Expensive Privacy Policy
The fine print — written to be read. Questions about anything here? Our contact page is one click away.
1. Introduction
This policy covers the Expensive mobile app for iOS and Android, operated by Code Junction ("we", "our", or "us"). It explains what data the app collects, why, and the choices you have. For the Code Junction website and other products, see our general Privacy Policy.
2. Information We Collect
Account data: Your email address, username, and password, managed through Firebase Authentication.
Financial data you enter: Expenses, amounts, categories, budgets, tags, notes, ledgers, group expenses, settlements, and comments. This data is stored on your device first and synced to our cloud database (Google Cloud Firestore) so it stays available across your devices and in shared groups.
Receipt photos: When you scan a receipt, the photos are transmitted to an AI vision service (via OpenRouter) solely to extract the merchant, items, amounts, and date. We do not store your receipt photos on our servers.
Voice input: When you use voice capture, speech is transcribed by your device's built-in speech recognition (Apple or Google, per their policies). Only the text transcript is sent to an AI parsing service (Groq) to turn it into an expense entry — the audio itself never reaches our servers.
Contacts: With your permission, the app reads your contacts on-device to help you add group members. Only the members you explicitly select are saved with a group.
Usage and diagnostics: We use Google Analytics for Firebase (feature-usage events, screen views, device model and OS, device identifiers) and Firebase Crashlytics (crash logs and diagnostics) to understand how the app is used and to fix problems. These events never include your financial amounts, descriptions, or personal names.
Push tokens: A device token (Firebase Cloud Messaging) so we can deliver group-activity notifications and reminders.
3. How We Use Your Information
- To provide the app: record, categorize, and sync your expenses across devices
- To power shared groups — splitting expenses, balances, and settle-ups with people you choose
- To process receipt photos and voice commands into expense entries
- To send push notifications about group activity and reminders
- To understand feature usage and improve the app (aggregate analytics)
- To detect and fix crashes and technical issues
- To comply with applicable legal obligations
4. Service Providers
We never sell your data, and the app contains no advertising or ad tracking. Data is shared only with service providers that process it on our behalf:
- Google Firebase — authentication, cloud database, file storage, analytics, crash reporting, and push notifications
- OpenRouter — AI processing of receipt photos you choose to scan
- Groq — AI parsing of voice-command transcripts
- Law enforcement — only when required by applicable law
5. Data Storage & Security
Expensive is local-first: your data lives in a database on your device and is synced to Google Cloud Firestore. All transfers use TLS encryption in transit, and cloud data is encrypted at rest by Google Cloud. Access to production data is restricted to authorised personnel only.
6. Data Retention & Deletion
Your account and financial data are retained for as long as your account exists. You can delete your account from within the app, which removes your data from our cloud database. Analytics data is retained by Google Analytics for up to 14 months; crash reports are retained by Crashlytics for 90 days.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and data
- Object to or restrict certain processing
- Data portability (export your data)
To exercise these rights, contact us at privacy@codejunction.io.
8. Children
Expensive is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be announced in the app or via the update notes, and the "last updated" date above will always reflect the current version.
10. Contact
Questions about this policy? Reach us at privacy@codejunction.io or via our contact page.