SpendYes

Privacy Policy

Effective September 12, 2026

The short version

SpendYes stores the money information you choose to enter so it can calculate your daily spending number. We do not sell your data, run advertising profiles, or require access to your bank account.

Information we process

How it is used

We use this information to provide calculations, sync your account, process the entries you request, troubleshoot failures, protect accounts and improve reliability. Submitted text, receipt images or audio may be sent to an AI processing provider when needed to interpret your request. SpendYes does not retain original receipt images or audio on its server after processing. While an entry is unfinished, the app may keep its photo, audio and draft details in this browser on your device so you can resume after closing it. Drafts expire after seven days without updates and expired content is removed when the app next accesses that storage. The app clears local drafts after confirmed saving, discarding, account sign-out or deletion; if storage is unavailable it shows a warning. Browser storage limits or clearing site data may remove drafts sooner. Unfinished drafts do not sync between devices.

Storage and service providers

Account and money data is stored in PostgreSQL on Railway-hosted infrastructure. Google Identity Services is not loaded with the daily dashboard; it loads when an account surface offers Google sign-in. Google processes the sign-in choice when you use it. We use limited service providers for hosting, database operation, currency data and optional AI processing. They process information only to provide those functions.

Retention and deletion

Your data remains until you delete it or request deletion. A guest plan stored for one phone can be exported or permanently deleted from the Account screen without creating an account. A signed-in account can use the same screen to export or delete its account data. You may also use our web deletion route.

Your choices

You can use SpendYes without connecting a bank, choose Google or email sign-in, export a copy of your data, stop submitting receipts or voice, sign out, and delete your account. Telegram access is optional.

Security

Connections use HTTPS. Standalone sessions use revocable secure cookies. Google credentials are verified with Google and Google passwords are never sent to SpendYes. Passwords, session tokens and recovery keys used by SpendYes are stored as one-way hashes. No internet service can guarantee absolute security, so keep your Google account secure or use a unique SpendYes password and keep your recovery key private.

Contact

For privacy questions or deletion requests, email hello@10row.com.

SpendYes is operated by Siren Group LLC.