Spent — Privacy Policy

Last updated: 15 August 2026

Spent is an offline expense tracker. Your privacy is the product.

What we collect

Nothing. Spent has no accounts, no sign-up, no analytics, no advertising SDKs, and makes no network requests. Everything you enter — transactions, categories, budgets, settings — is stored only in the app's private storage on your device.

Bank access

Spent never asks for, stores, or transmits banking credentials. There is no bank linking of any kind.

Notifications

Bill reminders are scheduled locally on your device. Reminder notifications deliberately exclude amounts so financial details do not appear on your lock screen. No notification data leaves your device.

App lock and biometrics

If you turn on app lock, your PIN is never stored in readable form. Only a salted cryptographic hash of it is kept, in your device's secure hardware storage (Android Keystore / iOS Keychain), and it is excluded from backup exports.

If you enable biometric unlock, your fingerprint or face is checked by the operating system's own biometric prompt. Spent never sees, receives, or stores your biometric data — the system only tells the app whether the check succeeded.

Because the PIN is stored as a hash and nothing leaves your device, there is no way for anyone — including us — to recover a forgotten PIN.

Backups

When you export a backup or CSV, the file is created on your device and handed to the app you choose via the system share sheet (e.g. your email or cloud storage). Where that file goes is entirely under your control; Spent never uploads it anywhere.

Data deletion

Uninstalling the app, or using Settings → Clear all data, permanently removes all data. Because we hold nothing, there is nothing for us to delete on any server.

Changes

If this policy ever changes, the updated version will ship with the app and be dated above.

Contact

Questions: mgsamukwevho@gmail.com