The short version
- You sign in with Google. We do not store passwords or ask for your bank login.
- We handle the records and files you add, to give you your dashboard, categories and reports.
- AI is optional and limited, and you can turn it off.
- We do not sell your personal information.
- You can export your data and delete it whenever you like.
- Questions or requests: support@spendix.app.
Who this policy covers
This policy applies to the SpendixAI website and to the SpendixAI web and mobile apps (together, the service). “SpendixAI”, “we” and “us” mean the team that operates the service. “You” means anyone who uses it.
Information we collect
Account information
You sign in with Google. We receive your name, email address and profile picture from Google, and we create your SpendixAI account and workspace from them. We do not receive or store your Google password, and SpendixAI does not offer password sign-in.
Financial records you add
Transactions, accounts, categories, budgets, merchants, tags, notes and rules that you enter, import or create. This includes the amounts, dates, currencies and merchant names on the statements you import.
Files you upload
Bank and card statements (PDF, CSV or Excel), receipts and similar documents. We process them to extract transactions and keep them in your workspace for the retention period you choose.
Workspace and team information
If you invite other people to a workspace, we hold their names, email addresses and roles. People in a workspace can see the data that their role allows.
Technical and security information
Sign-in sessions, IP address, browser and device details, and activity records such as audit entries, so that we can keep accounts secure, find faults and prevent misuse.
Messages to us
Anything you send to our support team, including your email address and the content of your message.
SpendixAI does not ask for your bank login details and does not connect to your bank accounts. Your records come from files you upload and entries you make.
How we use information
- To provide the service: importing statements, categorising transactions, building reports and showing your dashboard.
- To keep your account secure, prevent fraud and enforce our terms.
- To send notices you have asked for or that the service needs, such as import results and security alerts.
- To answer your questions and give support.
- To understand how the service is used and to fix and improve it.
Why we are allowed to
We handle your information because you ask us to provide the service, for example when you import a statement. Where the law requires your consent, for example when you switch on an AI feature or connect an AI assistant, we rely on that consent, and you can withdraw it at any time by turning the feature off or disconnecting. We also handle limited information for legitimate purposes such as security and preventing misuse.
AI and automatic categorisation
SpendixAI sorts transactions into categories in stages. Your own rules and your categorisation history come first, and they involve no AI. Only for transactions that those steps cannot place, we may ask an AI model to suggest a category.
- What is sent: the normalised merchant name and an amount band (for example ₹100–500).
- What is not sent for categorisation: your name, account numbers, full statement text or balances.
- Our AI provider is Anthropic. We configure the arrangement so that data sent is not kept beyond the request and is not used to train models.
Some optional AI features, such as reading a statement layout we do not recognise or structuring a scanned receipt, need to process the content of the document you uploaded. Each AI feature can be switched on or off in Settings, you can exclude specific accounts from AI, and you can turn AI off entirely. Everything that does not use AI keeps working when AI is off.
AI assistants you connect (MCP)
If you connect an assistant such as Claude or ChatGPT to your workspace using MCP, that assistant can read, and if you allow it, change, the data covered by the access level you approve. The assistant and its provider handle that information under their own terms and privacy policy. You can see and disconnect connected assistants at any time from the MCP connections page under Developer.
Emails and notifications
We send in-app notifications and some emails that the service needs, such as import results and security alerts, and optional ones such as a weekly summary. You can choose which types reach you in Settings, under Notifications. Some notices about your account or changes to our terms may still be sent.
Who we share information with
We do not sell your personal information. We share it only as follows:
- Service providers that help us run SpendixAI: cloud hosting, database and file storage, email delivery and the AI provider described above. They may use the information only to provide their service to us.
- Google, when you sign in with Google.
- Other members of a workspace you belong to, according to their role.
- Authorities or other parties where the law requires it, or where needed to protect people’s safety or our rights.
- A successor, if SpendixAI is involved in a merger, acquisition or sale of assets. We would tell you before your information becomes subject to a different policy.
Where information is processed
Our providers may process information in India or in other countries. Where information leaves your country, we rely on providers that apply appropriate safeguards.
How long we keep information
- Your records stay in your workspace until you delete them or the workspace.
- Workspace owners can set how long uploaded documents are kept, from 1 to 120 months.
- Transactions you delete can be restored from the recycle bin for 30 days.
- When a workspace is scheduled for deletion, nothing is removed for 7 days, and the owner can cancel in that time. After that, the workspace and its data are permanently deleted. Copies may remain in backups for a limited period until they are overwritten.
- Support messages are kept for as long as we need them to help you and to keep a record of what was done.
Your choices and rights
You decide what goes into SpendixAI, and you can:
- Export your data. Workspace owners can download an export of accounts, categories, transactions, budgets, merchants, rules, document details, members and billing invoices from Settings, Data and privacy.
- Correct or delete transactions, or clear a date range.
- Change AI settings or turn AI off.
- Disconnect AI assistants.
- Delete your workspace and its data.
- Ask us to access, correct or delete information we hold about you, or to answer a concern about how it is handled.
Depending on where you live, you may have further rights under data protection law, including India’s Digital Personal Data Protection Act, 2023. We will respond to valid requests within the time the law allows.
How to make a request
- Write to support@spendix.app with “Privacy request” in the subject line, from the email address linked to your account.
- Say what you would like: access, correction, deletion or a question.
- We may ask you to confirm that you are the account holder before we act.
- We will reply with what we did or why we could not.
Security
We use safeguards suited to financial information, including encrypted connections, sign-in through Google, access that is limited by role and kept separate for each workspace, and an audit log of important actions. No system is perfectly secure, so please also protect your Google account. If a breach affects your personal information, we will tell you and the authorities as the law requires.
Cookies and similar technologies
We use a small number of cookies and browser storage that the service needs. See our Cookie Policy.
Children
SpendixAI is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a child has given us information, write to us and we will delete it.
Changes to this policy
We may update this policy as the service changes. We will change the date at the top and, for significant changes, tell you in the service or by email.
Contact us
For privacy questions or requests, write to support@spendix.app with “Privacy” in the subject line.