Privacy Policy
Spendo reads your receipts, which means the app knows what you bought. So this page is written as a list of what goes where, not as a page of reassuring sentences.
Effective:
The short version
This box is a summary, not the agreement. If it conflicts with the text below, the text below wins.
- We never connect to your bank. The data comes from the receipt itself and from what you type.
- An AI reads your receipt. The photo is sent to the Google Gemini API to be read; when you ask Spendo AI a question, your question and a summary of your spending go there too. None of it trains an AI — we use the paid API tier.
- Location is optional. Decline it and the expense is saved without one — nothing else breaks.
- No ads, no trackers, no analytics SDK. We do not sell your data or share it for advertising. This website has no cookies and no JavaScript.
- Your data is processed outside the EU — our servers and the AI provider are US-based.
- You can request deletion from inside the app; it is completed within 30 days.
1. Who we are and what this covers
Spendo is the data controller for the processing described here. One address for every question, request and complaint: hello@tryspendo.com.
This policy covers the Spendo iOS app, the Spendo API behind it and the tryspendo.com website. In this text “Spendo”, “we” and “the app” all mean the same service.
It is written to meet the information duties of the EU General Data Protection Regulation (GDPR) and of Turkish Personal Data Protection Law No. 6698 (KVKK).
2. What we process
The table below is exhaustive: Spendo collects no personal data beyond it.
| Data | Where it comes from | Why | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Apple user identifier, email address, name | Sign in with Apple. If you choose to hide your email we receive Apple’s relay address, not your real one. Your name is only sent on the first sign-in. | Creating your account and recognising you between sessions | Performance of a contract |
| Account name, primary and secondary currencies, labels, language preference | From you — onboarding and settings | Running the app the way you set it up | Performance of a contract |
| Receipt photo | Your camera or photo library, when you take or pick one | Reading the receipt into an expense, and letting you look at it again later | Performance of a contract |
| Expense record: title, amount, currency, date and time, category, place name, note, recurrence | Read from the receipt, or typed by you | The core function of the app — list, totals, analytics | Performance of a contract |
| Line items and product data: item name, quantity, unit and total price, brand, package size, price normalised per litre or kilo | Read from the receipt | Product price tracking and basket inflation | Performance of a contract |
| Location: latitude and longitude | Your device — only if you granted the location permission, and only at the moment you save the receipt | Showing the expense on the map | Consent (the iOS permission). You can withdraw it at any time in iOS Settings. |
| Exchange-rate snapshot: the rate used and its date | Calculated when the expense is saved | So your past totals in foreign currencies never shift underneath you | Performance of a contract |
| Monthly usage counters: number of scans and chat messages | From your usage | Enforcing the free and Pro quotas | Legitimate interest — preventing abuse of the service |
| Product measurement events: which lock opened the Pro screen, whether it opened automatically, which plan was tapped | From the app | Seeing which explanation actually helps, and fixing the product accordingly | Legitimate interest — improving the product. These records are tied to your account but carry no expense content. |
| Subscription status and billing events: plan, start and end, renewal and cancellation events | Via Apple and our subscription infrastructure | Turning Spendo Pro access on and off | Performance of a contract |
| Session data: the hash of refresh tokens, their expiry and revocation time | Generated when you sign in | Keeping you signed in and revoking a stolen token | Performance of a contract |
| Technical logs: IP address, the time and outcome of the request | Created automatically whenever the app talks to our server | Running the service, spotting failures and preventing abuse | Legitimate interest — security and continuity of the service. These records carry no expense content. |
Because a receipt shows what you bought, receipt photos and line items may contain special category data — a pharmacy purchase, for example. Spendo does not single out, categorise or use such data for any purpose; it stores whatever the receipt says. If you would rather not have such a record, do not scan that receipt, or delete the expense afterwards.
3. What goes to the AI
Two features send data to an AI provider — the Google Gemini API. Because this is the part of Spendo that shares the most, it gets its own section.
- Receipt scanning. The photo itself is sent to Google and comes back as an amount, a date, a category and line items.
- Spendo AI. So that answers are not invented, your question is sent together with a summary of your spending: recent monthly totals, your recurring payments and up to 90 days of expense rows — date, title, category, amount, place name and note. Receipt photos are not sent for this feature.
Spendo uses the Gemini API on its paid tier. Google does not use prompts or responses from paid services to improve its products or models — receipt images included; the content is processed only to answer the request. Spendo also does not send your name, your email or your account identifier to the AI provider — what travels is the receipt image and the expense content.
AI output can be wrong. Checking the amounts is your job; the detail is in the Terms of Use.
4. What we do not collect
In a privacy policy, what is absent matters as much as what is present. Spendo has none of the following:
- No bank or card connection. We do not read statements and never see your card number. Payment happens entirely through Apple.
- No ad networks and no trackers. We do not read the advertising identifier and do not match you across devices.
- No third-party analytics or crash-reporting SDK. There is no Firebase, Sentry, Amplitude or similar measurement tool in the app.
- No push notifications. No notification tokens are collected.
- No contacts, no photo-library scanning, no microphone. Camera and library access is used only for the single file you pick.
- No cookies, JavaScript or third-party fonts on this website. The page is fully static and the fonts are served from our own origin.
- No data sales. We do not sell, rent or share your personal data for advertising.
5. Processors and international transfers
We do not run the infrastructure behind Spendo ourselves: hosting, storage, subscriptions and AI are handled by established providers. Each acts as a processor — it touches only what delivering the service requires and cannot use it for its own purposes. Here is who does what:
- Apple. Sign in with Apple and App Store subscriptions. Authentication and payment stay on Apple’s side.
- AI provider. Receipt reading and Spendo AI. What travels and what does not is spelled out in section 3.
- Hosting and database. Your account and expense records. Servers are in the United States and the European Union.
- File storage. Receipt photos only, kept separate from the database.
- Subscription infrastructure. Whether your subscription is active, plus your account identifier. No receipt or expense data goes there.
- Website infrastructure. Serving this page, and standard server access logs.
The conclusion: your personal data is transferred outside the EU and Türkiye, primarily to the United States. Using Spendo requires this transfer; if you do not want it, you should not use the service.
Transfers are made under GDPR Art. 44 et seq. and KVKK Art. 9. The providers commit to the European Commission’s Standard Contractual Clauses and/or the EU–US Data Privacy Framework. If you want the current list of providers by name, just email hello@tryspendo.com. The open-source exchange-rate service receives no personal data at all — our server fetches the daily rate list wholesale and caches it itself.
6. Who can see your data
Your expenses are scoped to your account and are not visible to other users. The one exception is the operations side: through Spendo’s admin panel, the person running the service can access account records, expense records and receipt records. That access is used only to resolve support requests, fix technical faults and investigate abuse.
Every administrator action — who, when, on which account — is written to a separate audit log that cannot be edited away.
Beyond that we do not share your personal data with third parties. The only exception is a lawful and binding request from a competent court or public authority, and we stay within the scope of such a request.
7. How long we keep it
- Account and expense data: for as long as your account exists. Spendo is an app about history — we do not quietly age your data out.
- An expense you delete: the app gives you three seconds to undo; once that passes, the record, its line items and its receipt photo are permanently deleted.
- An account deletion request: your account and everything attached to it — expenses, receipt photos, product records, session tokens — is deleted within 30 days of the request.
- Billing and subscription records: may be retained after account deletion for the period required by applicable financial law. These carry no expense content.
- Administrator audit logs: retained for security and accountability. They show who did what, not what you bought.
- Technical logs: kept for a short period, then deleted automatically.
8. Your rights
Under GDPR Art. 15–22 and KVKK Art. 11 you have the right to:
- Know whether we process personal data about you, and obtain a copy of it
- Learn the purpose of the processing and whether it is used accordingly
- Know the third parties the data is transferred to, at home or abroad
- Have inaccurate or incomplete data corrected
- Have your data erased
- Have corrections and erasures communicated to the parties the data was transferred to
- Restrict or object to processing based on our legitimate interests
- Object to a decision produced solely by automated analysis that works against you
- Receive your data in a structured, machine-readable format (portability)
- Withdraw consent at any time — for example by turning off the location permission in iOS Settings
- Claim compensation for damage caused by unlawful processing
Send your request to hello@tryspendo.com. We answer within 30 days. If our answer does not satisfy you, you may complain to your national data protection authority in the EU, or to the Personal Data Protection Authority (KVKK) in Türkiye.
9. Deleting your account
In the app, go to Settings › Delete account to raise a deletion request. The moment you confirm, you are signed out and your account is marked for deletion.
Deletion is carried out by hand and completed within 30 days. If you change your mind in the meantime, write to the address above to cancel the request.
Deletion cannot be undone: your expenses, receipt photos and product history are gone for good. Signing in again with the same Apple account starts an empty account. If you have a subscription you must also cancel it in the App Store — Spendo cannot end an Apple subscription on your behalf.
10. Security
- All traffic between the app and the server is encrypted with TLS.
- There is no separate Spendo password: authentication runs through Sign in with Apple, so there is no password of ours to break.
- Session tokens are stored as a hash, never in plain text.
- Receipt photos do not sit at a public address; the app reaches them only through short-lived signed links.
- The admin panel uses a separate credential family and writes every action to an audit log.
No system is perfectly secure. If a breach affects your personal data we will notify the competent authority within the statutory deadline, and you directly where the law requires it.
11. Children
Spendo is not intended for anyone under 13 and we do not knowingly collect data from them. If you are in the EU and your country sets a higher age (16 in some member states), that limit applies and you may not use the service below it without parental authorisation.
If we learn that we hold data about someone below that age we will delete the account. You can report such a case to hello@tryspendo.com.
12. Changes to this policy
We update this policy as the app changes. The effective date at the top of the page always identifies the current version.
If a change materially affects how your data is handled — a new category of data, or a new provider receiving it — we will announce it in the app and, where required, ask for your consent.
13. Contact
For any question about this policy, any request to the controller and any deletion request: hello@tryspendo.com