💸 Expense Tracker

Privacy Policy

Last updated: 13 August 2026

The short version

Expense Tracker keeps the expenses, budgets, and settings you enter on your device only — we never see them and they are never uploaded to us or any server. On Android, if you grant permission, the App also reads your bank transaction SMS on your phone to log your spends for you; those messages are parsed entirely on the device and their contents are never transmitted anywhere. The app uses Google Firebase to understand crashes, performance, and anonymous usage so we can improve it. We do not require an account, we do not show ads, and we do not sell your data.

This Privacy Policy explains how the Expense Tracker mobile application (the “App”, package com.innings.budget.expensetracker), published by Innings (“we”, “us”), handles information. By using the App you agree to this policy.

1. Information you enter (stays on your device)

Expense amounts, merchant names, categories, notes, dates, payment methods, budgets, lend & owe records, and preferences you create are stored locally on your device, in a private app database that other apps cannot read.

2. SMS messages (Android only, optional)

On-device only The App’s core feature is logging your spending automatically instead of making you type it in. To do that on Android it asks for the READ_SMS permission and reads the transaction alert messages your bank already sends you.

What we read, and why

Where it is processed

All reading and parsing happens on your device. No message body, amount, date, balance, account number, card tail, payment reference, UPI handle, phone number or contact is ever uploaded, transmitted, sold, or shared with us or with anyone else. There is no account system and no server that holds your transactions — the feature works with the device offline.

One narrow exception, for accuracy’s sake: so that we can tell when the App is failing to recognise a bank’s message format, our diagnostics record the business sender header of messages that were read (for example CBSSBI, which identifies a bank, never a person) together with a count of how many were understood, and occasionally a merchant keyword such as SWIGGY. Anything shaped like a phone number, handle or order id is discarded rather than sent, and messages from personal senders are excluded entirely. This carries no amounts, no dates and no message text, and it cannot be used to reconstruct what you spent. See section 4.

What the App does not do with SMS

The permission is entirely optional. If you decline it, every other part of the App works and you can add expenses manually. You can revoke it at any time in your device settings; the App simply stops importing and keeps the expenses already recorded.

3. Permissions the App requests

PermissionWhyRequired?
READ_SMS (Android) To detect bank debit alerts on the device and turn them into expenses, as described in section 2. Processed on-device only. Optional
POST_NOTIFICATIONS (Android 13+) To alert you when your spending approaches the budget target you set. Optional

4. Information collected automatically (diagnostics & analytics)

The App uses Google Firebase to collect limited technical and usage data that helps us keep the App stable and improve it. This data is processed by Google on our behalf and is not used to personally identify you.

ServiceWhat it collects
Firebase Analytics Anonymous app usage — screens viewed, feature interactions, session counts, app version, device model, operating system version, language, and coarse region (derived from IP address).
Firebase Crashlytics Crash reports — stack traces, device type and OS version, and app state at the time of a crash, tied to a random installation identifier.
Firebase Performance Monitoring Performance metrics — app start-up time, screen rendering speed, and similar diagnostics.

Firebase may use device and installation identifiers (such as a Firebase Installation ID / App Instance ID) and your IP address to provide these services. It does not collect your name, email, or the expense data you enter.

SMS and diagnostics. The analytics above include the bank sender headers and merchant keywords described at the end of section 2 — these exist so we can find message formats the App is failing to read, which is the difference between a missed transaction being fixed and it going unnoticed. They never include message text, amounts, dates, balances, account or card numbers, payment references, UPI handles, contacts, or anything from a personal sender. Your expenses, budgets and lend & owe records are never included in diagnostics in any form.

5. How we use this information

We do not use this information for advertising and we do not sell it.

6. Third-party services

Our only third-party processor is Google Firebase. Google’s handling of the data described above is governed by the Firebase Privacy & Security terms and the Google Privacy Policy.

7. Data sharing

We do not sell, rent, or trade your information. We share the diagnostic and analytics data only with Google (Firebase) as our service provider, and only as needed to operate the services above. We may disclose information if required by law.

8. Data retention

9. Your choices & rights

10. Children’s privacy

The App is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us and we will address it.

11. Changes to this policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date. Continued use of the App after changes take effect constitutes acceptance of the revised policy.

12. Contact us

If you have questions about this Privacy Policy, contact us at:
apps.innings@gmail.com