1. Who we are
Expenses is developed by What a Nice Idea ("we", "us", "our"), an independent software studio. This policy explains what the app does with information and the choices you have. For privacy matters, contact privacy@whataniceidea.com.
For the EU GDPR and Greek data-protection law, What a Nice Idea is the data controller for the limited processing described here.
2. Local-first, no backend
Expenses is local-first with no backend of its own. There are no user accounts, no login, and no cloud sync. The expenses you capture are stored in a database on your device and stay there. Uninstalling the app removes that data.
The single exception is optional receipt-QR enrichment, which reuses an existing service run for our sibling app, The Receipt (see §5). If you never scan a receipt QR, the app makes no personal-data network calls at all.
3. What data we process
| Category | Examples | Where it lives |
|---|---|---|
| Expense records | Amount, currency, category, merchant, notes, date/time | On your device only |
| Voice transcript | The text of an expense you dictated | On your device only |
| Receipt photos | Images you capture when scanning | On your device only |
| Location (optional) | Approximate/precise coordinates attached to an expense, if enabled | On your device only |
| Scanned QR URL | A receipt's QR URL, sent for enrichment if you scan one | Sent to the enrichment server (see §5) |
We collect no name, email, phone number, or account identifiers, because there is no account. We do not profile you or track you across apps.
4. Voice capture & on-device AI
The "Speak" button lets you dictate an expense. Two things then happen, and both are designed to run on your device:
- Speech-to-text is performed by your device's operating-system speech recognition. We prefer on-device recognition where the device offers it. Depending on your device model and settings, the OS speech service (for example Google's on some Android devices) may process the audio under its own privacy terms — this is a platform capability, not a server we operate.
- Turning your words into a structured expense is done by an on-device large language model (ML Kit GenAI / Gemini Nano) where available. Your transcript is not sent to us or to any cloud LLM for this. If no on-device model is available, a built-in rule-based parser runs entirely offline instead.
The resulting expense is saved locally. We do not retain your audio; transcripts are stored on-device as part of the expense only if the parsed result keeps them.
5. Scanning & receipt enrichment
The "Scan" button uses your camera to read a receipt's QR code and, where useful, its text (OCR via on-device ML Kit). The photo and any recognised text stay on your device.
To fill in richer details for a Greek receipt, the app can send the scanned QR URL to the enrichment service operated by What a Nice Idea for The Receipt (a Cloudflare Worker). That service looks up the receipt with the relevant Greek public/e-invoicing system and returns structured details. Only the receipt's own QR URL is sent — never your other expenses, and no tax credentials. This call is non-blocking: your expense is already saved locally, and if enrichment is rate-limited, not configured, or offline, the app just keeps what it has and shows a gentle notice.
6. Location
If you allow it, the app can attach your location to an expense to help you remember where it happened. Location is captured on-device and stored with that expense locally; it is not sent to us. Capturing an expense never waits on GPS — location is added in the background if and when it's available. You can decline or revoke the location permission at any time and keep using the app.
7. Device permissions
| Permission | Why |
|---|---|
| Microphone | To dictate an expense with the "Speak" button. |
| Camera | To scan receipt QR codes and read receipt text. |
| Location (optional) | To tag an expense with where it happened, if you enable it. |
| Photos / storage | Only if you save or attach a receipt image. |
8. Third-party services
- Your device's OS speech recognition — used for voice-to-text, under the platform's own terms.
- Google ML Kit — on-device text recognition (OCR) and the on-device GenAI model. These run locally on your device.
- Our receipt-QR enrichment service (Cloudflare) — contacted only when you scan a receipt QR, and only with that QR's URL.
- Your app store (Google Play) — distributes the app under its own privacy policy.
No advertising SDKs and no profiling analytics are integrated.
9. Legal basis
- Contract / performing the feature you invoked: enriching a receipt you chose to scan.
- Consent: microphone, camera, and location permissions, revocable at any time.
- Because expense data stays on your device, most processing does not involve us as a controller at all.
10. Retention & deletion
Your data stays on your device until you delete it in the app or uninstall the app. There is no server-side copy of your expenses for us to retain. Enrichment requests are transient and are not used to build a profile of you.
11. Your rights
Under the GDPR you have rights to access, correct, delete, export, restrict, and object. Since your data is held locally, you exercise these directly in the app (view, edit, export to CSV, delete). If you have any request that involves us, contact us. You may also complain to your supervisory authority — in Greece, the Hellenic Data Protection Authority (HDPA).
12. Security
Because your data stays on your device, it is protected by your device's own security (screen lock, encryption). The one network call — receipt enrichment — is made over HTTPS/TLS. We hold no account credentials because there are no accounts.
13. Children
Expenses is a general-audience productivity tool and is not directed at children. We do not knowingly collect data from children.
14. Changes to this policy
We'll update this policy as the app evolves, revising the "last updated" date and, where appropriate, notifying you in the app.
15. Contact
Reach us at privacy@whataniceidea.com.