This Privacy Policy explains what information SpendScope ("the App", "we", "us") collects, why, how it's used, and what control you have over it. SpendScope is developed and operated by Divora Labs ("Divora Labs", "we"). By using SpendScope, you agree to the collection and use of information as described here.
SpendScope is available in multiple countries. This policy is written to meet the requirements of India's Digital Personal Data Protection Act, 2023 (DPDP Act), and applies the same standard of transparency and user rights to everyone who uses the App, regardless of where you live โ including rights commonly associated with the EU's GDPR and California's CCPA/CPRA.
When you first open SpendScope, we create an anonymous account for you (via Firebase Authentication) โ we do not require your name, email, or phone number to use the App. We do store, tied to that anonymous account:
The core of the App: expenses, budgets, bills, EMIs/recurring payments, and savings goals you create. For each expense this includes the amount, merchant/description, category, date, an optional note, and how you logged it (typed, voice, receipt scan, or auto-detected recurring entry). This data is stored securely under your own account and is never visible to any other user.
Two input methods involve sensitive raw media, and we've deliberately kept both entirely on-device:
These Premium features are powered by third-party AI providers (currently Google's Gemini and Anthropic's Claude). We minimize what's sent to them:
Every AI response is automatically screened by our own safety checks before it reaches you, to catch unsupported numbers or inappropriate financial-advice language.
On whether these providers use your data to train their models: Anthropic states that data sent through its commercial API is never used to train its models without your express permission (see Anthropic's API & data retention policy). SpendScope currently uses Google's Gemini API on its free-of-charge tier, under which Google's terms permit it to use submitted content to help improve its products (see Google's Gemini API terms). Google's paid tier carries the same no-training commitment as Anthropic's instead, and we may move to it in the future โ this section will be updated if so. As described above, only a minimized, aggregate summary of your data (never your raw, itemized transactions, and never a photo or audio recording) is ever sent to any AI provider.
Premium subscriptions are processed by Google Play Billing and managed via RevenueCat, a subscription-management service. We receive confirmation of your subscription status, not your payment card details โ those are handled entirely by Google Play.
Free-tier use of the App shows ads served by Google AdMob. AdMob may collect device and advertising identifiers to serve and measure ads, subject to Google's own privacy policy. Ads are automatically turned off for Premium subscribers.
We keep lightweight technical logs of AI feature calls (which provider, response time, whether a response was blocked by our safety checks) to monitor cost and quality. These logs use a one-way cryptographic hash of your account ID, never your actual account identifier or any of your financial data.
We also use Firebase Analytics to understand how the App is used in aggregate โ for example, which features are used, or whether a purchase attempt succeeded โ and Firebase Crashlytics to capture technical crash reports (device model, OS version, and the code location of the error) so we can find and fix bugs. Neither collects your name, financial data, or the content of anything you've entered โ only the fact that an action happened and, where relevant, which type (e.g. "an expense was logged by voice," not the amount or merchant). These events are not linked to any advertising identifier or used for ad personalization.
We do not sell your personal or financial data to anyone, for any purpose.
Your data is stored on Google Cloud infrastructure via Firebase, encrypted at rest by default. Access is enforced at the database level: our security rules only allow a signed-in account to read or write its own data โ no exceptions, and this is enforced by Google's infrastructure, not just our app's code. Because the App serves multiple countries, your data may be processed in data centers outside your home country; Google's standard data processing terms (including Standard Contractual Clauses where applicable) govern these transfers.
We keep your data for as long as your account exists. When you delete an individual expense, it's marked deleted immediately in the App and excluded from all your totals โ we retain a soft-deleted copy for a limited time as an internal audit safeguard against accidental deletion, not for any other use. You can permanently erase everything at once at any time โ see Section 7. Our internal diagnostic logs (Section 1.7) are kept indefinitely for cost/quality monitoring, but are stored only against a one-way hash of your account ID and are never linked back to your financial data. AI providers' own retention of the data we send them is governed by their policies, described in Section 1.4.
| Provider | Purpose | What they receive |
|---|---|---|
| Google Firebase / Google Cloud | Database, backend functions, authentication | Your app data, as described above |
| Firebase Analytics & Crashlytics | Aggregate feature usage, crash diagnostics | Anonymous usage events and crash reports โ see 1.7 |
| Google Gemini & Anthropic Claude | AI-powered features (Premium only) | Minimized text summaries only โ see 1.4 |
| Google AdMob | Advertising (free tier only) | Device/advertising identifiers |
| RevenueCat & Google Play Billing | Subscription purchase processing | Purchase/subscription status |
Where GDPR or a similar law applies to you, we rely on: your consent (which you give during onboarding, and can withdraw at any time by deleting your account) for optional features like AI and advertising; and contractual necessity โ we can't provide the core expense-tracking service without storing the expenses you log โ for the App's basic functionality.
If you're a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to request its deletion, and to opt out of any "sale" or "sharing" of your personal information. We do not sell personal information. Because the App shows advertising through Google AdMob, which may use device/advertising identifiers for ad personalization, this can be considered a "share" under CPRA. You can opt out at any time by upgrading to Premium (which disables ads entirely) or by writing to us at the contact below and we will process your opt-out request. We will not discriminate against you โ with a lower level of service, a different price, or denied access to features โ for exercising any of these rights. These same rights are extended, as a matter of policy, to residents of other US states with similar privacy laws.
In line with the California Online Privacy Protection Act (CalOPPA), we disclose: this policy's effective date is shown at the top of this page; the categories of information we collect and who we share it with are described in Sections 1 and 5; and we do not currently respond differently to browser "Do Not Track" signals, because CalOPPA only requires us to state our practice, not to honor DNT requests. If you don't want ads to use your device's advertising identifier, the reliable way to opt out is through your device's own ad-personalization setting, or by upgrading to Premium, which turns ads off entirely.
SpendScope is not directed at, and we do not knowingly collect information from, anyone under the age of 18. For US users specifically, we do not knowingly collect personal information from children under 13, in compliance with the Children's Online Privacy Protection Act (COPPA). If you believe a child has provided us with personal information, contact us below and we will delete it.
If we make material changes to this policy, we'll update the "Last updated" date above and, where required by law, notify you in the App before the changes take effect.
For any question about this policy or your data, including data-protection/grievance requests under the DPDP Act, write to divora.labs@gmail.com.