XpenseAI

Privacy Policy

Last updated: September 11, 2026 (data breach notification commitment, registered business address, corrected raw Gmail data retention language)

XpenseAI ("the app", "we", "our") is a personal expense-tracking app. This policy explains what we access, why, and how you stay in control. Read it alongside our Terms of Service.

  1. 1. Our role in your privacy
  2. 2. What we access, and where it's stored
  3. 3. Google account access
  4. 4. Your consent & control
  5. 5. What we don't do
  6. 6. Data retention & deletion
  7. 7. Security
  8. 8. Children's privacy
  9. 9. Changes to this policy
  10. 10. Grievance & contact

01Our role in your privacy

We're a tool that reads and organizes data you already own. We don't run banking or payment systems, we never touch your money directly, and we don't sell or broker your financial data.

02What we access, and where it's kept

  • Signing in with Google (or a linked phone number) is required to use the app.
  • Your expenses, accounts, and settings are saved to your account so they follow you across devices and survive a lost phone or cleared browser.
  • If you turn on the optional Drive backup, a copy of your data is saved to a private, app-only space in your own Google Drive that no other app can see.

Other services we use

  • Crash reports & performance diagnostics (Firebase Crashlytics) — if the app crashes or runs slowly, your device model, OS version, app version, and a technical stack trace or performance metric are sent to Google so we can find bugs and keep the app fast and stable. This never includes your financial data, transactions, or account contents.
  • Basic usage analytics (Firebase Analytics) — automatic, aggregate app-usage events (like when the app is opened, or which screen is viewed) are collected so we can understand overall usage patterns and improve the app. This is never linked to advertising, never used to build a profile of you, never sold or shared with advertisers, and never includes your financial data, transactions, or account contents.
  • Subscription management (RevenueCat) — if you subscribe to Premium through the App Store or Play Store, your purchase receipt and subscription status are shared with RevenueCat, our subscription-management processor, so we can activate and keep your plan in sync. RevenueCat never receives your financial or transaction data.

03Google account access

Sign-in with Google (required)

Signing in confirms your identity. The following data is received from Google and retained:

  • Name — displayed in your app profile
  • Email address — used as your account identifier and to send you transactional emails (receipt confirmations, password resets, billing notifications)
  • Profile photo — displayed in your app profile

We never receive or store your Google password.

Optional Google permissions

Two additional permissions you can grant and revoke independently:

  • Google Drive backup (read/write) — lets us create a backup folder in your Drive and store encrypted copies of your expense data, accounts list, and settings. We can only read and write to this app-specific folder; we cannot access any other files or folders in your Drive. You control whether this backup is turned on and can delete it at any time.
  • Gmail (read-only) — lets us search your inbox for bank/credit-card statement emails (fetching message text and PDF attachments) and transaction-alert emails (parsing the message text for transaction details). This helps you track expenses without manual entry. We never send, reply to, delete, or modify any email, and we never read emails unrelated to statements or transaction alerts.
You choose whether to enable these permissions. Both are off by default. You can revoke either at any time from your Google Account permissions page, or by disconnecting them inside the app. Revoking access stops all new syncs immediately.

How we use Google data

  • Gmail data — used exclusively to extract transaction and statement information for display in your app. Parsed data (extracted transaction amounts, dates, merchants) stays in your app account.
  • Drive data — used exclusively for backing up your expense data so it's available across devices and survives a lost phone or cleared browser.
  • Sign-in data — name and email are used for authentication and to send account notifications (billing, security); profile photo is for visual identification in your account.

Data sharing and third parties

XpenseAI does NOT share, transfer, or disclose any Google data to third parties, except:

  • Payment processors — if you purchase a paid subscription, only the minimum billing information necessary (name, email, transaction ID, subscription tier) is sent to our payment processor to process and verify your payment. This data is not used for any other purpose.

Your Gmail and Drive data are used exclusively to provide this app's transaction-tracking features to you — never for advertising, never to train AI/ML models, never to profile you or build behavioral data, and never transferred or sold to any other party.

Compliance

XpenseAI's use and transfer of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including all Limited Use requirements.

  • Drive and Gmail access are off until you explicitly turn them on.
  • Sign out clears everything saved on that device.
  • Disconnecting Drive or Gmail in the app stops all further access immediately.
  • To delete your account data entirely, see our account deletion page for the exact steps, or contact us using the details in section 10.

05What we don't do

  • We don't run ads or ad tracking. We use basic, aggregate usage analytics and crash/performance diagnostics to improve the app — see "Other services we use" for exactly what that involves — but never for advertising, and never to build a profile of you.
  • We don't sell, rent, or share your data with any third party for marketing purposes. The only exception is the minimum billing information our payment partners need to process a subscription you've chosen to start — see Payment, billing and subscriptions in our Terms of Service.
  • We don't use your financial information for anything other than showing it back to you inside the app.

06Data retention & deletion

How long we keep your data:

  • Your expense data, accounts, and settings are retained as long as your account is active, so they're available whenever you sign back in.
  • Extracted Gmail data (parsed transactions) is retained indefinitely in your account for your own reference.
  • Drive backups are retained as long as the backup is enabled; disabling backup deletes the backup folder and its contents from your Drive immediately.
  • Transactional records (payment confirmations, activity logs) are retained for the duration of your account and 90 days after deletion for financial/legal compliance purposes.

Deleting your data:

  • Disconnect permissions — Stop Gmail or Drive access at any time. Gmail disconnection removes future syncs; Drive disconnection stops new backups.
  • Sign out — Clears the local copy of your data on that device (phone, browser, etc.), but the server-side copy stays until you delete your account.
  • Delete your account — All your data (expenses, accounts, settings, backups, transactional records) is permanently deleted within 30 days. See our account deletion page for step-by-step instructions, or contact us at ….

Google Drive backups you've created are also deleted from your Drive when you delete your account, but if you disconnect the Drive permission before account deletion, backups remain in your Drive under your control (we don't delete files we didn't create).

07Security

Data protection and encryption:

  • In transit — All communication between you and our servers uses HTTPS/TLS encryption. Your data is never transmitted in plain text.
  • At rest — Your data is stored in Supabase (a managed PostgreSQL database) with encryption at the database level. Each account's data is isolated via row-level security policies; no other user can access your data, even if they gain unauthorized server access.
  • Access control — Access to user data requires valid authentication (your account credentials). Admin access to production data is restricted, logged, and audited.
  • Gmail and Drive data — Treated with the same encryption and access controls as your own data. Parsed Gmail data (transactions extracted from emails) stays in your account.

We do not implement additional encryption beyond what our infrastructure (Supabase, Google APIs, Cloudflare) provides, because these providers' security is already audited and industry-standard.

Data breach notification: If a personal data breach occurs, we will notify India's Data Protection Board and affected users without undue delay, describing what happened, what data was involved, and what we're doing about it.

08Children's privacy

XpenseAI is not directed at children under 13, and we do not knowingly collect data from them.

09Changes to this policy

If this policy changes materially, the "Last updated" date above will change accordingly, and continued use of the app after a change means you accept the update.

10Grievance Officer & contact

In accordance with the Digital Personal Data Protection Act, 2023 and applicable Indian law, we've designated a Grievance Officer to handle complaints and requests about how your personal data is handled.

Grievance Officer
XpenseAI
Email: …
Registered business address: XpenseAI, Ghaziabad, Uttar Pradesh

We acknowledge grievances within 24 hours of receipt and aim to resolve them within 15 business days. This covers questions about this policy, requests to access, correct, or delete your data, and any complaint about how your information is collected or used.

For anything else — general support, billing questions — the same email reaches our support team.