Privacy Policy — Spendly Effective date: 12 July 2026 · Developer: Tidybitz Spendly is a personal finance app that helps users track transactions, budgets, savings, debts, accounts, goals, and insurance. This policy explains what data Spendly handles, why it is used, and the choices available to users. 1. Data Spendly handles SMS messages — Spendly can optionally process bank and payment SMS on your Android device to detect financial transactions. New-message capture and historical import are separate opt-in features. Messages from personal numeric phone numbers are ignored. Raw SMS bodies are processed locally and are not included in cloud backup, community-learning uploads, advertising, analytics, or AI requests. A low-confidence message may remain only on the device in the Capture Inbox for review for up to 90 days, or until the user reviews or deletes it. Account information — if you sign in, Spendly stores your name, email address, and optional profile photo supplied through your sign-in provider. Financial records — Spendly stores transaction records and information the user enters or approves, including amount, currency, type, merchant or institution, category, timestamp, masked account identifier, budgets, goals, debts, accounts, and insurance policy records. Insurance analysis — when the user explicitly requests insurance document analysis, document-page images are sent through Firebase Cloud Functions to OpenAI for extraction. Spendly does not retain the source document images in Firestore. Community learning signals — if the user separately opts in, Spendly can upload anonymised classification votes. These signals do not contain raw SMS text, merchant names, amounts, account identifiers, or personal identifiers. Local diagnostics — parser prediction logs use one-way text hashes rather than raw messages and are retained locally for up to 30 days. Spendly does not currently use Firebase Analytics or Firebase Crashlytics. 2. How Spendly uses data Spendly uses data to: - identify expenses, income, transfers, investments, refunds, and other financial events; - create transaction history, budgets, reports, reminders, and alerts; - provide Penny, the user-requested AI financial assistant; - back up approved financial records when the user enables Cloud Backup; - analyse insurance documents when explicitly requested; - improve SMS classification using anonymised, opt-in community votes; and - secure, maintain, and restore the user's account. Spendly does not sell personal or financial data and does not use SMS data for advertising. 3. SMS permissions Spendly requests only the SMS permissions needed for its optional money-management features: READ_SMS — requested only when the user chooses to import existing bank and payment SMS history. RECEIVE_SMS — requested only when the user enables automatic capture of new bank and payment SMS. Spendly does not request permission to send or write SMS. Before either Android permission prompt, Spendly explains what the permission does, how messages are processed, and that the user can decline. Manual transaction entry remains available without SMS access. OTPs, personal conversations, and non-financial messages are not saved as transactions. Only a derived transaction record approved or accepted by Spendly can be stored. It may be synced to the user's private Firestore area only when Cloud Backup is enabled. 4. Cloud services and data sharing Spendly uses these service providers only as needed to provide requested features: Google Firebase — Authentication, Firestore cloud backup, Cloud Functions, and supporting cloud delivery. OpenAI — Penny responses, transaction categorisation requested by the user, and insurance document analysis. Requests are proxied through Firebase Cloud Functions; API credentials are not stored in the Android app. Google Play Services — sign-in, app distribution, and Android platform services. Spendly does not share raw SMS bodies with these providers. 5. Storage, security, and retention Most app data is stored locally in Spendly's private app storage. Cloud Backup is optional. When enabled, approved financial records are stored in Firestore under the authenticated user's UID. Firestore security rules restrict each user to their own records. Financial cloud records remain until the user deletes them or deletes the account. Local Capture Inbox items expire after 90 days. Local parser logs expire after 30 days. Anonymised community vote totals cannot be linked back to an account and may be retained to improve classification. 6. User choices and rights Users can: - use manual transaction entry without SMS permissions; - independently enable or disable historical SMS import and new-message capture; - revoke READ_SMS or RECEIVE_SMS in Android Settings; - enable or disable Cloud Backup; - opt out of community learning and clear pending local signals; - edit or delete individual financial records; and - delete their Spendly account and associated cloud data. In-app account deletion: Settings → Account → Delete account. The deletion process recursively removes the user's Firestore data, Penny rate-limit records, Firebase Authentication account, and local Spendly financial data. This action cannot be undone. Web deletion request: If the user cannot access the app, they may email tidybitzminds@gmail.com with the subject "Delete Spendly Account" from the email address associated with the account. The request should state that deletion of the Spendly account and associated data is requested. Tidybitz may ask the user to verify account ownership before completing deletion. For access, correction, or deletion questions, users may contact the same email address. 7. Children Spendly is not directed to children under 13. We do not knowingly collect personal data from children under 13. If a parent or guardian believes a child provided data, they may contact us for deletion. 8. Changes to this policy If this policy changes materially, Spendly will update the effective date and may provide an in-app notice. 9. Contact Tidybitz tidybitzminds@gmail.com