Spendimo Privacy Policy
Effective date: August 1, 2026
Spendimo was built on one idea: your spending is nobody’s business — including ours. This policy explains exactly what that means in practice. It’s written to be read, not skimmed past.
The short version
- Without an account, Spendimo never talks to our servers. Not once. Everything — your entries, receipts, trends — lives only on your iPhone.
- With a free account, we hold your email, name, and a hashed password. Your financial entries still stay on your phone; free accounts don’t sync.
- With a Pro subscription, your entries sync to our server in Germany so they can back up, follow you across devices, and be shared with your partner — that’s the entire reason the server exists.
- Receipt photos stay on your iPhone unless you say otherwise. Scanning always runs on Apple’s on-device Vision engine — no server of ours ever reads or analyzes a receipt. Pro users can opt in to receipt sync (off by default) to store their receipt photos in their account.
- We use no analytics SDKs, no advertising networks, no trackers, and no AI — in the app or on this website.
Who we are
Spendimo is made by BekApps LLC, a limited liability company registered in Delaware, United States. For everything in this policy, BekApps LLC is the “data controller” — the party responsible for your data.
- Contact: [email protected]
- Postal address: 1111B S Governors Ave, Suite 29063, Dover, DE 19904, USA
What we collect — and what we never collect
If you use Spendimo without an account
Nothing. We collect nothing at all. The app makes no network requests to our servers in this mode — there is no account, no identifier, and no telemetry. Your data sits in the app’s protected storage on your iPhone, covered by iOS file protection.
The honest flip side: because we never see this data, we cannot back it up or recover it. If the phone is lost or the app is deleted, the data is gone. You can export everything to CSV at any time, free — we recommend doing so occasionally.
If you create a free account
We store the details you give us when signing up:
- Email address (to identify your account and reset your password)
- Full name (so the app can greet you and your partner can recognize you)
- Password — stored only as a cryptographic hash; we cannot read it
- Optionally, a phone number if you add one to your profile
- App preferences you choose to save, such as your display currency
Your financial entries do not sync on a free account. They remain on your device only.
If you subscribe to Pro
Everything above, plus the financial entries you create sync to our server: amounts and currencies, descriptions, categories, dates, notes, tags, payment-method labels, recurring-bill settings, and — if you use partner sharing — the sharing status of each record. If you additionally turn on receipt sync (off by default), the compressed receipt photos you scan are stored with their expenses too. This is what makes backup, multi-device sync, and partner sharing possible; it is the only purpose this data is used for.
What we never collect, on any tier
- Receipt photos — unless you opt in. Scanning happens on your iPhone with Apple’s Vision framework; no server of ours ever reads or analyzes a receipt. The photo is kept on your device with its expense. Only if you turn on receipt sync (Pro, off by default) is a compressed copy uploaded to your account so your other devices — and your partner, on shared records — can view it. Deleting the expense, the receipt, or your account deletes the server copy. With receipt sync off, receipts never leave your iPhone.
- Bank data. Spendimo connects to no banks, holds no credentials, and reads no accounts. Everything in the app is there because you typed or scanned it.
- Location, contacts, photos (beyond the receipt you actively point the camera at).
- Behavioral analytics, advertising identifiers, or tracking data of any kind. There are no third-party analytics or advertising SDKs in the app, and no AI system — ours or anyone’s — processes your data.
Why we’re allowed to process your data
European law (GDPR) requires us to name a lawful basis for each use:
| What | Why | Lawful basis |
|---|---|---|
| Account data (email, name, password hash) | Operating your account, signing you in, resetting passwords | Contract — Art. 6(1)(b) |
| Synced financial entries (Pro) | Providing the sync, backup, and sharing service you subscribed to | Contract — Art. 6(1)(b) |
| Sharing records with your partner | Only happens when you explicitly mark a record as shared | Consent — Art. 6(1)(a), withdrawable at any time |
| Subscription events (via RevenueCat) | Activating your purchase, preventing fraud | Contract — Art. 6(1)(b) and legitimate interest — Art. 6(1)(f) |
| Password-reset emails | Account security you requested | Contract — Art. 6(1)(b) |
We do not profile you, score you, or make automated decisions about you.
Partner sharing, precisely
Sharing is opt-in twice over: both people link accounts by explicit invitation, and then each individual record is private unless you mark it shared when creating it. Your partner sees only the records you shared — never your private entries, never your totals. Shared records use an approval flow: your partner can approve or dispute them, and deleting an approved shared record requires their consent too.
You can stop at any time. Unsharing and ending a partnership remove the shared records from your ex-partner’s view; the removal signal contains no record content. The real-time “something changed” notification between partners is exactly that — a content-free ping; your data is never inside it.
What your partner does with information they’ve seen while records were shared is, like anything you tell another person, between the two of you.
The complete list of companies that touch your data
- Hetzner Online GmbH (Germany) — hosts our server and database, in a German data center. All synced financial data lives here, inside the EU. Hetzner processes it under a data processing agreement (Art. 28 GDPR) and is ISO 27001 certified.
- RevenueCat, Inc. (United States) — manages subscription state. RevenueCat receives a random account identifier (UUID) and Apple purchase information only — never your email, name, or any financial entry. Transfers to RevenueCat are covered by the EU–U.S. Data Privacy Framework, under which RevenueCat is certified.
- Apple — processes your payment as an independent company under its own terms and privacy policy. We never see your payment details.
- Brevo (France, EU) — delivers password-reset emails. Receives only your email address, only when you request a reset.
That is the entire list. No analytics companies, no advertising networks, no data brokers — and this website loads nothing from third parties either, which is why it has no cookie banner: there are no cookies to warn you about.
Where your data lives
Synced financial data is stored exclusively in Germany, inside the European Union. The only data that leaves the EU is the pseudonymous subscription identifier sent to RevenueCat in the United States, protected by the EU–U.S. Data Privacy Framework. Password-reset emails are delivered by Brevo from within the EU.
How long we keep it, and how deletion works
We keep account and synced data for as long as your account exists.
You can delete your account from inside the app (Settings → Account). This is a real deletion, effective immediately — not a deactivation:
- Your account record and synced entries are permanently erased from our production database.
- If you ever shared records with a partner, blank, anonymized markers remain in place of the shared records — stripped of every amount, description, and name — solely so your ex-partner’s app knows to remove its copies. They contain no personal data.
- Encrypted server backups age out within 30 days at the latest, after which no trace remains.
One important note: deleting your account does not cancel an active subscription, because subscriptions are managed by Apple, not us. The app warns you about this during deletion and links you to Apple’s subscription settings.
Data on your device is always yours to delete by removing the app.
Your rights
If you’re in the EU or another jurisdiction with data protection laws, you have the right to:
- Access the data we hold about you
- Correct it (most of it you can edit directly in the app)
- Delete it (the in-app account deletion does exactly this)
- Export it — the app’s free CSV export gives you every transaction in full precision, anytime
- Restrict or object to processing
- Withdraw consent for partner sharing at any time
To exercise any of these, email [email protected] — we’ll respond within one month. You also have the right to complain to your data protection authority (in the Netherlands, the Autoriteit Persoonsgegevens; in Germany, your state’s supervisory authority).
If you’re in Turkey (KVKK)
The Turkish Personal Data Protection Law (KVKK, Law No. 6698) gives you the same substance of rights as listed above — access, correction, deletion, and objection. Our data protection representative in Turkey is Ebubekir Yazici; KVKK requests can be sent to [email protected] in Turkish or English.
Age
Spendimo is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18.
Changes to this policy
If we change this policy, we’ll change the date at the top and, for meaningful changes, say so plainly in the app’s release notes. We will never quietly weaken the commitments on this page.
Contact
Questions about privacy: [email protected]