Permissions & Data Use

Effective 28 September 2026

ExpenT asks only for capabilities supporting visible user features. Optional access can be declined or revoked in Android Settings.

Incoming SMS — optional

Detects new bank-debit, sent-payment, refund, and reversal alerts. ExpenT presents its own disclosure before Android requests access. Processing occurs on the device and non-matching messages are discarded. Manual entry works without this permission.

Notifications — recommended

Shows classification questions, reminders, and capture status. Turning notifications off does not delete the ledger.

Notification access — optional

Off by default. If enabled after a separate disclosure, ExpenT examines new visible notifications from only the WhatsApp or email apps selected by the user. ExpenT does not sign in or read historical inboxes, chats, or emails.

Camera — when requested

Photographs, crops, locally auto-reads, and attaches a receipt chosen by the user. ExpenT does not activate the camera in the background.

Photos and files — user selected

Android system pickers and the share sheet are used to select, locally auto-read, and attach receipt images, save exports, and choose where to save or open backups. ExpenT does not request broad all-files access.

Encrypted backups and reminders

New .expent backups are encrypted on the phone with a user-chosen password before Android writes the file to a selected provider. ExpenT does not store or transmit the password and cannot recover it. Optional reminders ask the user to create a backup; they do not upload files automatically or grant cloud-account access.

On-device receipt text recognition

Google ML Kit's Latin-script model is bundled in ExpenT and runs on the phone to suggest amount, merchant, date, reference, and payment mode. ExpenT does not upload the receipt or recognized text. The user reviews and may edit every suggestion before saving.

Start after reboot

Restores reminders for expenses still requiring classification. It does not upload data.

Internet

The alpha Play build uses Internet access only when the tester opens its device-authenticated feedback portal and submits feedback. The service receives a pseudonymous installation identifier and public key for secure handoff, plus only the feedback the tester chooses to provide. It does not receive the ledger, SMS or notification text, receipts, profile, exports, or backups. This release has no advertising, analytics, remote logging, online account, or cloud ledger synchronisation.

Questions: expentsupport@aceaum.com.