Privacy Policy

Last updated: 1 August 2026

This Privacy Policy explains what data Spendly ("the app", "we", "us") handles, where it is stored, and the choices you have. The app is designed to be local-first: your financial data lives on your device and is only sent to the cloud when you opt in by signing in and using sync features.

Using the app without an account

You can use the core app as a guest, without creating an account. In guest mode your expenses, accounts, categories and settings are stored only on your device (in an encrypted-at-rest local database provided by your operating system). We do not receive this data, and it is not backed up to our servers. Clearing the app's local data or uninstalling the app permanently deletes it.

Data stored on your device

Regardless of account status, the following is stored locally on your device:

Data we process when you sign in

If you create an account or sign in (including Sign in with Apple), we process the following through our authentication and database provider, Supabase:

We only upload your financial records to the cloud when you are a premium subscriber and sync is active. Free and guest users' financial records remain on-device.

Shared groups

If you create or join a shared group, the members of that group can see the expenses, splits and balances within that group, along with your display name. Do not add people to a group unless you intend to share that information with them.

Subscriptions and payments

Premium subscriptions are processed by the app stores (Apple App Store / Google Play) and managed through RevenueCat. We do not receive or store your full payment card details. We receive subscription status information (for example, whether your subscription is active, trial, or cancelled, and its renewal date) to unlock premium features.

Notifications

If you enable notifications while signed in, we use Firebase Cloud Messaging to deliver push notifications (for example, group activity). This involves storing a device push token linked to your account. You can disable notifications at any time in Settings or your device settings.

Crash and diagnostics data

To keep the app stable and fix problems, we use Firebase Crashlytics (Google) to collect crash reports and error diagnostics when the app misbehaves. When a crash or handled error occurs, this may include:

This data is used only to diagnose and fix stability issues. It is not used for advertising or profiling. We aim to avoid including your financial records in error reports, but you should not rely on error diagnostics being free of the values you entered. Crash reports are retained by the provider for a limited period (currently around 90 days). Diagnostics are not collected in development builds.

AI-assisted features

Third-party services

The app relies on the following processors, each under their own privacy terms:

Data retention and deletion

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to withdraw consent. You can exercise most of these directly in the app (export, delete account) or by contacting us at spendly@ashmmapp.com.

Children

The app is not directed to children under the age required by your local law to consent to data processing, and we do not knowingly collect their data.

Changes to this policy

We may update this policy. Material changes will be reflected by an updated effective date and, where appropriate, an in-app notice.

Contact

For any privacy question or request, contact us at spendly@ashmmapp.com.