Privacy Policy
1. Who we are and what Spendly is
Spendly is a personal finance tracking and AI money-coaching app. It helps you record expenses, see what’s safe to spend, set budgets, and get general money-habit guidance.
Spendly is not a bank, lender, broker, or licensed financial advisor. It does not hold your money, connect to your bank accounts, or move funds. Guidance in the app is educational and general in nature only (see Section 9).
2. Our privacy approach: local-first
Spendly is local-first. By default, your data is stored on your device and stays there. Cloud sync is optional and only happens if you choose to create an account and sign in (see Section 4). You can use Spendly without an account.
3. What data we collect and where it lives
a) Data you create in the app (stored locally on your device)
- Expenses you add: amount, merchant/description, category, date, source label, and optional note.
- Settings and preferences: display currency, monthly budget, savings goal, per-category budgets, AI-Coach on/off, dark mode.
- Learned merchant-to-category preferences (e.g. that you file a given merchant under a given category), stored only on your device.
- AI chat messages you type in the coach screen and their replies.
- App state: whether you’ve completed onboarding, and your local Pro-trial toggle status.
This data remains on your device unless you enable cloud sync.
b) Account data (only if you create an account)
If you choose to sign in, we use [Supabase] (our hosting and authentication provider) to create an account. We collect your email address, an authentication credential (password) handled by the auth provider, and a system-generated user ID. We ask for minimal personal information — an email is all that’s required. We do not require your name, phone number, address, or government ID.
c) Data synced to the cloud (only if you sign in)
If you’re signed in, the following is synced to your account so you can back it up and use it across devices:
- your expenses,
- your profile settings (currency, monthly budget, savings goal, AI-Coach preference), and
- your category budgets.
Not synced (kept on-device only): dark-mode preference, onboarding status, learned merchant-to-category preferences, AI usage counters, local Pro-trial status, and AI chat history.
d) Data we do NOT collect
- We do not connect to your bank, read your real SMS messages, or access your transactions automatically. Any “Auto-Track”, receipt-scan, or voice features currently in the app are simulated demonstrations (see Section 6).
- We do not sell your data.
- We do not knowingly collect data from children (see Section 12).
4. Accounts and authentication
- Accounts are optional. Without one, Spendly runs fully locally.
- Authentication is provided by [Supabase]. Your credentials are handled by that provider; we only ever use a public “anon” key in the app, and each account can only access its own data via database row-level security.
- Signing out ends your cloud session but keeps your data on your device.
5. Payments and subscriptions
- Spendly may offer an optional “Pro” subscription in the future.
- We do not process or store your payment details. Purchases will be handled by the Apple App Store, Google Play, and our subscription infrastructure provider [RevenueCat]. Their handling of your purchase and payment data is governed by their privacy policies.
- At present the in-app “Pro”/trial is a local toggle only — no real charge, no card, no purchase data collected. Payment processing is not live yet.
6. AI features (current status)
- Spendly’s AI money coach, expense parsing, and reports currently run on built-in rule-based logic on your device — the “real” cloud AI is not enabled yet. When real AI is enabled later, requests would be sent to our own backend service; this policy will be updated before that happens.
- Voice entry, receipt scanning (OCR), and Auto-Track are simulated placeholders today. They do not use your microphone, camera, or real SMS or bank data. We will update this policy before any of them becomes real.
- AI output is general educational guidance, not personalized financial, legal, or tax advice (see Section 9).
7. How we use data
We use your data to run the app’s core features (tracking, budgets, safe-to-spend, Money Age), provide optional backup and sync, operate accounts, and — if you enable it later — process subscriptions via the providers in Section 5. We do not use your financial data for advertising and do not sell it.
8. Sharing and third parties
We share data only with service providers strictly needed to run features you use:
- [Supabase] — account/authentication and cloud sync (only if you sign in).
- [Apple] / [Google] / [RevenueCat] — subscription processing (only if and when you subscribe, once live).
Each provider processes data under its own privacy policy. We do not otherwise share, rent, or sell your data.
9. No financial, legal, or tax advice
Spendly provides budgeting tools and general educational guidance only. It is not a licensed financial, investment, legal, or tax advisor, and nothing in the app is personalized professional advice. You are responsible for your own financial decisions; consider a qualified professional for advice specific to your situation.
10. Data retention and deletion
- Local data: stays on your device until you delete it. Use Settings → Delete transaction data to clear expenses on the device, or uninstall the app to remove all local data.
- Cloud data (if you have an account): you can delete your on-device transaction data (expenses) in the app at any time (via Delete transaction data); your budgets and settings remain on the device. Cloud account deletion must currently be requested by email at hello@spendlyapp.me — a full in-app account-deletion option is not yet available; you can start a request from Settings → Account. We process verified deletion requests within 30 days, except where we must retain limited records to comply with law.
- You can export your expenses to a CSV file from within the app at any time.
11. Data security
- Data in transit to our providers is protected with encryption (HTTPS); providers encrypt data at rest.
- Only a public key ships in the app; access to your account data is restricted to your own account by row-level security. No secret keys are embedded in the app.
- No method of storage or transmission is 100% secure; we cannot guarantee absolute security.
12. Children’s privacy
Spendly is intended for users aged 13 and over and is not intended for children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
13. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to withdraw consent. To exercise them, contact hello@spendlyapp.me. We may need to verify your identity first.
14. International users
Your data may be processed in countries other than your own (e.g. where our providers host data). Where required, we rely on appropriate safeguards. Data-hosting region: ap-northeast-1 (Tokyo).
15. Changes to this policy
We may update this policy. Material changes will be posted here with a new effective date, and where required we’ll seek your consent before new data uses take effect.
16. Contact
Questions or requests: hello@spendlyapp.me
Spendly, Available upon request