Skip to Content

Privacy Policy

Last updated: September 2026

The short version

  • ✓ No servers, no backend, no data ever sent to SpendCheck or its developer.
  • ✓ No analytics, advertising, or tracking SDKs of any kind.
  • ✓ No account, sign-in, or personal identifiers required.
  • ✓ Your data is never shared with any third party.

SpendCheck is an expense-tracking app built to keep every piece of your financial data private, on your own device, permanently.

What SpendCheck stores, and where

iOS: All expense entries, categories, notes, and receipt photos you add are stored locally on your iPhone using Apple's on-device SwiftData framework. This data stays in your device's local storage and is included only in your own device backups (e.g. iCloud Backup or Finder backup, if you have those enabled through iOS). The one exception is SpendCheck's optional Backup & Restore feature, described below. Even then, SpendCheck has no server to upload to: turning it on only saves a fully encrypted copy to your own iCloud or another cloud storage of your choice, never to SpendCheck or its developer.

Android: All expense entries, categories, notes, and receipt photos you add are stored locally on your phone. If your device has a screen lock (PIN, pattern, password, or fingerprint) and you have Android's own Backup service turned on, Android automatically includes this data in your regular Google Account backup, encrypted with a key tied to your screen lock before it ever leaves your phone, so it can be restored automatically if you reinstall SpendCheck or move to a new phone, and cannot be read by Google or anyone else but you. If your device has no screen lock, this data still backs up, but without that end-to-end encryption guarantee; SpendCheck's own Settings screen will tell you this and suggest adding a screen lock. Either way, this is Android's own operating-system backup service, not a SpendCheck server, SpendCheck never sees or receives this data.

Notification-based expense logging (Android)

If you grant SpendCheck Notification Access in Android system settings, it is technically able to read the text of any notification posted on your device, this is how Android's Notification Access permission itself works at the operating-system level, for any app that uses it, not a scope SpendCheck chooses. In practice, SpendCheck only ever keeps or acts on a notification if it's from a supported banking or payment app, or your phone's default messaging app carrying a recognizable bank SMS, and only if its text matches the shape of a real transaction, either logging it automatically or queuing it for you to confirm. A notification that doesn't match, a promotion, a different app entirely, an OTP code, a health or system notification, is discarded on-device immediately and never written to storage. All of this processing happens entirely on your device; notification text is never transmitted anywhere. This permission is entirely optional: SpendCheck works fully with manual entry if you never grant it, and you can revoke it at any time in Android Settings → Apps → Special app access → Notification access.

Encrypted Backup & Restore (optional, user-controlled)

Both iOS and Android versions of SpendCheck let you create an encrypted backup file of your expenses and receipts, protected by a passphrase you choose. This is separate from, and in addition to, the automatic device-level backup described above. SpendCheck never sees or stores your passphrase, it's used only on your device to derive an encryption key, and you choose where the resulting file is saved (for example, your device's file system, a cloud drive of your choosing, or email to yourself). If you forget your passphrase, the backup cannot be recovered by SpendCheck or anyone else, this is stated in the app before you create one. Restoring a backup only ever adds to your existing data; it never deletes or overwrites anything already on your device.

Camera and Photo access

If you choose to take a new photo of a receipt, SpendCheck requests access to your camera for that purpose. If you choose an existing photo instead, SpendCheck uses your device's own system photo picker (Apple's Photos Picker on iOS, Android's Photo Picker on Android), this shares only the specific photo you select, not broader access to your photo library, and no separate permission grant is required for it. Photos you capture or select are used only to attach to that expense entry and to run on-device text recognition (Apple's Vision framework on iOS, Google's ML Kit on Android) so receipt text becomes searchable within the app. This processing happens entirely on your device, no image or extracted text is ever sent anywhere.

Data deletion

Deleting an expense entry moves it to a "Recently Deleted" area within the app for up to 14 days, so you can undo an accidental deletion, during that window it isn't shown anywhere else in the app, but it hasn't been erased from your device yet. You can also delete it permanently at any time from that screen. After 14 days, or if you delete it permanently yourself, it, along with any attached receipt photo, is removed from your device for good. Deleting the app itself removes all remaining SpendCheck data from your device (subject to your own device backup settings, iCloud Backup on iOS, or Google's Backup service on Android, which are outside SpendCheck's control).

Changes to this policy

If SpendCheck's data practices ever change, this page will be updated to reflect that before any such change ships.