Budget Tracker — Privacy Policy
Last Updated: September 4, 2026
This policy applies specifically to the Budget TrackerAndroid application (“the App”) developed by HJIN Labs. It supplements our corporate Privacy Policy.
1. Information We Collect
Budget Tracker collects the following information when you use the application:
- Account Information: Email address and password (stored as a secure bcrypt hash) when you create an account.
- Transaction Data: Income and expense records you enter manually or capture automatically, including amounts, categories, dates, and merchant names.
- SMS Data (with permission): If you grant SMS permission, the app reads incoming bank SMS messages locally on your device to automatically extract transaction details (amount, merchant, date). The original SMS message text is never transmitted to our servers. Only the extracted transaction data may be securely synced to our cloud servers for cross-device access.
- Notification Data (with permission): If you grant notification access, the app monitors bank app notifications to detect transactions. Only extracted transaction data is synced; original notification content is never transmitted.
- Device Information: Android OS version and device model for analytics and crash reporting.
2. Local Data Processing — SMS Parsing
Budget Tracker's SMS auto-capture feature is designed with privacy as a priority:
- On-Device Processing: SMS messages are read and parsed entirely on your device. The original SMS content is never transmitted to our servers.
- Limited Scope: The app only reads messages that match known bank SMS patterns. It does not read personal conversations, OTP codes, or any non-financial messages.
- Cloud Sync of Extracted Data: After parsing, the extracted transaction details (amount, merchant, date, category) may be synced to our secure Supabase cloud servers for cross-device access. The original SMS text remains on your device only.
- User Control: You can revoke SMS permission at any time through Android system settings. The app will continue to function with manual entry only.
3. Notification Listener Data
With your permission (granted via the system's notification access settings), the app processes bank app notifications to detect transaction details. This requires the NotificationListenerService permission.
- Only notifications from known Azerbaijani bank applications are examined.
- Only extracted transaction data (amount, merchant, category, date) is synced to our secure cloud servers.
- The original notification content is never transmitted to our servers. It is processed locally and stored only on your device.
- Notifications from other apps are ignored.
4. How We Use Your Information
We use the collected information solely to provide and improve the application:
- To authenticate your account and secure your financial data.
- To display your financial records, charts, and analysis within the app.
- To sync data across devices when you are logged into your account.
- To improve app stability and fix bugs through anonymized crash reporting.
We do not sell, share, or transmit your financial data to any third party for marketing, advertising, or any other purpose. Your financial information belongs to you.
5. Data Storage and Security
Your data is stored in two locations with strong security measures:
- Locally on your device using Room database (encrypted at rest on supported devices). This is the primary storage for all your financial records.
- Remotely on Supabase cloud servers (us-west-1 region) for optional cross-device sync and backup. All data is transmitted over HTTPS/TLS encryption.
Passwords are hashed using bcrypt before storage. We never store plain-text passwords.
6. Firebase Analytics
We use Firebase Analytics to understand how the app is used. Firebase Analytics collects:
- App usage events and screen views
- Feature usage patterns
- Device information (model, OS version)
- Session data and user engagement metrics
This data is aggregated and does not include your financial records or personal transaction data.
7. Firebase Crashlytics
We use Firebase Crashlytics to diagnose and fix crashes. Crashlytics collects:
- Crash reports and stack traces
- Device model and OS version
- Non-personal diagnostic data
- App state at the time of crash
This data helps us improve app stability and does not include your financial information.
8. Third-Party Services
Budget Tracker uses the following third-party services:
- Supabase — Cloud database and authentication. Your synced data is stored on Supabase servers in the us-west-1 region.
- Google AdMob — Rewarded advertising SDK for optional ad-supported features. AdMob may collect and process device identifiers, advertising identifiers, and ad interaction data in accordance with Google's Privacy Policy. No personal financial data is shared with AdMob. Ad views are entirely optional and user-initiated.
- Firebase — Analytics and crash reporting services as described in sections 6 and 7 above.
9. Advertising and Consent (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and other regions requiring consent:
- We use Google User Messaging Platform (UMP) to manage your advertising consent.
- Personalized advertising is only shown after you provide explicit consent.
- You can withdraw consent at any time through the app's ad settings or your device settings.
- Non-personalized ads may be shown even without consent for ad-supported features.
10. Data Retention and Deletion
You have full control over your data:
- Local Data: Clear all local financial data by uninstalling the application or clearing app data through device settings.
- Cloud Data: You can request deletion of your account and all cloud-synced data using either method below.
In-App Deletion: Go to Profile → Delete account in the app to permanently delete your account and all data.
Web Deletion (No Login Required): You can also request account deletion without logging in by visiting:
https://www.hjinlabs.online/products/budget-tracker/delete-account/Alternatively, email hjinlabs@gmail.comwith the subject line “Budget Tracker Data Deletion Request.” We will process your request within 30 days.
11. User Rights
You have the right to:
- Access your personal data.
- Correct inaccurate data.
- Delete your account and associated data.
- Withdraw permissions (e.g., SMS and notification access) at any time via device settings.
- Opt out of personalized advertising via your device's ad settings.
12. Permissions
Budget Tracker requests the following permissions:
- SMS (Receive): Used solely to detect and parse bank transaction messages. Processing is 100% on-device. Original SMS content is never transmitted to servers. You can revoke this permission at any time.
- Notifications: Used to listen for bank app notifications for automatic transaction capture. Only extracted transaction data is synced.
- Biometric (Fingerprint): Used for optional fingerprint authentication. No biometric data leaves your device; Android's Biometric API handles all authentication securely.
13. Children's Privacy
Budget Tracker is not intended for children under the age of 13. We do not knowingly collect personal information from children.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last Updated” date.