๐Ÿ“ฑ EXPENSEBUDDY

Privacy Policy

Your privacy is our priority. Here's how we protect your data.

Effective Date: April 20, 2026
Section 1

Introduction

ExpenseBuddy ("we," "our," or "us") is a personal finance and expense-splitting application designed for iOS, developed by Surajit Roy (sole proprietor/individual developer). This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our mobile application ("App") and related services.

This Privacy Policy applies to all users of ExpenseBuddy worldwide, including users in the European Economic Area (EEA), United Kingdom (UK), United States (including California), Canada, India, United Arab Emirates (UAE), and all other jurisdictions where the App is available.

By downloading, installing, or using ExpenseBuddy, you acknowledge that you have read and understood this Privacy Policy. Where required by applicable law, we will obtain your consent before collecting or processing your personal data. If you do not agree with the terms of this Privacy Policy, please do not use the App.

Commitment: We are committed to protecting your privacy and ensuring transparency about our data practices. We adhere to the principles of data minimization, purpose limitation, and storage limitation โ€” collecting only information that is necessary to provide and improve our services.

Section 2

Data Controller Information

For the purposes of applicable data protection laws (including the EU General Data Protection Regulation, UK GDPR, and other applicable privacy laws), the data controller is:

Surajit Roy (Individual Developer)
Operating as: ExpenseBuddy
Email: surajitroy9064@gmail.com

If you are a resident of the EEA/UK and have concerns about our data processing that we cannot resolve, you have the right to lodge a complaint with your local Data Protection Authority (DPA).

Section 3

Information We Collect

We collect the following categories of information to provide and improve ExpenseBuddy:

3.1 Information You Provide Directly

Data Type Details Purpose
Account Information Full name, email address, mobile number (optional), profile picture Account creation, identification, friend matching
Authentication Credentials Email/password or Google Sign-In token Secure login and account access
Expense Data Expense titles, amounts, categories, notes, dates, payment records Expense tracking and splitting
Group Data Group names, types (Home, Trip, Office, Couple, Other), member lists Collaborative expense management
Friend Connections Friend relationships and associated balances Social expense splitting
Settlement Records Settlement amounts, participants, and dates Balance reconciliation
Recurring Expense Templates Recurring expense configurations (weekly, monthly, yearly) Automated expense creation
Budget Data Category budgets and spending limits Budget tracking and alerts

3.2 Information Collected Automatically

Data Type Details Purpose
Device Tokens Firebase Cloud Messaging (FCM) device token Push notification delivery
App Preferences Dark mode setting, notification preferences, currency preference Personalized user experience
Purchase Records In-App Purchase transaction status (premium/non-premium) Feature access management
Advertising Identifier (IDFA) Collected only with your explicit consent via App Tracking Transparency Personalized advertising (non-premium users only)

3.3 Camera & Photo Access

ExpenseBuddy may request access to your device camera or photo library for the following purposes:

On-Device Processing: Our AI Receipt Scanner uses Apple's Vision framework to perform optical character recognition (OCR) entirely on your device. No receipt images or extracted text are sent to any external server.

3.4 Information We Do NOT Collect

We want to be transparent about data we do not collect:

Section 4

Legal Basis for Processing

EU/EEA UK Under the General Data Protection Regulation (GDPR) and UK GDPR, we process your personal data on the following legal bases:

Legal Basis Processing Activity
Performance of Contract
(Art. 6(1)(b) GDPR)
Account creation, authentication, expense tracking, expense splitting, group management, friend connections, settlement tracking, push notifications, in-app purchase management, data synchronization
Consent
(Art. 6(1)(a) GDPR)
IDFA collection for personalized advertising (via Apple ATT), push notification delivery, optional profile picture upload, optional phone number
Legitimate Interest
(Art. 6(1)(f) GDPR)
App security and fraud prevention, service improvement through anonymized analytics, ensuring financial integrity of shared group ledgers upon account deletion
Legal Obligation
(Art. 6(1)(c) GDPR)
Compliance with applicable legal requirements, responding to lawful requests from authorities

Where we rely on consent, you may withdraw your consent at any time by contacting us or adjusting your device settings. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Section 5

How We Use Your Information

We use the information we collect for the following purposes:

No Automated Decision-Making: We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significant effects on you.

Section 6

Advertising & App Tracking Transparency

ExpenseBuddy displays advertisements to non-premium users through Google AdMob. We respect your choices regarding ad personalization:

Your Choice: You can change your tracking preference at any time in your device's Settings โ†’ Privacy & Security โ†’ Tracking.

EU/EEA For users in the European Economic Area, personalized ads are only served with your explicit consent in compliance with the ePrivacy Directive and GDPR. If you do not provide consent, only non-personalized ads will be shown.

CALIFORNIA California residents may opt out of the "sale" or "sharing" of personal information for advertising purposes. See Section 13 for details on your CCPA/CPRA rights.

Section 7

Data Storage & Security

We take the security of your data seriously and implement multiple layers of protection:

Data Breach Notification: In the unlikely event of a data breach that affects your personal information, we will notify affected users and relevant data protection authorities within the timeframes required by applicable law (72 hours for GDPR, as soon as reasonably practicable for other jurisdictions).

Section 8

International Data Transfers

ExpenseBuddy uses Google Firebase services, which store and process data on servers located in the United States and other countries where Google operates data centers. This means your personal data may be transferred to and processed in countries outside your country of residence.

EU/EEA UK For transfers of personal data from the EEA/UK to countries not recognized as providing adequate data protection, we rely on the following safeguards:

INDIA For users in India, your data may be transferred outside India in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and any rules issued thereunder. Such transfers are only made to jurisdictions not restricted by the Central Government.

UAE For users in the UAE, cross-border data transfers comply with the requirements of the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL).

Section 9

Data Sharing & Disclosure

We do not sell, trade, or rent your personal information to third parties.

CALIFORNIA Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), we confirm that we do not "sell" or "share" (as those terms are defined under CCPA/CPRA) your personal information.

Your information may be shared in the following limited circumstances:

Section 10

Third-Party Services

ExpenseBuddy integrates with the following third-party services, each with their own privacy policies. These are our "sub-processors" for the purposes of GDPR:

Firebase Authentication
Secure user login (email/password & Google Sign-In)
Privacy Policy โ†’
Cloud Firestore
Cloud database for expenses, groups, and user data
Privacy Policy โ†’
Firebase Cloud Messaging
Push notifications for reminders and alerts
Privacy Policy โ†’
Google AdMob
Display ads for free-tier users
Privacy Policy โ†’
Google Sign-In
OAuth-based authentication
Privacy Policy โ†’
Apple StoreKit
In-App Purchase processing (Premium upgrade)
Privacy Policy โ†’

Each of these service providers has been selected for their robust security practices and compliance with applicable data protection regulations, including GDPR, CCPA, and other international standards.

Section 11

In-App Purchases & Premium

ExpenseBuddy offers a one-time, lifetime premium upgrade ("ExpenseBuddy Premium") that unlocks additional features:

All purchases are processed securely through Apple's App Store using StoreKit. We do not collect or store any payment information (credit card numbers, billing addresses, etc.). Your purchase status is stored in your Firestore user profile to persist across devices.

Section 12

Push Notifications

We use Firebase Cloud Messaging (FCM) to send push notifications. Upon granting notification permission, your device's FCM token is saved to your user profile in Firestore. We use notifications for:

You can disable push notifications at any time via your device's Settings โ†’ Notifications โ†’ ExpenseBuddy. When you log out, your FCM token is removed from our systems.

Section 13

Your Privacy Rights by Region

Depending on your jurisdiction, you have specific rights regarding your personal data. We honor all applicable rights under the laws of your region:

13.1 All Users โ€” Universal Rights

13.2 European Economic Area & United Kingdom (GDPR / UK GDPR)

EU/EEA UK In addition to the universal rights above, you have the right to:

13.3 California, USA (CCPA/CPRA)

CALIFORNIA If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

CCPA Categories Disclosure: In the preceding 12 months, we have collected the following categories of personal information: Identifiers (name, email), commercial information (purchase records), and electronic activity (device tokens, app preferences). We have not sold any personal information.

13.4 Canada (PIPEDA & Provincial Laws)

CANADA Canadian users have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws:

13.5 India (DPDP Act, 2023)

INDIA Indian users ("Data Principals") have rights under the Digital Personal Data Protection Act, 2023:

13.6 United Arab Emirates (PDPL)

UAE Users in the UAE have rights under the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection:

13.7 Other Jurisdictions

If you reside in a jurisdiction not specifically mentioned above (e.g., Australia, Brazil, Japan, South Korea, etc.), we will respect and comply with the applicable data protection laws of your region. Please contact us to exercise your rights under your local law.

To exercise any of these rights, please contact us at surajitroy9064@gmail.com. We will respond within the timeframe mandated by your applicable law (typically 30 days, or 45 days for CCPA requests).

Section 14

Data Retention

We retain your data for as long as your account is active and as needed to provide our services. We apply the principle of storage limitation โ€” data is not kept longer than necessary. Specifically:

Section 15

Account & Data Deletion

You have the right to delete your account and associated data at any time. Here's how the process works:

Important: If you need help deleting your account or have questions about the process, please contact us at surajitroy9064@gmail.com. We can also process account deletion requests received via email.

Section 16

Children's Privacy

ExpenseBuddy is not intended for use by children. We adhere to the following age requirements based on your jurisdiction:

We do not knowingly collect personal information from children below the applicable minimum age in their jurisdiction. If we become aware that we have inadvertently collected personal information from a child below the applicable age, we will take immediate steps to delete such information from our records.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at surajitroy9064@gmail.com so we can take appropriate action.

Section 17

Cookies & Similar Technologies

The ExpenseBuddy mobile application does not use cookies. However, our third-party service providers may use the following similar technologies:

Our hosted web pages (privacy policy and terms pages) do not set any cookies or use any tracking technologies.

Section 18

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Section 19

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

ExpenseBuddy Support
Data Controller: Surajit Roy
Email: surajitroy9064@gmail.com

We will respond to your inquiry within a reasonable timeframe: