mTagger Back to site
Last updated 2 September 2026

Privacy Policy — mTagger

mTagger is an expense tracker for M-Pesa users in Kenya. It reads the transaction messages Safaricom already sends you, works out what each payment was, and adds them up.

This policy describes what the app does with your information. It is short because the app does very little with it. It sits alongside the Terms of Service, which cover what the app is and is not responsible for.

Who is responsible for your data

mTagger is provided by Roy Thande, an individual developer based in Kenya. For the purposes of the Kenyan Data Protection Act, 2019 — and of the GDPR, if you use the app from the EU or UK — the data controller is that individual, and the contact address is roy.thande@gmail.com.

In practice the controller holds nothing: your transaction data never leaves your device, so there is no copy of it for anyone, including the developer, to hold, access, disclose, or be compelled to produce.

The short version

Your transactions stay on your phone. The app also shows advertising, which is the one thing that talks to the internet. There is no account, no sign-in, no server of ours, and no analytics. Nobody — including the developer — can see your transactions, and nothing derived from your M-Pesa messages is ever sent anywhere or used to target an ad.

Permissions: what each one is for

Every permission mTagger asks for, why it needs it, and what happens if you say no. Nothing here is used for any purpose other than the one described, and nothing collected under any of them is transmitted off the device.

Permission Required? Why the app asks If you decline
RECEIVE_SMS Yes Notices an M-Pesa SMS the moment it arrives, so the payment shows up in the app straight away. New payments are never recorded. The app cannot do its job.
READ_SMS Yes Reads M-Pesa messages already in your inbox — up to the last 90 days on first launch — so the app opens with a history rather than empty. Nothing to read; the app cannot do its job.
INTERNET Yes Fetching ads from Google AdMob. This is the app's only network use. Not a runtime permission — it is granted at install.
ACCESS_NETWORK_STATE Yes Lets the ads library skip an ad request when there is no connection, and lets background housekeeping wait for one. Not a runtime permission.
POST_NOTIFICATIONS No Tells you what was just recorded and lets you confirm or change a category without opening the app. Everything else works. You just check the app yourself.
WRITE_EXTERNAL_STORAGE (Android 9 and older only) No Writing an exported spreadsheet to your Downloads folder. Export is unavailable on those Android versions.

You can withdraw any runtime permission at any time in Android Settings › Apps › mTagger › Permissions. Withdrawing SMS access stops the app working but does not delete what it already stored — use Settings › Start again in the app for that.

What the app reads, and what it keeps

SMS messages (READ_SMS, RECEIVE_SMS). mTagger reads the SMS messages on your device to find M-Pesa transaction confirmations. This is the app's core and only function: without them there is nothing to track.

Notifications (POST_NOTIFICATIONS). Used only to tell you what the app just recorded and to let you correct a category without opening the app. Declining this permission does not affect anything else.

What the app never collects: your name, email address, phone number, contacts, location, photos, call log, or the contents of any non-M-Pesa message. There is no account to create and nothing to sign in to.

Where your data goes

Your transaction data stays in the app's private storage on your device. It is not uploaded, and there is:

Advertising

mTagger displays ads supplied by Google AdMob, and includes the Google Mobile Ads SDK. This is why the app requests the INTERNET permission.

Earlier versions did not request INTERNET and could not open a network connection at all. That is no longer true, and this section replaces that guarantee. If that property was why you installed the app, this is the change you need to know about.

What this means in practice:

Google AdMob is the only third party the app sends anything to. There are no other SDKs that collect data — no analytics, no attribution, no crash reporting.

Agreeing to this

Before the app is usable it asks you to confirm, in one screen with a tick box, that you accept the terms and the app showing ads. Nothing is recorded until you tick it, and the button that continues stays disabled. The privacy policy and terms are linked from that screen and readable in full inside the app, offline, at any time.

If you do not agree, the app closes. Advertising is what pays for mTagger, so there is no version of it here that runs without ads — saying no means not using it, and it seemed more honest to say so plainly than to bury the choice. Nothing is saved when you decline, so opening the app again simply asks you again. Existing users upgrading from a version without ads are asked too: this is a change to what the app does, not a formality for new installs.

If you agree and later change your mind, uninstalling removes the app and everything it stored.

Android's own automatic backup is switched off (allowBackup="false"), so your transaction database is not copied to Google Drive either.

Other permissions you may see

Android lists a few permissions the app does not itself request. They are added automatically by the Google Mobile Ads SDK and by WorkManager, the Google-provided library that runs the app's background housekeeping (auto-confirming tags you did not respond to within 24 hours):

Permission Why it appears What it does here
READ_BASIC_PHONE_STATE Added by the ads SDK Tells the SDK what kind of connection you are on. It does not read your phone number, your calls, or who you are.
AD_ID Added by the ads SDK Lets the ad request carry your device's advertising ID, which you can reset or delete in Android settings.
RECEIVE_BOOT_COMPLETED Added by WorkManager Lets scheduled housekeeping survive a restart.
WAKE_LOCK Added by WorkManager Keeps the device awake for the seconds that housekeeping runs.
FOREGROUND_SERVICE Added by WorkManager Not used by this app.

How long data is kept, and how it is protected

Transactions are kept on your device indefinitely, until you delete them — there is no expiry, because the point of the app is a record that goes back. The 90-day window is only how far back the first read reaches; it is not a retention limit.

The database lives in the app's private storage, which Android isolates from other apps. It is not encrypted beyond the device encryption Android applies to the whole filesystem, so the protection it has is the protection your screen lock gives your phone. A rooted device, or one whose lock is bypassed, offers no such guarantee.

Data you choose to export

Settings offers an export to an .xlsx spreadsheet, written to Downloads/mTagger on your device. Once that file exists it is an ordinary file under your control — if you then email or upload it, that is outside the app and outside this policy.

Your rights, and how to use them

Because everything is on your device and nothing is held by us, you exercise these yourself, in the app, without asking anyone:

Right How
Access your data It is all visible in the app — History shows every transaction it holds.
Portability — get a copy Settings › Take the numbers out, which writes a spreadsheet to Downloads.
Rectification — correct it Tap any transaction to change its category; Settings › Categories, Rules and People correct everything else.
Erasure — delete it Settings › Start again deletes transactions, unparsed messages, learned rules, people and pool links, together or separately. Uninstalling removes everything the app stored.
Withdraw consent Revoke SMS access in Android settings, or uninstall.
Object to advertising ID use Android Settings › Privacy › Ads — reset or delete the advertising ID.

There is no request to make and no response to wait for, because there is no copy of your data anywhere for us to act on. If you believe otherwise, or want to complain, write to roy.thande@gmail.com. In Kenya you may also complain to the Office of the Data Protection Commissioner; in the EU or UK, to your local supervisory authority.

Deleting data in mTagger does not touch the original SMS messages in your messaging app. Because those remain, re-reading your inbox rebuilds the transactions — but not your corrections, which exist only inside mTagger.

Children

mTagger is not directed at children, is intended for adults managing their own money, and collects no data from anyone. We do not knowingly collect information from children under 13 (or the equivalent age where you live). There is no account, so there is nothing to delete on request — uninstalling the app removes everything it stored.

International use

The app is built for Kenya and expects Kenyan M-Pesa messages. Your transaction data does not cross any border, because it does not leave your device. The one exception is the ad request, which Google may serve and process from infrastructure outside Kenya under its own terms.

Changes to this policy

If this policy changes, the "Last updated" date above changes with it, and the revision history is public in the app's source repository. If a change materially affects what the app does with your data, the app will ask you to agree again rather than treating continued use as consent.

Contact

Questions about this policy, or about the app's handling of data: roy.thande@gmail.com, or open an issue on the project's public repository.


Terms of service mTagger