Spendr logoSpendr
Home Terms
Back to Spendr

Privacy Policy

Last updated: 10 July 2026 · Effective worldwide

This Privacy Policy explains how Spendr (“Spendr”, the “App”, “we”, “us”, or “our”) handles information when you use our mobile application and this website. Spendr is a personal expense-tracking application: you type an amount, tap a category, and the entry is saved. We built Spendr to be private by default, and this document describes exactly what that means.

Spendr is provided by its independent developer, Anton Beliakov (the “data controller” for the purposes of the EU/UK General Data Protection Regulation, and the “business” for the purposes of California privacy law). If you have any question about this policy or your data, you can reach us at kansio.uusi@gmail.com.

Contents

  1. A quick summary
  2. Information we collect
  3. How we use information
  4. Legal bases (EEA/UK)
  5. Service providers we use
  6. International transfers
  7. Data retention
  8. Your rights
  9. California privacy rights
  10. Children’s privacy
  11. Security
  12. Changes to this policy
  13. Contact us

1. A quick summary

  • Your expenses stay on your device. The amounts and categories you enter are stored locally on your phone. We do not upload them to our servers or read them.
  • We don’t ask for your name, email or bank. You can use Spendr without creating an account. Spendr never connects to your bank and never asks for card numbers.
  • We collect only minimal, non-identifying diagnostics (crash reports and coarse usage events) to keep the App working. These contain no expense data, and you can turn them off in the Menu.
  • We don’t sell your data. Ever.

2. Information we collect

2.1 Information you enter (stored on your device)

When you log an expense, you provide an amount, a category, a date/time, and optionally a short note. This content is stored in a local database on your device (the file spendr.db). By default it is not transmitted to us and remains under your control.

2.2 Backups you create

Spendr can create an encrypted backup file of your data so you can move it to another device. When you use this feature, your data is packaged into a single file that is encrypted on your device (AES‑256‑GCM) with a recovery code shown only to you; the file is then handed to your operating system’s share/save dialog for you to store or send wherever you choose. We do not receive, upload, or store these backups — they never pass through our servers, and the recovery code is never sent to us. Losing the recovery code means the backup cannot be decrypted.

Separately, your device’s own operating system may include the App’s local database in its native device backup (Android Auto Backup / Google One, or Apple iCloud Backup) if you have that enabled in your device settings. That backup is managed entirely by Google or Apple under your account, not by us.

2.3 Diagnostic & usage data

To understand whether the App is stable and which features are used, Spendr collects limited, aggregated, non-identifying telemetry through Firebase Analytics and crash reports through Firebase Crashlytics. This may include: app version, device model and operating-system version, general region derived from your IP address (not stored as a precise location), coarse feature-usage events (for example, “opened analytics screen”), and technical crash logs. We deliberately never log the content of your expenses — no amounts, category values, notes, or personal identifiers are included in this data. We do not collect an advertising identifier and do not use this data for advertising. This collection is on by default, and you can turn it off at any time with the toggle in the App’s Menu (or through your device’s privacy controls).

2.4 Purchase information

Spendr offers an optional one-time “Pro” upgrade. Payments are processed entirely by Apple App Store or Google Play; we never see or store your payment-card details. To recognise your purchase and restore it across your devices, we use RevenueCat, which receives a purchase receipt and an anonymous app-user identifier. We receive confirmation of entitlement status only.

2.6 Website

This website is served as static pages via GitHub Pages. Standard server logs (such as IP address and browser type) may be processed by the hosting provider for security and operation. The site sets no advertising or tracking cookies. It loads the Bodoni Moda and Inter fonts from Google Fonts, which may receive your IP address in order to deliver the font files.

3. How we use information

  • To provide the core functionality of recording and displaying your expenses (this happens on-device).
  • To operate optional features you turn on, such as backup, transfer, or the Pro upgrade.
  • To keep the App stable, diagnose crashes, and understand which features are useful (aggregated diagnostics only).
  • To comply with legal obligations and enforce our Terms of Use.

We do not use your data for advertising, profiling, or automated decision-making that produces legal effects, and we do not sell or rent personal information.

4. Legal bases for processing (EEA / UK)

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:

  • Performance of a contract — to provide the App and the features you request (Art. 6(1)(b)).
  • Consent — for optional diagnostics/analytics where consent is required; you may withdraw it at any time (Art. 6(1)(a)).
  • Legitimate interests — to keep the App secure and functioning, provided your rights don’t override them (Art. 6(1)(f)).
  • Legal obligation — where we must process data to comply with the law (Art. 6(1)(c)).

5. Service providers we use

We work with a small number of trusted providers that process data on our behalf under appropriate data-processing terms:

  • Google Firebase (analytics and crash reporting only) — privacy information.
  • RevenueCat (purchase validation and entitlement management) — privacy policy.
  • Apple App Store / Google Play (payment processing and distribution).
  • GitHub Pages (hosting of this website).

6. International data transfers

Because Spendr is available worldwide and our providers operate globally, information processed on our behalf may be transferred to and stored in countries other than yours, including the United States. Where such transfers involve personal data from the EEA or UK, they are safeguarded by mechanisms such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or an adequacy decision, as applicable.

7. Data retention

Expense data you enter is retained on your device until you delete it or uninstall the App. Encrypted backup files you create are stored wherever you choose to save them and are under your control; we do not hold copies. Aggregated diagnostic data is retained for a limited period in accordance with our providers’ standard retention windows (Analytics data retention is set to the minimum available) and then deleted or anonymised.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. Because most of your data lives only on your device, you can exercise many of these rights directly — by editing or deleting entries in the App, or by uninstalling it. For data held by our providers on our behalf, contact us at kansio.uusi@gmail.com and we will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data-protection authority.

9. California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information is collected, to request deletion or correction, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined under California law, and we do not knowingly process the personal information of consumers under 16 for such purposes. You may exercise your rights, without discrimination, by contacting us at kansio.uusi@gmail.com.

10. Children’s privacy

Spendr is not directed to children under the age of 13 (or the minimum age required in your jurisdiction, such as 16 in parts of the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Security

We take reasonable technical and organisational measures to protect your information. Data in transit to our providers is encrypted using industry-standard TLS. However, no method of storage or transmission is completely secure, and we cannot guarantee absolute security. Keeping your device itself secure (screen lock, up-to-date OS) is an important part of protecting your on-device data.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where changes are material, provide a more prominent notice. Your continued use of Spendr after an update means you accept the revised policy.

13. Contact us

For any privacy question or request — including any request addressed to the data controller, Anton Beliakov — please email kansio.uusi@gmail.com. We aim to respond promptly and within the period required by applicable law.

Read the Terms of Use →

© 2026 Spendr. All rights reserved. Home · Terms of Use