QuantumCreations Privacy ExpenseFlow

Privacy Policy for ExpenseFlow

Last updated: 9 May 2026 Effective date: 9 May 2026

Permanent URL: quantumcreations.in/privacy/expenseflow

Parent / umbrella policy: quantumcreations.in/privacy  (See the parent page for our website's general privacy practices and policies for our other apps.)

This Privacy Policy is specific to the ExpenseFlow mobile application and supersedes the general QuantumCreations privacy policy where the two differ. For privacy practices that aren't ExpenseFlow-specific (e.g. the QuantumCreations website itself, marketing pages, or other apps from us), please see the parent privacy policy.

It explains how QuantumCreations ("we", "us", "our") collects, uses, stores, shares, and protects your information when you use the ExpenseFlow mobile application and related services (collectively, the "Service"). It applies to the Android app published as in.quantumcreations.expenseflow.

We designed ExpenseFlow to be privacy-respecting by default. We collect the minimum data needed to make the app work, we never sell your data, and we give you tools to export and delete everything any time.

If you have questions about this policy, contact us at Quantumcreations.in@gmail.com.

1. Who we are

Data controllerQuantumCreations
Registered jurisdictionIndia
Websitequantumcreations.in
Privacy contactQuantumcreations.in@gmail.com
Grievance contactQuantumcreations.in@gmail.com

For users in the European Economic Area (EEA), United Kingdom, California (USA), or India, we are the controller of your personal data under the GDPR, UK GDPR, CCPA/CPRA, and DPDPA respectively.

2. What data we collect

2.1 Account data (when you sign in)

2.2 Financial data you enter

We never collect or have access to:

If you import a bank statement (PDF or CSV), the parsing happens on your device — the raw file is never uploaded. Only the extracted transaction descriptions and amounts are saved.

2.3 Usage, device, and diagnostics

We do not use a third-party behavioral analytics SDK for the v1.0 India launch.

2.4 AI interaction data (Pro users only)

We use Google Gemini as our AI provider. For AI features, we send only the minimum context needed for the specific request, such as your question, income, monthly spend, safe-to-spend amount, and top category totals. Raw imported bank statement files and full transaction history are not sent to Gemini. Server AI logs store token/cost metadata with prompt and response bodies redacted wherever our backend logging is used.

2.5 Advertising data

2.6 Data we do not collect

ExpenseFlow does not collect precise location, background location, contacts, SMS, call logs, calendar events, health data, or advertising ID in the v1.0 India launch.

3. How we collect data

SourceWhat we get
Directly from youEverything you type into the app: expenses, categories, income, goals
Authentication providers (Google, Apple)Email, name, profile photo URL (only with your consent during sign-in)
Your deviceApp version, OS version, push token if enabled, local app settings
Bank statements you importTransaction text and amounts, parsed locally on your device

We do not collect data from third-party data brokers, social media scraping, or hidden tracking SDKs.

4. Why we use your data (legal bases)

PurposeLegal basis (GDPR / UK GDPR)Equivalent under CCPA / DPDPA
Provide the Service (sync expenses across devices, run AI categorization, render dashboards)Performance of contract (Art. 6(1)(b))Necessary to provide the Service
Maintain account security, prevent abuseLegitimate interest (Art. 6(1)(f))Security
Improve the app (local usage counters and support diagnostics)Legitimate interest (Art. 6(1)(f))Improvement, with right to opt out where applicable
Personalize features for Pro usersPerformance of contractNecessary to provide the Service
Send service notifications (subscription expiring, security alerts)Performance of contractNecessary to provide the Service
Marketing emailsConsent (Art. 6(1)(a))Opt-in only
Comply with lawLegal obligation (Art. 6(1)(c))Compliance

We rely on legitimate interest only for purposes that we have weighed against your reasonable expectations. You can object to legitimate-interest processing at any time using the contacts in §11.

5. Who we share data with

We share only the minimum with these processors, each bound by a Data Processing Agreement:

ProcessorPurposeLocationData shared
Supabase Inc.Database hosting, authentication, real-time syncUSA, with EU/AP regions for our projectAll app data
Google Cloud (Gemini API)AI categorization, Smart Insights, Forecast, and AI Coach responses (Pro only)USA, EU, APPrompt content + minimal financial context
Google Firebase Cloud MessagingPush notificationsGlobalDevice push token and notification delivery metadata
Google Play BillingAndroid subscription purchase processingGlobalPurchase and subscription data handled by Google Play
Google AdMobDisabled for v1.0 launchGlobalNo data while the ad launch flag remains off
RevenueCat Inc.Subscription managementUSAPseudonymous user ID + subscription state

We do not sell or rent personal data. We do not engage in cross-context behavioral advertising.

If you are part of a shared group within the app (family, roommates, trip), other members of that group can see the expenses you share with the group, your display name, and your share/balance amounts. They cannot see your personal expenses outside the group.

6. International transfers

Your data is stored on servers operated by Supabase. Depending on your project region, this may be in the United States, the European Union, or the Asia-Pacific region. When data leaves your region of residence, we rely on:

You can request the SCCs we have in place by emailing Quantumcreations.in@gmail.com.

7. How long we keep your data

DataRetention
Your account and financial dataUntil you delete it or request account deletion. Verified deletion requests are usually processed within 7 working days; backup copies expire within 30 days after deletion.
AI prompts/responsesProcessed to answer your request. The primary Edge Function does not store prompt/response bodies; backend fallback chat sessions, if used, remain until account deletion unless removed earlier.
AI token/cost/quota metadataUp to 24 months
Crash reports30 days if crash reporting is enabled in a future release
Subscription receipts7 years (tax law requirement)
Local/anonymized usage counters24 months

You can delete individual expenses, categories, or your entire account at any time in More → Profile & Account → Delete Account, or request deletion at https://quantumcreations.in/expenseflow/delete_account. Deletion is permanent. We acknowledge email deletion requests within 72 hours, usually process verified deletion requests within 7 working days, and backup copies expire within 30 days after deletion.

8. How we secure your data

ExpenseFlow is not end-to-end encrypted. Your data is encrypted in transit, encrypted at rest, and access-controlled, but our server-side systems and trusted infrastructure providers process readable data when needed for sync, family sharing, AI features, support, security, and legal compliance.

In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours, in line with GDPR Art. 33–34 and DPDPA equivalents.

9. Your rights

Wherever you live, you have these rights over your personal data:

RightWhat it meansHow to exercise
AccessGet a copy of all data we hold about youMore → Export CSV, or email Quantumcreations.in@gmail.com
CorrectionFix inaccurate dataEdit in-app, or email Quantumcreations.in@gmail.com
DeletionErase your account and dataMore → Profile & Account → Delete Account
PortabilityGet your data in a machine-readable format (CSV)More → Export CSV
RestrictionPause processing in specific casesEmail Quantumcreations.in@gmail.com
ObjectionObject to processing based on legitimate interestEmail Quantumcreations.in@gmail.com
Withdraw consentFor processing that relies on consentToggles in Settings, or email Quantumcreations.in@gmail.com

Additional rights for specific regions:

We acknowledge privacy and grievance requests within 72 hours and respond to verified rights requests within 30 calendar days (sometimes extended to 60 days for complex requests, with notice). Verified account deletion requests are usually completed within 7 working days, with backup copies expiring within 30 days after deletion.

10. Children

ExpenseFlow is not intended for children under 13 (under 16 in the EEA, under 18 in India for non-essential processing). We do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.

11. Contact us

For California residents, you may designate an authorized agent to make CCPA requests on your behalf. We will verify their authority before responding.

12. Changes to this policy

We may update this policy as the Service evolves or laws change. When we do, we will:

  1. Update the "Last updated" date at the top
  2. Show an in-app banner for material changes
  3. Email you at least 30 days in advance for material changes affecting your rights
  4. Keep prior versions accessible at https://quantumcreations.in/privacy/expenseflow/archive

Continued use of the Service after a change means you accept the updated policy. If you don't agree, you can delete your account before the effective date.

13. Supervisory authorities

If you believe we have violated your rights, you can complain to:

We would, of course, prefer the chance to resolve your concern first — please reach out to Quantumcreations.in@gmail.com before escalating.

This policy was drafted in plain English and is the authoritative version. If you read a translation, the English version controls in the event of any discrepancy.