Privacy Policy
Last updated: 2026-09-26
This Privacy Policy explains how Spendify (“we”, “us”) collects, uses, and protects information when you use our website and the Spendify application (the “Service”).
1. Who we are
Spendify is a receipt capture and expense export service. For privacy questions, contact: privacy@spendifyapp.com.
2. Information we collect
- Account information (e.g., email address) when you create an account.
- Receipts and extracted data that you upload (images/PDFs) and the metadata derived from them (merchant, date, amount).
- YNAB connection data, if you connect YNAB: the encrypted access credentials issued by YNAB through OAuth, and the identifiers and names of the plan and account you choose. See section 6.
- Usage and technical data (e.g., log events, device/browser information, IP address) to operate and secure the Service.
- Billing data handled by our payment processor (Stripe). We do not store full card details.
3. How we use your information
- Provide and operate the Service (upload receipts, process documents, show results).
- Export transactions to YNAB when you request it.
- Provide customer support and respond to your requests.
- Security, fraud prevention, and abuse detection.
- Billing, subscription management, and invoicing.
- Improve reliability and performance (aggregated analytics and diagnostics).
4. Legal bases (EEA/UK)
Where applicable, we process personal data based on: performance of a contract (to deliver the Service), legitimate interests (security, improvement), compliance with legal obligations (e.g., billing records), and consent (where required).
5. Sharing of information
We share data only as needed to run the Service:
- Infrastructure providers (e.g., AWS) to host and process your uploaded receipts and data.
- Payment processing (Stripe) for subscriptions and billing.
- YNAB when you export transactions, using the access you authorised through OAuth and YNAB’s API. See section 6.
- Service providers for email forwarding/support tools (if used).
- Legal if required by law or to protect rights and safety.
6. YNAB integration
This section explains how data obtained through the YNAB API is handled. It applies only if you choose to connect YNAB.
What we access.
- When you choose “Connect YNAB” you sign in on YNAB’s own site and authorise Spendify (OAuth). Spendify never sees your YNAB password.
- YNAB gives us an access token and a refresh token. We use them only to read the names of your YNAB plans and accounts, so you can choose where receipts go, and to create the transactions you select. We do not read your existing transactions, categories, balances or budget amounts.
- We store the tokens (encrypted) and the identifiers and names of the plan and account you chose.
What we send to YNAB. For each receipt you export: the date, the amount, the merchant name, the memo “Export Spendify” and the receipt identifier (used so that the same receipt is never created twice). Spendify does not assign or send categories.
Why we use it. Only to connect your account, let you choose a plan and account, and create the transactions you ask for. We do not use it for advertising, profiling, analytics or training models, and we do not sell it.
How it is stored and protected. Tokens are encrypted with a dedicated AWS Key Management Service key, tied to your account, and stored on Amazon Web Services in the EU (Frankfurt) region. Data travels over HTTPS. All calls to YNAB are made from our servers; your tokens are never sent to your browser. Access is limited to the systems that need it.
Third parties. We do not pass data obtained through the YNAB API to any third party. Our infrastructure provider (AWS) processes it on our behalf, only to run the Service. Our payment processor (Stripe) never receives it.
How long we keep it. Until you disconnect YNAB, delete your account, or revoke Spendify’s access in YNAB (when YNAB tells us the access is no longer valid, we delete our copy). Disconnecting deletes the stored tokens and the plan and account details immediately. Encrypted backups of our database may retain earlier copies for up to 35 days, after which they are permanently removed. Transactions already created in YNAB belong to your YNAB account and are not affected; you manage them in YNAB.
Deleting your data. You can disconnect YNAB at any time in Settings inside the app. You can also ask us to delete your YNAB data, or your whole account, by writing to privacy@spendifyapp.com; we will do it within 30 days. You can revoke Spendify’s access at any time from your YNAB account settings.
Changes. If we ever change how data obtained through the YNAB API is used, we will update this policy and ask for your consent again before applying the change to your YNAB data.
7. Data retention
We retain your data as long as your account is active or as needed to provide the Service. Data obtained through the YNAB API follows the specific rules in section 6. You may request deletion of your receipts and account by contacting support@spendifyapp.com. We may retain certain records where required by law (e.g., billing/accounting).
8. Security
We implement reasonable technical and organizational measures to protect your data. No method of transmission or storage is 100% secure, but we work to safeguard your information.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your data, and to receive a copy of certain information. To exercise rights, contact privacy@spendifyapp.com.
10. Cookies
The website may use essential cookies for basic functionality. The app may use tokens/local storage for login. We do not sell personal information.
11. Children
The Service is not intended for children under 16. If you believe a child has provided personal information, contact us to remove it.
12. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.
Contact: privacy@spendifyapp.com