1. Introduction & Commitment
Welcome to Spence ("we," "our," or "us"). We believe that your personal financial data belongs solely to you. This Privacy Policy details how we handle, store, protect, and process information when you download and use the Spence mobile application on Android.
🔒 Core Privacy Promise: We do NOT sell, rent, monetize, or trade your personal or financial data to advertisers, data brokers, or third parties under any circumstances.
2. Information We Collect
A. Financial & Transaction Records
- Expense Data: Amounts, transaction dates, store/vendor names, categories, recurring frequencies, and notes entered by you or parsed from receipts.
- Storage: All primary transaction data is stored locally in an encrypted SQLite/Room database on your device.
B. Account Information (Optional)
- Local Guest Mode: Spence can be used 100% offline without creating an account or providing an email address.
- Cloud Sync & Family Account: If you sign in via Firebase Authentication (Google Sign-In or Email/Password), we store your display name, email address, and unique user identifier (UID).
C. Receipts & Image Data
- Smart Receipt Scanner: When you photograph or upload a receipt, optical character recognition (OCR) and item extraction process the image locally and via Google Gemini APIs with strict zero-retention policies. Raw images are not stored on our servers unless you back them up explicitly.
D. Biometric Security
- Fingerprint & Face Unlock: Handled entirely on-device via Android's secure BiometricPrompt APIs. Spence never accesses, transmits, or stores raw biometric identifiers.
3. How We Use Information
Your information is used strictly to provide and enhance core application features:
- To categorize and visualize your spending trends and budget limits.
- To calculate your dynamic Daily Safe-to-Spend runway and Financial Health Score.
- To detect recurring bills and inactive subscriptions via Subscription Radar.
- To calculate simplified debt settlements across multi-member family groups.
- To generate downloadable, branded monthly PDF statements and CSV exports.
4. Security & Data Architecture
- Offline-First: The app operates fully without internet access.
- Encryption in Transit: All communications between the app and cloud services (Firebase Auth / Firestore) use TLS 1.3 encryption.
- Encryption at Rest: Cloud Firestore stores user family data using AES-256 standard encryption.
- Personal Google Drive: If you choose Google Drive backup, your encrypted backup files reside exclusively inside your own private Google Drive storage.
5. Your Rights & Data Deletion
You have full sovereignty over your data at all times:
- Data Export: Export your complete financial history anytime to CSV or PDF via the app settings.
- One-Tap Deletion: You can permanently wipe all local database records and delete your cloud account instantly from Settings > Account > Delete Account & Data.
6. Children's Privacy
Spence is not designed for or directed at children under the age of 13. We do not knowingly collect personal data from children.
7. Contact & Inquiries
If you have any questions, feedback, or privacy-related requests, please contact us at:
- Email: oneexpenseapp@gmail.com
- Website: https://spenceapp.io