Legal
Privacy Policy
Introduction
This Privacy Policy describes how sind.pl – Łukasz Woźniak ("we", "our", or "us") handles information in connection with the Expensor mobile application ("the App"), available on the Google Play Store.
We are committed to protecting your privacy. Please read this policy carefully to understand how we handle your data.
Data We Collect
Expensor does not collect, sell, or share any personal data. All financial data entered into the App (transactions, categories, budgets) is stored locally on your device by default. If you enable optional synchronization, data is sent to a cloud service of your choice (Firebase, Google Drive, or Microsoft OneDrive), and you may choose to have it fully encrypted on your device. We have no access to your data or to your account with any of these services – data goes directly from your device to the provider you selected.
Specifically, the App does not:
- Require an Expensor account or registration with personal details
- Collect personally identifiable information (name, email, phone number, etc.)
- Collect sensitive financial data (bank account numbers, credit card numbers, etc.)
- Use advertising networks or display ads
- Access your microphone, contacts, or location
- Send your data to our servers – synchronization only goes to services you choose
Cloud Synchronization & Encryption
Expensor offers optional data synchronization between devices. You can choose one of the methods: Firebase Realtime Database, a Google Sheets document (Google Drive), or an Excel file (Microsoft OneDrive). Synchronization is entirely voluntary – without enabling it, the App operates 100% locally and offline. Files in the cloud can be stored in one of two forms: encrypted or plain (see below).
- Keys generated on your device: In encrypted mode, data is encrypted with keys generated exclusively on the client's device. These keys never leave your device and are never sent to the server or shared with us.
- Synchronization via Firebase: Data in Firebase is always stored encrypted, and the server has no technical means to read it. The initial setup and creation of the database requires a one-time sign-in (authentication) in Firebase – this is intended to deter abuse of the API. Afterwards, data is synchronized using an anonymous Firebase account that contains none of your personal information.
- Unlinkability: The encrypted data stored in Firebase is not linked by us to your identity in any way.
- Completely optional: You can turn synchronization off at any time and use the App purely locally.
Google Drive & Microsoft OneDrive Synchronization
Synchronization with Google Sheets or an Excel file takes place in your own Google or Microsoft account, after you grant consent (OAuth sign-in). The App receives only the access needed to handle the sync files and cannot access your other files. Data goes directly from your device to the selected provider – it does not pass through our servers. You can choose one of these locations:
- Hidden app folder: The file is stored in a special hidden app-data folder in your account (Google Drive or OneDrive). It is not visible among your regular files and can only be read by Expensor.
- File you choose: Data is saved to a normally visible document (Google Sheet or Excel file) that you select yourself. You can open and view it in any application.
- Encrypted mode: The file contents are encrypted on your device and the key never leaves it – the cloud provider sees only unreadable ciphertext.
- Plain mode: The file contents are stored unencrypted and are readable by anyone with access to the file, and by the service provider under its own privacy policy. By choosing this mode you do so knowingly and at your own responsibility.
You can revoke the App's access to your account at any time in your Google or Microsoft account settings. Data stored in your cloud can be deleted by you directly – it is subject to the privacy policy and terms of the selected provider.
Crashlytics
To improve the stability and performance of our app, we use Firebase Crashlytics, a service provided by Google. When the app crashes, Crashlytics automatically collects certain information to help us diagnose and fix the problem. This information includes:
- Crash logs
- Performance and diagnostic data
- Device identifier
- App interactions
App Permissions
Expensor requests only the permissions necessary for its core functionality. It does not require any dangerous or sensitive permissions on the device (such as location, microphone, contacts, or phone). The only exception is the camera, used solely to scan QR codes containing the synchronization key, so that data can be shared with other devices. The App does not save or transmit photos or camera images, and the permission is needed only when you use this feature. When you enable Google Drive or OneDrive sync, we ask for your consent to access the sync files in your account, which you can revoke at any time.
Data Storage
All data created within Expensor is stored locally on your device by default. When synchronization is enabled, a copy resides in the service you selected (Firebase, Google Drive, or OneDrive) – encrypted or, if you decide so, in plain form. We have no access to that data. Uninstalling the App permanently deletes all local data; cloud copies remain and you can delete them yourself.
Third-Party Services
The App only integrates with selected services: Firebase Crashlytics (crash reporting), Firebase Authentication and Realtime Database (authentication and storage for optional sync), and – if you use them – Google Drive / Google Sheets and Microsoft OneDrive / Excel. These services are governed by the privacy policies of Google and Microsoft respectively. We do not use any advertising networks or third-party marketing tracking tools.
Children's Privacy
Expensor does not knowingly collect any information from children under the age of 13. The App does not collect personal data, but using synchronization requires an account with a third-party provider, which is subject to that provider's terms and age restrictions.
Security
Data transmission for synchronization is protected by secure protocols (TLS/HTTPS). In encrypted mode, data is encrypted locally on your device using keys that neither the server nor the cloud provider possesses – even in the event of unauthorized server access or traffic interception, the data remains unreadable. In plain mode, data security depends on the protection of your account with the provider (we recommend a strong password and two-factor authentication). Device data security is additionally safeguarded by Android's built-in security features (screen lock, full-disk encryption, etc.).
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically. Continued use of the App after any changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy or the App, please contact us:
- Developer: Łukasz Woźniak (sind.pl)
- Email:kontakt@sind.pl
- Website:https://sind.pl