Privacy Policy

Last updated: 11 August 2026

Introduction

Amble ("we," "us," "our," "the app") is a personal finance app designed around a simple principle: your financial data belongs to you, and only you. This policy explains what information Amble interacts with, how it's handled, and why — in plain terms.

Amble is published by an individual developer, Mohammad Fahham Khan, registered as a personal developer account on Google Play.

The short version

Amble does not operate servers that store, process, or have access to your financial data. All entries you make are stored locally on your device and encrypted before anything ever leaves it. When you back up your data, it's encrypted on your device first, then stored in your own personal Google Drive — in a private storage area only your Amble app can access, not a folder you browse yourself, and never on infrastructure we control. We cannot read, recover, or reconstruct your financial data, under any circumstance, including if compelled to try.

What information we collect

Information you enter into the app

Everything you record in Amble — income, categories, expenses, savings goal — is created and stored locally on your device. This data is encrypted using keys derived from your PIN and your device's platform identity before it ever leaves your device, including for backup purposes. We do not have a copy of this data, do not have access to the encryption keys required to read it, and cannot view, recover, or restore it on your behalf.

Google Sign-In and Google Drive

Amble uses Google's Credential Manager and Authorization APIs to let you sign in and to enable encrypted backups. Through this:

  • We request access to Google's drive.appdata scope, a private, hidden storage area tied to your Google account that only Amble can read or write to — it is not visible in your regular Google Drive, and Google does not grant us access to any other files in your Drive.
  • Your Google account identity (such as your email address) is used locally on your device to help derive your encryption keys and to authenticate you with Google's services. We do not transmit this identity information to any server we operate, because we do not operate a server that receives it.

Information we do not collect

As of the date of this policy, we do not use analytics, tracking, or crash-reporting tools of any kind. We do not collect device identifiers, usage statistics, behavioural data, or advertising identifiers. We do not run advertising in the app and do not share data with advertisers, because there is no data on our servers to share.

Information collected by Google Play and Google's platform services

Separately from Amble itself, Google collects certain information as part of operating the Play Store and Android platform (such as install/crash data visible to us in aggregate through Play Console, if enabled). This is governed by Google's own Privacy Policy, not this one.

How your data is protected

  • Local-first: Your data lives on your device by default. Nothing is sent anywhere unless you choose to enable backup.
  • Client-side encryption: Encryption happens on your device, before data is transmitted, using keys derived from your PIN combined with your device's platform identity. We never receive your PIN, your derived keys, or your unencrypted data.
  • Zero-knowledge architecture: Because we never hold the keys needed to decrypt your data, we are structurally unable to access it — not as a policy choice, but as a technical fact of how the app is built. This also means we cannot recover your data for you if you lose your PIN and no longer have the original device — please keep appropriate backups of your recovery information.
  • User-owned storage: Encrypted backups are stored in your own Google Drive account, under Google's own security and infrastructure — not on servers owned or operated by us.

Your rights

Depending on where you live, you may have rights under data protection law (such as the UK GDPR) including the right to access, correct, delete, or export your data, and to object to or restrict certain processing.

In practice, because we do not hold your financial data, most of these rights are exercised directly within the app or through your own Google account settings:

  • Access and export: Your data is already on your device and in your own Google Drive; you can view or export it directly.
  • Deletion: Deleting the app and your local data, and removing Amble's backup data from your Google Drive (via your Google Account's third-party app data settings), removes your information entirely — we hold no separate copy to delete on our end.
  • Correction: All entries are editable directly within the app, apart from your PIN.

If you have questions about exercising these rights, contact us at info@amble.live.

Children's privacy

Amble is not directed at children and is not intended for use by anyone under the age of 16. We do not knowingly collect information from children, and given our architecture, we do not collect personal information from any user, child or otherwise.

International data

Because your data is encrypted on your device and stored in your own Google Drive account, its storage location follows Google's own infrastructure and your Google account settings, not a jurisdiction we choose. We do not transfer your data internationally ourselves, as we do not receive or hold it.

Changes to this policy

If we update this policy — for example, when we introduce new features such as subscriptions — we'll update the "Last updated" date above and, for material changes, notify you within the app.

Contact us

If you have questions about this policy or how Amble handles data, contact us at info@amble.live.