Expenseum Privacy policy
Legal
Privacy Policy
The short version. Your books, entries and attachments are stored on your own phone. You don't need an account to use Expenseum. Things only leave your device when you ask them to — a backup to your Google Drive, a split book shared with friends, a question to the AI assistant, or a post in the community forum. We do not sell your data, and the app contains no third-party advertising SDKs.
Who we are
Expenseum is built and operated by Appentium. In this policy, “we”, “us” and “our” mean Appentium; “you” means the person using the app.
For anything to do with privacy, write to info@appentium.com. We are the data controller for the information described below.
What stays on your device
Expenseum is offline-first. The following are written to a database in the app's private storage on your phone or tablet, and are not uploaded to us:
- Your books, transactions, amounts, notes and dates
- Categories, payment modes, custom fields and templates
- Budgets, goals, liabilities and net-worth entries
- Receipt photos and attachments you add to entries
- App settings, language, theme and reminders
If you never sign in and never turn on backup, this data stays on your device for its whole life — and deleting the app deletes it.
When you create an account
An account is optional. You only need one for Google Drive backup, split books, collaboration, the community forum, referrals or a Plus subscription. Accounts are handled by Firebase Authentication (Google LLC). You can use Sign in with Apple, sign in with Google, or use an email address and password; some flows verify your email with a one-time code.
When you sign in we store your user ID, email address, and — if your provider supplies them — the display name and profile photo. If you use Sign in with Apple and choose to hide your email, we only ever see Apple's private relay address.
What we collect, and why
| Data | Why we have it |
|---|---|
| Account identityuser ID, email, name, photo | To sign you in, show you to people you share books with, and route invitations. |
| Split & shared book contentsexpenses, shares, balances, comments | Stored in Firebase Firestore so every member of the book sees the same balances. Only members of a book can read it. |
| Collaborator invitationsinvitee email address | To deliver the invitation and attach the right person to the book once they accept. |
| Community forum poststitle, body, comments, votes, attachments | Forum content is public inside the app by design. Don't post anything you want kept private. |
| Subscription statepurchase token or receipt, plan, expiry | To verify your Plus purchase with the App Store or Google Play and unlock features on your devices. |
| Referral codesyour code, codes you redeemed | To credit the reward to both sides and to stop the same code being redeemed twice. |
| Push token | Held by OneSignal so we can notify you about split-book activity and reminders you asked for. |
| Usage analyticsscreen views, feature events, device model, app version, coarse region | Firebase Analytics, aggregated, so we can see which features are used and where the app breaks. Not tied to your transaction data. |
Expensight AI
Expensight is the in-app assistant. It runs only while you have the assistant open and send it a message.
- When you send a message, that message and the relevant parts of your books (for example the totals, categories and entries needed to answer) are sent to Google's Gemini API to generate a reply.
- You control what it may do. It starts in read-only mode; you can raise that to logging transactions and categories, or to full access, in Settings → AI Assistant.
- Confirm before changes is on by default, so nothing is written to your books until you approve it.
- We don't use your conversations to train any model. Google processes the request as our service provider under its own terms.
- If you never open the assistant, none of your book data is sent for AI processing.
Backups to your Google Drive
Backups are optional, and they go to your Drive, not to us. When you connect Drive, the app requests the drive.file scope, which means Expenseum can only see and manage the files it created itself — it cannot read the rest of your Drive.
You can also back up to a file on your device. Backup history shows dated restore points so you can choose exactly which one to restore. Deleting a backup file from your Drive deletes it for good; we hold no copy.
Sharing a book with other people
Split books and collaboration are shared by nature. When you add someone to a book:
- They can see the expenses, shares, balances, comments and attachments in that book, and the name or email you appear under.
- We send an invitation email to the address you entered, containing your name and the book name.
- Reminder emails and push notifications about unsettled balances may be sent to members of that book.
Your other books stay private. Sharing one book never exposes the rest.
Device permissions
- Camera / photos — only when you scan a receipt or attach an image. Receipt text recognition runs on your device; the photo is not uploaded for scanning.
- Microphone / speech recognition — only while you use voice entry. Speech is transcribed by your device's own speech-recognition service: Apple's on iPhone and iPad, and the device's provider (usually Google) on Android. On iOS this may be processed on-device or by Apple, depending on your device and language.
- Notifications — for reminders, budget alerts and split-book activity.
- Files — to import CSVs, and to save exports, reports and local backups.
Every one of these is asked for at the moment it's needed, and the app works without them.
Payments
Expenseum Plus is sold through the Apple App Store on iPhone and iPad, and through Google Play Billing on Android. We never see or receive your card number — the store handles the payment and tells us only whether a purchase is valid, which plan it is, and when it expires. We verify that purchase on our server so Plus unlocks on your devices.
Apple and Google process your payment under their own privacy policies. We do not receive your billing address, card details or store account password.
What we never do
- We don't sell or rent your personal data to anyone.
- We don't ship third-party advertising SDKs, and we don't build ad profiles from your spending.
- We don't read your books on our servers — the entries you keep privately are never uploaded to us in the first place.
- We don't ask for your bank credentials, and Expenseum does not connect to your bank.
- We don't track you across other companies' apps and websites.
How long we keep things
- On-device data — until you delete it or remove the app.
- Recycle bin — items you or a collaborator delete stay recoverable for 30 days, then go for good.
- Shared book data — kept while the book exists, so the other members' balances still add up.
- Account data — kept until you delete your account.
- Analytics — kept in aggregate on Firebase's standard retention schedule.
Deleting your data
In the app, open Settings → Account → Delete account. You'll be asked whether to also wipe the books stored on the device, or keep them and only remove the account. Deleting the account removes your profile, subscription record, referral record and forum authorship from our systems.
Content in a shared book may remain visible to the other members afterwards, because it is part of their record of who owed what. If you want something removed from a shared book, remove it before you delete the account, or ask us at info@appentium.com.
Your rights
Depending on where you live, you may have the right to access, correct, export or erase your personal data, to object to or restrict processing, and to complain to your local data protection authority. Most of this you can do yourself in the app; for anything else, email info@appentium.com and we'll respond within 30 days.
Service providers & international transfers
We rely on a small number of processors to run the app: Google (Firebase Authentication, Firestore, Storage, Cloud Functions, Remote Config, Analytics, Gemini API, Drive, Play Billing), Apple (Sign in with Apple, App Store purchases) and OneSignal (push delivery). These providers operate globally, so your data may be processed in countries other than your own, including the United States, under the safeguards those providers offer.
Children
Expenseum isn't directed at children under 13, and we don't knowingly collect their data. If you believe a child has given us personal information, contact us and we'll delete it.
Changes
If we change this policy we'll update the date at the top, and — when the change is significant — tell you in the app before it takes effect.
Contact
Appentium · info@appentium.com · appentium.com (opens in a new tab)