← Back to App

Privacy Policy

Privacy Statement

Last Updated: September 15, 2026

ExpenseReports is a local-first product available as a Progressive Web App (browser) and a native Android mobile application. Neither application requires an ExpenseReports.app account. Reports, expenses, receipts, metadata, trash state, images, and PDFs remain stored locally on your device (in IndexedDB for the Web app, or in a local Room SQLite database and private sandboxed file storage for the Android app). ExpenseReports.app does not operate a backend server or copy of this data and does not access Gmail.

Data you provide and local processing

The app processes the receipt files, report information, expense details, optional location information, and categories you choose to provide. Receipt/report PDFs, ERX archive packages, and internal backup snapshots are created entirely on your device. We do not sell personal information, track users across apps or websites, or use behavioral advertising.

Android native device permissions and on-device capabilities

On Android, the application requests minimal system permissions strictly to perform local-first user actions:

  • Camera: Used exclusively when you choose to scan a physical document or capture a receipt photo. The camera operates solely while the scanner interface is active. Scanned images are saved into the app's sandboxed private storage and are never transmitted to external servers.
  • Location: Used optionally and solely on-device to suggest nearby cities from an offline, bundled US cities dataset. Raw GPS coordinates and location timestamps are never stored in the database, never logged, and never transmitted.
  • On-Device Text Recognition (OCR): Receipt text extraction is performed entirely on your device using on-device ML Kit models. No receipt images or extracted text are uploaded to cloud servers for recognition.
  • File Storage: Receipt evidence is stored within the application's private sandbox. Trashed receipts reside in a local trash folder until permanently deleted by the user via "Empty Trash".

Optional Google account backup

If you select Connect Google, your device communicates directly with Google over HTTPS and requests only https://www.googleapis.com/auth/drive.appdata. This permission allows ExpenseReports to manage files it creates in its hidden Google Drive appDataFolder; it does not permit the app to browse your normal visible Drive files. Google authorization does not create an ExpenseReports.app account.

A backup contains the existing application records and attachment bytes in complete, versioned .erbackup snapshots. .erbackup is internal recovery infrastructure, not a readable report export. ExpenseReports does not apply client-side encryption to this cloud copy. Google, as the storage provider, may technically process or read the stored application data under Google's terms and privacy policies. ExpenseReports receives no backend copy.

The newest three verified compatible snapshots are retained. Disconnecting Google does not delete them. Delete Google Backup requests deletion of files in the app's appDataFolder; it does not delete local device data or readable reports already exported/shared. Clearing local application data does not delete Google backups.

ExpenseReports' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Report export and sharing

Readable PDF report export, ERX structured package export, receipt image/PDF inclusion, native OS share sheet handoff, and download fallback are independent of Google backup and do not require Google authorization. If you choose Google Drive, an email app, or another destination in an operating-system share sheet, the operating system or recipient app performs that transfer. Normal report export never creates .erbackup files.

Other processing and controls

Location access is optional and controlled by browser/device system permissions. You can edit/delete local data, clear application/site data, deny camera or location access, disconnect Google, revoke Google consent, or separately delete the cloud backup at any time.

Local data is protected by device and operating system application sandbox controls. Google transfers and retention are governed by Google. No system can guarantee absolute security.

We update this statement whenever product data flows or platform capabilities change. Questions may be submitted to privacy@expensereports.app.