Overview
Spendo is a personal expense and budget tracker. You manually enter your income and expenses — Spendo never connects to your bank or any financial institution. This document explains what information we collect, why we need it, and how we keep it safe.
By using Spendo you agree to the practices described here. If you have questions, contact us at hellospendo@gmail.com.
Data we collect
The table below lists every category of data Spendo accesses or stores.
| Data type | What is stored | Where | Collected |
|---|---|---|---|
| Email address | The address you register with | Firebase Authentication & Firestore | Yes |
| Password | Hashed and managed solely by Firebase Authentication — never stored in plain text by Spendo | Firebase Authentication | Yes |
| Budget accounts | Account name, budget amount, currency, period (weekly / monthly / yearly / custom) | Firestore + on-device cache | Yes |
| Transactions | Title (≤ 200 chars), amount, currency, date, type (income / expense), category | Firestore | Yes |
| Recurring transactions | Same fields as transactions plus frequency, interval, start / end date | Firestore | Yes |
| Spending categories | Category name, icon, type (need / want), colour | Firestore + on-device cache | Yes |
| App preferences | Currency, theme (light / dark), language (en / es / de), reminders toggle | Firestore + on-device cache | Yes |
| Device locale | Read on-device only to set a default language; not uploaded as a separate field | On-device only | On-device |
Device permissions
Spendo requests no special device permissions. The app does not access your camera, microphone, location, contacts, photo library, or clipboard.
| Permission | Requested |
|---|---|
| Camera | No |
| Location | No |
| Contacts | No |
| Microphone | No |
| Photo library | No |
| Push notifications | No |
| Biometrics / Face ID | No |
| Network (internet) | Yes — required to sync with Firebase |
How we use your data
- Authenticate you — your email and password are used to create and secure your account.
- Sync your data across devices — budgets, transactions, and categories are stored in Firestore so you can access them from any device where you sign in.
- Personalise your experience — currency, language, and theme preferences are saved so Spendo remembers your settings.
- Process recurring transactions — when you open the app, Spendo checks for any scheduled recurring entries that are due and creates them automatically.
We do not use your data for advertising, analytics profiling, or any purpose beyond operating the app for you.
Third-party services
Spendo relies on the following third-party services to function. No other external service receives your data.
| Service | Provider | Purpose | Data shared |
|---|---|---|---|
| Firebase Authentication | Google LLC | Account creation and sign-in | Email, hashed password |
| Cloud Firestore | Google LLC | Cloud storage for your budgets and transactions | All app data (see table above) |
| Expo / EAS | Expo Inc. | App build and distribution infrastructure | None at runtime |
Google's privacy practices are governed by the Google Privacy Policy. Firebase data is stored in Google Cloud data centres and subject to Google's security standards.
Data security
- All communication between the app and Firebase is encrypted in transit using TLS.
- Firestore security rules enforce strict owner-only access: your data can only be read or written by a signed-in user whose UID matches the data owner.
- Passwords are never stored by Spendo; they are managed exclusively by Firebase Authentication.
- Auth tokens are stored in your device's local storage using Firebase's built-in persistence — they are not shared with any other app or service.
Data retention and deletion
Your data is retained for as long as your account exists. You can delete individual budget accounts and all associated transactions from within the app at any time. To request complete deletion of all data linked to your account, email hellospendo@gmail.com and we will process your request within 30 days.
Cached data stored locally on your device (account list, categories, theme and language preferences) is cleared when you sign out or uninstall the app.
Your rights
Depending on where you live, you may have rights regarding your personal data, including the right to access, correct, or delete it. To exercise any of these rights, contact us at hellospendo@gmail.com.
- Access — request a copy of your data.
- Correction — update incorrect information inside the app or by contacting us.
- Deletion — request removal of your account and all associated data.
- Portability — request your data in a machine-readable format.
Children's privacy
Spendo is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
Changes to this document
We may update this Data Safety page from time to time. When we do, we will revise the "Last updated" date at the top of this page. Continued use of Spendo after changes are published constitutes your acceptance of the updated terms.
Contact
If you have any questions or concerns about your data, please reach out at hellospendo@gmail.com.