Privacy Policy
How we handle your data and protect your privacy
Last updated: July 28, 2026
Spenrol ("the app", "we", "us") is a personal expense-tracking app that helps you plan spending against a monthly budget you set yourself. Spenrol is developed and operated by Shreyash Mogaveera, an individual developer (not a registered company). This policy explains what data is collected, how it's used, and how you can control it.
Spenrol does not process, hold, or move your money in any way. All amounts in the app are figures you enter yourself to track a budget — the app has no payment or fund-transfer functionality.
Phone number
Your account identifier; used to log in via a one-time password (OTP)
OTP delivery records
Temporary, hashed OTP codes and the IP address of the request, kept briefly to verify login attempts and prevent abuse (e.g. rate-limiting repeated requests)
Profile details
Your full name and date of birth, which are required to finish setting up your account. Email, avatar selection, monthly income band, and occupation type are optional and only collected if you choose to fill them in. Preferred currency defaults to INR unless you change it
Budget & category data
The monthly budgets and spending categories you create
Transaction data
The description, amount, and category of expenses you log, plus — if you use split-bill — the number of people and your share
Spend-intent tags
If you label a confirmed transaction as impulsive, optional, or required, so the app can show you spending patterns (e.g. your Smart Spending Score)
Screenshot import (optional)
If you share a payment screenshot into the app, the image is processed on-device using on-device text recognition to pre-fill a transaction draft for your review before you save it. The screenshot itself is not uploaded to or stored on our servers
Push notification token
Used to send you budget alerts (e.g. nearing a category limit) if you enable notifications
Session/device data
A hashed session (refresh) token and the User-Agent string your device sends with requests, used to keep you logged in securely. If we detect suspicious activity (such as a reused or replayed session token), we may automatically end your other active sessions to protect your account
Crash & usage diagnostics
Crash reports and coarse usage metrics (via Sentry) to help us find and fix bugs
We do not collect your UPI PIN, bank account number, card details, or government ID — the app has no code path that asks for or stores any of these.
- To operate your account (OTP login, session management) and keep your budgets/transactions in sync across sessions.
- To enforce budget rules you've configured (e.g. flagging overspend at planning time) and send optional alerts (near-limit, monthly reset, daily summary) if you've turned them on.
- To calculate your Smart Spending Score and category breakdowns from the intent tags and transactions you log.
- To prevent abuse of the OTP login flow (rate-limiting, fraud detection).
- To diagnose crashes and bugs from real usage.
We do not use your data for advertising, and we do not sell it.
We do not share your personal data with third parties, except:
- Service providers that host our infrastructure or support core features — currently: our backend hosting/database provider, our SMS provider (to deliver OTP codes), Expo (to deliver push notifications, using your push token), and Sentry (crash/error monitoring). These providers only receive what's needed to run the service and are not permitted to use it for their own purposes.
- Legal requirements, if we're required to disclose data to comply with the law.
Your data is retained as long as your account is active. OTP request records are purged automatically shortly after they expire.
You can permanently delete your account at any time from Settings → Delete Account inside the app. This immediately and irreversibly deletes your profile, budgets, categories, and transaction history from our servers — there is no recovery period. If you no longer have the app installed, you can request the same deletion by emailing us (see Section 8); we'll delete your data within a reasonable time after verifying the request. See spenrol.com/delete-account for details.
You can access, correct, or delete your profile information from within the app, edit or delete individual transactions at any time, and permanently delete your entire account and all associated data as described in Section 4. You can also request a copy of your data by contacting us. If you're in India, this includes the rights available to you under the Digital Personal Data Protection Act, 2023.
Session tokens are hashed at rest, OTPs are hashed and short-lived, all traffic between the app and our backend is encrypted (HTTPS), screenshot text-recognition runs on your device rather than on our servers, and access to your data requires an authenticated session.
Spenrol is not directed at children and is not intended for use by anyone under 18.
Questions about this policy, or requests to access, correct, or delete your data:
Shreyash Mogaveera
[email protected]We may update this policy as the app changes. Material changes will be reflected by updating the "Last updated" date above.