Effective Date: February 18, 2026 Last Updated: September 3, 2026
WeSpend ("App", "we", "us", or "our") values your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our expense tracking application.
We comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), the California Consumer Privacy Act (CCPA) for California residents, and other applicable privacy laws worldwide.
| Data Type | Purpose | Required |
|---|---|---|
| Email address | Account identification, password reset | Required (email signup) |
| Password | Account authentication | Required (email signup) |
| Display name (nickname) | User identification within household | Optional |
| Apple ID information | Apple Sign-In authentication | Required (Apple login) |
| Google account information | Google Sign-In authentication | Required (Google login) |
| Data Type | Purpose |
|---|---|
| Expense records (amount, category, memo, date) | Core service functionality |
| Payment method (card/cash) | Expense categorization and statistics |
| Attribution (me/partner/together) | Shared household tracking |
| Household invite codes | Partner invitation feature |
| Wonny chat content and recent-expense summaries | Generate expense-entry or analysis responses requested by the user |
| Receipt or transaction screenshots selected by the user | Recognize transactions when requested by the user |
| Agent connection data (display name, Household, scopes, issue/expiry/revocation/last-used times, and hashed credential) | Authenticate, limit, audit, and revoke an external Agent authorized by the user |
| Agent expenses and provenance (amount, currency, category, memo, transaction/recorded times, service, tool, run, payment rail, and invoice URL) | Record and retrieve costs incurred by an Agent and let Household members audit them |
| Optional Household aggregate summary (totals and counts by currency, category, and Human/Agent expense type) | Provide user-authorized spending analysis without exposing individual expense rows |
| Feedback type and content, plus app version, OS version, and device model at submission | Respond to inquiries, diagnose issues, and improve the service |
| Optional product-research responses (campaign and locale, light answers, interview transcript, and user-confirmed summary) | Conduct research the user chooses to join and improve WeSpend |
| Data Type | Purpose |
|---|---|
| Device identifiers | Anonymous login, service provision |
| Pseudonymous user identifier (Firebase UID); expense-event attributes (amount, category, payment method, and currency); budget amounts and periods; interaction events; app/device information; and approximate location (country, region, and city) inferred from the IP address | Service analytics and improvement through Amplitude |
We use your personal data only for the following purposes:
| Purpose | Description | Legal Basis (GDPR) |
|---|---|---|
| Service Provision | Expense tracking, statistics, shared household features | Contract performance |
| Account Management | User identification, login, password reset | Contract performance |
| Partner Connection | Household sharing via invite codes | Consent |
| Service Improvement | Error analysis, usability improvements | Legitimate interest |
| Optional Product Research | Invite selected users, record only responses they choose to submit, and summarize an optional follow-up interview | Consent and user request |
| Optional AI Features | Wonny responses and screenshot transaction recognition requested by the user | Contract performance and user request |
| Agent Expense Ledger | Record costs incurred by a user-connected Agent in the same Household ledger and let members distinguish, review, and audit them | Contract performance and user request |
| Optional Household Summary Analysis | When explicitly enabled by the current owner of a one-person Household, calculate aggregate-only spending totals without returning individual expense rows | Contract performance and user request |
| Agent Connection Security | Issue, hash, expire, revoke, rate-limit, and audit least-privilege credentials bound to one Household | Contract performance and legitimate interest |
| Operational Support and Event Monitoring | Review sign-up, feedback, first AI chat, and purchase alerts plus hourly expense summaries in event-specific, restricted-access Slack operations channels, and review currently retained expense, feedback, sign-up, AI-session, and purchase records in a private operations console | Legitimate interest |
WeSpend does not sell your personal data. We share your information only in the following circumstances:
household_expense:read:summary, the default own-expense access remains active and the optional scope adds aggregate-only Household analysis. It is available only while the authorizing user is the current owner and sole member of the credential-bound Household. That optional scope returns aggregate totals and counts by currency, category, and Human/Agent expense type, plus the selected period's start and end boundaries; it does not return individual expense rows or individual expense timestamps, memos, merchants or vendors, invoices, tool or run identifiers, member data, or expense/category/member identifiers, and it grants no edit or delete access. The server rechecks ownership and membership on every request, fails closed, and permanently revokes the optional grant when either changes. It returns no partial result when the bounded scan exceeds 2,000 records or the Household has more than 100 total category records, including archived categories.We use the following third-party service providers:
| Provider | Service | Location | Transfer Method |
|---|---|---|---|
| Google LLC (Firebase) | Cloud storage, authentication, server functions | South Korea (Seoul) and United States, depending on the Firebase service region | Network transfer during service use |
| Apple Inc. | Apple Sign-In authentication | United States | Network transfer during Apple login |
| Amplitude, Inc. | Product analytics, including account-linked expense and budget event attributes | United States | Pseudonymous identifier, financial event attributes, interaction events, and app/device information transferred during app use |
| Anthropic, PBC | User-requested AI chat and screenshot transaction recognition | United States | Required prompts, screenshots, and expense summaries transferred when the feature is used |
| Slack Technologies Limited (Salesforce; Slack Technologies, LLC for US and Canadian customers) | Operational support and backend event monitoring | Ireland (processing entity for customers outside the US and Canada), the United States (default data storage), or the workspace's selected data-residency region | Sign-up account information, full feedback and submission details, the first AI request/response and proposed expense, and verified purchase metadata are transferred to event-specific operations channels through the HTTPS Slack Web API when the event occurs; expense counts, per-currency totals, and a private-console link are transferred hourly to the expense channel through an HTTPS Incoming Webhook |
| OpenAI OpCo, LLC or OpenAI Ireland Ltd. (ChatGPT Sites) | Hosting, authentication, maintenance, and support for the access-restricted private operations console | United States, Ireland, and locations identified in OpenAI's sub-processor list | When an authorized operator opens the console, permitted fields from currently retained operations records are transmitted by HTTPS for display; the console does not maintain a separate activity database |
International Transfer Safeguards: These providers are certified under the EU-US Data Privacy Framework or comply with GDPR Standard Contractual Clauses (SCCs).
We will respond to your request within 30 days (or as required by applicable law).
We implement appropriate technical and organizational measures to protect your data:
WeSpend is not intended for children under 16 years of age (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.
The WeSpend app does not use web cookies. The app uses Amplitude to collect a pseudonymous Firebase UID; expense-event attributes such as amount, category, payment method, and currency; budget amounts and periods; interaction events; app/device information; and approximate location (country, region, and city) inferred from the IP address for service analytics and improvement. We do not collect precise GPS location. You may object to this processing or request deletion of analytics data using the contact information below.
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via in-app notification or email before the changes take effect.
For questions or concerns about this Privacy Policy or our data practices:
You may lodge a complaint with your local Data Protection Authority: - EU DPA List: https://edpb.europa.eu/about-edpb/about-edpb/members
This Privacy Policy is effective as of February 18, 2026 and was last updated on September 3, 2026.