👋
Welcome to Expense Flow by Codes Cafe. We built this app to help you
track every rupee, set smarter budgets, and reach your financial goals — and we take the same care with
your data. This policy explains exactly what we collect, why, and how you stay in control.
Your data powers every feature of Expense Flow — nothing else.
- Transaction tracking: Record, categorise, and display your income and expenses across the Home and Timeline views
- Dashboard & analytics: Generate charts, summaries, and spending insights on the Analytics screen
- Budget monitoring: Compare your actual spending against the limits you set and alert you when you're close to the limit
- Goals tracking: Show progress toward your savings targets and project completion dates
- Lent tracker: Remind you of money you have lent or borrowed and upcoming due dates
- Calendar view: Display your transactions day-by-day so you can review any date's activity
- Account sync: Keep your data consistent across sign-outs and reinstalls via Firebase
- Notifications: Send budget alerts, goal milestones, and reminders you configure
- Net worth tracking: Calculate your total assets and liabilities from your account balances and store a daily snapshot so you can see your net worth trend over time (Pro)
- Spending insights: Analyse your own transactions, budgets, and bills to generate personalised observations — computed entirely from your data on our servers, with no external AI or third-party service involved (Pro)
- Engagement & streaks: Track your daily logging activity to show your current and longest streak and award badges for consistent use
- Spending challenges: Track your progress toward opt-in challenges (like a no-spend weekend or a category spending cap) that you choose to join
- Bank SMS parsing: If enabled, detect transactions from bank SMS messages on your device so you can add them with one tap instead of typing them manually
- Family budgets: If you create or join a household, let you share specific accounts or budgets with other members and show a combined activity feed for what you've shared
- Subscription verification: Confirm your purchase with Google Play or the Apple App Store and keep your subscription status current using the renewal, cancellation, and refund notifications they send us
- App improvement: Analyse anonymous usage patterns to prioritise new features and fix bugs
🚫
We will never sell, rent, or trade your personal or financial data to any third party for advertising or marketing purposes.
Expense Flow uses the following Google Firebase services to power authentication and cloud storage:
🔐 Firebase Auth
🗄️ Cloud Firestore
🔑 Google Sign-In
🧾 Google Play / App Store Billing
- Firebase Authentication: Manages secure sign-in with email/password or Google. Firebase stores your authentication token; we never see your Google account password
- Cloud Firestore: Your account data and transactions are stored in a private, user-scoped Firestore document — only your account can read or write it
- Google Sign-In: If you choose this option, Google shares your name, email, and profile photo with us. No other Google account data is accessed
- Google Play / Apple App Store: If you buy a Pro subscription, we exchange a purchase token or receipt with the store to verify it, and the store sends us renewal, cancellation, and refund notifications to keep your access accurate. Your card details are never shared with us
Google's own privacy practices apply to all Firebase services.
You can review them at firebase.google.com/support/privacy.
🌐
All Firebase data is transmitted over TLS/HTTPS and stored in Google's secure, compliant infrastructure.
Expense Flow is designed to work offline. A local SQLite database on your device stores
your transactions, budgets, goals, and settings so the app is always fast and functional — even without
internet access.
- The local database is private to the app's sandbox and cannot be accessed by other apps
- Deleting the app removes all locally stored data permanently
- Small preferences (theme, currency, last-seen state) are saved in SharedPreferences on your device
- Your App Lock PIN, if set, is kept in a separate encrypted secure-storage area (Keychain on iOS, Keystore on Android) and is never synced or backed up
- No local data is shared with third parties
🔒
Your financial data lives on your device first. Cloud sync is additive — it backs up your data but is never the only place it lives.
We implement multiple layers of security to protect your financial information:
- All network communication uses TLS 1.2 / 1.3 encryption
- Passwords are hashed via Firebase Auth — we never store or transmit plain-text passwords
- Firestore security rules ensure only the authenticated user can read or write their own data
- The local SQLite database resides in the app's private storage, inaccessible to other apps on non-rooted devices
- Google Sign-In tokens are short-lived and managed entirely by Google's OAuth 2.0 infrastructure
While we apply industry-standard protections, no system is 100% immune to breaches. We recommend using
a strong, unique password and keeping your device's OS up to date.
We keep your data only as long as your account is active or as required to provide the service.
- Active account data: Retained for the lifetime of your account
- Transaction records: Retained as long as your account exists; you may delete individual records at any time within the app
- Archived financial accounts: Archiving a bank/cash/card account (e.g. one you no longer use) hides it from your active list and totals but keeps its transaction history intact — nothing is deleted, and you can restore it at any time
- Household sharing: Unsharing an account or budget immediately stops it appearing in your household's shared feed; leaving or dissolving a household ends all sharing for that household right away
- Store notification logs: Raw renewal/cancellation/refund notifications from Google Play and Apple are logged briefly for troubleshooting and contain only purchase/subscription identifiers, not your financial data
- Account deletion: All Firestore data is purged within 30 days of a deletion request
- Anonymous analytics: Retained for up to 14 months, then automatically deleted by Google Analytics
- Local data: Removed immediately when you uninstall the app
🗑️
To delete your account and all associated data, go to More → Profile → Delete Account inside the app, or contact us at the address below.
You have full control over your data at any time:
- Access: View all your transactions, budgets, goals, and account settings inside the app at any time
- Correction: Edit any transaction, budget, goal, or profile detail directly within the app
- Deletion: Delete individual records from within the app, or delete your entire account and all data. Deleting a financial account with existing transactions first asks you to move (reassign) those transactions to another account of your choice, so your spending history is never silently lost
- Portability: Request an export of your data in a structured format by contacting us
- Opt-out of notifications: Disable any in-app notification from More → Notifications
- Revoke Google access: Disconnect Google Sign-In at any time from your Google account's security settings
📬
To exercise any right not available directly in the app, email us at support@codescafe.org and we will respond within 5 business days.
We share your information only in these limited, specific circumstances:
- Firebase / Google: As described in Section 03, your data is stored in Firebase services operated by Google
- Customer support: Our authorised support staff can view and, when needed to resolve a billing issue, promotion, or your direct request, manually adjust your subscription plan. They cannot see your transactions, budgets, goals, or other financial details
- Household members (opt-in): If you create or join a household (up to 6 people) and choose to share an account or budget, the transactions on it — amount, merchant, note, category, account name, date, and your name — become visible to the other members in a shared feed. You control what you share and can unshare an item or leave the household at any time
- Payment processors: To verify and manage your subscription, we exchange a purchase token or receipt with Google Play or the Apple App Store. We never receive your card number or other payment details — those are handled entirely by the store
- Legal obligations: If required by applicable law, court order, or government authority we will disclose the minimum necessary data
- Business transfer: In the event of a merger or acquisition, your data may transfer to the new entity, which will be bound by this policy
- Your explicit consent: We will not share your data for any other purpose without your clear, prior consent
🚫
We do not share your financial data with advertisers, data brokers, analytics resellers, or any other commercial third party.
Expense Flow is intended for users who are at least 13 years of age (or the applicable
minimum digital age in your country). We do not knowingly collect personal information from children
under this age.
If you are a parent or guardian and believe your child has created an account, please contact us
immediately at support@codescafe.org. We will promptly delete the account and all
associated data.
We may update this Privacy Policy as the app evolves or regulations change. When we make material
changes, we will notify you via an in-app notification and update the Last updated date at
the top of this page.
Continued use of Expense Flow after a policy update constitutes your acceptance of the revised terms.
If you do not agree, you may delete your account at any time.
Households (Pro feature) let you share part of your finances with people you trust — a partner, family,
or roommates — without handing over your whole account.
- You create a household and get a unique invite code, or join one using a code someone shares with you. Households are capped at 6 members
- Nothing is shared automatically. You choose exactly which accounts or budgets to share — everything else in your account stays private
- Once you share an account or budget, its transactions (amount, merchant, note, category, account name, and date) and your name become visible to the other members in a shared activity feed
- You can stop sharing an account or budget at any time — it disappears from the shared feed immediately
- Leaving a household removes your shared items from it. If the household's owner leaves, the household is dissolved and sharing ends for everyone
🔒
Household sharing is opt-in and reversible. Transactions and accounts you never mark as shared are not visible to anyone but you, even inside a household.