Privacy Policy
VeloSpend is an offline-first personal budgeting app. This policy explains what information the Android app and its supporting services handle, why it is used, and how you can control it.
Information VeloSpend Handles
You may enter a display name, account names and balances, categories, budgets, transactions, transfer details, recurring items, notes or descriptions, currency and language choices, reminder preferences, and home-screen settings. This can be sensitive financial information, but it is information you choose to enter; VeloSpend does not connect to your bank.
Guest Mode and Local Storage
You can use VeloSpend in guest mode without creating an account. Guest financial records are stored in the app's local database on that device and are not sent to the VeloSpend sync service. Android system backup is disabled for the local financial database.
An optional app PIN is stored using Android encrypted storage. If you enable biometric unlock, authentication is performed by Android using biometrics enrolled on your device; VeloSpend does not receive or store your fingerprint or face data.
Account and Cloud Sync
If you create an account, Firebase Authentication processes account and authentication information such as your email address, password credentials, Firebase user identifier, verification state, IP address, and user-agent information to provide sign-in and protect against abuse. See Firebase Privacy and Security.
After you verify your email and sync is enabled, VeloSpend sends eligible data over HTTPS to the VeloSpend sync service. Synced content includes accounts, categories, budgets, budget allocations, transactions, recurring records, and selected durable preferences such as currency, theme, language, reminder timing, display name, onboarding state, and home layout.
The sync service also handles your Firebase user identifier, email and verification state, an app-generated device identifier, record identifiers and versions, deletion markers, sync timestamps, status, and error information. These details are used to authenticate requests, merge changes, resolve conflicts, restore data, prevent duplicate operations, and protect the service.
Receipt Scanning and Camera
The camera permission is requested only when you use the receipt scanner. Camera frames are processed with Google ML Kit text recognition on the device to suggest receipt details; VeloSpend does not save or upload receipt images. Recognised text is not sent to the VeloSpend service unless you save relevant details in a transaction and cloud sync is enabled. Always review scanned results before saving.
Notifications
With your permission, VeloSpend schedules local notifications for budgets, bills, recurring transactions, and spending reminders. You can change reminder settings in the app or disable notification permission in Android settings.
VeloSpend Pro and Google Play
VeloSpend offers optional subscriptions through Google Play. Google handles payment credentials and checkout. VeloSpend does not receive your full card or bank details.
To verify and restore Pro access, the app and VeloSpend service process the Google Play product and base-plan identifiers, purchase token, purchase-token hash, order identifier when available, subscription status, renewal state, expiry time, and verification timestamps, associated with your VeloSpend account. Google Play may provide real-time subscription status notifications to the service.
Backups and Exports
You can create an explicit local backup, and Pro users can export transaction data to CSV. You choose where these files are saved or shared. They may contain financial information and are outside VeloSpend's control after export. Deleting app or cloud data does not delete copies you previously exported.
How Information Is Used
- to calculate balances, budgets, reports, reminders, and on-device forecasts;
- to provide sign-in, email verification, cloud sync, recovery, and account deletion;
- to verify and restore Pro subscription access;
- to maintain security, diagnose errors, prevent abuse, and operate the service; and
- to respond to support and privacy requests.
VeloSpend does not sell personal information and does not show advertising. Advertising identifiers and ad-personalisation signals are disabled in the app's Firebase configuration.
Analytics, Crash Reporting, and Performance
Release builds use Google Analytics for Firebase, Firebase Crashlytics, and Firebase Performance Monitoring to understand feature reliability and improve the app. Debug builds keep this collection disabled by default so development activity does not pollute production reporting.
- Analytics records app lifecycle events, Compose screen names, and limited operational events such as whether a cloud-sync attempt succeeded. It may also process an app-instance identifier and device, app, language, region, and general usage information.
- Crashlytics processes crash, non-fatal error, and application-not-responding diagnostics, including stack traces and relevant app, operating-system, and device state.
- Performance Monitoring measures app startup, screen rendering, selected internal operations, and network request timing, response size, and status. Network monitoring can include the requested host and path but excludes URL query parameters and request or response bodies.
VeloSpend's custom telemetry is deliberately limited to operational metadata. It does not add financial amounts or balances, transaction or receipt text, account or category names, email addresses, Firebase user identifiers, or Google Play purchase tokens to analytics events, performance traces, or Crashlytics custom fields.
Service Providers and Disclosure
Information is shared only as needed to provide the functions you choose:
- Google Firebase for account creation and sign-in, product analytics, crash and ANR diagnostics, and app and network performance monitoring;
- Google Play for subscription checkout, status, and entitlement verification;
- Google ML Kit for on-device receipt text recognition; and
- VeloSpend hosting and infrastructure providers for the authenticated sync service, database, security, and operational logs.
Providers may process information in countries other than yours under their own terms and legal obligations. We may also disclose information when required by law, to protect users or the service, or as part of a business reorganisation subject to appropriate safeguards.
Retention and Deletion
Local data remains on your device until you delete it, reset the app, uninstall the app, or replace it through restore. Synced content remains while your account is active unless you delete records, reset synced data, delete your account, or request deletion.
Limited deletion markers, device-sync state, security logs, and backup copies may be retained for a reasonable period for sync integrity, fraud prevention, disaster recovery, legal compliance, or dispute handling. When no longer needed, this information is deleted or de-identified according to operational retention settings and applicable law.
Firebase analytics and diagnostic information is retained according to VeloSpend's Firebase settings and Google's service-specific retention practices. See Firebase Privacy and Security for current service details.
For step-by-step choices and what each option removes, see Data Deletion. Deleting a VeloSpend account does not cancel a Google Play subscription.
Security
VeloSpend uses HTTPS for cloud requests, Firebase tokens for authenticated service access, encrypted Android storage for the optional app PIN, and server-side verification for Pro entitlements. No system can guarantee absolute security. Protect your device, email, Google account, exported files, and backup files.
Your Choices and Rights
You can use guest mode, decline camera or notification permission, choose whether to create an account, edit or delete records, export or back up data, reset synced data, and delete your account. Depending on your location, you may also have rights to request access, correction, deletion, restriction, portability, or objection.
To make a privacy request, email support@velospend.app from the address associated with your account. We may need to verify account ownership before acting on a request.
Children
VeloSpend is not directed to children who cannot legally consent to use an online account in their location. If you believe a child provided personal information without appropriate permission, contact us.
Changes to This Policy
We may update this policy as the app, service providers, or legal requirements change. The updated date will appear at the top of this page. Material changes may also be communicated in the app or through another appropriate channel.
Contact
Questions or privacy requests can be sent to support@velospend.app.