Privacy Policy
This Privacy Policy describes how Valtero (“the App”) handles information when you use the desktop or Android application.
Valtero is a personal expense and income tracker. There is no Valtero-operated backend server that collects or stores your expenses. Your expense data stays on your device unless you choose an optional integration described below.
1. Information stored on your device
The App stores expenses, income entries, tags, payment methods, exchange-rate cache, settings, and similar data locally using on-device SQLite (Drift) and Hive. This information is not sent to the developer by default.
2. Google Drive Sync (optional)
If you enable Google Drive Sync, the App uses Google OAuth 2.0 with PKCE to request access to Google APIs on your behalf. Depending on the sync flow you choose, the App may request:
- drive.appdata — read/write an encrypted sync snapshot in Google Drive’s app-specific folder for personal sync
- drive.file — only when you create a cross-account shared sync file that the App created
- drive (full Drive access) — only when a second Google account joins a shared sync, so the App can discover files shared with that account
- userinfo.email — to show which Google account is connected
Sync snapshots use client-side encryption (encrypted .valterobackup
files). Your sync passphrase stays on your device and is not sent to Google
or to the developer. Encrypted data stored in Google Drive is also subject
to
Google’s Privacy Policy.
You can disconnect Google Drive Sync in the App and revoke access at any time in your Google Account: myaccount.google.com/permissions.
3. Other optional integrations
- Telegram — if connected, your bot token and chat id are used only to send exports you explicitly trigger
- Frankfurter and ExchangeRate-API — used to fetch currency exchange rates; no personal expense content is sent
- ip-api.com — may be used once for country/currency suggestions based on IP geolocation; you can ignore or override suggestions
Integration credentials you enter (API keys, Telegram tokens, Google OAuth tokens, sync passphrase) are stored on your device and are excluded from exported encrypted backups that are designed not to include those secrets.
4. Voice input (Android only)
On Android, optional voice expense capture uses the device speech recognition service. Audio and transcripts are not persisted by Valtero; they are held in memory for the capture session only. Recognition errors may be written to the App’s local log without the spoken text.
5. Logging
The App can write redacted diagnostic logs to a local file on your device (errors and warnings always; verbose debug breadcrumbs only if you enable them). Logs are not uploaded automatically. Secrets are redacted before being written.
6. No advertising or sale of data
Valtero does not include advertising SDKs, analytics/tracking SDKs, or sell your personal data.
7. Children
The App is not directed at children under 13 (or the equivalent minimum age in your jurisdiction).
8. Your choices
- Do not enable optional integrations if you do not want those network features
- Disconnect integrations and revoke Google access as described above
- Uninstalling the App removes local App data from that device (subject to OS backup behavior)
9. Contact
Privacy questions: 6y6jlbmail@gmail.com