SpendSift Privacy Policy
Last updated: 23 August 2026
SpendSift is an expense tracker that reads bank transaction messages already on your phone and turns them into a spending summary. This policy describes what it handles and where that data goes.
The short version: everything stays on your device. SpendSift does not request internet access, so it is not technically capable of sending your data anywhere.
What SpendSift reads
SMS messages. SpendSift reads the messages in your phone’s inbox to find transaction alerts from banks and payment apps. It looks at every message in order to decide which ones are transactional, but only messages it recognises as transactions are stored.
Information taken from those messages. For each transaction it recognises, SpendSift stores the amount, the merchant or sender name, the date and time, the payment channel, the currency, and the text of the message it was parsed from.
Information you enter. Categories, budgets, notes, manually added transactions, your chosen currency, and your app-lock PIN if you set one.
Where that information is stored
All of it is stored on your device, in the app’s own private storage — a local database and a local preferences file. No account is required and none is created. Nothing is uploaded.
Your app-lock PIN is encrypted before it is written, using a key held in your device’s hardware-backed keystore. That key never leaves the device.
What SpendSift sends
Nothing. SpendSift does not declare the INTERNET permission, which means
Android will not allow it to open a network connection at all. There are no
analytics, no advertising, no crash reporting, and no third-party SDKs that
collect information about you.
Backups
If you have Google’s backup enabled for your phone, Android’s own Auto Backup may include SpendSift data in your device backup. This is a feature of Android rather than something SpendSift does, and the backup is between you and Google. Your app-lock PIN is explicitly excluded and is never included in a backup.
You can turn this off for all apps under Settings → Google → Backup on your device.
Permissions and why they are needed
| Permission | Why |
|---|---|
READ_SMS |
To scan your existing inbox for past transaction messages. |
RECEIVE_SMS |
To notice new transaction messages as they arrive. |
USE_BIOMETRIC / USE_FINGERPRINT |
To unlock the app with your fingerprint or face, if you enable the app lock. |
SpendSift never sends, forwards, or shares your messages. It reads them only to extract transaction details, and only on your device.
If you contact support
The app offers an email address for feedback and bug reports. Tapping it opens your own email app — SpendSift does not send anything itself, and does not have access to your email address unless you choose to write.
If you do write, your message arrives in a Gmail mailbox, which means Google hosts it and the developer can read it. Please leave out personal details such as account numbers, card details or balances. If you are reporting a parsing problem and need to include message text, remove the identifying parts first.
Deleting your data
Deleting a transaction hides it and keeps a copy, so that it can be undone. Settings → Deleted Transactions lists what is being held and lets you either restore it or delete it permanently. Until you delete it permanently, it is still stored on your device.
Deleting a transaction does not delete the bank message it was read from. That message stays in your phone’s SMS inbox, where only your messaging app can remove it.
Settings → Reset App Data clears all transactions, categories, budgets and preferences in one step. Uninstalling SpendSift removes the local database and preferences, and with them everything the app held. Because nothing is stored anywhere else, there is no server-side copy to request the deletion of.
If Android has backed the app up, removing that copy is done through your Google account’s backup settings.
Children
SpendSift is not directed at children and does not knowingly collect information from them.
Changes to this policy
If this policy changes, the updated version will be posted at this address and the date at the top will change.
Contact
Questions about this policy: hello.spendsift@gmail.com