Privacy Policy
This policy explains how Spendly handles personal data when you visit the website, create an account, connect providers, or contact support.
Last updated: 22 July 20261. Who is responsible for your data
Spendly is operated by Denis Efremov, a self-employed service provider established in Portugal. For privacy questions or requests, email privacy [at] spendly.team. Full operator details are available on the Legal page.
2. Scope and roles
Spendly acts as a data controller for account administration, security, support, website operation, and billing records. When a business customer adds employees, provider accounts, projects, or AI usage records, Spendly generally processes that information on the customer's instructions. The customer remains responsible for having an appropriate legal basis to provide that information.
3. Data we process
- Account data: email address, authentication identifiers, display name, language, and workspace role.
- Business workspace data: company settings, employees, teams, projects, budgets, alerts, and preferences.
- Provider data: provider account identifiers, encrypted credentials supplied by the customer, usage records, transactions, model names, quantities, currencies, costs, and synchronisation status.
- Technical and security data: request metadata, timestamps, rate-limit records, error logs, security events, and essential session cookies.
- Resource engagement data: first-party, cookieless events such as a resource page view, reading progress, a result count, or a call-to-action click. These events do not include account identifiers, IP addresses, full user-agent strings, or raw search terms.
- Optional analytics data: when you allow analytics, Google Analytics receives page views, referrer information, browser/device signals, and event names for public pages. Spendly does not send workspace data, account identifiers, financial values, or raw search terms to Google Analytics.
- Support data: messages and information you choose to send when requesting help.
- Billing data: subscription status, customer and transaction identifiers, invoices, and tax information when paid plans are activated. Payment card details are handled by the payment provider, not stored by Spendly.
4. Why we process data
| Purpose | Legal basis |
|---|---|
| Provide accounts, dashboards, synchronisation, reports, budgets, and support | Performance of a contract |
| Protect accounts, prevent abuse, diagnose failures, and maintain service reliability | Legitimate interests in operating a secure service |
| Measure aggregate use of public Resources and improve their usefulness | Legitimate interests for first-party, cookieless engagement events; optional Google Analytics uses consent |
| Issue invoices and retain required accounting records | Legal obligation and performance of a contract |
| Send essential service and security messages | Performance of a contract and legitimate interests |
| Use optional analytics or marketing technologies | Consent — Google Analytics is disabled until you choose to allow analytics |
5. Service providers and recipients
Data may be shared only where needed to operate Spendly, including:
- Google Firebase for account authentication, including email/password and the Google or Apple sign-in connection you choose;
- Cloudflare for DNS, security, encrypted traffic delivery, the application API, database storage, and file storage;
- Google Analytics when you explicitly allow optional analytics on public pages;
- Apple when you choose Sign in with Apple;
- temporary legacy authentication and migration infrastructure, used only while an existing customer proves and links an earlier account or while verified rollback data must be retained;
- AI service providers when you ask Spendly to connect to and synchronise a provider account;
- Stripe and PayPal when paid subscriptions are activated and you choose to pay through them;
- professional advisers or authorities where required by law or necessary to establish or defend legal claims.
Spendly does not sell personal data.
6. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism. Customers should also review the transfer terms of each AI provider they connect.
7. Retention
- Account and workspace data is kept while the account is active and for a limited period needed for recovery, security, or dispute handling after closure.
- Provider credentials are retained until the connection or workspace is deleted.
- Operational and security logs are kept only as long as reasonably needed for security and diagnostics.
- First-party Resource engagement events are kept only while needed to understand aggregate content performance and do not contain direct account identifiers or raw search terms.
- Optional Google Analytics data is retained according to the selected Google Analytics property settings and your consent choices.
- Invoices and tax records are retained for the period required by Portuguese law.
- Support correspondence is kept while the request is active and afterwards where reasonably required to document its resolution.
8. Security
Spendly uses server-side workspace and role authorisation, short-lived identity tokens, encryption in transit, restricted administrative access, and encrypted storage for provider credentials. Application requests use only the user identity verified by the server, not an account identifier supplied in a request body. No online service can promise absolute security, so customers should use unique passwords, protect their Apple or Google account, limit provider-key permissions, and remove unused connections.
9. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may withdraw consent where processing relies on consent. Send a request to privacy [at] spendly.team. Identity verification may be required before a request is completed.
You may also complain to Portugal's supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD).
10. Cookies, children, and changes
Spendly currently uses only essential cookies and local storage. See the Cookie Policy. Spendly is a business service and is not intended for children. Material changes to this policy will be announced in the service or by email where appropriate.
Back to Spendly