Privacy policy
Spendly is a personal-finance tracker made in India. It never asks for a net-banking password, never moves money, shows no ads, and never sells your data or shares it for anyone else’s use.
Last updated 2 October 2026
What we collect
- Your account. Your name, email address and, if you add one, phone number, all encrypted (AES-256-GCM) before they are stored. A password is kept only as a one-way bcrypt hash. If you sign in with Google, we receive your name and email from Google. If you choose an avatar, we store only which of Spendly’s own drawings you picked; no photo is ever uploaded.
- Your money records. The accounts, transactions, budgets, bills, goals, loans and investments you add or import.
- Gmail, only if you connect it. Read-only access. Spendly searches only for emails from known bank senders and keeps only the fields it extracts (amount, date, merchant, account ending, available balance). The email itself is never stored. The access token is encrypted, and disconnecting deletes it.
- Phone notifications, in the Android app. Your phone’s notification token (encrypted) and your notification choices, plus a record of which reminder was sent on which day so it is never sent twice. That record holds no message text and is deleted after 120 days.
- Invitations to Auto-track. While Gmail tracking is in beta, a Spendly admin can let an email address use it, sometimes before that person has signed up. We store the address encrypted, a keyed fingerprint of it so it can be matched at sign-in, and the date access ends. It is deleted when the admin removes it or when that account is deleted, and the security log records only that access was given or removed, never the address.
- Security records. Sign-ins, failed sign-ins, password resets, exports and deletions, with the time, a shortened IP address and the browser type. No names, emails or amounts. Each entry is kept for two years, including after an account is deleted.
- Spendly Premium payments. If you buy Premium, the plan, the amount, the date and the payment references — Razorpay’s on the website, Google Play’s order number in the Android app. Your card, UPI or bank details are entered in Razorpay’s or Google Play’s own payment window and never reach Spendly. If you ask for a refund or to cancel, we keep the request, the reason you give and our reply.
- What you send us. Feedback and feature requests, linked to your account.
- Bank alerts we could not read. When an email or SMS from a bank is not one we know how to read, we keep a masked outline of it so we can fix that — every number replaced with #, and every word that is not ordinary bank wording (names, payees, places) replaced with ▢ — plus the bank and a reason such as “no amount found”. It is not linked to you or your account, and it is deleted 30 days after that outline was last seen. The message itself is never stored.
Bank SMS (coming to the Android app)
Bank SMS tracking is off until you turn it on, and only reads messages that arrive after that; it never reads your inbox or past messages. It works in one of two ways, each switched on separately: by reading the notification your Messages app shows for a new text (this needs Android’s Notification access; notifications from every other app are ignored without being read), or by receiving the SMS itself (this needs the SMS permission). On your phone, every message that is not a transaction alert from a bank’s registered sender ID or the bank’s name (personal texts, one-time passwords, offers) is ignored and never leaves it. The text of each bank transaction alert is sent over an encrypted connection to Spendly, which reads the amount, account, date and payee from it and stores only those, exactly as with bank emails. The message text itself is not stored and not logged. Until it is sent, an alert waits on your phone for at most 7 days, and switching tracking off deletes anything still waiting.
Google user data
If you sign in with Google, Spendly receives your name and email address. If you connect Gmail, Spendly uses read-only access for one purpose: finding transaction alerts from banks and turning them into transactions in your account. It stores only the extracted fields listed above, never the email itself.
- Gmail data is used only to provide the transaction-import feature you turned on.
- It is never used for advertising, never sold, and never used to train AI or machine-learning models.
- No person at Spendly reads your email — the email itself is never stored, so there is nothing to read.
- It is shared with others only as needed to run that feature, as listed under “Services that process data for us”.
Spendly’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Read the Google API Services User Data Policy. You can remove Spendly’s access at any time by disconnecting Gmail in the app, or from your Google Account’s security settings.
How we use it
Only to run Spendly for you: show your balances and reports, remind you about bills, budgets and SIPs (by email or phone notification, each one you can switch off in Profile → Notifications), keep your account secure, and answer your feedback. We do not use your data for advertising, and nothing is sold.
Services that process data for us
- Hosting and database: Vercel (the app) and MongoDB Atlas (your records).
- Google: Google sign-in and Gmail, if you use them; Gemini answers questions you ask Spendly AI, using a summary of your own figures.
- Razorpay: processes Spendly Premium payments on the website (UPI, cards, netbanking) under its own privacy policy and India’s payment regulations.
- Google Play: processes Spendly Premium payments made in the Android app, under Google’s own privacy policy.
- Firebase Cloud Messaging: delivers phone notifications to the Android app.
- Email delivery: our mail provider sends the reminder and summary emails you choose.
- Error reports: when the server hits an error, Sentry receives the error and the page it happened on, never your identity or your data.
How long we keep it
Your account and records are kept until you delete them. Deleting your account erases them at once and permanently (see Delete your account). Security records expire two years after they are written; notification records after 120 days.
Your choices and rights
- Export your transactions and portfolio as CSV, Excel or a PDF report at any time, from Reports. The PDF is made on our server when you ask for it and is not kept.
- Edit or delete any record, disconnect Gmail, and switch any reminder off.
- Delete your account and everything in it, from the app.
- Ask us what we hold about you, or to correct it, under India’s Digital Personal Data Protection Act, 2023.
Children
Spendly is meant for adults managing their own money and is not directed at children under 18.
Changes
When this policy changes, the date at the top changes with it. A change in how your data is used will be announced in the app first.
Contact
Spendly is operated by MAYUR ROHOKALE. Questions, requests or a security report: support@spendlymoney.com. You can also write to us from the app: Profile → Feedback & feature requests.
- Operated by
- MAYUR ROHOKALE
- Address
- Ahmendnagar,414103
- Hours
- Mon–Sat, 10:00–18:00 IST
- Grievance officer
- MAYUR ROHOKALE