PRIVACY POLICY
Last updated May 01, 2026
This Privacy Notice for Expenny ( 'we', 'us', or 'our' ), describes how and why we might access, collect, store, use,
and/or share ( 'process' ) your personal information when
you use our services ( 'Services' ), including when you:
- Download and use
our mobile application ( Expenny) , or any other application of ours that links to this Privacy Notice
- Engage with us in other related ways, including any marketing
or events
Questions or concerns? Reading this Privacy
Notice will help you understand your privacy rights and choices.
We are responsible for making decisions about how your personal
information is processed. If you do not agree with our policies
and practices, please do not use our Services. If you still have any questions or
concerns, please contact us at support@getexpenny.com .
SUMMARY OF KEY POINTS
This summary provides key points from our Privacy Notice, but
you can find out more details about any of these topics by
clicking the link following each key point or by using our
table of contents
below to find the section you are looking for.
What personal information do we process? When you
visit, use, or navigate our Services, we may process personal information
depending on how you interact with us and the Services, the choices
you make, and the products and features you use. Learn more about
personal information you disclose to us.
Do we process any sensitive personal information?
Some of the information may be considered 'special' or 'sensitive' in certain jurisdictions, for example your
racial or ethnic origins, sexual orientation, and religious beliefs.
We do not process sensitive
personal information.
Do we collect any information from third parties? We do not collect any
information from third parties.
How do we process your information? We process your
information to provide, improve, and administer our Services, communicate
with you, for security and fraud prevention, and to comply with law.
We may also process your information for other purposes with your consent.
We process your information only when we have a valid legal reason to
do so. Learn more about
how we process your information.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific
third parties. Learn more about
when and with whom we share your personal information.
How do we keep your information safe? We have adequate
organisational and technical processes and procedures in
place to protect your personal information. However, no electronic transmission
over the internet or information storage technology can be guaranteed
to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals,
or other unauthorised third parties will not be able to defeat
our security and improperly collect, access, steal, or modify your information.
Learn more about
how we keep your information safe.
What are your rights? Depending on where you are located
geographically, the applicable privacy law may mean you have certain
rights regarding your personal information. Learn more about
your privacy rights.
How do you exercise your rights? The easiest way to
exercise your rights is by visiting support@getexpenny.com , or by contacting us. We will
consider and act upon any request in accordance with applicable
data protection laws.
Want to learn more about what we do with any information we
collect?
Review the Privacy Notice in full.
TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short:We collect limited account information and, if you are signed in, sync your financial entries so your data can be backed up and available on your logged-in devices. We collect personal information that you voluntarily provide to
us when you register on the Services or sign in using Google or a
passwordless email link,
use sync features, or otherwise when you contact us.
Personal Information Provided by You. Expenny collects
your email address for account access. If you sign in with Google,
we may also receive your name and profile picture from Google, depending
on your Google account and permissions. We use Google sign-in and
passwordless email links, so we do not collect or store passwords.
The personal information we collect may include the following:
-
names, only if you use Google sign-in
-
email addresses -
profile pictures, only if you use Google sign-in
Financial Data. Your financial entries are stored
locally on your device. If you are signed in, Expenny automatically
backs up and syncs those financial entries to our servers so you do
not lose your data after uninstalling the app and so your other logged-in
devices can have the latest data.
Sensitive Information. We do not process sensitive
information.
Payment Data. We may collect data necessary to process
your payment if you choose to make purchases, such as your payment
instrument number, and the security code associated with your payment
instrument. All payment data is handled and stored by Google Play / Google and RevenueCat . You may find their
privacy notice link(s)
here: https://policies.google.com/privacy and
https://www.revenuecat.com/privacy .
All
payments
are
processed
securely
through
the
Google
Play
Store.
The
app
does
not
collect
or
store
credit
card
numbers
or
bank
account
details.
We
use
RevenueCat
to
manage
subscription
status
and
verify
purchase
tokens.
We process
the personal information
for the following
purposes listed below. We may also
process your information
for other purposes
only with
your prior
explicit consent.
Google
Login
Data.
We
may
provide
you with
the
option
to
register
with us
using
your
existing
Google
account
details.
If you
choose
to
register
in this
way, we
will
collect
certain
profile
information
about
you from
Google,
as
described
in the
section
called ' HOW
DO
WE
HANDLE
YOUR
SOCIAL
LOGINS? ' below.
All
personal
information
that you
provide to
us must be
true,
complete,
and
accurate,
and you
must
notify us
of any
changes to
such
personal
information.
Google API
Our use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide account access, keep your financial entries backed up and synced across logged-in devices, and communicate with you. We process your
personal information
for a variety of
reasons, depending on
how you interact with
our Services,
including:
- To facilitate
account creation and
authentication and
otherwise manage
user accounts.
We may
process your
information so you can
create and log in to
your account, as well
as keep your account
in working order.
- To deliver and facilitate delivery of
services to the user.
We may process your information to
provide you with the requested service,
including backing up and syncing your financial
entries when you are signed in. Sync happens
automatically when you launch the app while
signed in and when you manually press sync
buttons.
- To respond to user inquiries/offer support to users.
We may process your information to respond to your
inquiries and solve any potential issues you might have with
the requested service.
- To send administrative information to you.
We may process your information to send you details
about our products and services, changes to our terms and
policies, and other similar information.
- To
fulfil and manage your orders. We may process your information to fulfil and manage your orders, payments, returns, and exchanges made through the Services.
- To request feedback. We may process your
information when necessary to request feedback and to
contact you about your use of our Services.
- To protect our Services. We may process your information
as part of our efforts to keep our Services safe and secure, including
fraud monitoring and prevention.
- To save or protect an individual's vital interest. We may process your information when necessary to save or protect
an individual’s vital interest, such as to prevent harm.
-
Financial entries and sync .To back up your financial entries, prevent data loss after app uninstall, and synchronize the latest data across your logged-in devices.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e. If you are located in the EU or UK, this section applies to
you.
The General Data Protection Regulation (GDPR) and UK GDPR require
us to explain the valid legal bases we rely on in order to process
your personal information. As such, we may rely on the following
legal bases to process your personal information:
- Consent. We may process your information if
you have given us permission (i.e.
consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
- Performance of a Contract. We may process your personal
information when we believe it is necessary to
fulfil our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
- Diagnose problems and/or prevent fraudulent activities
- Understand how our users use our products and services so we
can improve user experience
- Legal Obligations. We may process your information
where we believe it is necessary for compliance with our legal obligations,
such as to cooperate with a law enforcement body or regulatory agency,
exercise or defend our legal rights, or disclose your information
as evidence in litigation in which we are involved.
- Vital Interests. We may process your information
where we believe it is necessary to protect your vital interests or
the vital interests of a third party, such as situations involving
potential threats to the safety of any person.
If you are located in Canada, this section applies to you.
We may process your information if you have given us specific
permission (i.e. express consent)
to use your personal information for a specific purpose, or in situations
where your permission can be inferred (i.e. implied consent). You can
withdraw your consent at any time.
In some exceptional cases, we may be legally permitted under
applicable law to process your information without your consent,
including, for example:
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
- For investigations and fraud detection and prevention
- For business transactions provided certain conditions are met
- If it is contained in a witness statement and the collection is
necessary to assess, process, or settle an insurance claim
- For identifying injured, ill, or deceased persons and
communicating with next of kin
- If we have reasonable grounds to believe an individual has
been, is, or may be victim of financial abuse
- If it is reasonable to expect collection and use with consent
would compromise the availability or the accuracy of the
information and the collection is reasonable for purposes
related to investigating a breach of an agreement or a
contravention of the laws of Canada or a province
- If disclosure is required to comply with a subpoena, warrant,
court order, or rules of the court relating to the production of
records
- If it was produced by an individual in the course of their
employment, business, or profession and the collection is
consistent with the purposes for which the information was
produced
- If the collection is solely for journalistic, artistic, or
literary purposes
- If the information is publicly available and is specified by
the regulations
- We may disclose de-identified information for approved research
or statistics projects, subject to ethics oversight and
confidentiality commitments
We may need to share
your personal information in the following situations:
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Offer Wall. Our application(s) may display a
third-party hosted
'offer wall'. Such an offer wall allows third-party advertisers to offer virtual currency, gifts, or other items to users in return for the acceptance and completion of an advertisement offer. Such an offer wall may appear in our application(s) and be displayed to you based on certain data, such as your geographic area or demographic information. When you click on an offer wall, you will be brought to an external website belonging to other persons and will leave our application(s). A unique identifier, such as your user ID, will be shared with the offer wall provider in order to prevent fraud and properly credit your account with the relevant reward.
5. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies. As part of our Services, we offer products, features, or tools
powered by artificial intelligence, machine learning, or similar
technologies (collectively, ' AI Products ' ).
These tools power receipt scanning so you can extract details from
receipt images more easily. The terms in this Privacy Notice
govern your use of the AI Products within our Services.
Use of AI Technologies
We provide the AI Products through third-party service providers
( ' AI Service Providers ' ), including Gemini / Google Cloud AI . As outlined in this Privacy Notice, your input, output,
and personal information will be shared with and processed by
these AI Service Providers to enable your use of our AI Products
for purposes outlined in ' WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL
INFORMATION? ' You must not use the AI Products
in any way that violates the terms or policies of any AI Service Provider.
Our AI Products
Our AI Products are designed for the following functions:
-
Receipt image analysis
How We Process Your Data Using AI
All personal information processed using our AI Products is
handled in line with our Privacy Notice and our agreement with
third parties. When you scan a receipt, the receipt image is sent
to Gemini so it can read and extract receipt details. Receipt
images are not stored in our services and are not used for AI
training.
Our Services offer you the ability to register and log in using
your Google account. Where you choose to do this, we may receive
certain profile information from Google. The profile information
we receive may vary depending on your Google account and
permissions, but may include your name, email address, and
profile picture.
We will use the information we receive only for the purposes
that are described in this Privacy Notice or that are otherwise
made clear to you on the relevant Services. Please note that we
do not control, and are not responsible for, other uses of your
personal information by your third-party social media provider.
We recommend that you review their privacy notice to understand
how they collect, use, and share your personal information, and
how you can set your privacy preferences on their sites and
apps.
7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
In Short: We may transfer, store, and process your information in countries other than your own. Our servers are located in Finland . Regardless of your location,
please be aware that your information may be transferred to,
stored by, and processed by us in our facilities and in the
facilities of the third parties with whom we may share your
personal information (see ' WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION? ' above), including facilities in the United States, Germany,
and other countries.
If you are a resident in the European Economic Area (EEA),
United Kingdom (UK), or Switzerland, then these countries may
not necessarily have data protection laws or other similar laws
as comprehensive as those in your country. However, we will take
all necessary measures to protect your personal information in
accordance with this Privacy Notice and applicable law.
European Commission's Standard Contractual Clauses:
We have implemented measures to protect your personal
information, including by using the European Commission's
Standard Contractual Clauses for transfers of personal
information between our group companies and between us and our
third-party providers. These clauses require all recipients to
protect all personal information that they process originating
from the EEA or UK in accordance with European data protection
laws and regulations. Our Standard Contractual Clauses can be provided upon
request. We have implemented similar appropriate safeguards with
our third-party service providers and partners and further
details can be provided upon request.
8. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to We will only keep your personal information for as long as it
is necessary for the purposes set out in this Privacy Notice,
unless a longer retention period is required or permitted by law
(such as tax, accounting, or other legal requirements). No purpose in this notice will require
us keeping your account information or synced financial data for longer
than the period of time in which
users have an active account with us . If you delete your account, we will completely wipe all
related account data and synced financial data from Expenny
servers.
When you delete your account, we delete your related account
information and synced financial data from our servers. When we
otherwise have no ongoing legitimate business need to process
your personal information, we will either delete or anonymise such information, or, if this is not possible (for example,
because your personal information has been stored in backup archives),
then we will securely store your personal information and isolate
it from any further processing until deletion is possible.
9. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of We have implemented appropriate and reasonable technical and organisational security measures designed to protect
the security of any personal information we process. However, despite
our safeguards and efforts to secure your information, no electronic
transmission over the Internet or information storage technology can
be guaranteed to be 100% secure, so we cannot promise or guarantee
that hackers, cybercriminals, or other unauthorised third parties will not be able to defeat
our security and improperly collect, access, steal, or modify your
information. Although we will do our best to protect your personal
information, transmission of personal information to and from our
Services is at your own risk. You should only access the Services
within a secure environment.
10. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to We do not knowingly collect, solicit data from, or market to
children under 18 years of age or the equivalent age as specified by law in your jurisdiction , nor do we knowingly
sell such personal information. By using the Services, you
represent that you are at least 18 or the equivalent age as specified by law in your jurisdiction or that you are the parent
or guardian of such a minor and consent to such minor dependent’s
use of the Services. If we learn that personal information from users
less than 18 years of age or the
equivalent age as specified by law in your jurisdiction has been collected, we
will deactivate the account and take reasonable measures to promptly
delete such data from our records. If you become aware of any data
we may have collected from children under age 18 or the equivalent age as specified
by law in your jurisdiction , please contact us
at support@getexpenny.com .
11. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: In some regions (like the
EEA, UK, Switzerland, and Canada ), you have certain rights under applicable data
protection laws. These may include the right (i) to request
access and obtain a copy of your personal information, (ii) to
request rectification or erasure; (iii) to restrict the
processing of your personal information; (iv) if applicable, to
data portability; and (v) not to be subject to automated
decision-making. If a decision
that produces legal or similarly significant effects is made solely
by automated means, we will inform you, explain the main factors,
and offer a simple way to request human review. In certain circumstances,
you may also have the right to object to the processing of your personal
information. You can make such a request by contacting us by using
the contact details provided in the section ' HOW CAN YOU CONTACT US ABOUT THIS NOTICE? ' below.
We will consider and act upon any request in accordance with
applicable data protection laws.
If you are located in the EEA or UK and you believe we are
unlawfully processing your personal information, you also have
the right to complain to your Member State data protection authority or
UK data protection authority.
If you are located in Switzerland, you may contact the Federal Data Protection and Information
Commissioner.
Withdrawing your consent: If we are relying
on your consent to process your personal information, which may be express and/or implied
consent depending on the applicable law, you have the right to
withdraw your consent at any time. You can withdraw your consent at
any time by contacting us by using the contact details provided in
the section ' HOW CAN YOU CONTACT US ABOUT THIS NOTICE? ' below or updating your
preferences .
However, please note that this will not affect the lawfulness of
the processing before its withdrawal nor, when applicable law allows, will it affect the processing
of your personal information conducted in reliance on lawful processing
grounds other than consent.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:-
Log in to your account settings and update your user account.
-
Contact us using the contact information provided.
Upon your request to terminate your account, we will deactivate
or delete your account and information from our active databases.
However, we may retain some information in our files to prevent
fraud, troubleshoot problems, assist with any investigations,
enforce our legal terms and/or comply with applicable legal
requirements.
If you have questions or comments about your privacy rights, you
may email us at support@getexpenny.com .
12. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ( California law requires us to let you know how we respond to web
browser DNT signals. Because there currently is not an industry or
legal standard for recognising or honouring DNT signals, we do not respond to them at this time.
13. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: If you are a resident ofCategories of Personal Information We Collect
The table below shows the categories of personal information we have collected in the past twelve (12) months. The table includes illustrative examples of each category and does not reflect the personal information we collect from you. For a comprehensive inventory of all personal information we process, please refer to the section| Category | Examples | Collected |
|---|---|---|
A. Identifiers | Contact details, such as real name, alias, postal
address, telephone or mobile contact number, unique
personal identifier, online identifier, Internet
Protocol address, email address, and account name |
B. Personal information as defined in the California
Customer Records statute | Name, contact information, education, employment,
employment history, and financial information |
We may also collect other personal
information outside of these categories
through instances where you interact with us
in person, online, or by phone or mail in the
context of:
- Receiving help through our customer support
channels;
- Participation in customer surveys or
contests; and
- Facilitation in the delivery of our Services
and to respond to your inquiries.
- Category A -
As long as the user has an account with us
- Category B -
As long as the user has an account with us
- Category
D - As long as the user has an account with us
- Category
F - As long as the user has an account with us
- Category
G - As long as the user has an account with us
Sources of Personal Information
Learn more about the sources of personal information we collect inHow We Use and Share Personal Information
Gender, age, date of birth, race and ethnicity,
national origin, marital status, and other
demographic data | ||
Transaction information, purchase history,
financial details, and payment information | ||
Fingerprints and voiceprints | ||
Browsing history, search history, online | ||
Device location | ||
Images and audio, video or call
recordings created in connection with
our business activities | ||
Business contact details in order
to provide you our Services at a
business level or job title, work
history, and professional
qualifications if you apply for a
job with us | ||
Student records and directory
information | ||
Inferences drawn from any of
the collected personal
information listed above to
create a profile or summary
about, for example, an
individual’s preferences and
characteristics | ||
Will your information be shared with anyone else?
We may disclose your personal information with our service
providers pursuant to a written contract between us and each
service provider. Learn more about how we disclose personal
information to in the section, ' WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION? '
We may use your personal information for our own business
purposes, such as for undertaking internal research for
technological development and demonstration. This is not
considered to be 'selling' of your personal information.
We have not disclosed, sold, or shared any personal information
to third parties for a business or commercial purpose in the
preceding twelve (12) months. Wewill not sell or share personal information in the future
belonging to website visitors, users, and other consumers.
Your Rights
You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:- Right to know whether or not we are processing your
personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal
data
- Right to request the deletion of your personal data
- Right to obtain a copy of the personal data you
previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of the processing of your personal
data if it is used for targeted advertising
(or sharing as defined under California’s privacy law) , the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ( 'profiling' )
Depending upon the state where you live, you may also have the
following rights:
- Right to access the categories of personal data being processed
(as permitted by applicable law, including the privacy law in
Minnesota)
- Right to obtain a list of the categories of third parties to
which we have disclosed personal data (as permitted by applicable
law, including the privacy law in
California, Delaware, and Maryland )
- Right to obtain a list of specific third parties to which we have
disclosed personal data (as permitted by applicable law, including
the privacy law in
Minnesota and Oregon )
-
Right to obtain a list of third parties to which we have sold
personal data (as permitted by applicable law, including the privacy
law in Connecticut)
- Right to review, understand, question, and depending on where you
live, correct how personal data has been profiled (as permitted by
applicable law, including the privacy law in
Connecticut and Minnesota )
- Right to limit use and disclosure of sensitive personal data (as
permitted by applicable law, including the privacy law in
California)
- Right to opt out of the collection of sensitive data and personal
data collected through the operation of a voice or facial
recognition feature (as permitted by applicable law, including the
privacy law in Florida)
How to Exercise Your Rights
To exercise these rights, you can contact us Under certain US state data protection laws, you can designate an authorised agent to make a request on your behalf. We may deny a request
from an authorised agent that does not submit proof that they
have been validly authorised to act on your behalf
in accordance with applicable laws.
Request Verification
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. If you submit the request through an authorised agent, we may need to
collect additional information to verify your identity before processing
your request and the agent will need to provide a written and signed
permission from you to submit such request on your behalf.support@getexpenny.com . We will inform you in writing of
any action taken or not taken in response to the appeal, including
a written explanation of the reasons for the decisions. If your
appeal is denied, you may submit a complaint to your state
attorney general.
Appeals
Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at
California 'Shine The Light' Law
California Civil Code Section 1798.83, also known as the 14. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: You may have additional rights based on the country you reside in. Australia and New Zealand
We collect and process your personal information under the
obligations and conditions set by Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020 (Privacy Act).
This Privacy Notice satisfies the notice requirements defined in both Privacy Acts , in particular: what personal
information we collect from you, from which sources, for which
purposes, and other recipients of your personal information.
If you do not wish to provide the personal information necessary
to fulfil their applicable purpose, it may affect
our ability to provide our services, in particular:
- offer you the products or services that you want
- respond to or help with your requests
- manage your account with us
- confirm your identity and protect your account
At any time, you have the right to request access to or
correction of your personal information. You can make such a
request by contacting us by using the contact details provided in
the section ' HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT
FROM YOU? '
If you believe we are unlawfully processing your personal
information, you have the right to submit a complaint about a breach of the Australian Privacy
Principles to the Office of the Australian Information Commissioner and a breach of New Zealand's Privacy
Principles to the Office of New Zealand Privacy Commissioner . ' HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT
FROM YOU? '
Republic of South Africa
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section If you are unsatisfied with the manner in which we address any
complaint with regard to our processing of personal information,
you can contact the office of the regulator, the details of which
are:
General enquiries: enquiries@inforegulator.org.za
Complaints (complete POPIA/PAIA form 5):
PAIAComplaints@inforegulator.org.za & POPIAComplaints@inforegulator.org.za
15. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws. We may update this Privacy Notice from time to time. The
updated version will be indicated by an updated 'Revised' date at the top of this Privacy Notice. If we make material
changes to this Privacy Notice, we may notify you either by prominently
posting a notice of such changes or by directly sending you a notification.
We encourage you to review this Privacy Notice frequently to be informed
of how we are protecting your information.
6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
In Short: If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.