SpendNivo
Privacy Policy
Effective Date: June 10, 2026
Last Updated: June 10, 2026
At SpendNivo (developed by Invention Hill, referred to as \"we,\" \"us,\" or \"our\"), we respect your privacy and are committed to protecting your personal and financial data. This Privacy Policy describes how we collect, use, store, process, and share your information when you use our mobile application (the \"Application\") and its related services.
Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we treat it. By downloading, accessing, or using SpendNivo, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
We collect information to provide a seamless, secure, and personalized financial tracking experience. The types of data we collect include:
A. Personal Information
- Account Credentials: When you sign in to SpendNivo, we collect information provided by your authentication provider:
- Google Sign-In: Full name, email address, profile picture URL, and Google ID.
- Sign in with Apple: Name, email address, and unique user identifier.
- Telegram Authentication: Phone number, username, and Telegram ID (processed securely via our bot
@SpendNivoAuthBot).
- Contact Information: Email address and phone number for account verification, support, and billing queries.
B. Financial and Transaction Data
- Ledger Records: Income and expense values, account details (e.g., cash, bank accounts, cards), categories, notes, transaction dates, and times.
- Relationships and Splitting: Information regarding transacting parties (payees/relationships) for shared expenses and lending/borrowing tracking.
- Recurring Transactions: Scheduled rules and triggers configured by you to automate future logs.
C. Device and Usage Information
- System Metadata: Device type, operating system version, unique device identifiers, and local settings (e.g., language and regional settings).
- Analytics and Performance Log: Crash logs, load times, and diagnostic statistics captured via Firebase Crashlytics to monitor application performance and resolve bugs.
D. Device Permissions
To enable advanced features, the Application may request permission to access:
- Camera and Gallery (Photos): To allow you to take photos or upload images of physical receipts/bills to attach to transactions.
- Biometric Lock (FaceID/TouchID/Fingerprint): To secure your ledger data locally. Biometric data is handled entirely by your device's operating system (via local authentication APIs) and is never transmitted to or stored on our servers.
- Speech Recognition / Microphone: To allow voice transcribing of expenses. Voice recordings are processed by native speech-to-text engines and are not uploaded or stored as raw audio files.
- Notifications: To deliver transaction alerts, backup reminders, and system updates.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and Maintain the Service: To manage your account, authenticate your sessions, sync data across devices, and record transactions.
- Enable Sync and Cloud Backups: To backup your financial data securely to the cloud (using Firebase Firestore/Storage) or to your own Google Drive (if enabled).
- Process Payments and Subscriptions: To handle transactions and verify premium memberships (SpendNivo Pro) via RevenueCat.
- Improve the Application: To analyze diagnostics, debug issues, optimize performance, and design new financial intelligence features.
- Customer Support: To respond to your inquiries, support tickets, and resolve account issues.
- Security and Fraud Prevention: To verify phone numbers via Telegram or WhatsApp proxies, ensuring secure access to your financial information.
3. Storage and Security of Data
Your privacy is paramount, and we employ industry-standard safety practices to protect your data.
- Local Storage: On-device financial records are stored securely using local key-value databases (Hive) and encrypted secure storage (
flutter_secure_storage) for sensitive keys.
- Cloud Sync: Cloud database records are hosted on Firebase (Google Cloud) using robust rules and access permissions to ensure that only authenticated owners can access their respective workspaces.
- Google Drive Backups: If you choose to enable the Google Drive backup option, the encrypted ledger files are stored directly inside your personal Google Drive account. We do not access, view, or modify any other files in your Google Drive.
- Encryption: Communication between the Application, Firebase services, and third-party APIs is encrypted using secure Transport Layer Security (TLS/HTTPS).
4. Sharing Your Information
We do not sell, trade, or rent your personal or financial data to third parties. We share information only with trusted service providers to run the application:
- Firebase (Google LLC): For authentication, hosting, cloud functions, storage, and crash reporting (Firebase Crashlytics).
- RevenueCat Inc.: For in-app purchase validation and subscription lifecycle management.
- WhatsApp Cloud API / Telegram Webhooks: Used strictly for sending verification codes (OTPs) and connecting contact profiles for login verification.
We may also disclose information if required to do so by law, to enforce our terms, or to protect the safety and security of our users and the public.
5. Data Retention and Deletion
We keep your data as long as your account remains active or as needed to provide the services.
- Account Deletion: You can permanently delete your account and purge all your personal and financial history at any time. Inside the Application, navigate to:
Settings > Profile > Delete Account
- Purge Process: Upon initiating account deletion, all personal data, transaction history, attached receipts, and workspaces stored in our cloud database (Firebase) will be permanently and irreversibly deleted.
6. Children's Privacy
Our Application does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If we discover that a child under 13 has provided us with personal information, we immediately delete this from our servers.
7. Your Legal Rights (GDPR, CCPA, and DPDP Act)
Depending on your jurisdiction (such as the European Union under GDPR, California under CCPA, or India under the DPDP Act), you may have the following rights:
- The right to access and receive a copy of your personal data.
- The right to request correction of inaccurate data.
- The right to request the erasure of your data.
- The right to withdraw consent at any time where we rely on consent to process your information.
To exercise any of these rights, please contact us at the support details provided below.
8. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top of this document. We encourage you to review this Privacy Policy periodically for any changes.
9. Contact Us
If you have any questions or suggestions about this Privacy Policy, please contact us at: