Expenso privacy policy
Last updated: 28 July 2026
Expenso is a personal expense tracker published by Zorizon Labs (zorizonlabs.com). It is built around one principle: your financial data never leaves your phone.
Zorizon Labs is the data controller for the anonymous usage statistics described below. That is the only category of data the app collects at all.
What we collect
None of your financial data. Ever. Expenso has no user accounts and no ads. Your amounts, merchants, accounts, categories, budgets, trips and notes are never transmitted anywhere.
The one thing we do collect is anonymous usage statistics, through Google Firebase Analytics, to see whether the app is being used and which parts people actually open. This covers:
- app opens, session counts and app version
- device model and Android version
- whether a feature was used at all, for example that an expense was added or that notification capture was switched on
It explicitly does not include the amount, the merchant, the category, the account, the note, or anything else you type. Those values are never passed to the analytics SDK at all. By design, the app’s analytics code accepts no free-form data, only a fixed list of event names.
We do not collect an advertising ID. Ad ID collection is disabled and the permission is removed from the app.
You can switch this off. Settings, then anonymous usage data. Turning it off stops all collection and upload at the SDK level, not merely in our own code.
What stays on your device
- Accounts, cards, transactions, categories, trips and budgets you enter, stored in a local database on your phone only.
- Optional spend capture: if you enable it, Expenso reads incoming bank notifications, or SMS in the sideloaded build, on your device to suggest a transaction. The message text is parsed locally and immediately discarded. Only the amount and merchant you choose to save are kept. Nothing is uploaded.
Backups
Weekly backups and manual exports are written as CSV files to your phone’s Downloads folder. They are ordinary files under your control, and sharing them is always your explicit action.
Optional AI mode
AI mode is off by default. If you enable it, you provide your own Google Gemini API key. When, and only when, you explicitly submit an entry, meaning typed text, a voice note you record, or an image or PDF you attach, that content is sent directly from your device to Google’s Gemini API using your key, to extract the transaction details. We operate no server, never see the content or the key, and nothing is sent in the background. Google’s handling of those requests is governed by Google’s own terms. Disable AI mode at any time to stop all network use.
Data deletion
Settings, then erase all data, permanently deletes everything on the device, after writing a final backup to your Downloads folder. Uninstalling the app deletes all app data as governed by Android.
To have already-collected anonymous usage data deleted, email the address below with the request. Because the data carries no name, email or account, please send it from a device where the app is installed so we can match the app instance. There is no user account to delete, as Expenso has none.
Permissions
- Notifications, to remind you about bills and show capture suggestions.
- Notification access (optional, off by default), solely to detect bank spend alerts locally. Revocable at any time in system settings.
- Microphone (optional, only with AI mode), records a voice note only while the listening UI is on screen, to describe an expense. The recording is sent once to Google’s Gemini API with your own key and is not stored by us.
- Internet, used only by AI mode, for the Gemini requests above.
Children
Expenso is not directed at children under 13 and we do not knowingly collect data from them.
Changes
Any change to this policy will be published at this same address, with the date at the top updated.
Contact
Zorizon Labs
hello@zorizonlabs.com
zorizonlabs.com