Privacy policy
Last updated: July 2026
Draft — pending counsel review before public launch1. What Spendkin is
Spendkin is a personal finance app that turns transaction alerts you already receive — app notifications, text messages, emails, and receipts — into a private record of your spending. It is built around one principle: capture, don’t connect. We never ask for, store, or transmit your bank credentials, and there is no bank linking.
2. Information we collect
- Account: your email address, used to sign you in.
- Transactions: the entries you record and the ones created from captures. Their content is end-to-end encrypted on your device before it reaches us (see §9), so we store it but cannot read it.
- Captured text: raw alert, message, or receipt text reaches our servers only for the two channels that need it — email forwarding, and the opt-in “Ask AI about new formats” setting — and is deleted as soon as it is parsed (§5). Everything else is parsed on your device and never sent.
We do not collect your contacts, location, browsing history, or photo library. Receipt images are processed on your device; only extracted text reaches our servers.
3. Capture channels are opt-in, individually
- Notification capture (Android): reads notifications only from the apps you select, after an explicit in-app disclosure and the system permission. Disable any time.
- Text messages (iPhone): forwarded by a Shortcut you install and control, authenticated with a key you can revoke.
- Ingest email: only mail sent to your personal Spendkin address is processed. Rotate the address any time.
- Share & receipts: processed only when you explicitly share content into Spendkin or pick an image; OCR runs on-device.
4. How parsing works
Most captures are parsed on your device by Spendkin’s built-in parser — the text never leaves your phone. Only two cases send text to our servers: a forwarded email (parsed on the server, then immediately end-to-end encrypted to your key), and — only if you keep “Ask AI about new formats” on — a message in a format Spendkin has never seen, sent once to an AI model (Anthropic Claude, under a no-training, zero-retention API configuration) to learn the pattern. Turn that setting off for strict-local parsing, where nothing is ever sent. Parse inputs are not logged, and the resulting transaction is stored end-to-end encrypted (§9).
5. Data retention
Raw captured text is deleted as soon as it has been parsed (or when you approve or reject a capture under review). Any remainder is permanently purged within 72 hours. One-time sign-in codes expire after 10 minutes; sessions after 90 days. The structured transaction remains until you delete it. Because your ledger is end-to-end encrypted (§9), a review capture's original text is stored as ciphertext we cannot read while it awaits your device.
6. Your controls and rights
- Export everything from Settings at any time (JSON + CSV).
- Delete all transactions without closing your account.
- Delete your account in-app — it closes immediately and irreversibly; the encrypted data we hold, which we cannot read, is permanently erased within 72 hours.
- GDPR/CCPA requests: hello@spendkin.com.
7. Third-party processors
Hosting provider, Cloudflare (inbound email routing), Anthropic (parsing; no-training, zero-retention), Google (push delivery; on-device ML Kit OCR on Android), Apple (on-device Vision OCR on iOS), Apple/Google (sign-in and billing), RevenueCat (subscription state). We sell data to no one and run no ads.
8. Security
Data is encrypted in transit; capture endpoints are authenticated per user with revocable keys; untrusted email senders are quarantined for your review so a leaked address can’t forge cleared transactions.
9. End-to-end encryption (on by default)
End-to-end encryption is on by default for every account. It is set up during onboarding — you save one recovery code — and cannot be turned off; there is no unencrypted mode.
- Your transactions, accounts, rules, and custom categories are encrypted on your device before they sync. We store only the ciphertext and cannot read your money data. (System category names — the default vocabulary — are not personal data and remain readable.)
- Encryption uses one key, held only on your device and exported to you as a single recovery code. That code is the only key. If you lose it, your encrypted data cannot be recovered — not by you and not by us. Please save it somewhere safe.
- One honest exception: email forwarding is optional — you choose to turn it on, and you can turn it off at any time. When it is on, a transaction forwarded to you by email is parsed on our server (so we read that one message to extract it), then immediately sealed to your key and the plaintext discarded. That single message is readable only for the moment it is parsed; the stored result is ciphertext we cannot read, the same as everything else. Everything captured on your phone is encrypted before it ever leaves the device.
- Because we hold no key, encrypted content cannot be included in a human-readable data export or recovered through support — an export returns your encrypted blobs, and only your device can decrypt them.
End-to-end encryption is independent of the “Ask AI about new formats” setting: that setting governs whether an unrecognized message format is sent once to be parsed, not what we can read of your stored data.
10. Children’s privacy
Spendkin is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect their data.
11. Changes to this policy
We’ll post changes here and, for material changes, notify you in the app before they take effect.