Legal

Privacy Policy

Effective date: 1 May 2026  ·  Last updated: 2 July 2026

The short version: Expenditi is built to work entirely on your device. Your receipts, expenses, subscriptions and notes are stored only on your phone and are never uploaded to us or anyone else. We have no server that holds your financial data.

1. Introduction

Welcome to Expenditi.

Expenditi (“us”, “we”, or “our”) is a mobile application operated by Neumeral Technologies OPC Pvt Ltd This Privacy Policy governs your use of the Expenditi mobile app (the “App”) and our website at https://expenditi.neumeral.com (together, the “Service”), and explains how we collect, safeguard and disclose information that results from your use of the Service.

By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, the terms used here have the same meanings as in our Terms of Service.

2. Definitions

SERVICE means the Expenditi mobile application and the website operated by Neumeral Technologies OPC Pvt Ltd

PERSONAL DATA means data about a living individual who can be identified from that data (or from that data and other information either in our possession or likely to come into our possession).

ON-DEVICE DATA means the receipts, images, expense records, subscription details, categories and notes you create in the App, which are stored locally on your device and are not transmitted to us.

USAGE DATA means data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit on our website).

COOKIES are small files stored on your device when you visit our website.

DATA CONTROLLER means the person who determines the purposes for which, and the manner in which, any personal data is processed. For the purpose of this Privacy Policy, we are the Data Controller of your data.

DATA PROCESSORS (OR SERVICE PROVIDERS) means any person who processes data on behalf of the Data Controller.

THE USER is the individual using our Service, corresponding to the Data Subject who is the subject of Personal Data.

3. Information Collection and Use

Expenditi is designed to require as little information as possible. You do not need to create an account to use the App, and the financial information you record stays on your device.

On-Device Data (never collected by us)

The core of what you do in Expenditi — scanning receipts, recording expenses, tracking subscriptions, adding notes and categories — happens entirely on your device. This On-Device Data:

  • is stored locally in the App on your phone;
  • is not transmitted to our servers (we do not operate a server that receives it);
  • is not accessible to us, and is not shared with or sold to any third party;
  • is processed on-device for features such as reading text from receipt images.

If you delete the App, or use its in-app delete/reset functions, this data is removed from your device. Because we never hold a copy, we cannot recover it for you — we recommend using your device's own backup tools if you wish to keep a copy.

Device Permissions

To provide its features, the App may request the following permissions, each of which you can grant or deny in your device settings:

  • Camera — to capture photos of receipts. Images are processed and stored on-device only.
  • Photo Library — to let you import an existing receipt image. Only the images you select are read, and they are handled on-device.
  • Notifications — to remind you about upcoming subscription renewals. These reminders are scheduled locally on your device.

Personal Data you choose to give us

We only receive Personal Data if you choose to send it to us — for example, if you email our support address or subscribe to product updates. In those cases, Personal Data may include:

  • Email address
  • First name and last name
  • The content of any message or feedback you send us

We may use this Personal Data to respond to you and, where you have opted in, to send you newsletters or product news. You may opt out of these communications at any time by following the unsubscribe link or by emailing us.

Usage Data (website)

When you visit our website, we may collect standard Usage Data that your browser sends, such as your device's Internet Protocol (IP) address, browser type and version, the pages you visit, and the time and date of your visit. This helps us understand how our website is used. The Expenditi mobile App does not send analytics about your financial activity to us.

Cookies (website)

Our website may use cookies and similar technologies to operate the site and remember your preferences. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. Examples of cookies we may use include Session Cookies (to operate the website), Preference Cookies (to remember your settings) and Security Cookies (for security purposes).

4. Use of Data

Neumeral Technologies OPC Pvt Ltd uses the limited data it does receive for the following purposes:

  • to provide and maintain our Service;
  • to notify you about changes to our Service;
  • to provide customer support and respond to your enquiries;
  • to gather analysis or valuable information so that we can improve our website and App;
  • to monitor the usage of our website;
  • to detect, prevent and address technical issues;
  • to send you product news and updates where you have opted in;
  • for any other purpose with your consent.

5. Retention of Data

Your On-Device Data is retained on your device for as long as you keep it there; we hold no copy. Any Personal Data you send us (such as support emails) is retained only for as long as necessary for the purposes set out in this Privacy Policy, and to comply with our legal obligations, resolve disputes and enforce our agreements.

6. Transfer of Data

Because your On-Device Data stays on your device, it is not transferred by us. Any Personal Data you choose to send us (such as an email) may be processed in India, where Neumeral Technologies OPC Pvt Ltd is based, and possibly in other jurisdictions where our Service Providers operate. Where data is transferred, we take all steps reasonably necessary to ensure it is treated securely and in accordance with this Privacy Policy.

7. Disclosure of Data

We may disclose the limited Personal Data we hold (such as support correspondence):

  • For law enforcement. Under certain circumstances, we may be required to disclose Personal Data if required to do so by law or in response to valid requests by public authorities.
  • Business transaction. If we are involved in a merger, acquisition or asset sale, Personal Data we hold may be transferred.

We cannot disclose your On-Device Data because we do not have it.

8. Security of Data

Keeping your financial data on your own device is central to how we protect it — there is no central server holding your receipts for an attacker to target. For any Personal Data you do send us, the security of your data is important to us, but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect it, we cannot guarantee its absolute security. We also recommend you protect your device with a passcode or biometric lock.

9. Your Data Protection Rights Under GDPR

If you are a resident of the European Union (EU) or European Economic Area (EEA), you have certain data protection rights covered by the GDPR. We aim to take reasonable steps to allow you to correct, amend, delete or limit the use of any Personal Data we hold about you.

In certain circumstances, you have the right to access, update or delete the information we have on you; the right of rectification; the right to object to our processing; the right of restriction; the right to data portability; and the right to withdraw consent. To exercise any of these rights, please email us at expenditi@neumeral.com. Note that most of your data lives only on your device and is under your direct control there.

10. Your Data Protection Rights Under CalOPPA & CCPA

If you are a California resident, you are entitled to learn what data we collect about you, ask us to delete it, and ask us not to sell it. We do not sell your personal information. You may visit our website anonymously, and this Privacy Policy is clearly linked from our home page. We honor “Do Not Track” signals on our website. To exercise your California privacy rights, email us at expenditi@neumeral.com.

11. Service Providers

For our website and communications, we may employ third-party companies (“Service Providers”) to facilitate our Service, provide it on our behalf, or help us understand how our website is used. These third parties have access only to the limited Personal Data needed to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. Our Service Providers do not receive your On-Device Data.

12. Analytics

We may use privacy-respecting third-party analytics on our website to understand aggregate traffic. Any such analytics measure website visits, not your in-App financial activity. Where we use a provider that offers an opt-out, you can exercise it through that provider's tools or your browser settings.

13. Payments

If Expenditi offers paid features, payments are processed by the app store you downloaded the App from (such as the Apple App Store or Google Play) or by a third-party payment processor. We do not store or collect your payment card details. That information is provided directly to the store or processor, whose use of your information is governed by their own privacy policy and who adhere to PCI-DSS standards.

14. Links to Other Sites

Our Service may contain links to other sites that are not operated by us. If you click a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over, and assume no responsibility for, the content or privacy practices of any third-party sites or services.

15. Children's Privacy

Our Service is not intended for use by children under the age of 13 (“Children”). We do not knowingly collect personally identifiable information from Children under 13. If you become aware that a Child has provided us with Personal Data, please contact us so we can remove it.

16. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last updated” date at the top. You are advised to review this Privacy Policy periodically for any changes. Changes are effective when they are posted on this page.

17. Contact Us

If you have any questions about this Privacy Policy, please contact us by email at expenditi@neumeral.com.