Oneby2
Last updated 14 September 2026
Oneby2 is built to work without knowing anything about you. There is no account and no sign-in. Your transactions, accounts, budgets, notes and receipts are stored only on your device and never leave it — with a handful of narrow, disclosed exceptions described below. All but one only ever happen when you deliberately trigger them; the one that doesn't (a crash report) is called out plainly under Network access.
Nothing about your finances, with exactly one exception. There is no account, no sign-in, and this app runs no analytics of its own. Three Google-provided components used elsewhere in the app exchange their own technical data with Google when you use them — never your financial data. AI Insights is the one feature that is different: only if you turn it on, and only when you ask it something, it sends a summary of your own figures — category totals, net worth, budget progress, never a merchant, a note or an account name — to the AI provider you set up. Every case is covered under Network access below.
Only on your device, in a database encrypted with a key held in the Android Keystore. Uninstalling the app deletes it. Export a CSV first if you want to keep a copy — see Your data is yours.
Five things can reach the internet. Skip the first four and only crash reports still go out:
Scanning a receipt needs no network at all — recognition happens on your phone, from a model shipped inside the app, though Google's library may report its own usage data. See If you scan a receipt.
Tapping Share on a shared expense (Split) sends that one expense's description, amount, date, and the names of who paid and who owes what to Firebase, so the friend you send the link to can confirm or dispute it with no install and no account of their own. Nothing else about your ledger goes with it — not your other transactions, not your accounts, not any other expense. The link expires after 30 days, and you can revoke it yourself at any time from the same Share sheet.
Once a day the app downloads AMFI's daily NAV file — the public price list for every Indian mutual fund, published free for exactly this use — and keeps it on your phone so a holding's value is current. It is a download and nothing more: the request says which file it wants and nothing about you, and no part of your ledger, your holdings or your identity leaves the phone. The daily fetch runs only while you actually hold something priced this way, and stops once you remove the last one.
Off by default, and does nothing until you paste your own API key — for Anthropic, OpenAI or Google — and ask a question. What is sent is a summary this app builds fresh each time — this month's category totals, net worth and budget progress — never a merchant name, a transaction note, an account name or a person's name. That summary goes to the provider you set up, using the key you entered, billed to your own account there — this app runs no server of its own for this and never sees what it costs. Nothing about the question or the answer is saved once you leave the screen. Removing the key at any time turns the feature back off.
One condition specific to a single provider: on Google's free Gemini tier, Google's own terms permit using what you send to improve their products — a paid Gemini plan does not carry that condition. That is Google's policy for their free tier, not something this app has any part in.
A crash report — the stack trace, the app version, and what kind of device you're on — uploads automatically to Firebase Crashlytics, Google's crash-reporting service, so a bug that only shows up on one phone can still be found and fixed. It carries technical details about the failure, never your transactions, accounts, notes or receipts. This is the one exception to every other line on this page: it happens automatically, with no prompt and no way to turn it off from inside the app, because releasing worldwide with no visibility into real crashes was judged the worse tradeoff. The diagnostic log below, by contrast, stays on your phone until you choose to share it.
The app needs no permissions to do its job. It never asks for SMS access, contacts, or location. Two optional features ask separately, only when you turn them on: notifications, if you want a reminder, and notification access, if you want bank alerts captured. Declining either leaves the app fully usable.
Only apps you tick are read, and only to pull out an amount, merchant, date and card digits. The notification text is never saved — not in the app, not in a log, not in a backup. Reading happens on your phone and nothing is uploaded. Every capture waits as a draft until you confirm it.
The scan runs entirely on your phone, using Google's on-device text recognition. The model is built into the app rather than fetched when you first use it, so scanning works in aeroplane mode and on a phone with no Google Play services at all. Google's recognition library may still report diagnostic and usage data of its own — separately from, and never including, the photo or the text pulled from it. Neither the receipt image nor its contents are uploaded anywhere by this app.
Purchases are handled entirely by Google Play Billing, which contacts Google's payment servers to process them — this app never sees your payment details and has none to protect. Google's own privacy policy covers that exchange.
The app keeps a short record of its own failures — a backup that did not run, an export that did not finish — so there is something to send when you report a problem. It records what the app did, never what you spent: no amounts, merchants, notes or account names. You can read it in the app under Settings › Diagnostics, and it is sent nowhere unless you choose to share it.
CSV export is free, always, and never restricted. There is nothing to lock you in.
There is no account for us to delete, because there is no account. Uninstalling the app removes everything it stored on your device. A shared expense sent through the Share feature is deleted from Firebase automatically 30 days after it's sent, or sooner if you revoke it yourself from the Share sheet — whichever comes first. A crash report sent to Firebase Crashlytics is retained under Google's own Crashlytics data-retention policy, not this app's. AI Insights keeps nothing at all after you leave the screen — no question, no answer, no summary is ever written to storage this app controls.
Oneby2 is a personal finance app intended for a general adult audience and is not directed at children. It does not knowingly collect information from children.
If what the app collects or how it handles data changes, this page and the in-app Privacy screen (Settings › Privacy) are updated together, and the date at the top of this page will change.
Questions about this policy or your data can be sent to kaydeeslabs@gmail.com.