Public privacy information
SpendYse privacy policy
This policy explains how SpendYse handles information when people use the public website, sign in, or work inside a private family-finance ledger.
Effective and last updated: 1 September 2026
1. Scope and service
SpendYse is a private family-finance application used to organize accounts, income, expenses, transfers, recurring items, budgets, assets, liabilities, reports, and related evidence in invitation-controlled family ledgers. This policy applies to the SpendYse web application and public website. The optional Android SMS Companion has additional details in its separate privacy notice.
2. Information SpendYse handles
Account and Google sign-in information
When you choose Google sign-in, SpendYse requests only the standard OpenID identity, email address, and basic profile information needed to identify you and establish a secure session. This may include your Google account identifier, email address, display name, and profile image. SpendYse does not request access to Gmail, Google Drive, Google Contacts, Google Calendar, or financial information held by Google.
Financial and workspace information
People with authorized ledger access may enter financial records, categories, account balances, budgets, asset and liability details, reminders, notes, and supporting evidence. SpendYse also stores ledger membership, roles, permissions, invitations, and audit evidence needed to control and explain access and changes.
Security and operational information
SpendYse processes session, authentication, security-event, device, backup, feedback, and diagnostic metadata needed to operate, protect, troubleshoot, and improve the service. Public website requests may produce standard hosting logs such as request time, browser or device information, and network address.
3. How information is used
- Authenticate users and verify their active family-ledger access.
- Provide the finance, reporting, planning, backup, and collaboration features users request.
- Protect accounts, enforce permissions, investigate faults, and retain security and audit evidence.
- Respond to support, privacy, deletion, and user-submitted feedback requests.
- Maintain service reliability, prevent misuse, and meet applicable operational obligations.
SpendYse does not sell personal or financial information and does not use it for advertising.
4. Google user data
Google sign-in data is used only to identify the user, establish and protect the SpendYse session, display the user's basic account identity, and associate that identity with authorized ledger access. It is not used to build advertising profiles or for unrelated purposes.
SpendYse's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Service providers and sharing
SpendYse uses service providers to host and secure the application and public website, authenticate users, store application data and private evidence, deliver operational email, and process user-requested feedback or backups. Current infrastructure includes Vercel for the application, Supabase for authentication/database/storage, Cloudflare for domain and public-site delivery, and GitHub when an authenticated user deliberately submits feedback. Providers process information only as needed to deliver their contracted service.
Information may also be disclosed when required by applicable law, to protect users or the service, or as part of a user-directed export, backup, or integration. SpendYse does not make a family ledger public.
6. Retention, access, and deletion
Information is retained while it is needed to provide the ledger, preserve financial and audit integrity, protect the service, meet backup or security requirements, or resolve a request. Administrators can manage invitations, ledger access, devices, transactions, backups, and other records using available controls. Some audit, transaction, security, or relationship records may remain when necessary to preserve ledger integrity and accountability.
To request access, correction, or deletion that is not available in the application, contact the family-ledger administrator or email the service operator below. Requests are evaluated against the requester's identity, ledger permissions, integrity requirements, and applicable obligations.
7. Security
SpendYse uses HTTPS in Production, permission-controlled ledgers, protected application routes, server-side authorization, multi-factor security options, encrypted credential/payload handling where applicable, private storage boundaries, and security/audit logging. No system can guarantee absolute security, so users should protect their account and report suspected misuse promptly.
8. Children
SpendYse is intended for private family financial management and is not directed to children as a standalone service. Family-ledger administrators are responsible for invitations and access.
9. Policy changes
This policy will be updated when material data handling, features, providers, or legal requirements change. The latest effective date appears at the top of this page. Material changes may also be communicated through the application or another appropriate channel.
10. Contact
Privacy, access, correction, or deletion questions can be sent to nadeeka.adithya@gmail.com.