Privacy Policy
Last updated: January 2026
Our Commitment to Privacy
SpendLens is built on a foundation of privacy. We believe your financial data is deeply personal, and we have designed our entire system to minimize data exposure while still providing powerful insights.
What We Collect
Account Information: Your email address and optional name for account management and communication.
Transaction Data: When you upload CSV files, we store transaction data (date, merchant, amount) to generate reports. This data is encrypted at rest.
Usage Data: Basic analytics about how you use the app (pages visited, features used) to improve our service.
Chat History: Conversations with our AI assistant are stored encrypted to maintain context across sessions.
How We Protect Your Data
Encryption at Rest: All uploaded files and sensitive database fields are encrypted using AES-256-GCM with per-file encryption keys.
AI Data Minimization: We never send your raw transaction descriptions or merchant names to AI systems. Our AI only receives aggregated statistics (category totals, spending trends) and anonymized merchant identifiers.
Secure Infrastructure: We use industry-standard security practices including HTTPS, secure session management, and database-level access controls.
What We Never Do
- Sell your data to third parties
- Send raw transaction data to AI providers
- Store unencrypted financial information
- Log sensitive transaction details
- Keep data after you delete your account
Your Rights
Access: You can view all your stored data through your dashboard at any time.
Export: You can export all your data in JSON or CSV format from the Settings page.
Delete: You can permanently delete all your data with one click. This is irreversible and removes everything including files, reports, chat history, and your profile.
Third-Party Services
We use the following third-party services, each with their own privacy policies:
- Supabase: Database and authentication infrastructure
- OpenAI: AI insights (receives only aggregated, anonymized data)
- Stripe: Payment processing (for Pro subscriptions)
- Vercel: Application hosting and analytics
Contact Us
If you have questions about this privacy policy or your data, contact us at privacy@spendlens.app