Privacy Policy
Last updated: June 2026
1. Introduction
Spendently ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have. It applies to all users of spendently.com and is written to comply with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
If you have questions about this policy, contact us at: [email protected]
2. Data We Collect
Account data
- Email address (required to create an account)
- Full name (optional, used for display only)
- Password (stored as a one-way cryptographic hash — we cannot see your password)
- Account creation date and last login timestamp
- Timezone, preferred language, and number/date format preferences
Financial data you enter
- Accounts (bank accounts, wallets, cash) and their balances
- Transactions (amount, date, merchant, category, notes)
- Budgets, categories, and currency preferences
- Receipt images you upload
- Transfer records between your accounts
This data is entered by you voluntarily and is used solely to provide the expense tracking functionality. We do not automatically retrieve data from your banks or financial institutions.
Usage and technical data
- IP address and browser type (for security and fraud prevention)
- Session data (to keep you logged in)
- CSRF tokens (to protect against cross-site request forgery)
We do not currently use third-party analytics or advertising tracking.
3. How We Use Your Data
- To provide and operate the Service — storing your transactions, accounts, and budgets.
- To authenticate you and keep your account secure.
- To send transactional emails — password resets, account invitations, security alerts.
- To notify you of service changes or updates (where required by law or these Terms).
- To comply with legal obligations.
We do not use your financial data for advertising, profiling, or any purpose other than providing the Service.
4. Legal Basis for Processing (GDPR)
- Contract: Processing your account and financial data is necessary to deliver the Service you signed up for.
- Legitimate interests: Maintaining security logs and preventing fraud.
- Legal obligation: Retaining certain records as required by applicable law.
- Consent: Where we request consent separately (e.g. optional notifications), you may withdraw it at any time.
5. Third-Party Services
We use the following third-party infrastructure providers to operate the Service. Each has its own privacy policy.
| Provider | Purpose | Data shared | Privacy policy |
|---|---|---|---|
| Railway | Application and database hosting | All application data (stored on Railway servers) | railway.app |
| Cloudflare | CDN, DNS, DDoS protection, media storage (R2) | IP address, request metadata, uploaded media files | cloudflare.com |
| Brevo | Transactional email delivery | Email address, email content (password resets, notifications) | brevo.com |
| Frankfurter API | Currency exchange rate data | No personal data — only currency code requests | frankfurter.app |
We do not sell your data to any third party.
6. International Data Transfers
Our infrastructure providers (Railway, Cloudflare, Brevo) are based primarily in the United States. If you are located in the European Economic Area (EEA) or the United Kingdom, your data may be transferred to and processed in the United States. These transfers are made under appropriate safeguards (Standard Contractual Clauses or equivalent mechanisms) as required by GDPR.
7. Data Retention
- Your account data and financial records are retained for as long as your account is active.
- When you close your account, your data is deleted within 30 days, except where we are legally required to retain it.
- Server logs (IP addresses, access records) are retained for up to 90 days for security purposes.
- Uploaded receipt images are deleted within 30 days of account closure.
8. Your Rights (GDPR)
If you are located in the EEA or UK, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Correct inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data ("right to be forgotten").
- Right to portability: Receive your data in a machine-readable format.
- Right to restriction: Request that we limit how we process your data.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
9. Security
We implement industry-standard security measures including encrypted HTTPS connections, hashed passwords (never stored in plain text), CSRF protection, and access controls. However, no system is 100% secure — you are responsible for keeping your account password confidential. Report any suspected security issue to [email protected] immediately.
10. Cookies
We use only essential cookies required for the Service to function (session management and CSRF protection). We do not use tracking or advertising cookies. For full details, see our Cookie Policy.
11. Children's Privacy
Spendently is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us immediately and we will delete the account.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or by a prominent notice in the Service. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
For all privacy-related requests and questions:
[email protected]