets you choose where to save or share it (via the
Android share sheet). What happens to that file afterwards is entirely under
your control.
Permissions
- Internet — for the optional Google Drive backup, and
for the optional Groq AI SMS classification described above. Neither runs
unless you turn it on yourself.
- Notifications and scheduled alarms —
for local bill / due-date reminders. These are generated on-device; nothing
is sent to a server.
- Vibration — for haptic feedback.
It does not request access to your contacts, location, microphone, your
SMS inbox, or general external storage.
Your choices and data deletion
- Delete all data: uninstalling the app removes the local
database, all records, and any attached images. Files you exported yourself,
and any backup you uploaded to your own Google Drive, are retained until you
delete them.
- Revoke cloud access: disconnect Spendlo from your
Google Account at any time via Google Account → Security → Third-party
access.
- App lock: you can enable, change, or disable the PIN at
any time in Settings.
Children's privacy
Spendlo is a general-purpose finance tool and is not directed at children
under 13. We do not knowingly collect any data from children (or anyone
else).
Changes to this policy
If this policy changes, the updated version will be published at the same
URL with a revised "Last updated" date.
Contact
For any privacy questions, contact:
devkhalil1337@gmail.com