WeSpend Privacy Policy

Effective Date: February 18, 2026 Last Updated: September 3, 2026


1. Introduction

WeSpend ("App", "we", "us", or "our") values your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our expense tracking application.

We comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), the California Consumer Privacy Act (CCPA) for California residents, and other applicable privacy laws worldwide.


2. Information We Collect

2.1 Information You Provide

Data Type Purpose Required
Email address Account identification, password reset Required (email signup)
Password Account authentication Required (email signup)
Display name (nickname) User identification within household Optional
Apple ID information Apple Sign-In authentication Required (Apple login)
Google account information Google Sign-In authentication Required (Google login)

2.2 Information Generated Through Service Use

Data Type Purpose
Expense records (amount, category, memo, date) Core service functionality
Payment method (card/cash) Expense categorization and statistics
Attribution (me/partner/together) Shared household tracking
Household invite codes Partner invitation feature
Wonny chat content and recent-expense summaries Generate expense-entry or analysis responses requested by the user
Receipt or transaction screenshots selected by the user Recognize transactions when requested by the user
Agent connection data (display name, Household, scopes, issue/expiry/revocation/last-used times, and hashed credential) Authenticate, limit, audit, and revoke an external Agent authorized by the user
Agent expenses and provenance (amount, currency, category, memo, transaction/recorded times, service, tool, run, payment rail, and invoice URL) Record and retrieve costs incurred by an Agent and let Household members audit them
Optional Household aggregate summary (totals and counts by currency, category, and Human/Agent expense type) Provide user-authorized spending analysis without exposing individual expense rows
Feedback type and content, plus app version, OS version, and device model at submission Respond to inquiries, diagnose issues, and improve the service
Optional product-research responses (campaign and locale, light answers, interview transcript, and user-confirmed summary) Conduct research the user chooses to join and improve WeSpend

2.3 Automatically Collected Information

Data Type Purpose
Device identifiers Anonymous login, service provision
Pseudonymous user identifier (Firebase UID); expense-event attributes (amount, category, payment method, and currency); budget amounts and periods; interaction events; app/device information; and approximate location (country, region, and city) inferred from the IP address Service analytics and improvement through Amplitude

3. How We Collect Information


4. How We Use Your Information

We use your personal data only for the following purposes:

Purpose Description Legal Basis (GDPR)
Service Provision Expense tracking, statistics, shared household features Contract performance
Account Management User identification, login, password reset Contract performance
Partner Connection Household sharing via invite codes Consent
Service Improvement Error analysis, usability improvements Legitimate interest
Optional Product Research Invite selected users, record only responses they choose to submit, and summarize an optional follow-up interview Consent and user request
Optional AI Features Wonny responses and screenshot transaction recognition requested by the user Contract performance and user request
Agent Expense Ledger Record costs incurred by a user-connected Agent in the same Household ledger and let members distinguish, review, and audit them Contract performance and user request
Optional Household Summary Analysis When explicitly enabled by the current owner of a one-person Household, calculate aggregate-only spending totals without returning individual expense rows Contract performance and user request
Agent Connection Security Issue, hash, expire, revoke, rate-limit, and audit least-privilege credentials bound to one Household Contract performance and legitimate interest
Operational Support and Event Monitoring Review sign-up, feedback, first AI chat, and purchase alerts plus hourly expense summaries in event-specific, restricted-access Slack operations channels, and review currently retained expense, feedback, sign-up, AI-session, and purchase records in a private operations console Legitimate interest

5. Data Retention


6. Data Sharing

WeSpend does not sell your personal data. We share your information only in the following circumstances:

  1. With your consent: When you explicitly agree to share
  2. Legal requirements: When required by law or legal process
  3. Shared household: With partners you connect via invite code (core service feature)
  4. External Agent connected by the user: By default, the Agent may retrieve only expenses recorded by that same Agent connection. If the user separately enables household_expense:read:summary, the default own-expense access remains active and the optional scope adds aggregate-only Household analysis. It is available only while the authorizing user is the current owner and sole member of the credential-bound Household. That optional scope returns aggregate totals and counts by currency, category, and Human/Agent expense type, plus the selected period's start and end boundaries; it does not return individual expense rows or individual expense timestamps, memos, merchants or vendors, invoices, tool or run identifiers, member data, or expense/category/member identifiers, and it grants no edit or delete access. The server rechecks ownership and membership on every request, fails closed, and permanently revokes the optional grant when either changes. It returns no partial result when the bounded scan exceeds 2,000 records or the Household has more than 100 total category records, including archived categories.

7. Data Processors and International Transfers

We use the following third-party service providers:

Provider Service Location Transfer Method
Google LLC (Firebase) Cloud storage, authentication, server functions South Korea (Seoul) and United States, depending on the Firebase service region Network transfer during service use
Apple Inc. Apple Sign-In authentication United States Network transfer during Apple login
Amplitude, Inc. Product analytics, including account-linked expense and budget event attributes United States Pseudonymous identifier, financial event attributes, interaction events, and app/device information transferred during app use
Anthropic, PBC User-requested AI chat and screenshot transaction recognition United States Required prompts, screenshots, and expense summaries transferred when the feature is used
Slack Technologies Limited (Salesforce; Slack Technologies, LLC for US and Canadian customers) Operational support and backend event monitoring Ireland (processing entity for customers outside the US and Canada), the United States (default data storage), or the workspace's selected data-residency region Sign-up account information, full feedback and submission details, the first AI request/response and proposed expense, and verified purchase metadata are transferred to event-specific operations channels through the HTTPS Slack Web API when the event occurs; expense counts, per-currency totals, and a private-console link are transferred hourly to the expense channel through an HTTPS Incoming Webhook
OpenAI OpCo, LLC or OpenAI Ireland Ltd. (ChatGPT Sites) Hosting, authentication, maintenance, and support for the access-restricted private operations console United States, Ireland, and locations identified in OpenAI's sub-processor list When an authorized operator opens the console, permitted fields from currently retained operations records are transmitted by HTTPS for display; the console does not maintain a separate activity database

International Transfer Safeguards: These providers are certified under the EU-US Data Privacy Framework or comply with GDPR Standard Contractual Clauses (SCCs).


8. Your Rights

All Users

EU/EEA Residents (GDPR Rights)

California Residents (CCPA Rights)

How to Exercise Your Rights

We will respond to your request within 30 days (or as required by applicable law).


9. Data Security

We implement appropriate technical and organizational measures to protect your data:

  1. Encryption: Passwords are encrypted at rest (Firebase Authentication)
  2. Transport Security: All data transmitted via TLS/HTTPS
  3. Access Controls: Database access restricted via Firestore Security Rules
  4. Authentication: Industry-standard OAuth 2.0 for social logins
  5. Regular Reviews: Periodic security assessments and updates

10. Children's Privacy

WeSpend is not intended for children under 16 years of age (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.


11. Cookies and Tracking

The WeSpend app does not use web cookies. The app uses Amplitude to collect a pseudonymous Firebase UID; expense-event attributes such as amount, category, payment method, and currency; budget amounts and periods; interaction events; app/device information; and approximate location (country, region, and city) inferred from the IP address for service analytics and improvement. We do not collect precise GPS location. You may object to this processing or request deletion of analytics data using the contact information below.


12. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via in-app notification or email before the changes take effect.


13. Contact Us

For questions or concerns about this Privacy Policy or our data practices:


14. Regulatory Contacts

European Union (EU/EEA)

You may lodge a complaint with your local Data Protection Authority: - EU DPA List: https://edpb.europa.eu/about-edpb/about-edpb/members

United States (California)

South Korea


This Privacy Policy is effective as of February 18, 2026 and was last updated on September 3, 2026.