This Privacy Policy explains what information Spika collects, how it's used, and how you can control it. Spika is a personal finance tracking app distributed on Google Play.
1. Information we collect
- What you enter: transactions, accounts, categories, budget/income settings, your display name, and an optional profile photo stored locally.
- Google account info (only if you sign in): basic profile details from Google Sign-In — name, email, photo. We only request Drive access when you turn on backup or confirm a restore, never during ordinary sign-in.
- Permissions you grant: microphone (for voice entry), notifications, network access.
- App preferences stored on your device: theme, language, currency, backup settings.
- Diagnostics: crash reports and basic usage stats via Firebase (Section 4). These never include your financial data.
By default, everything above stays on your device. We don't run a Spika-owned server that stores or reads your transactions.
2. Backups (Google Drive, optional)
When you turn on Drive backup in Settings, Spika encrypts your data on your device — using a key derived from your App Lock PIN — before uploading it to the hidden App Data folder in your Google account. Google can't derive this key from your account, and restoring on a new device requires the same PIN (biometrics don't work for this). If you forget your PIN, account recovery unlocks the app but can't decrypt an existing backup — only the original PIN can.
3. Other places data touches
- Voice entry (Spika Now) uses your device's built-in speech-to-text service, which may send audio off-device depending on your OS and speech provider.
- Market prices (metals, currencies) are fetched from public data providers — these requests never include your transaction data.
- If you contact us or answer a feature poll, that message (plus your locale and OS) reaches us through a Google Apps Script webhook.
4. Who we share with
We don't sell your data or share your transaction history with advertisers. Limited processing happens through:
- Google — Sign-In, Drive backup, Firebase Analytics and Crashlytics
- Your device's speech service — if you use voice entry
- Google Apps Script — for contact and feedback messages
- Market data providers — jsDelivr (World Bank reference data), currency-api.pages.dev, gold-api.com
- Google Play — app distribution, and future subscriptions
Firebase Analytics and Crashlytics never receive your financial data — only usage events (app opens, sessions) and crash reports (stack traces, device and app version).
5. Security
- App Lock: a PIN or biometric lock blocks the main app. Repeated wrong PIN attempts are throttled, and if Spika can't verify the lock state, it stays locked rather than opening.
- Your local database is encrypted at rest with a device-bound key stored in Android Keystore — separate from your PIN and from backup encryption.
- Spika doesn't block screenshots or recent-apps previews — anyone with your unlocked device can see what's on screen.
- Release builds are signed with a private key kept outside the app's source code.
No storage or transmission method is perfectly secure — keep your device and Google account protected.
6. Retention & deletion
- Local data stays until you delete it in-app or uninstall Spika.
- Drive backups stay until you remove them (via restore/overwrite, Google account tools, or in-app controls) — uninstalling doesn't delete an existing backup.
- Firebase data is kept by Google per their standard practices until we delete it; uninstalling stops further collection from that device.
7. Your choices
- Use Spika without Google Sign-In (local-only features)
- Turn off backup, notifications, or microphone access anytime
- Sign out of Google from Settings
- Forgot your PIN? Use in-app PIN recovery — it confirms you're still signed into the same Google account, then lets you reset the PIN. This doesn't decrypt an existing Drive backup, which still needs the original PIN.
- Delete your data: use “Delete all data” in Settings for local data, or remove a Drive backup separately via backup controls or your Google account.
- Email spika.support@gmail.com for anything else
8. Children
Spika isn't directed at children under 13 (or the minimum age required where you live). Please don't use it if you're under that age.
9. International users
Google Play services are required for Sign-In and Drive backup; the app works offline without them. Since your data lives mainly on your device and your own Google account, processing generally follows wherever you and Google operate.
10. Subscriptions (future)
Spika is free today. If we add paid plans later, Google Play (or another store, if we expand distribution) will handle billing, prices will be shown before purchase, and we won't charge you without your confirmation.
11. Changes
We'll update the effective date above whenever we revise this Policy. Continuing to use Spika after a change means you accept the revised Policy.
12. Governing law
This Policy follows the laws of the operator's country of residence, except where mandatory consumer protections in your country require otherwise — those rights still apply.
13. Contact
spika.support@gmail.com — also see our Terms of Service.