Privacy Policy — Vaultsum
Last updated: 27 September 2026
Vaultsum is a personal expense tracker for Android. It is built to keep your financial data on your phone. This policy explains what the app handles, where it goes, and how to delete it.
Contact and grievance officer: Manthan Bhatt, vaultsum.app@gmail.com. This covers questions, complaints, and requests to access, correct or erase your data, including under India's Digital Personal Data Protection Act, 2023. We reply within 30 days.
1. Your personal finances stay on your phone
Your accounts, transactions, categories, tags, budgets, scheduled entries, attachments and settings are stored only on your device.
- The database is encrypted (SQLCipher, AES-256). Its key is generated on the device and protected by the Android Keystore.
- This data is never uploaded to us or to anyone else. There is no cloud sync.
- Android's automatic cloud backup is turned off for this app.
- Backups happen only when you export a file yourself, or when you turn on automatic backup and pick a folder. You choose where they go. Automatic backups are always encrypted with your passphrase (AES-256-GCM); if the folder is synced by a cloud app, that app uploads the encrypted file. We never receive it.
- Attachment files you add are encrypted on the device as well.
- The app contains no analytics, advertising, tracking or crash-reporting SDKs.
2. Exchange rates (internet use)
Once a day the app downloads public currency exchange rates from open.er-api.com. The
request contains only your base currency code (for example INR). It never contains
any of your financial data.
3. Transaction detection from notifications (optional, off by default)
If you turn on Notification detection and grant notification access, the app reads notifications only from the apps you switch on. These are Google Pay, PhonePe and Paytm, plus bank SMS (SBI, ICICI, HDFC, Axis, Kotak, Bank of Baroda, PNB, YES BANK and IDFC FIRST) as shown by Google Messages, Samsung Messages or Truecaller. The app ignores every other notification without reading it.
From the notifications it does read, the app extracts the amount, the merchant or sender, and whether money went in or out. It then suggests a transaction for you to review. Nothing is saved until you confirm it. Detection runs entirely on your phone and nothing is sent anywhere. The app does not request the SMS permission.
You can revoke access at any time in Android Settings → Notification access.
4. Groups — shared expenses (optional, uses the cloud)
Groups is the only feature that stores data online. It runs on Google Firebase (Authentication, Cloud Firestore and Cloud Messaging), operated by Google. Nothing is sent until you open Groups and sign in. You are asked to confirm before you create or join a group.
When you use Groups, the following is stored in Firebase:
| Data | Why |
|---|---|
| Your Google account email and name (if you sign in with Google) | Sign-in, and matching invites sent to your email |
| Your phone number (if you signed in with a phone number in an earlier version) | Sign-in (one-time code by SMS) and matching invites to you |
| Display name and optional UPI ID | Shown to members of your groups; the UPI ID pre-fills payments when someone settles up with you |
| Groups you create or join: name, currency, members | To run the group |
| Shared expenses and settlements: description, amount, who paid, the split | To work out who owes whom |
| Invites you send: the invitee's phone number or email address | So that person can join |
| Push-notification tokens for your device | To tell you about new group activity (the notification text never contains amounts or names) |
This data is visible only to the members of the group concerned. Access is enforced by server-side security rules. It is encrypted in transit (TLS) and at rest by Google. Settle up never moves money. It opens your own UPI app with the details filled in.
If you invite someone, you share their phone number or email address with us so that they can join. Please invite only people who expect it.
Google's own handling of this data is described at https://firebase.google.com/support/privacy.
5. Permissions
| Permission | Used for |
|---|---|
| Internet, network state | The daily exchange-rate download; Groups |
| Notifications | Reminders for scheduled entries; the "transactions detected" alert; Groups activity |
| Exact alarms | Reminders at the time you set |
| Run at startup | Re-arming reminders after a reboot |
| Biometric / screen lock | The optional app lock |
| Notification access (special access, which you grant in system settings) | Transaction detection (section 3) |
6. Deleting your data
- Personal data: Settings → Clear all data, or uninstall the app. Both erase it permanently from the device. We hold no copy.
- Groups account: Groups → Profile → Delete Groups account deletes your profile, UPI ID, device tokens and sign-in. Expenses and settlements you added to shared groups stay visible to the other members, together with your name and phone number, so their balances still add up. To have those removed too, email vaultsum.app@gmail.com from any device, giving the phone number or Google email you signed in with. We will act on it within 30 days.
7. Children
The app is meant for adults. It is not directed at anyone under 18, and Groups should not be used by them.
8. Changes
Changes to this policy are posted at this address, with the date updated at the top.