Expenses

Privacy Policy

Effective September 8, 2026.

What this covers

This describes what Expenses collects when you use it, why, and who else ever sees it. Expenses is a personal expense and reimbursement tracker — everything below is written against what it actually does, not a generic template.

Information we collect

Account information. The name and email address you sign up with, and your password (stored hashed by our authentication provider — we never see it in plain text). If you turn on two-factor authentication, we store the authenticator secret needed to verify your codes, not the codes themselves.

What you enter. Every transaction, amount, date, vendor, bill/category, note, and bucket (savings pot) you create. Any file you upload to import transactions from a bank statement.

Bank connection data, if you choose to connect one. Connecting a bank is entirely optional. If you do, we request only Plaid’s Transactions product — transaction history and account balances for the accounts you select. We never receive your online banking username or password (Plaid handles that directly with your bank and never shares it with us), and we don’t request routing/account numbers or identity-verification data. See “Plaid” below for how Plaid itself handles this.

Automatically collected. Standard server logs (IP address, timestamps, request metadata) kept for security and abuse prevention. We don’t run analytics, advertising, or tracking scripts of any kind — there is nothing in this app watching how you use it beyond what’s needed to make it run.

How we use it

Solely to run the service you asked for: storing and showing you your own transactions, connecting to a bank you’ve authorized, sending you account emails (sign-up confirmation, password reset), and letting you export or delete your data on demand. We don’t sell your data, and we don’t use it for advertising — there’s no advertising in this app at all.

Who we share it with

Supabase hosts our database and handles sign-in. Every query is scoped so only your own account can read your own rows — Supabase is our infrastructure, not a separate audience for your data.

Plaid connects your bank account, if you choose to add one. Plaid has its own privacy obligations for the data it collects on our behalf — read Plaid’s End User Privacy Policy for how Plaid itself handles it, separately from how we handle what Plaid passes to us.

Resend delivers the account emails we send (confirmation, password reset). It only ever sees the email address and message content needed to send that one email.

None of these process your data for their own purposes — only to provide their service to us.

How long we keep it, and how to delete it

We keep your data for as long as your account exists. You can delete your account at any time from Settings → Account: it removes every transaction, import, bank connection, and your sign-in itself, immediately and permanently. Export a copy first from Settings → Export if you want to keep one — there’s no undo once deletion runs.

Security

Every row in the database is scoped to your account alone (row-level security), so one user’s data is never reachable by another’s query. You can add two-factor authentication yourself under Settings → Account for an extra layer on sign-in.

Your choices

Connecting a bank is opt-in — the app works fully on manually-entered transactions and file imports alone. You can disconnect a bank, export your data, or delete your account entirely at any time, all from Settings.

Changes to this policy

If this changes in a way that affects how your data is shared, we’ll update the effective date above and make that change clear rather than let it pass quietly.

Contact

Questions about this policy or your data — reach out at [CONTACT EMAIL].