Privacy Policy
Effective date: July 13, 2026
ExpenseKeeper is built around a simple idea: your financial data never touches our servers’ storage. Every transaction, tag, budget and setting you create is written directly to a Google Sheet in your own Google Drive. ExpenseKeeper has no database and stores no user content.
Data we do not store
- Your transactions and settings. They live only in a spreadsheet in your Google Drive. When our servers relay a request to Google (e.g. to add a transaction), the data passes through in memory and is never written to disk or retained.
- Your Google account credentials. Sign-in happens with Google OAuth; we never see your password.
- OAuth tokens. The access and refresh tokens Google issues are stored only inside an encrypted session cookie in your browser, not on our servers. Signing out or clearing cookies removes them.
- Anything else in your Google Drive. We request the minimal
drive.filescope, which limits the app to the one spreadsheet it creates. It cannot see or touch any other file.
The only data we log
ExpenseKeeper runs no analytics, no trackers, and no advertising. The complete list of what is recorded is:
- Server error logs. When an API request fails, we log the route that failed (e.g.
GET /api/transactions) and the technical error message, so problems can be diagnosed. These logs do not include your transactions. - Standard infrastructure logs. The hosting provider that serves the app may record basic request metadata (such as IP address, timestamp and requested URL) as part of ordinary operation, per its own retention policy.
That is the entire list.
Data we access but do not keep
- Basic Google profile. Your name, email address and profile picture are read from Google to display who is signed in. They are held in your session cookie only, never stored server-side.
- Spreadsheet contents. Read and written on your behalf solely to show and update your data in the app, in the moment you request it.
Cookies and local storage
We use a single encrypted session cookie to keep you signed in. The app is also installable as a PWA and may cache pages and assets on your device so it can load offline. All of this stays on your device and can be cleared through your browser.
Google API Services disclosure
ExpenseKeeper’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide the app’s user-facing features and is never sold, shared, or used for advertising.
Revoking access & deleting data
- Revoke ExpenseKeeper’s access at any time from your Google Account permissions.
- Delete all of your data by deleting the ExpenseKeeper spreadsheet from your Google Drive. Because we store nothing, there is nothing further to delete on our side.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new effective date.
Contact
For questions about this policy, contact contact@abishekmosesraj.com.