QuantumCreations Privacy ExpenseFlow

Privacy Policy for ExpenseFlow

This copy is hosted on quantumcreations.in, the developer's website. It describes the same practices as the in-app policy at expenseflow-mobile-app-web.web.app/privacy in a more detailed layout; if the two ever differ, the in-app copy governs.

Last updated: 11 August 2026 Effective date: 5 July 2026

Permanent URL: quantumcreations.in/privacy/expenseflow

Parent / umbrella policy: quantumcreations.in/privacy  (See the parent page for our website's general privacy practices and policies for our other apps.)

This Privacy Policy is specific to the ExpenseFlow mobile application and supersedes the general QuantumCreations privacy policy where the two differ. For privacy practices that aren't ExpenseFlow-specific (e.g. the QuantumCreations website itself, marketing pages, or other apps from us), please see the parent privacy policy.

It explains how QuantumCreations ("we", "us", "our") collects, uses, stores, shares, and protects your information when you use the ExpenseFlow mobile application and related services (collectively, the "Service"). It applies to the Android app published as in.quantumcreations.expenseflow and to the ExpenseFlow iOS app distributed through the Apple App Store or TestFlight.

We designed ExpenseFlow to be privacy-respecting by default. We collect the minimum data needed to make the app work, we never sell your data, and we give you tools to export and delete everything any time. Free plan users may see ads through Google AdMob; Premium users receive an ad-free experience.

If you have questions about this policy, contact us at Quantumcreations.in@gmail.com.

1. Who we are

Data controllerQuantumCreations (Jaya Pankaj Jambhulkar)
Registered jurisdictionIndia
Postal addressFL-C/801, Pristine Prolife 170, Nr. Sayaji Hotel, Maharashtra 411057, India
Websitequantumcreations.in
Privacy contactQuantumcreations.in@gmail.com
Grievance contactQuantumcreations.in@gmail.com

For users in the European Economic Area (EEA), United Kingdom, California (USA), India, or the United Arab Emirates, we are the controller of your personal data under the GDPR, UK GDPR, CCPA/CPRA, DPDPA, and the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) respectively.

2. What data we collect

2.1 Account data (when you sign in)

2.2 Financial data you enter

We never collect or have access to:

One narrow exception on payment handles: an earlier version of the group-settlement feature let members optionally save a UPI ID so other members could pay them back easily. That entry option has been removed; any UPI ID you saved then remains stored with your group profile until you delete your account, or you can email us (see Contact) and we will remove it for you. A UPI ID is a payment handle — it cannot be used to access your bank account, and we never see your banking credentials or transactions.

If you import a bank statement (PDF or CSV), parsing happens on your device by default — the file and its contents stay on your phone. If the on-device parser cannot read a particular statement, we ask for your explicit permission before sending the statement text to our AI provider (Google Gemini) to extract the transactions; if you decline, nothing leaves your device. Statement text sent for AI extraction is used only to pull out transactions and is not stored after processing. Only the extracted transaction descriptions and amounts are saved to your account.

2.3 Usage, device, and diagnostics

We do not use a separate third-party behavioral analytics SDK for general product analytics. When ads are enabled, the Google Mobile Ads SDK may still process app and ad interaction data for ad delivery, measurement, fraud prevention, security, and compliance.

2.4 AI interaction data (Pro users only)

We use Google Gemini as our AI provider. For AI features, we send only the minimum context needed for the specific request, such as your question, income, monthly spend, safe-to-spend amount, and top category totals. By default, imported bank statements are parsed on your device and not sent to Gemini; if the on-device parser cannot read a statement, its text is sent to Gemini only after you explicitly opt in, and only to extract the transactions. Your full transaction history is never sent. Server AI logs store token/cost metadata with prompt and response bodies redacted wherever our backend logging is used.

If you use Import from Screenshot (Premium), the screenshot you select or share is sent to Gemini to read the transactions out of it, after you consent to that specific import. The image is used only for that extraction: it is not stored on our servers, is not used to train any model, and the copy on your device is deleted once it has been read. Nothing is added to your expenses until you review the extracted entries and save them. Notification text read by the optional Android capture feature described in §2.7 is never sent to Gemini — it is parsed entirely on your device.

2.5 Advertising data

2.6 Data we do not collect

ExpenseFlow does not collect precise location, background location, contacts, SMS, call logs, calendar events, health data, bank credentials, card numbers, UPI credentials, OTPs, or raw imported bank statement files. Advertising identifiers may be used only in ad-enabled builds and only for ad delivery, measurement, fraud prevention, security, and compliance.

We never read your SMS or email

Many expense apps ask for permission to read your text messages or email inbox to log transactions automatically. ExpenseFlow deliberately does not do this and never will. Your bank alerts, OTPs, personal messages, and email stay entirely on your device — the app does not request SMS or email permissions at all. Automatic capture is offered only through privacy-respecting means you explicitly trigger: typing a quick line, speaking a voice note, scanning a receipt you choose to photograph, importing a statement file or screenshot you pick yourself, or — on Android, if you turn it on — the notification-based expense suggestions described in section 2.7, which read only the payment apps listed there, process everything on your device, and are off by default.

2.7 Notification access (Android only, optional, off by default)

If you turn on Automatic expense suggestions — a Premium feature, offered on Android only and only while your display currency is set to Indian Rupees (₹) — ExpenseFlow reads notifications from supported payment apps (Google Pay, PhonePe and Paytm) to create expense suggestions, including while the app is closed. You are asked for explicit consent in the app before this is enabled, and you grant notification access yourself in Android settings. If you change your display currency away from ₹, reading stops immediately.

Raw notification content never leaves your device. Parsing happens on the phone, notifications we do not recognise are discarded immediately, and nothing from them is stored on our servers or sent to our AI provider. A suggestion stays only on your phone until you confirm it; if you do, its amount and payee are saved as an expense and sync like any expense you enter yourself. You can turn this off at any time in Settings, which stops all reading. This feature does not exist on iOS, which does not allow apps to read other apps' notifications.

3. How we collect data

SourceWhat we get
Directly from youEverything you type into the app: expenses, categories, income, goals
Authentication providers (Google, Apple)Email, name, profile photo URL (only with your consent during sign-in)
Your deviceApp version, OS version, push token if enabled, local app settings
Bank statements you importTransaction text and amounts, parsed on your device by default; if a statement can't be read locally, its text is sent to our AI provider (Gemini) to extract transactions only after you explicitly opt in
Screenshots you importThe image you pick or share, sent to our AI provider (Gemini) to extract the transactions after you consent to that import; not stored on our servers and deleted from your device once read
Payment notifications (Android, optional)Amount, payee and reference parsed on your device from supported UPI apps after you opt in; the notification text itself is never transmitted

We do not collect data from third-party data brokers, social media scraping, or hidden tracking SDKs.

4. Why we use your data (legal bases)

PurposeLegal basis (GDPR / UK GDPR)Equivalent under CCPA / DPDPA
Provide the Service (sync expenses across devices, run AI categorization, render dashboards)Performance of contract (Art. 6(1)(b))Necessary to provide the Service
Maintain account security, prevent abuseLegitimate interest (Art. 6(1)(f))Security
Improve the app (local usage counters and support diagnostics)Legitimate interest (Art. 6(1)(f))Improvement, with right to opt out where applicable
Personalize features for Pro usersPerformance of contractNecessary to provide the Service
Send service notifications (subscription expiring, security alerts)Performance of contractNecessary to provide the Service
Marketing emailsConsent (Art. 6(1)(a))Opt-in only
Comply with lawLegal obligation (Art. 6(1)(c))Compliance
Show ads on the Free plan, measure ad performance, limit repeated ads, and prevent invalid ad activityConsent where required; legitimate interest or performance of contract where permittedAdvertising/marketing with opt-out rights where applicable

We rely on legitimate interest only for purposes that we have weighed against your reasonable expectations. You can object to legitimate-interest processing at any time using the contacts in §11.

5. Who we share data with

We share only the minimum with these processors, each bound by a Data Processing Agreement:

ProcessorPurposeLocationData shared
Supabase Inc.Database hosting, authentication, real-time syncUSA, with EU/AP regions for our projectAll app data
ResendTransactional email delivery — account verification, password reset, group-invitation emails, and shared-group activity and balance-reminder emails (statement and member balances for a group you belong to; schedule is controlled by the group admin and every email carries an unsubscribe option)USA, globalRecipient email address and email content; for group invitations, the invitee’s email address (which may be a non-user); for group emails, group member names and balance amounts
Google Cloud (Gemini API)AI categorization, Smart Insights, Forecast, and AI Coach responses (Pro only), receipt scanning, and reading statements or screenshots you choose to importUSA, EU, APPrompt content + minimal financial context; receipt and screenshot images you choose to import, and statement text when on-device parsing fails and you opt in. Notification text from the optional Android capture feature is never sent.
Google Firebase Cloud MessagingPush notificationsGlobalDevice push token and notification delivery metadata
Google Play Billing / Apple In-App PurchaseAndroid and iOS subscription purchase processingGlobalPurchase and subscription data handled by the relevant app store. For users in India, all prices are inclusive of applicable taxes (GST); the store checkout and receipt show the final price charged.
Google AdMobAds for Free plan users, ad measurement, frequency capping, fraud prevention, security, and complianceGlobalAdvertising ID where available, app set ID, IP address, device/account identifiers, app and ad interactions, diagnostics, and approximate region inferred from IP address
Google User Messaging Platform (UMP)Consent and privacy-choice management for adsGlobalConsent status, region signals, device information, and related privacy-choice metadata
RevenueCat Inc.Subscription managementUSAPseudonymous user ID + subscription state
Google Firebase (Hosting & Crashlytics)Hosts the web app and legal pages; crash reporting for app stabilityGlobalCrash reports with device model, OS version, and app state at crash time; standard web-server logs for hosted pages
ExchangeRate-API (open.er-api.com)Live currency exchange rates for multi-currency displayGlobalOnly the rate request (currency codes) — no personal or financial data is sent

We do not sell or rent personal data. We do not share your financial entries, income, savings goals, coach messages, or imported statement files with ad networks. Where privacy laws treat personalized advertising as "sharing," "targeted advertising," or similar, you can opt out through the in-app privacy options where available and through your device advertising settings.

If you are part of a shared group within the app (family, roommates, trip), other members of that group can see the expenses you share with the group, your display name, and your share/balance amounts. They cannot see your personal expenses outside the group.

6. International transfers

Your data is stored on servers operated by Supabase. Depending on your project region, this may be in the United States, the European Union, or the Asia-Pacific region. When data leaves your region of residence, we rely on:

You can request the SCCs we have in place by emailing Quantumcreations.in@gmail.com.

7. How long we keep your data

DataRetention
Your account and financial dataUntil you delete it or request account deletion. Verified deletion requests are usually processed within 7 working days; backup copies expire within 30 days after deletion.
AI prompts/responsesProcessed to answer your request. The primary Edge Function does not store prompt/response bodies; backend fallback chat sessions, if used, remain until account deletion unless removed earlier.
AI token/cost/quota metadataUp to 24 months
Screenshots you importNot retained. The image is sent to Gemini only to extract the transactions in it, is not stored on our servers, and is not used to train any model; the copy on your device is deleted once it has been read. Only the entries you review and save are kept, as ordinary expense data.
Payment notifications (Android, optional)Not retained. Notification content is parsed on your device and never transmitted; notifications we do not recognise are discarded immediately, and a suggestion you do not confirm never leaves your phone. A suggestion you do confirm is kept as an ordinary expense entry.
Crash reportsRetained by Firebase Crashlytics for 90 days (Firebase default), associated with device and app-state data only
Ad request, ad interaction, and consent metadataHandled by Google AdMob/UMP according to Google's policies. ExpenseFlow does not store your advertising ID in its own database.
Subscription receipts7 years (tax law requirement)
Local/anonymized usage counters24 months

You can delete individual expenses, categories, or your entire account at any time in More → Profile & Account → Delete Account, or request deletion at https://www.quantumcreations.in/expenseflow/delete_account. Deletion is permanent. We acknowledge email deletion requests within 72 hours, usually process verified deletion requests within 7 working days, and backup copies expire within 30 days after deletion.

8. How we secure your data

ExpenseFlow is not end-to-end encrypted. Your data is encrypted in transit, encrypted at rest, and access-controlled, but our server-side systems and trusted infrastructure providers process readable data when needed for sync, family sharing, AI features, support, security, and legal compliance.

In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours, in line with GDPR Art. 33–34 and DPDPA equivalents.

9. Your rights

Wherever you live, you have these rights over your personal data:

RightWhat it meansHow to exercise
AccessGet a copy of all data we hold about youMore → Export CSV, or email Quantumcreations.in@gmail.com
CorrectionFix inaccurate dataEdit in-app, or email Quantumcreations.in@gmail.com
DeletionErase your account and dataMore → Profile & Account → Delete Account
PortabilityGet your data in a machine-readable format (CSV)More → Export CSV
RestrictionPause processing in specific casesEmail Quantumcreations.in@gmail.com
ObjectionObject to processing based on legitimate interestEmail Quantumcreations.in@gmail.com
Withdraw consentFor processing that relies on consentToggles in Settings, ad privacy options where available, Android Advertising ID settings, iOS tracking settings, or email Quantumcreations.in@gmail.com

Additional rights for specific regions:

We acknowledge privacy and grievance requests within 72 hours and respond to verified rights requests within 30 calendar days (sometimes extended to 60 days for complex requests, with notice). Verified account deletion requests are usually completed within 7 working days, with backup copies expiring within 30 days after deletion.

10. Children

ExpenseFlow is not intended for children under 13 (under 16 in the EEA, under 18 in India for non-essential processing). We do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.

11. Contact us

For California residents, you may designate an authorized agent to make CCPA requests on your behalf. We will verify their authority before responding.

12. Changes to this policy

We may update this policy as the Service evolves or laws change. When we do, we will:

  1. Update the "Last updated" date at the top
  2. Show an in-app banner for material changes
  3. Email you at least 30 days in advance for material changes affecting your rights
  4. Keep prior versions accessible at https://www.quantumcreations.in/privacy/expenseflow/archive

Continued use of the Service after a change means you accept the updated policy. If you don't agree, you can delete your account before the effective date.

13. Supervisory authorities

If you believe we have violated your rights, you can complain to:

We would, of course, prefer the chance to resolve your concern first — please reach out to Quantumcreations.in@gmail.com before escalating.

This policy was drafted in plain English and is the authoritative version. If you read a translation, the English version controls in the event of any discrepancy.