Notes
Notes from The Brink Labs Budgeting App Privacy: A 15-Minute Audit Anyone Can Run
The Brink LabsLast reviewed
Your spending history is one of the most revealing records you own. A study of three months of card records for 1.1 million people found that four purchases were enough to single out 90% of them, even with names removed (Science, 2015). Yet most people choose a budgeting app on features and price, and take its privacy on trust.
You don't have to. Seven checks, about 15 minutes, no technical skills. Together they show what any Android finance app collects, who it shares data with, and whether it needs the internet at all. At the end, we run the same audit on our own app — including the results that don't flatter us.
The Audit At A Glance
| # | Check | Where | Time | A good answer |
|---|---|---|---|---|
| 1 | Data safety label | The app's Google Play listing | 2 min | No data shared; anything collected is encrypted in transit and can be deleted |
| 2 | Privacy policy, five words | The developer's website | 3 min | A plain no to selling and sharing |
| 3 | Tracker report | εxodus Privacy | 2 min | 0 trackers |
| 4 | Permissions | The εxodus report | 2 min | Every permission matches a feature you can see |
| 5 | Airplane-mode test | Your phone | 3 min | Logging, budgets and reports still work |
| 6 | Background data | Your phone's settings | 1 min | Near zero unless you back up or sync |
| 7 | The exits | Inside the app | 2 min | Full export; a backup only you can open |
1. Read The Data Safety Label — Then Discount It
On the app's Play listing, open Data safety. It splits what the developer declares into data collected (anything the app sends off your phone, including through code libraries bundled inside it) and data shared (anything passed on to another company).
Three lines deserve your attention:
- Financial info listed as shared. Your transactions or balances go to a third party.
- "Data isn't encrypted." What the app collects travels without encryption.
- No way to request deletion. Once collected, it stays.
Now the limit. The developer fills in this label, and Google's own guidance tells developers they alone are responsible for its accuracy and that Google's review isn't designed to verify it (Google Play Console Help). Google's page frames it the same way: the label is information the developer provided. Treat it as a claim to test, not a certificate. One detail works in your favour: data an app processes only on your phone doesn't count as collected. An app that keeps your ledger on the device can therefore honestly declare far less than one that syncs it to a server.
2. Search The Privacy Policy For Five Words
Open the policy and use find-in-page. Five searches cover most of what matters:
- "Sell." A plain "we do not sell" is the answer you want. "We do not sell, except…" is a different answer.
- "Share" or "third parties." Who receives data, and which data. Hosting and payment providers are normal; advertisers and unnamed "partners" deserve a closer look.
- "Advertising" or "marketing." Whether your data shapes ads, inside the app or elsewhere.
- "Aggregate," "de-identified" or "anonymized." This clause often permits using or licensing transaction data once names are stripped. The study above is why that offers less protection than it sounds.
- "Retain" or "retention." How long data is kept after you leave, and whether deleting the app deletes it.
3. Look The App Up On εxodus
εxodus Privacy is a non-profit that analyses Android apps and publishes free reports. Search the app's name, or its package name (the part after id= in its Play link), at reports.exodus-privacy.eu.org. If no report exists yet, you can request one there.
A report lists two things:
- Trackers: analytics, advertising, attribution and crash-reporting code found inside the app.
- Permissions: everything the app declares, including permissions Android never asks you about, such as full network access.
Know its limit too. εxodus recognises known tracker code inside the app; it doesn't watch what the app sends, and it can't flag a tracker it has never seen. Zero trackers is a strong signal, not proof — which is why checks 5 and 6 exist.
4. Match Every Permission To A Feature
A budgeting app needs very little. For each permission on the list, ask one question: which feature that I can see uses this?
- Usually explainable: internet (backup, sync, purchases), notifications (reminders), biometrics (an app lock), alarms and start-up (reminders that still fire after a restart).
- Worth a question: location, contacts, camera or microphone. Few budgeting features need any of them.
- Read the fine print: SMS and notification access. Some expense trackers read bank alerts to create entries automatically. It's convenient, and it means the app can read every message in that inbox, or every notification on your phone — not only the bank's.
5. Run The Airplane-Mode Test
This is the most telling check of the seven. Turn on airplane mode, make sure Wi-Fi is off too, then open the app and:
- Log an expense.
- Move money between two budget categories.
- Open a report or chart.
If all three work, your data is being processed on your phone. If you get a spinner, an error or a sign-in screen, your ledger lives on a server and the app is a window onto it. Neither design is automatically wrong, but you should know which one you're trusting. Working offline doesn't prove an app never uploads later, so pair this with the next check.
6. Check Background Data Use
Android records how much mobile data and Wi-Fi each app uses. The path varies by manufacturer: search Settings for "data usage," or open the app's App info page and look for mobile data and Wi-Fi.
An app you have never synced or backed up should show very little. A steady trickle on days you didn't open it means something is being sent. Go back to the policy and find out what.
7. Test The Exits
Privacy includes the freedom to leave.
- Export: can you export every transaction to CSV, a plain file any spreadsheet opens?
- Deletion: if there is an account, is there a delete button, and does the policy say what deletion removes?
- Backup: is the backup encrypted on your phone before it leaves, and who holds the key — you or the company? A backup the company can open is a copy of your finances on its servers.
Three Choices Behind Every Result
Most of what the seven checks turn up traces back to three design choices every budgeting app makes. Each one trades convenience against exposure:
- Bank sync: how your transactions get into the app.
- Telemetry: what the app reports about how you use it.
- Offline-first: where your ledger lives.
Bank Sync: The Trade You Are Making
Many budgeting apps import transactions by connecting to your bank. That connection usually runs through a data aggregator, a company that reads your bank data on the app's behalf and passes it along. Access is typically read-only and you consent to it. The trade is breadth and duration: your full transaction history passes through at least one company besides your bank and the app, and it keeps flowing until you revoke access.
If you use bank sync:
- Review the connected apps in your bank's settings and revoke the ones you no longer use.
- When you stop using a budgeting app, delete its account, not just the app.
The alternative is manual entry, or importing a statement file you download yourself. It costs a few seconds per purchase. It is also the only setup in which no company but your bank ever holds your transaction history.
Telemetry: Data About How You Use The App
Telemetry is data about your behaviour inside an app: screens opened, buttons tapped, session length, device model, crashes. It usually flows to third-party analytics and crash-reporting services bundled into the app. An app can keep your transactions private and still report how you use it — and in a finance app, how often you open the debt screen, and when, is personal too.
Zero telemetry means no analytics or crash-reporting code in the app at all, not code that is present and switched off by a setting. Check 3 shows which one you have. The cost is real: the developer gets no automatic crash reports. The honest substitute is an on-device diagnostic log that you read in full and choose to send.
What Offline-First Actually Means
Three designs give three different answers to one question: where does my money data live?
| Cloud-first | Offline-first | Local-only | |
|---|---|---|---|
| Primary copy of your ledger | The company's servers | Your phone | Your phone |
| Works without a connection | Partly, or not at all | Fully, for core features | Fully |
| Network used for | Everything | Named, optional features such as backup | Nothing |
| If you lose your phone | Sign in elsewhere | Restore a backup you made | Gone, unless you exported it |
Offline-first keeps your phone as the source of truth and treats the network as optional plumbing for features you name and switch on. It asks one thing of you in return: make a backup, because nobody else holds a copy.
We Ran The Audit On MyneWallet
MyneWallet is a private, offline expense tracker and zero-based budget planner for Android. We build it, so don't take our word for any of this — every line below is something you can check with the seven steps above.
- Data safety: "No data shared with third parties" and "No data collected." It's still our own declaration, which is why the rest of this list exists.
- Privacy policy: no account, no analytics, no advertising and no servers of ours that receive your ledger; a plain no to selling, renting or sharing data. Read it here.
- Trackers: no analytics, crash-reporting or advertising SDKs. They were removed from the code, not switched off. There's no public εxodus report for MyneWallet yet; we'll link one here once it's published.
- Permissions: the feature-facing ones are internet (Google Drive backup and Google Play purchases only), notifications and exact alarms (reminders), start-up (re-arming reminders after a restart) and biometrics (App Lock). There is no location, contacts, SMS, notification-access, camera or microphone permission.
- Airplane mode: logging, budgets, reports and App Lock all work. Drive backup and Google Play purchases need a connection, which is why we say MyneWallet works fully offline for its core features, not for everything.
- Background data: near zero unless you turn on Drive backup.
- Exits: CSV export of everything, with no upgrade required. There is no account, so there is nothing of yours on servers of ours to delete. Backups are encrypted on your phone with AES-256-GCM, using a key derived from your passphrase with PBKDF2-HMAC-SHA256 at 600,000 iterations, then stored in a hidden app folder in your own Google Drive or in a file you save. We never see the passphrase. Lose it, and we can't open the backup for you.
What it doesn't do, said plainly:
- The working copy isn't encrypted by MyneWallet itself. It sits in Android's private app sandbox, walled off from other apps and protected by your phone's own built-in encryption. Someone holding your unlocked phone with root access could read it. App Lock covers the everyday case of someone picking up your phone.
- Android's automatic cloud backup is switched off for MyneWallet, so the system never copies the unencrypted ledger off your phone. The only copies that leave are the encrypted backups you choose to make.
- There is no bank sync, by design. You log purchases with Quick Add, or import a CSV file from your bank.
The same standard applies to this page. It sets no cookies and loads nothing from any other website. Open your browser's Network tab to confirm it, or read exactly what this website does with data.
We're a small lab, and the point of this audit is that you shouldn't need to trust a small lab — or a large one. If you'd like to run it on MyneWallet yourself, it's on Google Play. The same seven checks work on every other app you're considering.
Questions
Questions.
Do budgeting apps sell your data?
It depends on the app, and the answer sits in two places you can read in minutes. Search the privacy policy for "sell," "share" and "aggregate," then compare it with the Data safety label on Google Play. Watch for clauses that allow using or licensing "de-identified" transaction data: research on card records shows spending data is easy to re-identify.
Is it safe to link my bank account to a budgeting app?
Linking usually grants read-only access you consent to, often through a data aggregator. The trade-off is reach and duration: your full transaction history passes through at least one company besides your bank and the app until you revoke access. If you link, review connected apps in your bank's settings and delete the budgeting app's account when you stop using it.
Can a budgeting app work without the internet?
Yes. An offline-first app keeps your ledger on your phone and works without a connection for its core features. To test any app, turn on airplane mode, switch off Wi-Fi, then log an expense, move money between categories and open a report. If all three work, the app processes your data on the phone.
What does "zero telemetry" mean?
It means the app contains no analytics or crash-reporting code at all, so no data about how you use it is sent automatically. That is different from telemetry that is present but switched off in settings. You can check for tracker code in the app's εxodus Privacy report.
If an app's backups are encrypted, is its data encrypted too?
Not necessarily. Backup encryption protects the copy that leaves your phone. The working copy on the phone may rely on Android's app sandbox and the phone's built-in encryption instead. Read the policy for both, separately: an honest app states the difference plainly.