SpendWe ("SpendWe", "we", "us") makes a personal and couple expense-tracking app for iPhone, iPad and Android. This policy explains what data the app handles, why, and the choices you have. We built SpendWe to be useful without profiling you: there are no ads, no third-party trackers, and we never sell your data.
The short version. Used on its own, SpendWe keeps everything on your device and sends us nothing. Your data reaches our servers only when you turn on a cloud feature — automatic backup, or sharing a household with your partner. Sharing works without signing up, in which case your cloud data is tied to an anonymous identifier rather than to your email. We collect the minimum needed, protect it with encryption in transit and strict per-user access rules, and let you export or delete it at any time.
1. What we collect
Data you create in the app
- Financial entries — expenses and income you add (amount, currency, merchant, date, note, category, and who paid), your categories, and your budgets.
- Receipt images — photos you scan are processed on your device to read text; the images are not uploaded to us for scanning.
- Display name — a first name you enter, used to label who paid for an expense.
- Apple Pay purchases you choose to log (iPhone) — the app never reads your Apple Wallet. If you set up a Shortcuts automation yourself, your Shortcut sends SpendWe only the amount, merchant and date of a purchase, which are saved as an expense like any entry you type.
- Incomes used for an income-based split — if you split household costs in proportion to income, the incomes you enter stay on your device. Only the resulting share percentages are synced with your household.
- Price memory — item prices remembered from your receipts are kept on your device only. They are not synced and are not included in the cloud backup.
As long as you don't use a cloud feature, all of the above stays on your device and is never sent to us.
What changes when you use a cloud feature
Two things send data to our servers: automatic backup, and sharing a household with a partner. Either one needs an identity to attach your data to:
- Without signing up — for example if you only share a household — the app creates an anonymous identifier for your device. We hold no email or name for you, but your synced entries are stored on our servers under that identifier. Because it lives only on that device, resetting or replacing the phone can permanently lose access to it.
- If you add your email, that identity becomes a real account, which is what lets you restore your data on a new phone and keep several devices in sync.
Data collected only if you use a cloud feature (backup or household sharing)
- Email address — only if you choose to add one. Used to sign in with a one-time code and to identify your account. If you sign in with Apple or Google, we receive the identifier those services provide (and, with Apple's Hide My Email, a relay address). Without it, your cloud data is tied to an anonymous identifier instead.
- Your synced financial entries — the entries above, stored in your private cloud space so they can be backed up and shared within your household.
- Household membership — if you link with a partner, the fact that your accounts share a household, and a display name for each member.
- Reactions & comments — reactions and comments you add to an expense in a shared household are stored with that household and are visible to its members.
- Notification preferences — which notifications you've enabled, your quiet-hours window, and your time zone, so alerts and summaries arrive at sensible local times.
- Device push token — a token from Apple/Google Cloud Messaging so we can deliver the notifications you turned on. Stored only while notifications are enabled.
Crash reports
If the app crashes, Firebase Crashlytics (Google) sends us a diagnostic report so we can fix it: the technical stack trace, your device model, OS version and app version, plus a random installation identifier. These reports contain none of your financial data — no expenses, amounts, merchants, categories or email — and carry no advertising identifier. They are used only to find and fix crashes.
What we do not collect
- No advertising identifiers, no ad SDKs, no behavioural or usage analytics, and no location tracking. We do not track what you tap, which screens you visit, or how often you use the app.
- We do not access your bank accounts. PDF statement import happens from files you choose.
- We never log your session tokens or the contents of your entries on our servers.
2. How we use it
- To run the core app features on your device (tracking, budgets, categories, charts, scanning, import/export).
- To back up your entries and sync them across your devices and with your household partner, when you use an account.
- To send only the notifications you have switched on, honoring your quiet hours.
- To secure the service (for example, alerting you to a new sign-in) and to fix problems.
We do not use your financial data for advertising, and we do not sell or rent it.
3. Legal bases (GDPR / EEA & UK)
- Performance of a contract — to provide the account, backup, sync and notification features you request.
- Consent — for push notifications and for optional sign-in providers; you can withdraw it at any time in the app or your device settings.
- Legitimate interests — to keep the service secure and working, balanced against your privacy.
4. Who processes your data
We use a small number of reputable providers strictly to operate the app. They process data on our behalf under their own security and privacy commitments:
- Supabase — hosts the database, authentication and backup storage for accounts.
- Google Firebase — Cloud Messaging delivers push notifications, a small configuration document is delivered to the app at launch, and Crashlytics receives crash diagnostics. Apple Push Notification service is used for notifications on Apple devices.
- Currency exchange rates — a public, keyless rates source is queried to convert foreign-currency receipts; these requests do not include your identity or your entries.
We share data with a household member only when you deliberately link accounts, and only the shared household's entries. We may disclose information if required by law, or to protect our rights and users' safety.
5. Retention
On-device data remains until you delete it or remove the app. Account data is kept while your account is active. When you delete your account, its data is removed from our systems; short-lived operational records (such as a one-time "sent once" notification marker) are automatically purged within days. Deleting the app from a device does not by itself delete a cloud account — use in-app deletion for that.
6. Your rights & controls
- Access & portability — export a full JSON backup or a CSV spreadsheet any time from Settings.
- Erasure — delete your account and its data in the app (Settings → Automatic backup), or via our account deletion page.
- Rectification — edit or remove any entry directly in the app.
- Withdraw consent — turn off notifications or unlink your household at any time.
- Objection / complaint — contact us, and if you're in the EEA/UK you may also lodge a complaint with your local data protection authority.
To exercise any right, email privacy@spendwe.com.
7. Security
Traffic is encrypted with HTTPS. Session tokens are stored in the device's secure storage (iOS Keychain / Android encrypted preferences), never in plain files. Cloud data is protected by per-user, row-level access rules so one account cannot read another's data. The apps ship without embedded secret keys — sensitive credentials live only on secured servers. No system is perfectly secure, but we work to protect your information and to limit what we hold in the first place.
8. Children
SpendWe is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
9. Changes to this policy
We may update this policy as the app evolves. We'll revise the "Last updated" date above and, for material changes, provide a more prominent notice.
10. Contact
Questions or requests about privacy: privacy@spendwe.com. General support: spendwe.com/support.