ExTrExTr← Home
ExTr

Privacy

The short version: ExTr is local-first and doesn’t track you. Everything you enter stays on your device — and if you turn on backup or sharing, it’s end-to-end encrypted, so we can’t read your expenses even though we store them. No ads, no analytics, no AI.

Last updated: 19 July 2026 · Version 2.0 · Reflects the M2 release. This summary is written plainly; the sections below are the full policy.

1 · The shape of it

ExTr is local-first. With no account, everything you enter stays in a private database on your own device and nothing leaves it — exactly as before.

Three optional features, all off by default and turned on only by you, involve a backend:

  • An account — sign in with Google to unlock backup and sharing. Your email address is stored as your account identifier.
  • Encrypted backup & sync — your entries are encrypted on your device and the encrypted copy is stored on our backend so you can restore on another phone. We cannot read it.
  • Spaces — invite people by email to share a set of expenses, end-to-end encrypted to the group.

There are still no analytics, no advertising, no tracking, and no AI anywhere in ExTr. We never sell or share your data for anyone else’s purposes.

2 · What we collect (and only if you turn it on)

Everything is entered manually by you. Depending on what you enable:

  • Always local, never sent: your expenses, goals, recurring-bill templates, and “money owed to me” records (which may include a contact name you type). With no account, these never leave your device.
  • With an account: your email address (from Google sign-in).
  • With backup on: an encrypted copy of your entries — an opaque blob we cannot read — plus minimal routing information (a row id, your user id, timestamps). No amounts, descriptions, or categories are ever readable by us.
  • With Spaces: the email addresses you enter to invite people, and short name hints (the Space’s name and your display name) shown to invitees. The shared entries themselves are end-to-end encrypted.

ExTr is intended for adults; we set a minimum age of 18 and do not knowingly collect data from children.

3 · End-to-end encryption

When you turn on backup, your device creates a random encryption key and seals every entry with it before anything is uploaded. That key never reaches our server in a form we can use — it is protected by a one-time recovery code shown to you once at setup, which only you hold.

This means we cannot read your expenses, goals, or amounts — not the developer, not the hosting provider. It also means the recovery code is essential: if you lose it and lose your devices, your encrypted backup cannot be recovered by anyone, including us. Keep it somewhere safe.

4 · Spaces (shared tracking)

A Space lets you and the people you invite see a shared set of expenses. Shared entries are end-to-end encrypted to the Space’s members; the server cannot read them. Members of a Space can see each other’s shared entries, display names, and email addresses within that Space — that is the feature. Your personal, un-shared entries are never part of a Space.

To make invitations work before someone has joined, some metadata is stored in plain form on the backend: the invitee email addresses, a short Space-name hint, and the inviter’s display name. No amounts or descriptions are ever stored in plain form.

5 · Where your data is stored

Your entries always live locally, in a private database on your device (on iPhone/iPad in the app’s private App Group container, shared only with ExTr’s own widget; on Android in the app’s private storage).

If you turn on backup or Spaces, the data described above is also stored on our backend, hosted by Supabase in Singapore. Because the publisher is in India and the servers are in Singapore, this is a cross-border transfer of the readable data (your email and, for Spaces, invite emails and name hints); your expense content is end-to-end encrypted regardless of where it sits. Supabase processes this data on our behalf to provide backup, sync, and sharing, and is not permitted to use it for its own purposes.

One honest nuance — device backups. Separately from ExTr’s own backup, your on-device database may be included in your own operating-system backup (iCloud on iOS; Google / Android Auto Backup on Android) — strictly between you and Apple/Google, under your account and their terms. The developer has no access to it, and you can turn it off in your device settings.

6 · What we don't do

To be concrete, ExTr does not:

  • Run any analytics or telemetry — first-party or third-party. It does not track usage, log events, count feature use, collect metrics, or report crashes to anyone.
  • Show advertising, use advertising identifiers, or include any ad SDK.
  • Include any analytics, advertising, crash-reporting, or telemetry SDK (for example, none of Firebase / Google Analytics, Crashlytics, Sentry, Amplitude, Segment, Mixpanel, AppsFlyer, Adjust, or the Meta SDK).
  • Connect to banks or cards, read your SMS/texts, scan your email, or scan photos/receipts — there is no automatic import of transactions of any kind.
  • Use any artificial-intelligence service or on-device machine-learning model. The goal-motivation coaching runs entirely on your device from fixed calculations and pre-written templates, and sends nothing anywhere.
  • Sell your data, or share it with third parties for their own purposes.

7 · Who else is involved

The backend relies on a small number of service providers:

  • Supabase — hosts the backend (authentication + encrypted storage) in Singapore, as our data processor.
  • Google — provides sign-in when you choose to create an account; it receives the sign-in request as your identity provider.
  • Google Play (Android only) — the app can ask the on-device Play Store to check for and download an ExTr update; only ExTr’s version number is involved, data Google Play already has.

None of these receive your data to use for their own purposes, and your expense content is end-to-end encrypted from all of them.

8 · Permissions

ExTr keeps its permissions minimal:

  • Camera — requested only if you choose to scan your recovery-code QR when restoring a backup. The camera is used on-device to read the code; nothing from it is uploaded, and you can always type the code instead. ExTr does not take photos or scan receipts.
  • Internet — used for encrypted backup/sync and sign-in (when you turn backup on), and for the Android app-update check. With backup off, ExTr makes no data network calls of its own.

ExTr does not use location/GPS, contacts, photos/media library, microphone, or SMS/text access. A few low-level entries in the technical manifests are framework defaults (for example, on Android: vibration, a “draw over other apps” flag) and are used by no feature to collect personal data.

9 · Your rights & deletion

You are in control of your data. You can edit or delete any entry in the app at any time. To remove data more broadly:

  • Delete your account & data (Profile → Account) permanently removes your entire backend footprint — encrypted backup, keys, Spaces membership (including invite emails and name hints), any Spaces you own, and your account email itself — then wipes ExTr’s database from your device. See the deletion page for details.
  • Turn off backup deletes your encrypted copy and key from the backend but keeps your account.
  • Delete the app removes its on-device database.

Under laws such as India’s DPDP Act and the GDPR you may have rights to access, correct, or delete your personal data; because your content is end-to-end encrypted we cannot read it, but we can delete it. Email contact@extr.in with any request.

10 · Changes & contact

If this policy changes, we will post the new version here and update the “Last updated” date above. This version reflects ExTr’s M2 release — optional accounts, end-to-end-encrypted backup, and Spaces. A future change to what data is involved (for example, adding AI-generated text) will be reflected here before it ships.

ExTr is a personal project published by Nishant Mishra, an individual based in Jaipur, Rajasthan, India, who is the data controller. For any privacy question or request, email contact@extr.in.