Terms of Use · Impressum / Legal Notice · Deutsch
Last updated: September 4, 2026
This privacy policy applies to the Android app ExpiKeep
(package ID: com.expikeep.licenses).
Robert Peringer
Ittlinger Hauptstraße 17
94315 Straubing
Germany
Email: FsNaviVfr@gmail.com
ExpiKeep is a record-keeping app for things that expire or renew themselves — domains, annual licences, maintenance contracts, certificates, hosting and subscriptions to developer tools. The data you enter (provider and description, cost, currency, payment interval, next renewal date, kind of entry and — if you enter them — the customer or contract number, the notice period and the expiry date) is stored in a local database on your device. A document you attach to an entry or to a logged payment — a photo or PDF of an invoice or a licence document, optionally taken with the camera on the spot — is stored as a file in the app’s private storage on the same device (see Section 3.2). There is no user account, no registration, and no server/backend of our own. The app itself never transmits your entry data, or the documents you attach, to the developer or any third party.
Some of this data is worth protecting, though none of it is a special category under Art. 9 GDPR. This app records no health data, and this policy claims no Art. 9 basis it does not need. What it does record still deserves care, for two concrete reasons. A customer or contract number identifies you to your provider, and in a support channel it is often most of what is needed to be treated as you. And a list of domains, hosting contracts and developer tools describes your projects and, for a freelancer or a small business, your commercial activity — what you run, for how long, and how much of it there is. ExpiKeep is built so that this data never leaves your device by any route the app controls: it is recorded because you chose to record it, it is used only to show your entries and to schedule local reminders, and there is no account and no server it could be sent to.
Some functions involve third-party services: Google Play Billing is used to process premium purchases, and the Frankfurter API may be contacted directly from your device to fetch exchange rates when you use the currency conversion feature. Neither receives your entry data. No advertising, analytics, or tracking services are used.
If Android’s Auto Backup feature is enabled on your device, the app’s local database and any documents you have attached may be included in a backup associated with your Google Account. The developer has no access to such backups (see Section 5).
Provider and description, cost, currency, payment interval, next renewal date, kind of entry and — if you enter them — the customer or contract number, the notice period in days and the expiry date are stored, for each entry you add, in the app’s local database on your device. This data is used to display your entries and to schedule local reminder notifications before a renewal date, before a notice period you entered runs out, or before an entry expires. It is never uploaded to a server operated by the developer.
The customer or contract number is the field to be aware of: it identifies you to your provider. It is optional in the sense that the app works without it, and it stays on your device either way.
The app deliberately has no field for a licence key, a serial number or a password, and none of these belongs in the free-text fields it does have. The name is shown in full in the entry list; a long contract number appears there with its beginning and end only, and in full inside the opened entry. Anyone who can see the screen — or a screenshot of it — reads what is shown there.
If you pick one of the symbols that ship with the app for an entry, that choice is stored there as well. The symbols are part of the app; no image is uploaded and none is fetched from the internet.
When you tick off a payment, or add one yourself, a record is stored in the payment history: name, amount, currency and date. That data stays in the local database on your device as well.
If you turn on the setting that records elapsed payments automatically, the app creates such records itself, without you ticking anything off. When an entry’s renewal date lies in the past, it writes one record per elapsed payment interval, dated to the day that charge fell due. The values come solely from what you already entered for that entry; nothing is fetched and no other source is consulted. The setting is off by default and can be turned off again at any time, at most 24 records are added per entry in one run, and a record created this way can be edited and deleted like any other.
For any payment you log you can attach up to ten documents — typically the invoice or the payment confirmation. There are three ways to do so: an existing photo from your gallery, an existing file from your device storage (a photo or a PDF), or a photo you take with your device camera then and there. The app then makes its own copy in its private storage on your device; photos are scaled down and re-encoded in the process. The metadata embedded in the original does not survive that — including the place the photo was taken and the camera model, where your device had written them. Only the orientation is carried over, so that a document photographed upright is not shown lying on its side. Only the file name of that copy is written to the local database, and an original you picked is left untouched.
When you take a photo, the app does not open the camera itself; it hands the capture to the camera app on your device. That app writes the image into a temporary file in ExpiKeep’s cache, from which the app produces the scaled copy; the temporary file is then deleted. Cancelling the capture deletes it too. Whether the camera app additionally keeps its own copy in your gallery is decided by the camera app alone; ExpiKeep has no influence over that.
A document is free-form content and can therefore contain more than the fields you type elsewhere in the app — a customer or contract number, your name and address, the last digits of a payment card, a provider’s details, or anything else printed on the document. Please bear that in mind when deciding what to attach.
The app does not read, analyse, or interpret what a document contains, and does not upload it to the developer or to any third party. None of the three routes requires an additional Android permission for the app: an existing file is chosen in the Android system’s own photo picker or document picker, which grants the app access to that single file only, and for a capture the camera app asks for whatever permissions it needs itself (see Section 4).
Removing a document from an entry, or deleting the entry itself, also deletes the stored copy from your device. Uninstalling the app or clearing its data removes all stored documents.
Unlike the rest of your data, a document is a file rather than a database row, and it is included in Android’s Auto Backup alongside the database. If Auto Backup is enabled on your device, attached documents can therefore form part of a backup associated with your Google Account (see Sections 5 and 6).
Paid premium features are purchased through Google Play Billing. Payment details (card numbers, billing address, etc.) are processed entirely by Google, which acts as an independent data controller for that processing — ExpiKeep never sees or receives your payment details.
To determine whether premium features should be unlocked, the app queries your purchase status directly from Google Play each time it starts. This purchase information is not transmitted to the developer — there is no developer-operated server to receive it — and is not stored on your device either; it is only held in memory for the current app session. See Google’s Privacy Policy.
If you use the Insights screen to display totals in a currency other
than the one an entry was recorded in, the app fetches current
exchange rates from the free, keyless Frankfurter API
(api.frankfurter.app, based on European Central Bank reference
rates) over the internet. The purpose of this request is solely to
convert amounts between currencies for display; no entry data
or other personal data is included in or derived from this request,
only the currency codes needed to look up a rate. The request is sent
directly from your device to the Frankfurter API; the developer does
not operate or route this request through its own server, does not
receive this request, and the app does not store your IP address. As
with any network request, your device’s IP address is technically
visible to the Frankfurter service and any technical infrastructure
providers (for example hosting or content-delivery services) it
relies on to operate that API. How long that connection data is
retained is determined by those services’ own policies, not by the
developer, who has no control over it. Fetched rates are cached
locally on your device for 24 hours to minimize how often this
request is made.
The app declares and uses the following Android permissions:
| Permission | Purpose |
|---|---|
Notifications (android.permission.POST_NOTIFICATIONS) |
Used to remind you before a renewal falls due, a notice period runs out or an entry expires. Reminders are scheduled entirely on your device. On Android 13+, this requires your explicit consent, which the OS will ask for. |
Internet (android.permission.INTERNET) |
Used for Google Play Billing and fetching exchange rates for currency conversion (see 3.3–3.4). This is a standard permission automatically granted at install time, not something you are separately prompted to approve. |
The app does not request access to your contacts, location, camera, microphone, photos, or other sensitive device data.
This includes attaching a document. An existing file is chosen in the Android
system’s own photo picker or document picker, which hands the app a read grant
for the single file you selected and nothing else. The app therefore does not
declare READ_MEDIA_IMAGES or any comparable storage permission.
Taking a document photo does not require a camera permission for the app
either. The picture is taken by the camera app on your device, using its own
permissions; ExpiKeep merely provides a temporary file for it to write into,
and does not declare android.permission.CAMERA.
The app uses Google Play Billing to process premium purchases, and the Frankfurter API to fetch exchange rates for currency conversion in the Insights screen (see 3.4). No advertising, tracking, or analytics/statistics SDKs are used (e.g. no Google Analytics, Firebase Analytics, or similar).
The app also supports Android’s built-in Auto Backup, which — if enabled on your device — automatically backs up the app’s local database and the document files you have attached, as part of the standard Android OS backup service. The backup is handled by Android and associated with your Google Account; the developer does not operate this backup service and has no access to its contents. See Google’s documentation on Android Auto Backup for details, and Android’s device backup settings to control it.
The data you enter is stored in the app’s local database on your device, and documents you attach are stored as files in the app’s private storage on the same device. Both remain there until you edit or delete them, or delete the app’s local data. The developer does not operate its own server and does not receive or disclose this data to third parties.
If Android Auto Backup is enabled for ExpiKeep, this local database and the attached document files may also be included in a backup associated with your Google Account, as described in Section 5.
Under the GDPR, you generally have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), and restriction of processing (Art. 18). Where the respective legal requirements are met, you may also have the right to data portability (Art. 20 GDPR) and the right to object to processing based on legitimate interests (Art. 21 GDPR).
Since ExpiKeep does not store or transmit your entry data, or the documents you attach, on the developer’s side, most of these rights are already effectively in your own hands: you can view, edit, or delete your data directly in the app at any time. This is not the same as formally exercising a right under the GDPR, however. To formally invoke any of the above rights — for example regarding the limited technical data described in Sections 3.3–3.4 — please contact the developer using the details in Section 10.
Deleting the app or its local data removes this data from your device. If Android Auto Backup is enabled, a backup may remain associated with your Google Account until it is managed or deleted through Android’s backup settings or your Google Account — the developer cannot delete this on your behalf, as it has no access to it (see Section 5).
You also have the right to lodge a complaint with a data protection supervisory authority.
Where the GDPR applies, different processing activities described in this policy rely on different legal bases:
This privacy policy may be updated as needed, for example due to changes in the app’s functionality or legal requirements. The current version is always available via the link provided in the app and in the Play Store listing.
For privacy-related questions, please contact: FsNaviVfr@gmail.com
ExpiKeep names no registrars, certificate authorities, hosting providers or software vendors. The quick-fill entries the app offers when you create an entry name kinds of thing — domain, annual licence, maintenance contract, certificate, hosting, developer tool — and never a company. You type the provider’s name yourself, into a free-text field; whatever you enter there is your own text and stays on your device.
Any trademarks that may appear in a document you attach are the property of their respective owners. The app does not read, analyse or interpret what a document contains.