1. Introduction
Welcome to Spendo. Spendo is a personal expense and budget tracking application ("the App") available on Android, iOS, and the web.
This Privacy Policy explains what personal information we collect when you use the App, why we collect it, how we use and protect it, and what choices you have. Please read it carefully. By creating an account or using the App you agree to the practices described here.
If you have questions or concerns at any time, contact us at hellospendo@gmail.com.
2. Who we are
Spendo is an independent mobile application. For the purposes of this policy, "Spendo", "we", "us", and "our" refer to the developer(s) of the Spendo application. We act as the data controller for personal information collected through the App.
3. Information we collect
We collect only the information necessary to provide the App.
3.1 Account information
When you register, we collect your email address and a password. Your password is never stored by Spendo in plain text; it is hashed and managed exclusively by Firebase Authentication.
3.2 Financial data you enter
Spendo stores the financial information you manually enter into the App:
- Budget accounts — name, budget amount, currency, and period (weekly, monthly, yearly, or custom).
- Transactions — title (up to 200 characters), amount, currency, date, type (income or expense), and category.
- Recurring transactions — the same fields as transactions, plus frequency, interval, start date, and end date.
- Spending categories — name, icon, colour, and classification (need or want).
Spendo is not connected to any bank, payment processor, or financial institution. We never receive or store real bank account numbers, card numbers, or any financial credentials.
3.3 App preferences
We store your in-app preferences — preferred currency, display language (English, Spanish, or German), colour theme (light or dark), and reminders setting — so your experience remains consistent across sessions and devices.
3.4 Device locale
On first launch, Spendo reads your device's locale setting to suggest a default language. This is processed on-device only and is not uploaded to our servers as a separate data field.
3.5 What we do not collect
4. How we collect information
- Directly from you — when you register, add transactions, create budgets, or update your preferences inside the App.
- Automatically on your device — your device locale is read locally at first launch to suggest a default language.
We do not use cookies, pixel trackers, device fingerprinting, or third-party analytics tools.
5. How we use your information
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure your account | Email, password | Performance of contract |
| Sync your data across devices | Budgets, transactions, categories | Performance of contract |
| Personalise your experience | Currency, language, theme | Performance of contract |
| Process recurring transactions automatically | Recurring transaction schedules | Performance of contract |
| Respond to support or data requests | Legitimate interest |
We do not use your data for advertising, marketing to third parties, profiling, or any purpose beyond operating the App for you.
6. How we share your information
We do not sell, rent, or trade your personal information to anyone. The only parties who receive your data are:
- Google LLC (Firebase) — Firebase Authentication and Cloud Firestore are used to authenticate users and store app data. Google acts as a data processor on our behalf and is bound by Google's data processing agreements. See Google's Privacy Policy.
- Expo Inc. — Expo provides the build and distribution infrastructure for the App. Expo does not receive your personal data at runtime.
We may disclose your information if required to do so by law or in response to a valid legal request (such as a court order or government subpoena).
7. Data storage and security
Your data is stored in Google Cloud Firestore data centres. All communication between the App and our cloud services is encrypted in transit using TLS (HTTPS). At rest, data is protected by Google Cloud's standard encryption.
Access to your data in Firestore is governed by strict security rules: only a signed-in user whose unique ID matches the data owner can read or write their own data. No other user, and no Spendo employee via the client app, can access your records.
Authentication tokens are stored in your device's local storage using Firebase's built-in persistence mechanism. A local cache of accounts, categories, and preferences is stored on-device for performance; this cache is cleared when you sign out or uninstall the App.
While we take reasonable technical and organisational measures to protect your data, no method of transmission or storage is 100% secure. We encourage you to use a strong, unique password for your account.
8. Data retention
We retain your personal information for as long as your account is active. If you request deletion of your account, we will remove all associated data within 30 days.
You can delete individual budget accounts and all their transactions from within the App at any time. To request full account deletion, email us at hellospendo@gmail.com.
9. Your rights
Depending on where you are located, you may have the following rights regarding your personal data. To exercise any of them, contact us at hellospendo@gmail.com.
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data. Most data can be edited directly inside the App.
- Right to erasure ("right to be forgotten") — request deletion of your account and all associated data.
- Right to data portability — request your data in a structured, machine-readable format.
- Right to object — object to the processing of your data where we rely on legitimate interest as the legal basis.
- Right to restriction — request that we restrict processing of your data in certain circumstances.
If you are located in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.
If you are a California resident (CCPA), you have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information.
10. Device permissions
Spendo does not request access to your camera, microphone, contacts, photo library, precise location, push notifications, or biometric sensors. The only network permission used is standard internet access, required to communicate with Firebase.
11. Children's privacy
Spendo is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe that a child has provided personal information through the App, please contact us at hellospendo@gmail.com and we will delete the information promptly.
12. Third-party links
The App and this website may contain links to third-party sites (for example, the Google Play store). We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will make reasonable efforts to notify you (for example, by a notice within the App). Continued use of Spendo after changes are published constitutes your acceptance of the updated policy.
14. Contact
If you have any questions, requests, or complaints about this Privacy Policy or how we handle your personal data, please contact us:
- Email: hellospendo@gmail.com
We will respond to all legitimate requests within 30 days.