Privacy Policy
Last updated: July 23, 2026
1. Overview
Spendly (“we”, “the app”) is a personal expense tracker that lets you record expenses manually, via our Telegram bot, or by uploading photos of receipts that are processed with AI. This policy explains what data we collect, how we use it, and the choices you have.
2. Data we collect
- Account data: your Telegram ID and username (if you sign in via Telegram) or your Google account email (if you sign in with Google).
- Financial data you provide: expenses, amounts, currencies, dates, categories, merchants, notes, income entries, budgets/limits, and goals.
- Receipt images: photos and PDF files of receipts you upload or send to the bot. These are processed to extract expense and product information.
- Technical data: basic usage events (e.g. page visits and feature usage) used to improve the product. We do not sell this data or use third-party advertising trackers.
3. AI processing
When you upload a receipt photo or use AI features (receipt scanning, cost analysis, price analysis, recipe suggestions), the image and/or relevant expense data are sent to a third-party AI provider strictly for processing your request. The results (recognised products, amounts, suggestions) are stored in your account. We do not use your data to train AI models.
4. How we use your data
- To provide the core service: tracking, analytics, charts, reports, reminders.
- To process receipts and generate AI-powered insights at your request.
- To maintain security of your account (session cookies, one-time login codes).
- To improve app functionality based on aggregate usage.
We never sell your personal data to third parties.
5. Storage and security
Your data is stored in a managed PostgreSQL database. Access to your account is protected with short-lived one-time codes and signed session cookies transmitted only over HTTPS. Receipt files are retained only as long as needed to process them.
6. Sharing
- Shared reports: if you create a shared report link, anyone with the link can see the report data. You can revoke all shared links at any time in Settings.
- Guest access: guest tokens you create grant read-only access. You can revoke them at any time in Settings.
- Service providers: hosting, database, and AI processing providers acting on our instructions.
7. Data export and deletion
You can export your expenses and products as CSV at any time from the Settings page. You can delete shared reports, guest tokens, and insights in Settings. To request full deletion of your account and all associated data, contact us using the details below — we will complete the deletion within 30 days.
8. Children
The app is not directed at children under 13, and we do not knowingly collect data from them.
9. Changes
We may update this policy from time to time. Material changes will be announced in the app. Continued use after changes means you accept the updated policy.
10. Contact
Questions or data requests: Dmitrii Vasilkov or via the Telegram bot.