Privacy Policy
Last updated: July 22, 2026
Privacy at a glance
Privacy policies are rarely fun to read. Here is the short version of how SpendMoney thinks about your data. The full policy below is the complete version.
- We do not sell your data. SpendMoney is not funded by advertising against your budget content.
- No bank connections. You enter or upload transactions yourself. We do not link to your bank login.
- Sensitive budget fields are encrypted in the app before storage, with strict row-level access controls.
- You control sharing. Only people you invite can see a shared budget, and you can revoke access.
- You can delete your account in Settings. That removes your account and associated app data.
Your privacy matters
Your financial data belongs to you. This Privacy Policy explains what SpendMoney collects, how we use it, who helps us run the service, and the choices you have.
SpendMoney is a personal budgeting web app. By creating an account or using the service, you agree to this policy. If you do not agree, please do not use SpendMoney.
Who we are
SpendMoney is the service available at https://spendmoney.io (and temporary hosting hostnames we may operate during deployment).
Questions about privacy or this policy can be sent through our Contact page or by emailing support@spendmoney.io.
What information we collect
Account information
When you create an account, we collect your email address and any profile details you provide (such as a username). Passwords are handled by our authentication provider and are never stored in plain text. If you enable two-factor authentication, we process the codes and related verification data needed to protect your sign-in.
Budget and financial content you enter
You provide budget information such as income entries, spending categories, budget limits, funds, and transaction details. You may also upload transaction files (for example CSV or Excel). You control what you enter or upload. We do not connect to your bank accounts.
Developers do not have routine access to your private budget content. Access is restricted, role-based, and used only when required to operate, secure, or support the service.
Sharing relationships
If you share a budget, we store the relationship between accounts (who invited whom, permission level, and acceptance status) so shared access can work.
Usage and operational information
We may process limited operational information—such as error logs, authentication events, and service events—to run, secure, and improve SpendMoney. We do not sell this information. Access to logs and data is restricted by role and limited to operational or support needs.
Contact information
If you contact us through the Contact page, we collect your name, email address, and message so we can respond. We may also send a confirmation email that includes a copy of your message.
Device preferences stored on your device
SpendMoney may store small preference and session values in your browser (for example font size, high-contrast mode, keyboard-shortcut preference, selected budget, and temporary sign-in or tutorial flags). These stay on your device unless needed for authentication with our providers.
How we use your information
- To provide and maintain the SpendMoney service (accounts, budgets, funds, transactions, sharing)
- To authenticate you and protect your account (including optional two-factor authentication and security notices)
- To respond to support requests and contact-form messages
- To operate, secure, debug, and improve the app based on how the service is used
- To send important account notifications (security alerts, password reset, account changes)
- To enforce our Terms of Service and protect against fraud or abuse
We do not sell your personal information. We do not use your budget content to target third-party ads.
How we protect your data
We use multiple layers of protection to keep your data private and secure.
- Application-layer encryption for sensitive budget fields before they are stored
- Secure authentication (email and password, with optional two-factor authentication)
- Row-level security policies that limit data access by account and sharing scope
- Encrypted transport (HTTPS) between your browser and our service
- Regular security reviews and updates
- No direct bank account connections—you upload or enter transactions yourself
Some operational metadata may still be required for app features (for example IDs, timestamps, and sharing relationships). We minimize this data and protect access to it.
No internet service can promise absolute security. We continuously improve safeguards and notify users when legally required if a material security incident occurs.
Sharing and shared access
SpendMoney allows you to share budget access with trusted people (for example family members or partners). When you share:
- You control who can see and edit your budget
- Shared users only see budgets you explicitly grant access to
- You can revoke access at any time
- Shared users are bound by the same privacy commitments and Terms of Service
We do not share your budget content with third parties for their own marketing. We only disclose data as described in this policy (service providers, legal requirements, or with people you invite).
Third-party services
We use limited third-party services to operate SpendMoney. We only share the minimum information necessary for each provider to perform its role:
- Supabase: authentication and secure data storage
- Postmark: transactional email (password resets, security notices, contact messages, and similar)
- Netlify: application hosting and delivery of the web app
These services have their own privacy policies. They process data as our processors (service providers), not as independent sellers of your budget content.
Cookies and local storage
SpendMoney uses browser storage and cookies (or similar technologies) that are needed to run the product:
- Authentication and session state so you stay signed in securely
- UI preferences such as font size, contrast, and keyboard shortcuts
- Lightweight product state such as the last selected budget or temporary onboarding flags
We do not use third-party advertising cookies to track you across other sites.
How long we keep information
- Account and budget data: kept while your account is active so the service can work.
- Account deletion: when you delete your account in Settings, we remove your authentication account and associated app data. Some residual copies may temporarily remain in encrypted backups or logs until those systems cycle, and email systems may retain messages you already sent or received.
- Contact messages: retained as needed to respond and keep a reasonable support record.
- Operational logs: retained for a limited period for security, reliability, and troubleshooting.
Where information is processed
SpendMoney is operated using cloud infrastructure. Your information may be processed and stored in the United States or other countries where our service providers (such as Supabase, Postmark, and Netlify) operate. Those providers apply their own security and compliance controls. If you access SpendMoney from outside the country where our providers host data, you understand that your information may be transferred across borders to provide the service.
Legal requests and safety
We may disclose information if we believe in good faith that it is required by law, regulation, legal process, or governmental request, or if needed to protect the rights, safety, or security of SpendMoney, our users, or the public. We will limit any disclosure to what is reasonably necessary.
Your rights and choices
Depending on where you live, you may have rights over your personal information. In practice, SpendMoney supports the following:
- Access: view your account and budget data while signed in
- Correct: update profile details and edit budget content in the app
- Delete: remove your account and associated data from Settings
- Copy / portability requests: request help obtaining a copy of personal data we hold about you by using the Contact page (self-serve bulk export is not currently offered in the product)
- Communications: opt out of non-essential messages; security and account emails may still be required to operate the service
- Sharing: revoke shared budget access at any time
To exercise a privacy request, use Settings where available, or contact us through the Contact page. We may need to verify that the request comes from the account holder.
Children’s privacy
SpendMoney is not directed to children under 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will take appropriate steps to delete it.
Changes to this Privacy Policy
We may update this Privacy Policy over time. We will show important changes by updating the "Last updated" date at the top of this page. Continuing to use SpendMoney after those changes means you accept the updated policy, as permitted by applicable law. For material changes, we may also provide additional notice when practical (for example, an in-app notice or email).
Contact us
If you have questions about this Privacy Policy or how we handle your data, please reach out via the contact form or email support@spendmoney.io:
Contact UsRelated: Terms of Service