Privacy Policy for Trackate
Last Updated: May 26, 2026
Version: 2.1
Introduction
Trackate ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application for expense tracking and group expense management ("the App"), available on Google Play Store and Apple App Store.
By using Trackate, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Personal Information
When you register for Trackate, we collect:
- Account Information: Name, email address, username, date of birth, and gender
- Optional Profile Information: Phone number and occupation (only if you choose to provide them)
- Authentication Data: Google Sign-In credentials (handled securely through Google OAuth 2.0) or Apple Sign-In credentials (handled securely through Apple's Sign in with Apple service)
- Profile Information: Username, profile photo
- Device Information: FCM (Firebase Cloud Messaging) tokens for push notifications, device model, OS version, app version
Financial Information
- Expense Data: Transaction amounts, descriptions, categories, dates, and attached receipts
- Auto-Detected Transactions: Payment information extracted from bank/UPI notifications (amount, merchant name, payment method) when you explicitly enable auto-expense detection (Android only)
- Group Expense Details: Split amounts, participants, settlement records
- Debt Records: Outstanding balances between you and your connections
- Budget Information: Budget limits, spending categories, and tracking data
Usage Information
- Activity Data: App usage patterns, feature interactions
- Contact Connections: Phone numbers of contacts you add to expenses (stored only as references)
- Friend Relationships: Your friend list and trust scores
- Notifications: Reminder preferences and notification history
Information Stored Locally
- QR Codes: Expense QR codes generated for sharing
- Cached Data: Temporary storage for offline access and faster app startup
- Media Files: Receipt images and expense-related photos stored in device gallery
- Pending Transactions: Auto-detected transactions temporarily stored locally (encrypted) when the app is closed, to prevent data loss
Permissions We Request
| Permission | Platform | Purpose |
|---|---|---|
| Camera | Android & iOS | Capture receipt photos for expense tracking |
| Storage / Photos | Android & iOS | Save and access receipt images; select screenshots for bug reports |
| Notifications | Android & iOS | Send expense reminders, friend request alerts, and payment reminders |
| Notification Access (Accessibility) | Android only | Read bank/UPI payment notifications for optional auto-expense detection |
| Internet | Android & iOS | Sync data with cloud and enable real-time features |
| Location (approximate) | Android & iOS | Collect city/state/country for marketing analytics (optional, requires explicit permission) |
| Contacts | Android & iOS | Easily add friends from your contact list (optional) |
| Siri | iOS | Add expenses quickly using voice shortcuts (optional) |
Notification Access (Android only — Auto-Expense Detection): When you explicitly enable this optional feature, we read notifications only from a whitelist of 100+ approved financial apps including:
- UPI Apps: Google Pay, PhonePe, Paytm, BHIM, Amazon Pay, WhatsApp Pay, Flipkart, MobiKwik, FreeCharge, Airtel Payments Bank, JioMoney, and more
- Private Banks: ICICI, HDFC, Axis, Kotak, YES Bank, IndusInd, IDBI, RBL, DBS, Standard Chartered, Citibank, HSBC, Federal, Karur Vysya, and 15+ others
- Public Sector Banks: SBI, Bank of Baroda, Canara Bank, Union Bank, PNB, Central Bank, Indian Bank, Bank of Maharashtra, and more
- Wallets: MobiKwik, FreeCharge, CRED, Ola Money, Oxigen, Paytm Business
- Neo-Banks: Slice, Jupiter, Fi Money, Niyo Global
- SMS Apps: Samsung Messages, Google Messages, and all major phone brand messaging apps (for SMS-based bank notifications)
No raw notification text is ever stored — only extracted transaction data (amount, merchant, payment method).
How We Use Your Information
1. Core Functionality
Account management, expense tracking, auto-expense detection (when enabled), split calculations, debt management, expense reports.
2. Social Features
Friend connections, friend requests, shared expenses, group transactions, debt settlements.
3. Notifications
Expense reminders, friend request alerts, payment reminders, app update announcements.
4. Personalization
Spending insights, budget optimization suggestions, AI-powered categorization, customized analytics.
5. Security and Compliance
Identity verification, fraud prevention, Terms of Service enforcement, legal compliance.
6. Marketing and Analytics
Understanding user distribution by location, targeted campaigns, regional feature optimization, service expansion planning.
7. App Updates
Checking for available updates via Google Play In-App Update API (Android) and App Store version checks (iOS) to ensure you have the latest version.
8. Siri Shortcuts (iOS)
When you use the "Add Expense" Siri Shortcut, your voice input (amount, description, category, date) is collected and submitted to Trackate's servers to log the expense to your account.
Data Sharing and Disclosure
With Other Users
- Friends: Can see expenses you share with them, debt balances, and profile information (based on your privacy settings)
- Pending Contacts: Users you add to expenses before they register can see expense details
- Group Participants: Can view shared expense details and split amounts
Third-Party Services
1. Firebase (Google)
Cloud Firestore (database), Cloud Storage (receipts/media), Firebase Authentication, Firebase Cloud Messaging (push notifications), Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, Firebase App Check.
Subject to Google's Privacy Policy: https://policies.google.com/privacy
2. Google AdMob (Advertising)
We display ads to keep the app free. AdMob may use your device's advertising identifier (IDFA on iOS, GAID on Android) to show relevant ads.
- iOS: You will be asked for permission via Apple's App Tracking Transparency (ATT) prompt before any advertising identifier is accessed. You can opt out via iOS Settings → Privacy & Security → Tracking.
- Android: You can opt out via Google Settings → Ads → Opt out of Ads Personalization.
AdMob Privacy Policy: https://policies.google.com/privacy
3. Google Sign-In
OAuth 2.0 for secure authentication. Subject to Google's Terms of Service.
4. Apple Sign-In (iOS)
Sign in with Apple for secure authentication on iOS devices. Apple may provide a private relay email address to protect your real email.
Subject to Apple's Privacy Policy: https://www.apple.com/legal/privacy/
5. Google Maps / Geocoding
Used to convert GPS coordinates to approximate location (city, state, country) for marketing analytics. Exact GPS coordinates are never stored.
What We Do NOT Do
- We do not sell your personal information to third parties
- We do not process payments or hold funds
- We do not share financial data with advertisers
- We do not use biometric data for authentication
- We do not track your real-time location continuously
- We do not store raw notification text from your device
Legal Requirements
We may disclose your information if required by law, court order, government request, or to protect our rights, safety, or the safety of others.
Business Transfers
If Trackate is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
Location Information
- What we collect: City, state, and country (derived from GPS coordinates via geocoding)
- Purpose: Marketing analytics and understanding user distribution
- Precision: We do NOT store exact GPS coordinates — only city/district, state, and country
- Frequency: Collected once on first login, updated periodically
- Permission: Requires explicit user permission; can be denied without affecting core features
- Sharing: Location analytics are visible only to app administrators
Siri Shortcuts (iOS Only — Optional Feature)
How It Works
Trackate offers an optional "Add Expense" Siri Shortcut that lets you log expenses without opening the app. The shortcut is built using Apple's AppIntents framework and is automatically registered with the system when you install Trackate — it appears in the Shortcuts app under Trackate with no manual setup required. There are two ways to trigger it:
| Trigger Method | How to Set Up | What Happens |
|---|---|---|
| Siri voice | Say any registered phrase (see list below) | Siri activates and asks for amount, description, category, date |
| Back Tap | iOS Settings → Accessibility → Touch → Back Tap → choose Double Tap or Triple Tap → select "Add Expense in Trackate" | Tap the back of your iPhone twice or three times; Siri UI appears and asks for the same parameters |
Registered Siri trigger phrases:
| # | Phrase |
|---|---|
| 1 | "Add expense in Trackate" |
| 2 | "Add expense to Trackate" |
| 3 | "Add a new expense in Trackate" |
| 4 | "Log expense in Trackate" |
| 5 | "Log expense to Trackate" |
| 6 | "Track expense in Trackate" |
| 7 | "Track expense to Trackate" |
| 8 | "Record expense in Trackate" |
| 9 | "Save expense to Trackate" |
| 10 | "Enter expense in Trackate" |
- No app launch required: The shortcut runs entirely as a background extension (
TrackateShortcuts) - Parameter collection: Regardless of trigger method, Siri asks you for amount, description, category, and date through its voice/on-screen prompts
- Back Tap uses no additional data beyond what Siri voice already uses — it is simply a different physical trigger
What Data Is Accessed and Transmitted
| Data | Source | Sent to Server? |
|---|---|---|
| Firebase auth token | Shared App Group (stored locally on your device) | Used as Bearer token — not stored separately |
| Expense amount | Your voice input via Siri | Yes — sent to Firebase Cloud Function |
| Expense description | Your voice input via Siri | Yes — sent to Firebase Cloud Function |
| Expense category | Your selection via Siri | Yes — sent to Firebase Cloud Function |
| Expense date | Your selection or current time | Yes — sent to Firebase Cloud Function |
| Currency code | Shared App Group (your account preference) | Yes — sent to Firebase Cloud Function |
- The shortcut calls our Firebase Cloud Function (
addExpenseFromShortcut) over HTTPS - The auth token is a temporary Firebase ID token, not your password
- No voice audio is ever stored by Trackate — Siri handles all speech-to-text locally via Apple
- Apple's Siri platform is subject to Apple's own Privacy Policy: https://www.apple.com/legal/privacy/
Your Control
- You must be signed in to Trackate before using the shortcut
- Revoke Siri access: iOS Settings → Siri & Search → Trackate
- Remove Back Tap assignment: iOS Settings → Accessibility → Touch → Back Tap → set to None
- Delete the shortcut: Open the Shortcuts app → find "Add Expense in Trackate" → delete
- All expenses added via shortcut appear in the app and can be edited or deleted like any other expense
Auto-Expense Detection (Android Only — Optional Feature)
How It Works
When you enable auto-expense detection, Trackate reads payment notifications from your device to automatically track expenses. This feature:
- Requires explicit opt-in: Disabled by default; you must grant "Notification Access" permission in Android Settings
- Processes notifications locally: Initial parsing happens on your device
- Filters by whitelist: Only reads notifications from 100+ approved financial apps
- Runs as a foreground service: Shows a persistent notification ("Trackate is monitoring expenses") when active, for full transparency and Android 16 compatibility
- Works offline: Transactions detected when the app is closed are saved locally (encrypted) and synced when you reopen the app
What We Extract
- Transaction amount, merchant name, payment method, timestamp, source app
- We never store: raw notification text, OTPs, card numbers, CVV, PINs, or personal messages
Your Control
- Enable/disable anytime in Settings
- Revoke notification access permission in Android Settings at any time
- Review and edit all auto-detected expenses before they are finalized
- Delete auto-detected expenses like any other expense
In-App Updates
The App uses the following mechanisms to deliver updates:
- Android: Google Play In-App Update API to prompt for immediate or flexible updates directly within the app
- iOS: Version checks against our remote configuration to notify you when a new version is available on the App Store
- Remote Configuration: We store update settings (minimum version, latest version, force update flag) in Firebase Firestore to control update behavior
No additional personal data is collected during the update process beyond what is already described in this policy.
First-Time User Onboarding
When you first log in, the App displays a feature tutorial (walkthrough) to help you understand key features. This tutorial:
- Is shown only once per device/account
- Completion status is stored locally on your device (SharedPreferences)
- Does not collect any additional personal data
Optional Profile Fields
- Phone number and occupation are optional during onboarding.
- You can use Trackate core features without providing either field.
- If provided, phone number may be used for optional friend discovery and expense linking.
- If provided, occupation may be used for optional personalization insights.
FCM Token Management
- When you log in, your device's FCM (Firebase Cloud Messaging) token is saved to your account in Firestore to enable push notifications
- When you log out, your FCM token is immediately deleted from Firestore, ensuring you no longer receive push notifications for that account on that device
- This prevents notifications from being delivered to a device after a user has logged out
Data Security
We implement industry-standard security measures:
- Encryption in transit: All data transmitted over HTTPS/TLS
- Encryption at rest: Firebase Firestore and Cloud Storage with server-side encryption
- Authentication: Secure OAuth 2.0 (Google), Sign in with Apple, and Firebase Authentication
- App Integrity: Firebase App Check (Play Integrity on Android, App Attest on iOS) to prevent unauthorized API access
- Access Controls: Role-based access and Firestore security rules
- Crash Reporting: Firebase Crashlytics for identifying and fixing security-related bugs
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
Your Privacy Rights and Choices
Access and Update
- View and edit your profile information in Settings
- Update your privacy preferences
- Manage friend connections
- Delete individual expenses or groups
Privacy Settings (In-App)
- Allow Friend Search: Let others find you by email or username
- Show Profile Details: Display profile information to friends
- Show Expenses to Friends: Allow friends to view your personal expenses
- Show Budgets to Friends: Share your budget information
- Auto-Expense Detection: Enable/disable automatic expense detection (Android only)
- Auto-Expense Alerts: Control notifications for auto-detected expenses
Data Export
You can request a copy of your data by contacting us at support@svnate.com.
Account Deletion
To delete your account:
- Go to Settings → Account → Delete Account inside the App
- Confirm deletion
When you delete your account:
- Your personal profile is permanently removed
- Your personal expenses are deleted
- Shared expenses remain visible to other participants but your name is anonymized
- Your FCM token is removed from all records
- Outstanding debts should be settled before deletion
Account deletion is handled entirely within the App. If you are unable to access the App, contact us at support@svnate.com to request manual deletion.
Opt-Out Options
- Notifications: Disable in-app or in device Settings
- Auto-Expense Detection: Revoke notification access in Android Settings
- Friend Search: Toggle off in Privacy Settings
- Location Collection: Deny location permission in device Settings
- Ad Personalization (iOS): Deny ATT prompt or via iOS Settings → Privacy & Security → Tracking
- Ad Personalization (Android): Google Settings → Ads → Opt out of Ads Personalization
Data Retention
We retain your information for as long as:
- Your account is active
- Needed to provide services
- Required by law
- Necessary for legitimate business purposes
After account deletion:
- Personal data is removed within 30 days
- Anonymous usage data may be retained for analytics
- Transaction records for financial compliance may be retained up to 7 years
- Backup copies are automatically deleted within 90 days
Children's Privacy
Trackate is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at support@svnate.com and we will delete it promptly.
International Data Transfers
Your information may be transferred to and stored on servers located outside your country (primarily in the United States via Google Firebase infrastructure). By using Trackate, you consent to such transfers. We ensure appropriate safeguards are in place for cross-border data transfers in compliance with applicable data protection laws.
Cookies and Tracking Technologies
We use:
- Local Storage (SharedPreferences): For offline functionality, caching, and user preferences
- Firebase Analytics: For app usage insights (collection disabled in debug builds)
- Firebase Crashlytics: For identifying and fixing bugs (collection disabled in debug builds)
- Firebase Performance Monitoring: For app performance insights (collection disabled in debug builds)
You can disable analytics collection in your device settings, but this may affect app functionality.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via:
- In-app notification
- Email notification to your registered address
- Prominent notice on app launch
Continued use of Trackate after changes constitutes acceptance of the updated policy. The "Last Updated" date at the top of this policy reflects the most recent revision.
Compliance
Trackate complies with:
- Google Play Store Developer Program Policies
- Apple App Store Review Guidelines and App Store Connect policies
- General Data Protection Regulation (GDPR) for EU users
- California Consumer Privacy Act (CCPA) for California users
- Information Technology Act, 2000 (India)
- Digital Personal Data Protection Act, 2023 (India)
- Apple App Tracking Transparency (ATT) framework requirements
- Firebase and Google Terms of Service
Additional Rights for EU Users (GDPR)
If you are in the European Union, you have additional rights:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Rights related to automated decision-making
To exercise these rights, contact us at support@svnate.com.
Additional Rights for California Users (CCPA)
If you are a California resident, you have:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to say no to the sale of personal information
- Right to access your personal information
- Right to equal service and price
We do not sell your personal information.
Contact Us
If you have questions about this Privacy Policy, your data, or to exercise your rights:
Email: support@svnate.com
Developer: SVNATE
Address: Pune, Maharashtra, India
Account Deletion: Settings → Account → Delete Account (inside the App), or email support@svnate.com if you cannot access the App
Privacy Policy URL: https://trackate.svnate.com/privacy-policy
Effective Date: May 26, 2026
Version: 2.1
Content was updated to reflect: Siri Shortcuts (iOS) feature disclosure, optional profile fields clarification (phone number and occupation), Siri permission added to permissions table, and Siri Shortcuts data usage added to "How We Use Your Information."
©️ 2026 Trackate by SVNATE. All rights reserved.