Security & Trust

Privacy Policy

Effective date: September 8, 2026. Your money data belongs strictly to you. Built with privacy-first engineering from day one.

Xpense Manager Pro ("XMP", "we", "us") is a personal expense management application built and operated by Zaf Khan. We built XMP with one principle that governs everything else: your money data belongs to you, and nobody else needs a copy of it.

If anything here is unclear, email support@xpensemanagerpro.in.

Local-First Storage

Your transactions, custom categories, and budgets are saved locally in your browser's secure local storage, scoped to your authenticated account.

Zero Third-Party Ads

We never sell your personal financial data to advertisers, data brokers, or lending platforms. No ads, ever.

No SMS Access

We do not read your bank SMS messages or auto-track your notification inbox. You maintain 100% control of what is logged.

Encrypted Google Drive Sync

Backups are strongly encrypted on your device before upload to your private Google Drive folder.

1The Short Version

  • Your personal finance data lives on your device in secure local storage. It is stored locally for speed and privacy.
  • Optionally, back up to your own Google Drive, protected with strong encryption before it leaves your device.
  • We keep a minimal account (email, display name, avatar) — never your financial data.
  • We never sell, share, rent, or monetize your personal financial data. No ads. No data brokers. No lending partners. Ever.
  • You can export or delete everything we hold about you, from inside the app, at any time.

2Data We Handle

2a. Data You Provide Directly

Expenses — amount, category, date, description

Core tracking of spending and income

Device (local storage), Google Drive backup (encrypted)

Budgets — monthly amounts per category

Budget progress on dashboard

Device (local storage)

Custom categories — name, icon, colour

Personalised categorisation

Device (local storage), cloud sync (cross-device)

Scheduled transactions

Recurring bill reminders and auto-logging

Device (local storage)

Voice recordings (up to 20s)

Transcription for expense extraction

Ephemeral AI processing — never stored

UPI statement PDFs (VibeScan)

Import transactions from PhonePe, GPay, Paytm

Parsed entirely on your device — never uploaded

Riza AI queries

Context-aware financial assistance

Ephemeral AI processing — never stored

2b. Data Created Automatically

Authentication tokens (secure session cookies)

Keeping you signed in securely

Browser cookies (HTTP-only, secure)

FCM device token

Delivering push notifications

Cloud database (linked to user ID)

Subscription record

Verifying Pro subscription status

Cloud database

2c. What We Do NOT Collect

  • We do not read your bank SMS messages or auto-track your notification inbox.
  • We do not collect your contacts list, call logs, browsing history, or data from other apps.
  • We do not collect your bank account number, credit card number, UPI PIN, OTP, or any financial credential.
  • We do not use cookies for advertising, fingerprinting, IDFA, or cross-app tracking.
  • We do not collect your location or GPS coordinates.

3Where Your Data Lives

XMP is built on a local-first architecture. Your core financial data lives in your browser's secure local storage, scoped strictly to your authenticated account.

On-device (primary)

Browser local storage

All expenses, budgets, categories, scheduled items

Cloud authentication

Secure cloud authentication

Email, display name, avatar, hashed password

Cloud sync (optional)

Real-time cloud sync

Custom categories, preferences, FCM tokens

Encrypted backup (optional)

Your Google Drive (app-private folder)

Encrypted backup of your complete data

Logging out completely purges in-memory active states and clears user-scoped local storage data, preventing data leakage on shared devices.

4AI Feature Processing

XMP includes three AI-powered features. Here is exactly how each handles your data:

Voice-to-Expense

  • Your voice audio (up to 20 seconds) is sent to our server-side AI proxy.
  • The AI receives only the spoken amount and description/name for category classification based on predefined rules.
  • Audio and transcript are not stored after the response is returned.
  • Nothing is auto-saved without your explicit confirmation.

Riza AI

  • What is sent: Aggregated spending summaries (amounts and category names only) and your question.
  • What is NOT sent: Your email, name, user ID, or any personally identifying information.
  • Responses are generated ephemerally and not retained for model training.

VibeScan (UPI Statement Scanner)

  • PDF statement parsing runs entirely client-side in your browser.
  • Bank statement passwords are entered locally and never leave your device.
  • No PDF content, parsed transactions, or bank passwords are transmitted to any server.

What is NEVER Sent to Any AI Provider

  • UTR numbers (Unique Transaction References)
  • Transaction IDs or payment reference numbers
  • Bank account numbers, IFSC codes, or UPI IDs
  • UPI transaction references or order IDs
  • Razorpay payment IDs or subscription identifiers
  • Merchant UPI addresses or beneficiary details
  • Bank statement raw data (parsed entirely client-side)

Only two things are ever shared with AI: the amount (e.g., ₹250) and the description/name (e.g., "Swiggy", "Auto", "Room Rent") — solely for intelligent category classification. All other transaction identifiers remain exclusively on your device.

5Authentication & Account

XMP uses secure cloud authentication. You can sign in with:

  • Google OAuth 2.0 — We receive your Google email, display name, and profile picture from Google's consent flow.
  • Email and Password — Your password is securely hashed using industry-standard algorithms before storage; we never store plaintext passwords.

Your account record contains only: email address, display name, avatar URL, authentication provider, and account creation date. It never contains your expenses, budgets, or financial data.

6Cloud Backup (Google Drive)

When you connect Google Drive from Settings → Data & Backup:

  1. OAuth Scope: We request only an app-private folder scope — the app can only read its own isolated folder, never your personal Drive files.
  2. Client-Side Encryption: All data is protected with strong encryption before it leaves your browser, with a key derived from your credentials.
  3. Your Private Folder: The encrypted file is uploaded to your Google Drive's hidden app-private folder. Only the XMP app can read this folder.
  4. Restore Preview: When restoring, the app downloads and decrypts locally, showing you a comparison before overwriting.
  5. Offline Fallback: You can also export/import plain .json backup files locally without internet.

7Subscription & Payment (Razorpay)

  • What Razorpay receives: Your payment method details (UPI, card, netbanking) are processed entirely by Razorpay's PCI-DSS Level 1 compliant infrastructure. We never see, store, or handle your card number, CVV, or UPI PIN.
  • What we store: Razorpay order ID, payment ID, plan type, activation date, and expiry date — solely to verify your Pro entitlement.
  • Server-side verification: Payment signatures are verified using cryptographic signature verification to prevent tampering.
  • Invoices: PDF invoices with GST details are generated and available for download inside the app.

8Push Notifications (Firebase Cloud Messaging)

  • What we send: Daily expense reminders, scheduled bill alerts, plan expiry warnings, and admin broadcasts.
  • What we store: Your FCM device token linked to your user ID. This token is an opaque Firebase identifier and cannot identify you personally.
  • Notification payloads contain only title, body text, and optional image. They never contain your financial data.
  • You can disable push notifications at any time from device settings or within the app.

9Zero Silent-Save Principle

  • The app never silently injects or saves an expense without your explicit interaction.
  • Voice-parsed, PDF-imported, and AI-suggested transactions always present a confirmation screen.
  • Scheduled transactions configured for "Auto-Log" are the only exception — and you explicitly opt into this.

10Data Ownership & Your Rights

You can, at any time and without contacting us:

  • View every piece of data XMP holds about you — it's all visible in the app.
  • Edit any expense, budget, category, or scheduled transaction.
  • Export your complete transaction ledger in PDF, Excel (.xlsx), or CSV format.
  • Backup your data to your own Google Drive with client-side encryption.
  • Delete all local data with one tap from Settings → Clear Data.
  • Delete your account permanently from Settings → Delete Account.

If you are a resident of a jurisdiction with additional data protection rights (e.g., India's DPDP Act 2023, EU GDPR), you can exercise those rights by emailing support@xpensemanagerpro.in.

11Data Retention

Local expenses & budgets

Kept until you clear or delete them

Google Drive backup

Kept in your Drive until you delete it

Authentication account

Kept until you delete your account

Subscription record

Active + 30 days after expiry, then auto-deleted

FCM device token

Kept while account exists; removed on deletion

AI request/response

Not retained — processed ephemerally

12Third-Party Services

Cloud Auth Provider

Auth, sync, database

Email, name, avatar

Provider-specific

Google OAuth

Sign-in with Google

Email, name, picture

View

Google Drive API

Encrypted cloud backup

Encrypted backup file

View

Razorpay

Payment processing

Payment details (handled by Razorpay)

View

Firebase (FCM)

Push notifications

FCM device token

View

AI Provider

Voice, Riza AI, VibeScan

Ephemeral context (no identity)

Provider-specific

13What We Will Never Do

  • Sell your data to advertisers, data brokers, or lending platforms.
  • Show you ads or use ad-tracking SDKs.
  • Read your bank SMS messages or scrape your notification inbox.
  • Use your financial data to train public AI models.
  • Share your transaction history with any third party.
  • Connect to your bank account or UPI app directly.

14Children's Privacy

XMP is intended for users aged 13 and above. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will promptly delete it.

15Changes to This Policy

If we change this policy materially, we will update the date at the top, post the new version at this URL, and surface the change inside the app. Material changes do not take effect retroactively for data already collected.

16Contact