SpendWise — Household Finance
Privacy Policy
Version 1.0 · Last updated August 2026
SpendWise is a private household finance application built and operated by Keyur Patel for use by two named individuals ("the account holders"). It is not a public product — there is no self-service sign-up, and no one outside the account holders can create an account or access this data. This policy explains what data the application collects about the account holders, why, and how it is protected.
What data is collected
- Account data: your email address, authentication credentials, and household membership.
- Financial data you enter directly: transactions, budgets, income, and receipt photos you add or import (CSV) yourself.
- Financial data from linked banks (via Plaid): if you choose to connect a bank account, we receive account balances and transaction history for the accounts you select. We never receive your online banking password — that is handled entirely by Plaid and your bank.
- AI-assisted processing: transaction descriptions and spending summaries may be sent to Google's Gemini API to suggest categories, detect recurring bills, or generate budget insights. No account credentials or bank access tokens are ever included in these requests.
How it's used
Solely to provide the budgeting, transaction-tracking, and bill-reminder features of the application to the account holders. Data is never sold, rented, or shared with advertisers, data brokers, or any third party for marketing purposes. It is not used to train any AI model.
Who can access it
Only the account holder(s) who are members of a given household can read that household's data, enforced at the database level on every request — not just in the application's interface. Bank access tokens are additionally encrypted and are never accessible through any user-facing account, including the account holders' own.
Service providers
The following providers process data on our behalf, strictly to operate the application:
- Supabase — database and authentication hosting.
- Vercel — application hosting.
- Plaid — bank account connectivity, only for accounts you choose to link.
- Google (Gemini API) — AI-assisted categorization and insights.
- Resend — delivery of bill-due-date reminder emails.
Data retention & deletion
- Bank-linked transaction data is retained only while a bank connection remains active.
- Disconnecting a bank immediately revokes its access token with Plaid and deletes the transactions it synced from our database — this happens automatically, not on request.
- Manually entered or imported transactions are retained until you delete them yourself.
- An account holder may request full deletion of their account and all associated household data at any time by contacting the policy owner below; this is completed within 30 days.
Your rights
As an account holder, you can access, correct, export, or delete your data at any time from within the application, or by contacting the policy owner directly for anything not self-serviceable in the interface.
Contact
Keyur Patel — keyur.patel182@gmail.com