Privacy Policy for Xpenote
Last updated: 2026-06-23
1. Introduction
Xpenote (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains what information the Xpenote mobile application (“App”) collects, how it is used and shared, and the choices you have.
Xpenote is local-first: you can use the App as a guest, with your data stored only on your device. If you choose to create an account, your data is also stored on our cloud backend so it can sync across your devices. Some features (the AI assistant and document import) send data to third-party AI providers for processing. Free and guest users are also shown ads provided by Google AdMob; Xpenote Pro subscribers see no ads. The details are below.
2. Information We Collect
If you use the App as a guest (no account):
- Your goals, expenses, budgets, participants (including any names and phone numbers you enter), splits, and preferences are stored on your device in a private database. We do not receive them. (If you have Android's system backup turned on, your device may include this data in your own Google account backup — see Section 11.)
If you create an account or sign in (optional):
- Account information: your email address, and — if you sign in with Google — the basic profile information in your Google ID token (email, Google account ID, and name). You may also provide a display name and phone number.
- Your financial data: goals, expenses, amounts, budgets, currencies, categories, participants (including names and phone numbers you enter for other people), and splits. This data is uploaded to our cloud backend and linked to your account so it can sync across devices.
- Subscription information: if you purchase Xpenote Pro, Google Play provides us with a purchase token and order identifier so we can verify and activate your subscription. We do not receive your full payment card details.
When you use AI features (optional):
- Chat messages and context: the text you type and the relevant goal/expense context for your request.
- Imported documents: images and PDFs of bills, receipts, or statements that you choose to import. CSV files you import are parsed on your device and are not sent to AI providers.
When you are shown ads (free and guest users only — Pro removes ads):
- Our advertising partner, Google AdMob, collects your device's advertising ID and certain device and usage information in order to serve and measure ads (including, where permitted, personalized ads). We do not provide the financial data you enter (your expenses, goals, participants, or messages) to AdMob. See Sections 6 and 7.
3. How We Use Your Information
We use your information to:
- provide core expense-tracking and split-calculation features;
- sync your data across your devices when you are signed in;
- process your AI chat requests and extract expense details from documents you import;
- activate Xpenote Pro subscriptions;
- show and measure ads for free and guest users (Xpenote Pro removes all ads);
- maintain the security and reliability of the service.
We do not sell your personal information, and we do not share the financial data you enter (goals, expenses, participants, or messages) with advertisers. Ad serving relies on your device's advertising ID and device data collected by the Google AdMob SDK — not on your expense records.
4. Cloud Accounts and Sync
Accounts and cloud sync are powered by Supabase (our backend provider). When you are signed in:
- your financial data is stored on Supabase servers and protected by per-user access controls (Row Level Security), so only your account can access your records;
- guest data created before sign-in is associated with your new account when you sign in;
- you can stop syncing by signing out; data already synced remains in your account until you delete it (see Section 10).
5. AI and Machine Learning
The App’s AI assistant and document-import features are powered by cloud AI models, not on-device models. When you use these features:
- your message (and relevant context), or the image/PDF you import, is sent over HTTPS to our inference service, which routes the request to a third-party AI provider — currently Groq, OpenRouter, and/or Together AI — to generate a response or extract expense details;
- if you configure your own provider API key in settings, requests are sent directly to that provider instead;
- we do not store your AI conversation history on our servers; it stays in your local database on your device and is not synced to the cloud;
- CSV imports are processed entirely on your device and are not sent to any AI provider.
Please avoid including highly sensitive information in chat messages or imported documents.
6. How We Share Information
We share data only with service providers that help us operate the App:
- Supabase — account authentication and cloud storage/sync of your data.
- Google — when you choose Google Sign-In (to authenticate you).
- AI providers (Groq, OpenRouter, Together AI) — to process AI chat and document-import requests.
- Google Play Billing — to process and verify subscription purchases.
- Google AdMob — to show and measure ads for free and guest users. AdMob receives your device's advertising ID and related device/usage data. Xpenote Pro subscribers are not shown ads.
These providers process data on our behalf or to provide the feature you requested. We do not share the personal or financial data you enter with advertisers.
7. Advertising and Your Choices
Free and guest users are shown ads served by Google AdMob. Xpenote Pro removes all ads.
- What AdMob collects. AdMob may use your device's advertising ID and device/usage data to show and measure ads, including (where permitted) personalized ads. AdMob's handling of this data is governed by Google's Privacy Policy and the AdMob/Google Ads disclosures.
- Rewarded ads are optional. In some places you can choose to watch a short ad to unlock extra AI messages or a document import. You are never required to watch an ad — Xpenote Pro provides these without ads.
- Banner ads appear at the bottom of the analytics screen for free and guest users.
- Your choices:
- Where required (e.g. the EEA, the UK, and other applicable regions), we show a consent prompt (Google's User Messaging Platform) before serving personalized ads, and you can decline.
- You can reset or delete your advertising ID, or opt out of ad personalization, in your device settings (Settings → Google → Ads).
- Subscribe to Xpenote Pro to remove ads entirely.
8. Exchange Rates
The App fetches public currency exchange rates from the Frankfurter API over HTTPS. These requests contain no user-identifying information.
9. Permissions
The App requests the following permissions solely for the stated purposes:
- INTERNET: sync your data, fetch exchange rates, use AI features, and load ads.
- POST_NOTIFICATIONS: show sync status and reminder notifications.
- VIBRATE: provide light haptic feedback during AI response streaming.
- AD_ID (com.google.android.gms.permission.AD_ID): access the device advertising ID so Google AdMob can serve and measure ads for free and guest users (added by the Google Mobile Ads SDK).
The App does not request location, contacts, camera, or storage permissions. When you import a document, you choose the file through the Android system picker; the App does not browse your files.
10. Data Retention and Deletion
- Guest data is stored only on your device. Uninstalling the App, or using Android Settings > Apps > Xpenote > Storage > Clear storage, removes it.
- Account data: you can delete your account and all associated cloud data at any time from within the App (Settings > Delete account). This permanently deletes your account and the goals, expenses, participants, splits, and profile associated with it from our servers, and clears the data from your device.
- You may also request account and data deletion by emailing support@xpenote.com, or via our web request page: https://xpenote.com/delete-account.
- We retain subscription/purchase records as required for accounting and to comply with Google Play and legal obligations.
11. Data Security
Data is encrypted in transit (HTTPS/TLS). Your cloud data is isolated per account using Row Level Security. On your device, the local database is protected by the Android application sandbox, and sensitive preferences (such as API keys) are stored in encrypted storage and excluded from device backups.
Device backups. If you have Android’s system backup (Backup by Google One) enabled, Android may include the App’s local database in your personal, Google-account-encrypted backup. This is a device feature controlled by you and your Google account — we have no access to it. You can disable it in your device’s backup settings. We recommend keeping your device’s OS and security patches up to date.
12. Children’s Privacy
The App is not directed to children under 13, and the ads we show are not directed to children. We do not knowingly collect personal information from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted in the App and on this page with an updated “Last updated” date.
14. Open-Source Software
Xpenote is built with open-source software, and we comply with the terms of each component's license. These libraries provide app functionality; they do not change what data we collect or how we use it as described above.
Notably, the app's user interface uses Haze (© Chris Banes and the Haze project contributors), licensed under the Apache License 2.0, to render visual blur effects. Other core components — including AndroidX, Jetpack Compose, and Material Components — are likewise distributed under the Apache License 2.0. A full list of the app's open-source components and their licenses is available in the app under Settings → Open-source licenses.
15. Contact Us
support@xpenote.com