Cookie Policy
Spendly uses necessary storage for secure authentication, language and interface preferences, and remembering your privacy choice. Optional analytics is disabled until you allow it.
Last updated: 22 July 20261. What cookies are
Cookies are small text values stored by your browser. Similar browser storage, such as local storage, can remember interface preferences on your device. Some cookies are necessary for a requested service; optional analytics or advertising cookies require a separate choice.
2. Storage currently used
| Storage | Purpose | Typical duration |
|---|---|---|
| Firebase authentication storage | Maintain the signed-in state and refresh the selected email, Google, or Apple session safely on this device | Session-dependent; removed when you sign out or clear site data |
| __Host-spendly_id | Provide a short-lived, HttpOnly copy of an already verified Firebase ID token for private server-rendered pages; it never contains a refresh token | No later than the current ID token expiry |
| __Host-spendly_legacy_proof | Carry a one-time, HttpOnly proof while an existing customer explicitly links an earlier account to the new Firebase identity | 5–10 minutes or until consumed |
| Temporary legacy authentication storage | Support an existing customer who deliberately chooses the controlled account-migration sign-in; it is not used for new accounts | Only for the migration session |
| spendly_cookie_notice | Remember that the essential-cookie notice was dismissed | Up to 12 months |
| spendly_analytics_consent | Remember whether optional Google Analytics is allowed or declined | Up to 12 months |
| Language and interface storage | Remember the language and local UI preferences selected on the device | Until cleared or replaced |
3. Optional analytics
Spendly does not load Google Analytics, behavioural advertising, or cross-site tracking until you choose “Allow analytics”. If you choose “Only necessary”, optional analytics remains disabled.
Public Resources may send limited first-party, cookieless engagement events to Spendly. They contain no direct account identifier, raw search term, or cross-site identifier and do not write browser storage.
When enabled, Google Analytics measures public page views and selected resource interactions. Spendly does not configure advertising features and does not send account, workspace, financial, or raw search data.
4. Controls
You can remove cookies and local storage in your browser settings. Blocking authentication cookies may prevent login or cause the dashboard to stop working. You can reopen the notice below.
5. Contact
Questions about browser storage or privacy may be sent to privacy [at] spendly.team.
Back to Spendly