Privacy policy
Spendly is a personal-finance tracker made in India. It never asks for a net-banking password, never moves money, shows no ads, and never sells your data or shares it for anyone else’s use.
Last updated 26 September 2026
What we collect
- Your account. Your name, email address and, if you add one, phone number, all encrypted (AES-256-GCM) before they are stored. A password is kept only as a one-way bcrypt hash. If you sign in with Google, we receive your name and email from Google. If you choose an avatar, we store only which of Spendly’s own drawings you picked; no photo is ever uploaded.
- Your money records. The accounts, transactions, budgets, bills, goals, loans and investments you add or import.
- Gmail, only if you connect it. Read-only access. Spendly searches only for emails from known bank senders and keeps only the fields it extracts (amount, date, merchant, account ending, available balance). The email itself is never stored. The access token is encrypted, and disconnecting deletes it.
- Phone notifications, in the Android app. Your phone’s notification token (encrypted) and your notification choices, plus a record of which reminder was sent on which day so it is never sent twice. That record holds no message text and is deleted after 120 days.
- Invitations to Auto-track. While Gmail tracking is in beta, a Spendly admin can let an email address use it, sometimes before that person has signed up. We store the address encrypted, a keyed fingerprint of it so it can be matched at sign-in, and the date access ends. It is deleted when the admin removes it or when that account is deleted, and the security log records only that access was given or removed, never the address.
- Security records. Sign-ins, failed sign-ins, password resets, exports and deletions, with the time, a shortened IP address and the browser type. No names, emails or amounts. Each entry is kept for two years, including after an account is deleted.
- Spendly Premium payments. If you buy Premium, the plan, the amount, the date and Razorpay’s order and payment references. Your card, UPI or bank details are entered in Razorpay’s own payment window and never reach Spendly.
- What you send us. Feedback and feature requests, linked to your account.
Bank SMS (coming to the Android app)
Bank SMS tracking is off until you turn it on, and only reads messages that arrive after that; it never reads your inbox or past messages. It works in one of two ways, each switched on separately: by reading the notification your Messages app shows for a new text (this needs Android’s Notification access; notifications from every other app are ignored without being read), or by receiving the SMS itself (this needs the SMS permission). On your phone, every message that is not a transaction alert from a bank’s registered sender ID or the bank’s name (personal texts, one-time passwords, offers) is ignored and never leaves it. The text of each bank transaction alert is sent over an encrypted connection to Spendly, which reads the amount, account, date and payee from it and stores only those, exactly as with bank emails. The message text itself is not stored and not logged. Until it is sent, an alert waits on your phone for at most 7 days, and switching tracking off deletes anything still waiting.
How we use it
Only to run Spendly for you: show your balances and reports, remind you about bills, budgets and SIPs (by email or phone notification, each one you can switch off in Profile → Notifications), keep your account secure, and answer your feedback. We do not use your data for advertising, and nothing is sold.
Services that process data for us
- Hosting and database: Vercel (the app) and MongoDB Atlas (your records).
- Google: Google sign-in and Gmail, if you use them; Gemini answers questions you ask Spendly AI, using a summary of your own figures.
- Anthropic: if a bank email cannot be read by our own rules, its text may be sent to Anthropic’s API to pull out the transaction. It is not stored by Spendly. When no rule recognises a business’s name, that name alone may be sent to suggest a category; a name that could be a person’s is never sent, and bank SMS text is never sent.
- Razorpay: processes Spendly Premium payments (UPI, cards, netbanking) under its own privacy policy and India’s payment regulations.
- Firebase Cloud Messaging: delivers phone notifications to the Android app.
- Email delivery: our mail provider sends the reminder and summary emails you choose.
- Error reports: when the server hits an error, Sentry receives the error and the page it happened on, never your identity or your data.
How long we keep it
Your account and records are kept until you delete them. Deleting your account erases them at once and permanently (see Delete your account). Security records expire two years after they are written; notification records after 120 days.
Your choices and rights
- Export your transactions and portfolio as CSV, Excel or a PDF report at any time, from Reports. The PDF is made on our server when you ask for it and is not kept.
- Edit or delete any record, disconnect Gmail, and switch any reminder off.
- Delete your account and everything in it, from the app.
- Ask us what we hold about you, or to correct it, under India’s Digital Personal Data Protection Act, 2023.
Children
Spendly is meant for adults managing their own money and is not directed at children under 18.
Changes
When this policy changes, the date at the top changes with it. A change in how your data is used will be announced in the app first.
Contact
Questions, requests or a security report: support@spendlymoney.com. You can also write to us from the app: Profile → Feedback & feature requests.