Spentato

Privacy policy

Updated 17 September 2026 · Development version

Spentato is operated by Vladimir Karailiev, the controller responsible for the personal data described here. Contact spentato.support@gmail.com for privacy questions or requests.

This policy describes the local diary and optional online and subscription features. Some features are not enabled in every development build. Data is processed for a feature only when that feature is used.

Your diary stays on your device

Saved expense amounts, currencies, categories, merchants, notes, purchase dates and preferences are stored in a local database. Searches and totals run locally. We do not upload your saved transaction history or provide diary cloud sync. Chat messages last for the current session rather than being saved as a permanent transcript.

Your operating system or your own backup tools may include app data in device backups. Spentato does not provide a recovery service. Losing your device or uninstalling the app can lose your diary. The database has no additional app-managed encryption.

Optional smart understanding

Simple supported messages are interpreted locally. If you enable smart understanding, eligible messages the local parser cannot understand are sent through our Cloudflare service to OpenAI. Each request contains your current message, current date, default currency, timezone and language/locale. A message may itself contain expense information you type. We do not automatically include your saved history, earlier messages or spending totals.

OpenAI interprets the wording; Spentato validates the result and performs calculations locally. Turn smart understanding off in Settings to stop future interpretation requests. Cancelling a request cannot recall data already sent.

Our application does not intentionally log message bodies or model responses. We request no stored Responses API application state. This is not a zero-retention guarantee: OpenAI may retain content in abuse-monitoring logs for up to 30 days, or longer where legally required. See OpenAI data controls.

Online access and security

Apple App Attest and Google Firebase App Check process app/device attestation material to help verify requests. When identity-based online access is enabled, Firebase Authentication creates an anonymous account identifier without requiring your name, email or password. This identifier is pseudonymous, not proof that you cannot be identified.

Cloudflare receives network information such as your IP address when serving requests. Our quota database stores keyed hashes of IP addresses and anonymous identifiers, usage counters and short-lived request reservations, rather than expense contents. These records enforce allowances, prevent abuse and protect service availability.

Counter records cover minute, day or month windows and expired records are removed during later successful quota activity; removal is not an exact timed deletion job. Pending identity-deletion blocks remain until remote cleanup succeeds. After confirmed cleanup, the block remains valid for 62 minutes to reject old tokens and is removed during later quota activity.

When you request recoverable online-account deletion, the service temporarily stores your anonymous account identifier, deletion progress and a hash of a random recovery token. These records let cleanup continue if your sign-in stops working. Your device keeps the recovery token in platform secure storage; it cannot access your diary, online interpretation or purchases. Pending deletion records remain until cleanup succeeds. On completion, the service removes the account identifier from these operation records and retains a completion receipt that expires after seven days and is removed during subsequent deletion activity. Old requests without a recovery token, lost tokens or expired receipts may require support. No expense contents are stored in deletion records.

Plus purchases

If you use purchase features, Apple processes payment and RevenueCat processes your anonymous app identifier, subscription product, transaction/receipt information, purchase and expiry dates, status, and related device/app and storefront information to verify and restore access. Our server checks that status. We do not receive your full payment-card details and do not send your diary or spending messages to RevenueCat.

Online status checks may create a RevenueCat customer record even before a purchase. Apple and RevenueCat may retain transaction records for service, accounting, fraud prevention and legal purposes. See RevenueCat privacy information and Apple privacy information.

Support and this website

If you email us, Google Gmail processes your address, message and any attachments. We use them to answer you and resolve the issue; please avoid sending diary contents, payment details or passwords. We retain correspondence while needed to resolve the request and any related dispute or legal obligation, and review it for deletion when no longer needed.

These pages contain no analytics scripts, advertising SDKs or tracking pixels. Their hosting provider receives connection information needed to deliver and protect the website. The app currently contains no advertising SDK and does not sell personal data or target advertising using spending information. This policy and consent controls will be updated before advertising is introduced.

Why we process data

Where European data-protection law applies, optional online interpretation relies on your consent. Providing requested online access, purchases and support relies on performing the service agreement or taking steps at your request. Security and abuse prevention rely on our legitimate interest in protecting users and keeping the service available. Records required by law are processed to meet legal obligations. Withdrawing consent does not affect earlier lawful processing or your access to local diary features.

Providers and international processing

Our providers include Cloudflare (request delivery and security), OpenAI (optional interpretation), Google Firebase (authentication and attestation), RevenueCat (purchases), Apple (attestation and payments), and Google Gmail (support). They may process data outside your country, including in the United States. Applicable provider agreements describe transfer safeguards such as standard contractual clauses and, where applicable, adequacy decisions. Contact us for information about the safeguards applicable to your data.

More information: Firebase privacy and retention, Cloudflare privacy, and Google privacy. Firebase states that authentication IP logs are retained for a few weeks and other authentication data is removed from live and backup systems within 180 days after a customer initiates deletion.

Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction or portability of personal data, object to processing, and withdraw consent. Email us to exercise these rights. We may need proportionate verification to locate and protect your records. We cannot retrieve a diary that exists only on your device. Provider backups and legally required records may persist after deletion.

You may complain to your local data-protection authority, including Bulgaria's Commission for Personal Data Protection. Interpretation does not make legal or similarly significant decisions about you; Spentato does not provide financial advice.

Changes

We will update the date and wording when practices change, and obtain new permission where required before introducing materially different optional processing.