Data Safety
This page mirrors the categories in Google Play Console's Data Safety section, so the declaration shown on the Play Store listing matches what's documented here in detail.
Nothing is sent to Spend Sutra's developer
Spend Sutra has no backend server. There is no destination for your data to be collected into. The only network activity the app performs is: fetching your own email over IMAP (if you connect an account), an exchange-rate lookup for foreign-currency amounts, an optional encrypted backup to your own Google Drive app-data folder, and — once enabled in a future release — ad requests.
Data collected
| Data type | Collected? | Details |
|---|---|---|
| Financial info (transaction amount, merchant, category, bank) | Processed on-device only | Extracted from SMS/email alerts you already receive. Stored in an encrypted local database. Not transmitted to us. |
| Email address | Optional, on-device only | Only if you connect an email account for IMAP-based transaction sync. Stored encrypted on-device; never sent to us. |
| SMS or MMS messages | Read on-device, not stored or transmitted | Read locally to detect transaction alerts. Non-transaction messages are discarded immediately without being saved anywhere. |
| App activity, usage analytics, crash logs | No | Spend Sutra does not integrate any analytics or crash-reporting SDK. |
| Device or advertising identifiers | Not currently | Will apply only once advertising is enabled in a future release (via Google AdMob) — see Ads. |
| Location | No | Spend Sutra does not request or use location data. |
| Contacts, photos, files, calendar | No | Not accessed. |
Data sharing
Spend Sutra does not share user data with any third party for their own purposes. The one exception is the optional Google Drive backup: when enabled, encrypted backup data is written to your own Google account's private app-data storage. This is data you're storing with Google under your own account — it is not shared with, or accessible to, Spend Sutra's developer.
Security practices
| Practice | Status |
|---|---|
| Data encrypted in transit | Yes — IMAP/TLS, HTTPS for all network calls |
| Data encrypted at rest | Yes — AES-256 for the on-device transaction database and any stored email credentials |
| Users can request data deletion | Yes — in-app (Settings) and by uninstalling the app |
| Committed to Google Play Families Policy | Not applicable — app is not directed at children |
| Independent security review | Not currently applicable to the data/scopes this app requests |
Data deletion
You can delete individual transactions, disconnect email accounts (which also removes their stored credentials), or clear all local data from within Settings at any time. Uninstalling the app removes all on-device data. If you've enabled Google Drive backup, that backup persists in your Google account until you delete it yourself, either from the app's Settings or directly through your Google account.
For the full narrative version of this information, see the Privacy Policy.