Effective date: June 15, 2026
Spendojo ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have.
By using the Service, you agree to the practices described in this policy.
When you sign in with Google or Apple, we receive and store:
We do not receive your Google or Apple password. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We store the content you create within the Service in order to operate the app. This includes household settings, spending accounts, expense records, recurring templates, budget preferences, and invitation records (including email addresses of people you invite).
All household data is strictly scoped to your household — other households cannot access your data, and your household members cannot access data from any other household.
When you use the receipt scanning feature, the image is sent to our document processing service to extract the merchant name, amount, currency, and date. We do not store the receipt image. Only the extracted data fields are returned to you to pre-fill the expense form — you review and confirm before saving.
This feature uses AI-powered image and text analysis to process your receipt. The image is discarded immediately after extraction is complete.
We never receive or store your payment card details. All payment processing is handled directly by Stripe.
We do not use advertising analytics, tracking pixels, or data brokers. We may use limited product analytics to improve the Service — any such tools are used only for product improvement and are never used for advertising purposes.
If you use the AI Monthly Summary feature, available on our mobile app for Plus subscribers, category totals, merchant names, and expense descriptions already stored in your household's data are sent to our AI provider to generate a short natural-language summary and answer a small set of guided questions about your spending. Notes you've added to individual expenses are never included. Generated summaries and answers are cached per account, per month, per language, and are not regenerated on every view.
| Purpose | Legal basis (GDPR) |
|---|---|
| Authenticate and identify you | Contract performance |
| Operate the expense tracking service | Contract performance |
| Send transactional emails (invitations, billing alerts) | Contract performance / Legitimate interest |
| Process subscription payments | Contract performance |
| Extract data from receipt images | Contract performance |
| Generate AI-powered spending insights | Contract performance |
| Prevent abuse and ensure security | Legitimate interest |
| Analyze usage to improve the Service | Legitimate interest |
| Comply with legal obligations | Legal obligation |
We do not use your data for advertising, profiling, or sale to third parties. Ever.
We share data with third-party service providers only as necessary to operate the Service. Each is bound by data processing agreements consistent with applicable privacy law. We do not sell your data.
We use Google for account authentication. When you sign in, your browser communicates with Google to verify your identity. We receive only the profile data described in Section 2.1. Google Privacy Policy.
We use Apple for account authentication (Sign in with Apple). When you sign in, your browser or device communicates with Apple to verify your identity. We receive only the profile data described in Section 2.1. If you choose Hide My Email, Apple operates a private email relay on your behalf. Apple Privacy Policy.
Our service runs on Microsoft Azure cloud infrastructure, which we use for hosting, data storage, email delivery, and document processing. Microsoft processes data on our behalf under a Data Processing Agreement. Microsoft Privacy Statement.
Stripe handles all payment processing for Plus subscriptions. Stripe receives your email address and payment card details directly — we never see or store your card information. Stripe is PCI-DSS Level 1 certified. Stripe Privacy Policy.
We use Cloudflare's bot protection service to prevent automated abuse of the Service. Cloudflare analyzes browser signals to verify you are human. Cloudflare Privacy Policy.
Indicative exchange rates are fetched from a third-party currency rate provider. This request contains only the currency pair being queried — no personal data is transmitted.
If Spendojo is involved in a merger, acquisition, financing, or sale of assets, your data may be transferred as part of that transaction. We will provide reasonable notice via email or a prominent notice in the app before your data becomes subject to a different privacy policy, and a reasonable opportunity to delete your account and data prior to any such transfer.
We may disclose data when required by law, court order, or governmental authority. Where legally permitted, we will notify you before disclosure.
If you use the AI Monthly Summary feature, structured spending data described in Section 2.6 is sent to Azure OpenAI, a Microsoft service, to generate the summary and answers. This is a distinct processing purpose from the general hosting described in Section 4.3, even though it runs on the same underlying provider. Azure OpenAI's terms commit to not using customer prompts or completions to train the underlying foundation models. Microsoft Privacy Statement.
| Data Type | Retention Period |
|---|---|
| Active account data | Retained for the lifetime of the account |
| Deleted households | Removed from active systems promptly; purged from encrypted backups within 90 days |
| Invitation records | Links expire after 7 days; records retained until deleted by an admin |
| Session tokens | Expire automatically; immediately invalidated on sign-out |
| Payment event records | Retained for a limited period as required by financial regulations |
| Server logs | Retained for a limited period for security and debugging |
| Receipt images | Not stored — discarded immediately after text extraction |
| AI-generated monthly summaries/answers | Retained until the household is deleted; automatically superseded each new month |
We take the security of your data seriously and apply industry-standard protections:
No system is 100% secure. If you believe your account has been compromised, contact us immediately at support@spendojo.com.
Depending on your location, you may have the right to:
To exercise any of these rights, contact us at support@spendojo.com. We will respond within 30 days and may verify your identity before acting on your request.
If you are located in the European Economic Area or United Kingdom, GDPR gives you rights over your personal data — including the right to access, correct, export, or delete the information Spendojo holds about you. To exercise any of these rights, contact us at support@spendojo.com and we will respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority if you feel your rights have not been respected.
California residents have rights under the CCPA, including the right to know what personal information is collected, the right to delete it, and the right to opt out of the sale of personal information. We do not sell personal information. Contact us at support@spendojo.com to exercise your rights.
The "Shine the Light" law (California Civil Code Section 1798.83) permits California residents to request information about categories of personal information disclosed to third parties for direct marketing purposes. We do not disclose personal information to third parties for direct marketing purposes.
If you are located outside the EEA or California, you may have similar rights under the laws of your country. Contact us at support@spendojo.com to exercise any privacy rights applicable to you.
We use only essential session cookies required to keep you signed in and to operate the Service securely. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
Our servers are hosted in the United States. If you access Spendojo from outside the United States, your data is transferred to and processed in the United States. For EEA users, transfers are covered by Standard Contractual Clauses (SCCs) in our agreements with our cloud providers. For UK users, transfers are covered by the UK International Data Transfer Agreement (IDTA) or equivalent mechanism in our agreements with our cloud providers. For users in other jurisdictions, transfers are made subject to appropriate safeguards consistent with applicable local law.
The Service is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect data from children under these ages. If you believe a child has provided us with personal data, contact us at support@spendojo.com and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice in the app at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance of the updated policy.
For privacy questions or data requests:
Email: support@spendojo.com
Subject line: Privacy Request — [your name or email]
Mailing address:
4601 E Douglas Ave
STE 150
Wichita, KS 67281
United States
We aim to respond within 30 days.
This Privacy Policy was last reviewed and updated: July 4, 2026.