← Back to Track Daily Expense
Privacy Policy
Last updated: August 19, 2026
Overview
Track Daily Expense ("the App", "we", "us") is a personal finance app that helps
you record and analyze your income and expenses. The App stores your financial data
in your own Google Sheets, inside your own Google Drive. This policy
explains what data the App accesses, how it is used, and the choices you have.
Information We Access
When you sign in with Google, the App requests only the access it needs to function:
- Basic Google profile (name, email address, profile picture) — to
sign you in and show which account you are using.
- Google Drive & Sheets — per-file access only
(
.../auth/drive.file) — to create, open, read, update, and delete only the
App's own spreadsheets (your expense books and settings) and receipt files, plus any
spreadsheet you explicitly pick. This single per-file scope covers both managing those
files and reading and writing the expense data inside them through the Google Sheets API.
The App can access only files it created or that you specifically opened with it.
It does not list, read, or use your unrelated Google Drive files, and it does not request
access to your other Google Sheets.
Google API Services User Data Policy — Limited Use
Track Daily Expense's use and transfer of information received from Google APIs to
any other app will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements.
In particular:
- We only use Google user data to provide and improve the App's user-facing features.
- We do not transfer or sell this data to third parties, except as needed to operate
the App, comply with law, or as part of a merger you are notified of.
- We do not use Google user data for advertising.
- We do not allow humans to read your data, unless we have your consent for a specific
support issue, it is required for security or to comply with law, or the data is
aggregated and anonymized.
Where Your Data Is Stored
- Your expense records and settings live exclusively in Google Sheets in your
own Google Drive. You can open, edit, or delete them directly in Google Sheets
at any time.
- Receipt images (if you attach them) are stored as files in your own Google Drive.
- We do not store your expense data, receipts, or spreadsheet contents
on our servers.
What We Do Store
To authenticate you and operate features across sessions and devices, the App stores the
following limited information on Google Firebase:
- An OAuth refresh token encrypted using AES-256-GCM, held in Cloud
Firestore and handled only by our server-side Cloud Functions. It is used solely to obtain
short-lived access tokens for the Google Sheets and Drive features you authorize.
- Your Google account identifier, email address, and display name, used to associate the
token and App features with the correct account.
- Identifiers for the App's Drive folder and spreadsheets, used to reconnect you to the
correct App-created or user-selected files without searching your Drive.
- If you use spreadsheet sharing or notifications: the sender and recipient email
addresses, spreadsheet identifier and name, notification status, device identifier, and
push-notification token needed to deliver and display those notifications.
- We never store your Google password.
Data Security
We take the protection of your information seriously and apply the following safeguards to your
sensitive data:
- Encryption in transit — all communication between the App, Google's APIs,
and our services uses HTTPS/TLS, so your data is encrypted while travelling over the network.
- Encryption at rest — OAuth refresh tokens are encrypted with AES-256-GCM
before they are written to Cloud Firestore. The encryption key is stored separately using
Google Cloud's secret-management controls. Google Cloud also encrypts stored data at rest.
- Restricted access — refresh tokens are handled only by authenticated,
server-side Cloud Functions. Firestore security rules deny all client read and write access
to token documents, so tokens are not exposed to the browser, mobile client, or other users.
- Principle of least privilege — the App requests only the single
narrowest data scope it needs:
.../auth/drive.file (per-file access), rather
than full Google Drive or full Google Sheets access. This scope is limited to spreadsheets
the App creates and spreadsheets you explicitly select, open, or share through the App; the
App reads and writes their contents via the Google Sheets API, which supports this per-file
scope.
- Your data stays in your account — your expense records and receipt images
remain in your own Google Drive and Google Sheets, protected by Google's own account security;
we do not copy them to our servers.
- No human access — we do not allow humans to read your Google user data
except with your consent for a specific support issue, where required for security, or to
comply with applicable law.
No storage or transmission system can be guaranteed to be completely secure. We regularly
review these safeguards and limit the information we retain to what is needed to operate the App.
How We Use Information
Information is used only to operate the App: to authenticate you, to read and write your
expenses in your spreadsheets, to keep you signed in, and to display your data back to you.
We do not use your Google Sheets or Drive data for advertising or analytics.
Service Providers
We use Google Cloud and Firebase to provide authentication, server-side token handling,
encrypted storage, notifications, hosting, and crash reporting. These providers process
information only to supply those services on our behalf and are subject to their applicable
security and data-protection terms. We do not sell Google user data.
Advertising
The mobile App may display ads via Google AdMob. AdMob may collect device identifiers and
usage data to serve and measure ads. This is independent of your Google Sheets/Drive data,
which is never used for advertising. You can control ad personalization in your device and
Google account settings.
Analytics & Crash Reporting
We use Google Firebase, including Crashlytics on supported platforms, to record crashes and
diagnostic information such as App version, device or operating-system information, and crash
details so we can improve stability. We do not intentionally include your expense records,
receipt contents, or spreadsheet contents in crash reports.
Cookies & Local Storage
On the web, the App uses browser local storage to retain an installation identifier,
preferences, file references, and a short-lived Google access token and its expiration time.
This information stays on your device. Authentication data is cleared or replaced when it
expires or when you sign out; preferences and other local data remain until the App removes
them or you clear the browser's site data.
Data Retention & Deletion
You are in control of your data at all times. You can:
- Sign out in the App — this asks Google to revoke the refresh token for
that device, deletes the corresponding stored token from our servers, removes that device's
push token, and clears the local authentication session.
- Revoke the App's access at
myaccount.google.com/permissions.
- Delete your data by removing the App's spreadsheets and receipt files
from your Google Drive.
- Automatic token deletion — stored refresh tokens and push tokens that
have not been used for 60 days are automatically deleted from our infrastructure.
- Operational metadata — App file identifiers are retained while needed
to reconnect your account to its spreadsheets. Sharing notifications remain until you
dismiss them or request their deletion.
- Request deletion of remaining App metadata, such as stored file
identifiers or sharing notifications, by contacting us at the address below. We will verify
the request and delete information we are not legally required to retain.
Children's Privacy
The App is not directed to children under 13, and we do not knowingly collect personal
information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected
here with a new "Last updated" date.
Contact
If you have any questions about this Privacy Policy or your data, contact us at
trackdailyexpense@gmail.com.