The short version
Expense Tracker keeps the expenses, budgets, and settings you enter on your device only — we never see them and they are never uploaded to us or any server. On Android, if you grant permission, the App also reads your bank transaction SMS on your phone to log your spends for you; those messages are parsed entirely on the device and their contents are never transmitted anywhere. The app uses Google Firebase to understand crashes, performance, and anonymous usage so we can improve it. We do not require an account, we do not show ads, and we do not sell your data.
This Privacy Policy explains how the Expense Tracker mobile application
(the “App”, package com.innings.budget.expensetracker), published by
Innings (“we”, “us”), handles information. By using the App you agree to this policy.
1. Information you enter (stays on your device)
Expense amounts, merchant names, categories, notes, dates, payment methods, budgets, lend & owe records, and preferences you create are stored locally on your device, in a private app database that other apps cannot read.
- This data is not transmitted to us or to any third party.
- We have no access to it and cannot read it.
- It is removed when you clear the App’s data or uninstall the App.
- It is excluded from Android’s automatic cloud backup, so a reinstall starts clean.
2. SMS messages (Android only, optional)
On-device only
The App’s core feature is logging your spending automatically instead of making you type it in. To do
that on Android it asks for the READ_SMS permission and reads the transaction alert
messages your bank already sends you.
What we read, and why
- The App reads messages in your device inbox to identify debit transaction alerts from banks, UPI and payment senders.
- From those messages it extracts only the amount, date, merchant name, and masked account tail, and records them as expenses you can edit or delete.
- Messages from personal senders (ordinary phone numbers) are never read. OTPs, one-time passcodes, promotional messages and personal conversations are ignored and are not recorded anywhere in the App.
- You can see exactly which senders were read, and mute any of them, under Settings → Message sources.
Where it is processed
All reading and parsing happens on your device. No message body, amount, date, balance, account number, card tail, payment reference, UPI handle, phone number or contact is ever uploaded, transmitted, sold, or shared with us or with anyone else. There is no account system and no server that holds your transactions — the feature works with the device offline.
One narrow exception, for accuracy’s sake: so that we can tell when the App is failing to recognise a
bank’s message format, our diagnostics record the business sender header of messages
that were read (for example CBSSBI, which identifies a bank, never a person) together
with a count of how many were understood, and occasionally a merchant keyword such as
SWIGGY. Anything shaped like a phone number, handle or order id is discarded rather than
sent, and messages from personal senders are excluded entirely. This carries no amounts, no dates and
no message text, and it cannot be used to reconstruct what you spent. See section 4.
What the App does not do with SMS
- It is not a default SMS handler. It never sends, writes, modifies or deletes messages.
- It does not read or act on OTPs, and performs no account verification, payment authorisation, or fraud detection.
- It does not read your call log or contacts.
The permission is entirely optional. If you decline it, every other part of the App works and you can add expenses manually. You can revoke it at any time in your device settings; the App simply stops importing and keeps the expenses already recorded.
3. Permissions the App requests
| Permission | Why | Required? |
|---|---|---|
READ_SMS (Android) |
To detect bank debit alerts on the device and turn them into expenses, as described in section 2. Processed on-device only. | Optional |
POST_NOTIFICATIONS (Android 13+) |
To alert you when your spending approaches the budget target you set. | Optional |
4. Information collected automatically (diagnostics & analytics)
The App uses Google Firebase to collect limited technical and usage data that helps us keep the App stable and improve it. This data is processed by Google on our behalf and is not used to personally identify you.
| Service | What it collects |
|---|---|
| Firebase Analytics | Anonymous app usage — screens viewed, feature interactions, session counts, app version, device model, operating system version, language, and coarse region (derived from IP address). |
| Firebase Crashlytics | Crash reports — stack traces, device type and OS version, and app state at the time of a crash, tied to a random installation identifier. |
| Firebase Performance Monitoring | Performance metrics — app start-up time, screen rendering speed, and similar diagnostics. |
Firebase may use device and installation identifiers (such as a Firebase Installation ID / App Instance ID) and your IP address to provide these services. It does not collect your name, email, or the expense data you enter.
SMS and diagnostics. The analytics above include the bank sender headers and merchant keywords described at the end of section 2 — these exist so we can find message formats the App is failing to read, which is the difference between a missed transaction being fixed and it going unnoticed. They never include message text, amounts, dates, balances, account or card numbers, payment references, UPI handles, contacts, or anything from a personal sender. Your expenses, budgets and lend & owe records are never included in diagnostics in any form.
5. How we use this information
- Stability Diagnose and fix crashes and bugs.
- Performance Measure and improve app speed and reliability.
- Product Understand which features are used so we can improve the App.
We do not use this information for advertising and we do not sell it.
6. Third-party services
Our only third-party processor is Google Firebase. Google’s handling of the data described above is governed by the Firebase Privacy & Security terms and the Google Privacy Policy.
7. Data sharing
We do not sell, rent, or trade your information. We share the diagnostic and analytics data only with Google (Firebase) as our service provider, and only as needed to operate the services above. We may disclose information if required by law.
8. Data retention
- On-device data remains until you delete it, clear app data, or uninstall the App.
- Firebase diagnostic/analytics data is retained according to Google’s Firebase retention settings and policies (analytics data is retained for a limited period and then aggregated or deleted).
9. Your choices & rights
- SMS access: decline it, or revoke it at any time in Android’s app permission settings. The App keeps working with manual entry. You can also mute individual senders under Settings → Message sources.
- Delete your data: use Settings → Clear all data, clear the App’s storage, or uninstall the App to remove all on-device information.
- Analytics: because the App requires no account, Firebase data is not linked to your identity. You can further limit collection through your device’s privacy settings.
- Depending on where you live (e.g. under GDPR or CCPA), you may have rights to access, correct, or delete personal data. Contact us using the details below and we will respond as required by applicable law.
10. Children’s privacy
The App is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us and we will address it.
11. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date. Continued use of the App after changes take effect constitutes acceptance of the revised policy.
12. Contact us
If you have questions about this Privacy Policy, contact us at:
apps.innings@gmail.com