Spendimo Privacy Policy

Effective date: August 1, 2026

Spendimo was built on one idea: your spending is nobody’s business — including ours. This policy explains exactly what that means in practice. It’s written to be read, not skimmed past.

The short version

Who we are

Spendimo is made by BekApps LLC, a limited liability company registered in Delaware, United States. For everything in this policy, BekApps LLC is the “data controller” — the party responsible for your data.

What we collect — and what we never collect

If you use Spendimo without an account

Nothing. We collect nothing at all. The app makes no network requests to our servers in this mode — there is no account, no identifier, and no telemetry. Your data sits in the app’s protected storage on your iPhone, covered by iOS file protection.

The honest flip side: because we never see this data, we cannot back it up or recover it. If the phone is lost or the app is deleted, the data is gone. You can export everything to CSV at any time, free — we recommend doing so occasionally.

If you create a free account

We store the details you give us when signing up:

Your financial entries do not sync on a free account. They remain on your device only.

If you subscribe to Pro

Everything above, plus the financial entries you create sync to our server: amounts and currencies, descriptions, categories, dates, notes, tags, payment-method labels, recurring-bill settings, and — if you use partner sharing — the sharing status of each record. If you additionally turn on receipt sync (off by default), the compressed receipt photos you scan are stored with their expenses too. This is what makes backup, multi-device sync, and partner sharing possible; it is the only purpose this data is used for.

What we never collect, on any tier

Why we’re allowed to process your data

European law (GDPR) requires us to name a lawful basis for each use:

WhatWhyLawful basis
Account data (email, name, password hash)Operating your account, signing you in, resetting passwordsContract — Art. 6(1)(b)
Synced financial entries (Pro)Providing the sync, backup, and sharing service you subscribed toContract — Art. 6(1)(b)
Sharing records with your partnerOnly happens when you explicitly mark a record as sharedConsent — Art. 6(1)(a), withdrawable at any time
Subscription events (via RevenueCat)Activating your purchase, preventing fraudContract — Art. 6(1)(b) and legitimate interest — Art. 6(1)(f)
Password-reset emailsAccount security you requestedContract — Art. 6(1)(b)

We do not profile you, score you, or make automated decisions about you.

Partner sharing, precisely

Sharing is opt-in twice over: both people link accounts by explicit invitation, and then each individual record is private unless you mark it shared when creating it. Your partner sees only the records you shared — never your private entries, never your totals. Shared records use an approval flow: your partner can approve or dispute them, and deleting an approved shared record requires their consent too.

You can stop at any time. Unsharing and ending a partnership remove the shared records from your ex-partner’s view; the removal signal contains no record content. The real-time “something changed” notification between partners is exactly that — a content-free ping; your data is never inside it.

What your partner does with information they’ve seen while records were shared is, like anything you tell another person, between the two of you.

The complete list of companies that touch your data

That is the entire list. No analytics companies, no advertising networks, no data brokers — and this website loads nothing from third parties either, which is why it has no cookie banner: there are no cookies to warn you about.

Where your data lives

Synced financial data is stored exclusively in Germany, inside the European Union. The only data that leaves the EU is the pseudonymous subscription identifier sent to RevenueCat in the United States, protected by the EU–U.S. Data Privacy Framework. Password-reset emails are delivered by Brevo from within the EU.

How long we keep it, and how deletion works

We keep account and synced data for as long as your account exists.

You can delete your account from inside the app (Settings → Account). This is a real deletion, effective immediately — not a deactivation:

One important note: deleting your account does not cancel an active subscription, because subscriptions are managed by Apple, not us. The app warns you about this during deletion and links you to Apple’s subscription settings.

Data on your device is always yours to delete by removing the app.

Your rights

If you’re in the EU or another jurisdiction with data protection laws, you have the right to:

To exercise any of these, email [email protected] — we’ll respond within one month. You also have the right to complain to your data protection authority (in the Netherlands, the Autoriteit Persoonsgegevens; in Germany, your state’s supervisory authority).

If you’re in Turkey (KVKK)

The Turkish Personal Data Protection Law (KVKK, Law No. 6698) gives you the same substance of rights as listed above — access, correction, deletion, and objection. Our data protection representative in Turkey is Ebubekir Yazici; KVKK requests can be sent to [email protected] in Turkish or English.

Age

Spendimo is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18.

Changes to this policy

If we change this policy, we’ll change the date at the top and, for meaningful changes, say so plainly in the app’s release notes. We will never quietly weaken the commitments on this page.

Contact

Questions about privacy: [email protected]