FinTrack ("the App", "we", "our") is a personal finance tracking application for Android. It is developed as an independent project and is available on the Google Play Store.
We never collect any personal or financial data. Specifically, we do not collect:
The only data transmitted off your device is anonymous crash reports and usage statistics via Firebase (see Section 8).
All data you enter stays exclusively on your device in the following locations:
| What | Where | Purpose |
|---|---|---|
| Transactions, dues, balances | Local Room database (SQLite) | Core app functionality |
| Your name, preferred currency, opening balance | EncryptedSharedPreferences (AES-256, device storage) | Personalisation |
| PIN hash (PBKDF2-SHA256, 100 000 iterations) | EncryptedSharedPreferences (AES-256, device storage) | App lock security |
| App settings (reminders, auto-backup toggle, etc.) | EncryptedSharedPreferences (AES-256, device storage) | User preferences |
| Backup files (JSON) | External app-specific folder on your device | Manual & auto backup |
None of this data ever leaves your device unless you explicitly choose to share a backup file yourself.
This includes transactions, balances, settings, and security related data (including all user entered financial and app-related data) stored locally using Android storage mechanisms.
FinTrack can create a JSON backup file saved to your device's external storage
(Android/data/com.fintrack/files/backups/).
When you tap Share backup, your device's standard share sheet opens and you
choose where to send the file (e.g. email, cloud drive, messaging app). We never receive or
see this file.
Auto-backup (optional, off by default) silently saves one backup per day to the same local folder. No network transfer occurs.
Backup files contain all your transaction and balance data in plain JSON. Keep these files private and store them securely.
If you enable fingerprint or face unlock, the App calls the Android BiometricPrompt API. Your biometric data is processed entirely by the Android OS and the device's secure hardware (TEE / Secure Enclave). FinTrack never accesses, reads, or stores any biometric data.
Your PIN is never stored in plain text. It is hashed using PBKDF2-SHA256 with a random 256-bit salt and 100 000 iterations before being saved to EncryptedSharedPreferences (AES-256). The raw PIN is never written to disk or transmitted anywhere.
POST_NOTIFICATIONS: to send local reminders (no data is collected or transmitted)
With your permission (POST_NOTIFICATIONS), the App sends a local daily reminder
to log your transactions. These notifications are generated on-device by Android's
WorkManager. No notification content is sent to any server.
FinTrack uses the following Firebase services provided by Google:
Both services are governed by Google's Privacy Policy. No advertising SDKs are used.
FinTrack does not knowingly collect any personal information from anyone, including children under the age of 13. The only data collected is anonymous crash reports and usage statistics via Firebase, which contain no personal or financial information.
All data is stored locally on your device. You can delete it at any time by:
Android/data/com.fintrack/files/backups/We take the security of your local data seriously:
If we update this privacy policy, the new version will be posted at this URL and the "Last updated" date at the top will be revised. Continued use of the App after any changes constitutes acceptance of the updated policy.
If you have any questions or concerns about this privacy policy, please contact us: