Privacy policy
Last updated: September 20, 2026
Draft — pending counsel review before public launch1. What Spendkin is
Spendkin builds a private financial history from payment evidence you choose to capture: alerts passed through user-configured Shortcuts, shared text and images, direct receipt camera scans, Photos, on-device OCR, and manual entries. We do not ask for, store, or transmit your bank credentials, and the iPhone app does not connect to your bank account.
2. Information we collect
- Account: your Sign in with Apple account identifier, optional email or private relay address, and the session/device metadata needed to operate your account.
- Financial record: transactions and associated evidence are processed locally and encrypted on your device before sync. Our server stores encrypted records and coordination metadata, not a readable ledger.
- Capture content: notification text, shared text, and OCR results are parsed on-device by Spendkin. Raw capture content and decrypted financial fields are not sent to our server for AI parsing.
We do not request your bank credentials. Capture does not upload receipt images or extracted OCR text for server-side parsing.
3. Capture is under your control
- Shortcuts automation: on supported iOS versions, you may configure your own Notification automation for a selected financial app to pass notification input to Spendkin. Spendkin cannot directly read other apps’ notification streams. We are still testing this option on iPhone; it is not yet offered as a supported capture option.
- Camera, Photos, Share, and manual entry: you scan or choose a receipt, share text or an image, or enter a transaction yourself. OCR runs on-device; receipt images are not kept after the capture workspace closes.
4. How parsing works
iPhone capture follows one on-device path: normalize evidence, parse it, assess confidence, check for duplicate representations, then add a transaction or ask you to review it. Multiple sources can contribute to one transaction while retaining their provenance. No server-side AI parser reads this evidence.
5. Data retention
Capture evidence is kept in protected local storage only as needed for review, reconciliation, and your financial record; it follows local deletion controls. Server sync stores encrypted records, not raw alert or OCR text. Deleting your account ends access immediately. The account enters a 72-hour server purge grace period, after which the scheduled purge removes its data. A minimal deletion-operation receipt may remain for 30 days after purge to support retries and lost-response recovery; it contains no financial record or Apple token.
6. Your controls and rights
- Export a readable copy of your local ledger as CSV from Settings. Treat an exported file as sensitive; it is no longer protected by Spendkin’s vault.
- Delete your account in-app after fresh Sign in with Apple confirmation. Access ends when the deletion request is accepted; the 72-hour purge grace and scheduled cleanup are described above.
- GDPR/CCPA requests: hello@spendkin.com.
7. Third-party processors
Spendkin uses its hosting/database provider for account metadata and encrypted sync, and Apple for Sign in with Apple and on-device OCR. There is no billing provider or server-side AI parsing provider. We do not sell your financial data or run ads.
8. Security
Connections to the backend use encrypted transport. Account access uses revocable sessions; financial records are encrypted on-device before sync. Sensitive capture content, merchant names, amounts, recovery secrets, and Apple authorization material are excluded from application analytics and ordinary logs.
9. End-to-end encryption (on by default)
Your financial record is encrypted on your device before sync. Keep your recovery kit safe; supported iCloud Keychain recovery may also be available after verification.
- Spendkin’s server stores encrypted financial records and cannot read your transaction history. Some account and sync metadata remains readable to operate the service.
- If all available recovery methods are lost, Spendkin support cannot decrypt or restore your record. A readable CSV export is created locally only when you request it.
- Account deletion requests fresh Apple authentication. A short-lived authorization code is exchanged for revocation; Spendkin does not keep a long-lived Apple refresh token solely for deletion. If programmatic Apple revocation fails, account deletion can still proceed with guidance to revoke Spendkin access in Apple settings.
10. Children’s privacy
Spendkin is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect their data.
11. Changes to this policy
We’ll post changes here and, for material changes, notify you in the app before they take effect.