Our promise
Spend Sense is built to protect your privacy. We are funded primarily by subscriptions. We may also earn revenue from partnerships and, in the future, from licensing technology we build — never by selling your identifiable financial data to advertisers or data brokers.
This Privacy Policy explains what limited information we process for the website and waitlist, how app data is stored today, how splitting and settle-up features handle information, and the rights you have over your data.
We will never
- Sell your identifiable financial data to advertisers.
- Share your identifiable financial data with data brokers.
- Access your financial data without your explicit permission.
- Retain data longer than necessary to provide the service or meet legal requirements.
How we use information to improve the product
Today, Spend Sense app account data — including email/password login credentials and the financial information you enter in the app — is stored fully on your device. The iOS app uses encrypted local storage (SQLCipher for the local database and secure on-device storage for authentication). There is no hosted account backend in production today, and we do not use your on-device financial picture to train remote models.
For this website, we use limited waitlist and aggregate analytics information to understand what is working and improve Spend Sense — for example, which pages people visit and how the site performs.
We do not currently sell or license identifiable user data, and we do not currently license aggregated or de-identified user data to other businesses. If that changes, we will update this policy before doing so.
What we collect — app vs. website
Spend Sense has two surfaces: the iOS app and this marketing website. They handle data differently.
| Data | iOS app | Website |
|---|---|---|
| Account login (email / password) | Stored on your device only. No hosted account component in production today. | Not collected. The website waitlist is email-only and separate from the app account. |
| Budgets, expenses, vacations, savings goals, analytics you create | Stored encrypted on your device. Not sent to Spend Sense servers today. | Never collected. |
| Split participant names / contacts you enter | Stored on your device as part of the split you create. See “When you split an expense.” | On the free /split tool: processed only in your browser; not sent to or stored on our servers. |
| Payment handles you choose to store for settle-up | Optional Venmo / Cash App handles you save for deep-link settle-up stay on your device. See “When you split an expense.” | Not collected. |
| Website analytics | N/A. | Aggregate page views and Web Vitals. No financial data and no raw transaction content. |
| Performance metrics | None collected by Spend Sense servers today. | Vercel edge and runtime metrics (for example response times and error rates) in aggregated form. |
| Crash reports | Release builds may send crash diagnostics to Sentry with aggressive PII scrubbing. See Data retention. | N/A. |
| IP address | Not collected by a Spend Sense hosted backend today. | Processed transiently by Vercel for routing and security. Retained in edge logs for up to 7 days, then rotated and aggregated. |
What we do not collect
For the iOS app, we do not sell your financial data to advertisers or data brokers. For the website, we keep collection to what is needed to operate the waitlist and understand aggregate usage.
We do not currently collect:
- Card verification codes (CVV)
- Government IDs, Social Security Numbers, or tax IDs
- Biometric templates — Touch ID / Face ID stay with iOS
- Precise GPS history used to build movement profiles
- Bank account or card numbers (bank linking is not live)
Features that are not yet live — including receipt scanning as a product feature, bank account linking, iCloud encrypted backup, a hosted backend for app accounts, and Stripe-based split payment processing — are not described here as current practices. If we ship them, we will update this policy and, where required, ask for permission before collecting anything new.
When you split an expense
Spend Sense lets you split expenses in the iOS app (including Squads) and on the free website tool at /split.
Participant information
When you split an expense, other people are identified only by a name or contact information you enter. They are not required to create a Spend Sense account for the split itself. Spend Sense does not collect information about them beyond what you provide.
Free web bill splitter (/split)
The /split tool processes everything client-side in your browser. Information about you or other participants in that tool is not sent to or stored on a Spend Sense server.
Venmo and Cash App settle-up (iOS app)
The iOS app includes a live settle-up feature that can open Venmo or Cash App on your device via a deep link, using payment details you choose to send (including any payment handle you optionally store in the app for that purpose). This is a user-triggered deep link on your device. Spend Sense does not transmit data to Venmo or Cash App on its own, does not connect your Spend Sense account to those services, and does not share information with them directly — your action opens the other app with information you chose to include.
Always verify the amount and recipient shown before you complete any payment through that deep-link flow. Split results and payment requests are based on information you entered and are not independently verified by Spend Sense.
Stripe-based direct payment processing for splits (sometimes described as “split payment processing” on pricing pages) is a separate, future feature and is not available today. It should not be confused with the deep-link settle-up feature described above.
Security
We take reasonable technical and organizational measures to protect information we process, including encrypting app data stored on your device. No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
If we become aware of a security incident that affects personal information we process, we will take appropriate steps under applicable law, which may include notifying you and regulators where required.
GDPR data subject rights
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights over any personal data we process about you (typically limited to website and waitlist data):
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete personal data.
- Right to erasure — ask us to delete your personal data in certain circumstances.
- Right to restriction — ask us to limit how we process your personal data.
- Right to portability — receive your data in a portable format where applicable.
- Right to object — object to certain types of processing (for example, direct marketing).
- Right to lodge a complaint with a supervisory authority.
To exercise any of these rights, email privacy@spendsenseapp.io. We aim to respond within 30 days.
Your U.S. privacy rights
Depending on where you live in the United States, you may have rights over personal information we process about you. For Spend Sense today, that processing is typically limited to website and waitlist data — app account data remains on your device and is not held on our servers.
Subject to applicable law, these rights may include:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate personal information.
- Deletion — ask us to delete personal information, subject to certain exceptions.
- Opt-out — opt out of the sale or sharing of personal information, where those concepts apply.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
Spend Sense does not currently sell or license identifiable user data, and does not currently license aggregated or de-identified user data to other businesses. Nevada residents may still submit a request directing us not to sell covered information under Nevada law (NRS Chapter 603A) by emailing privacy@spendsenseapp.io.
To exercise any of these rights, email privacy@spendsenseapp.io. We aim to respond within the timeframes required by applicable law (for California residents, see below).
California (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides additional rights and process details:
- Right to know what categories of personal information we collect and how we use it.
- Right to request deletion of personal information, subject to certain exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information. We do not currently sell or share personal information as those terms are commonly understood under the CCPA/CPRA.
- Right to non-discrimination for exercising your CCPA/CPRA rights.
To exercise these rights, email privacy@spendsenseapp.io with the subject line "California Privacy Request". We aim to respond within 45 days.
Children's privacy
You must be at least 13 years old to use Spend Sense. If you are between 13 and 17 years old, you confirm that your parent or legal guardian has given you permission to use the Service.
Spend Sense is not directed to children under 13, and we do not knowingly collect information from children. If you believe a child has provided us personal information, please email privacy@spendsenseapp.io so we can delete it.
Data retention
We keep information only as long as we need it to provide the service, comply with law, or resolve disputes.
| Data type | Retention |
|---|---|
| App account and financial data | Stored encrypted on your device (SQLCipher / secure on-device storage). No app account data is held on Spend Sense servers in production today. |
| Hosted backend / cloud sync | Not yet in production. A hosted backend is actively in development (schema, APIs, and data modeling are underway). There is no committed launch date. When it ships, this policy will be updated to describe what is stored, where, and for how long. |
| Support conversations | 1 year after our last interaction with you. |
| Crash reports (Sentry) | Release builds only. Crash diagnostics may be sent to Sentry with aggressive PII scrubbing configured in the app. We do not intentionally include account credentials or raw financial records in those reports. |
| Website analytics (Vercel) | Up to 2 years in aggregated form (no raw financial content). |
Questions about privacy?
If you have questions about this policy or how we handle data, email privacy@spendsenseapp.io.