Data Safety

Last updated: July 24, 2026

This page mirrors the categories in Google Play Console's Data Safety section, so the declaration shown on the Play Store listing matches what's documented here in detail.

No data leaves your device, except by your choice

Nothing is sent to Spend Sutra's developer

Spend Sutra has no backend server. There is no destination for your data to be collected into. The only network activity the app performs is: fetching your own email over IMAP (if you connect an account), an exchange-rate lookup for foreign-currency amounts, an optional encrypted backup to your own Google Drive app-data folder, and — once enabled in a future release — ad requests.

Data collected

Data typeCollected?Details
Financial info (transaction amount, merchant, category, bank) Processed on-device only Extracted from SMS/email alerts you already receive. Stored in an encrypted local database. Not transmitted to us.
Email address Optional, on-device only Only if you connect an email account for IMAP-based transaction sync. Stored encrypted on-device; never sent to us.
SMS or MMS messages Read on-device, not stored or transmitted Read locally to detect transaction alerts. Non-transaction messages are discarded immediately without being saved anywhere.
App activity, usage analytics, crash logs No Spend Sutra does not integrate any analytics or crash-reporting SDK.
Device or advertising identifiers Not currently Will apply only once advertising is enabled in a future release (via Google AdMob) — see Ads.
Location No Spend Sutra does not request or use location data.
Contacts, photos, files, calendar No Not accessed.

Data sharing

Spend Sutra does not share user data with any third party for their own purposes. The one exception is the optional Google Drive backup: when enabled, encrypted backup data is written to your own Google account's private app-data storage. This is data you're storing with Google under your own account — it is not shared with, or accessible to, Spend Sutra's developer.

Security practices

PracticeStatus
Data encrypted in transitYes — IMAP/TLS, HTTPS for all network calls
Data encrypted at restYes — AES-256 for the on-device transaction database and any stored email credentials
Users can request data deletionYes — in-app (Settings) and by uninstalling the app
Committed to Google Play Families PolicyNot applicable — app is not directed at children
Independent security reviewNot currently applicable to the data/scopes this app requests

Data deletion

You can delete individual transactions, disconnect email accounts (which also removes their stored credentials), or clear all local data from within Settings at any time. Uninstalling the app removes all on-device data. If you've enabled Google Drive backup, that backup persists in your Google account until you delete it yourself, either from the app's Settings or directly through your Google account.

For the full narrative version of this information, see the Privacy Policy.