Privacy Policy
Last updated: August 8, 2026
This Privacy Policy describes how Expensology ("Expensology", "we", "us") collects, uses, stores, shares and protects your information when you use the Expensology web application at expensology.netlify.app (the "Service") or visit this website at expensologyapp.com.
In short: we store the account details and expense data you give us so the app can work, and nothing more. We do not show ads, we do not sell your data, and we do not use trackers for advertising or analytics. If you sign in with Google, we receive only your name, email address and profile picture — never your Gmail, Drive, Calendar or any other Google content.
1. Information we collect
Information you provide
- Account information. When you sign up with an email address, we collect that email address and a password (stored only in securely hashed form by our authentication provider), plus the display name you choose.
- Expense data. The content you enter while using the Service: expenses and their amounts, currencies, dates, categories, payment-method labels, notes, recurring-expense definitions, and the spaces you create.
- Invitations. If you invite someone to a shared space, we collect the email address you invite so we can deliver the invitation.
Information from Google Sign-In
If you choose to sign in with your Google Account, we receive your
name, email address and
profile picture from Google, using only the basic
openid, email and profile sign-in scopes. We do
not request access to, and cannot read, any other Google data — no Gmail, no Drive, no
Calendar, no Contacts. See section 3 for exactly how
this data is handled.
Information collected automatically
The Service keeps only what is technically necessary: our hosting and authentication providers record standard server logs (such as IP address and browser type) for security and abuse prevention, and your browser stores a session token and small preferences (such as your theme and currently selected space) so you stay signed in. We do not use advertising cookies, tracking pixels or third-party analytics.
2. How we use your information
- To create your account, authenticate you and keep your session secure.
- To provide the Service's features: storing and syncing your expenses, logging recurring charges automatically when they are due, computing dashboard statistics, and converting amounts between currencies using public exchange rates.
- To show your display name (and, with Google Sign-In, your profile picture) to the other members of shared spaces you belong to.
- To send transactional emails only: signup confirmation and space-invitation notifications. We do not send marketing email.
- To protect the Service against abuse and to comply with legal obligations.
We do not use your information for advertising, we do not build marketing profiles, and we do not sell or rent your information to anyone.
3. Google user data
This section applies specifically to information Expensology receives from Google when you use Google Sign-In.
-
What we access. Only your basic profile information: name, email
address and profile picture (
openid,email,profilescopes). Expensology does not request any sensitive or restricted Google scopes. - How we use it. Solely to create and secure your Expensology account, to display your name and picture inside the app (including to members of your shared spaces), and to send you the transactional emails described above — that is, to provide and improve user-facing features of the Service.
- How we store it. In our application database hosted by Supabase, protected by row-level access rules; all data is transmitted over encrypted connections (HTTPS/TLS).
- How we share it. We do not transfer or disclose Google user data to third parties, except to the service providers listed in section 5 as needed to operate the Service, or if required by law.
- How you delete it. You can disconnect Expensology from your Google Account at any time at myaccount.google.com/permissions, and you can ask us to delete your account and all associated data (see section 6).
Expensology's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for targeted, personalized or interest-based advertising; we do not sell it to data brokers or information resellers; we do not use it to determine credit-worthiness or for lending purposes; and we do not use it to develop, improve or train generalized (non-personalized) artificial-intelligence or machine-learning models.
4. Who can see your data inside the app
- Personal space. The expenses in your personal space are visible only to you.
- Shared spaces. If you join or create a shared space, the members of that space can see the expenses recorded in it, together with each contributor's display name and profile picture. Your email address is not shown to other members.
5. Service providers
We use a small number of infrastructure providers to run Expensology. They process data only on our behalf and to provide their service to us:
- Supabase — database and authentication for the Service (stores your account and expense data).
- Netlify — hosts the Expensology web application.
- Hostinger — hosts this website (expensologyapp.com).
- Resend — delivers our transactional emails (signup confirmation and space invitations).
Beyond these providers, we do not share your personal information with any third party, unless we are legally required to do so.
6. Data retention and deletion
- We keep your data for as long as your account exists, so the Service can show your expense history.
- You can delete individual expenses, recurring definitions, categories and shared spaces you own directly in the app at any time.
- To delete your account and all data associated with it — including any data received from Google — email us at sasan.ebrm@gmail.com from your account's email address. We will complete the deletion within 30 days and confirm it to you.
7. Security
All traffic between your browser and the Service is encrypted with HTTPS/TLS. Passwords are stored only as secure hashes. Every database table is protected by row-level security rules, so each account can only ever read and write the data of the spaces it belongs to. Access to production infrastructure is restricted to the operator of the Service.
8. Children
Expensology is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
9. Changes to this policy
If our data practices change, we will update this page and its "Last updated" date before the change takes effect. Significant changes will also be announced in the app.
10. Contact
For any question about this policy or your data, contact us at sasan.ebrm@gmail.com.