Privacy Policy

Expensy

Effective Date: December 1, 2025

BoringSoft ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and share information when you use Expensy ("the App").

1. Information We Collect

1.1 Information You Provide

1.2 Information Collected Automatically

2. How We Use Your Information

We use your information to:

3. Data Storage and Processing

3.1 Local Storage

Your expense data is stored locally on your device by default. Receipt images are always stored locally on your device and are never uploaded to our servers, regardless of whether cloud synchronization is enabled.

3.2 Cloud Synchronization

If you enable sync, only your transaction data (amounts, categories, dates, merchant names, and notes) is uploaded to Supabase servers. This is text data only. Receipt images are never uploaded—they remain exclusively on your device. Supabase provides secure, encrypted cloud storage for your synced transaction data.

3.3 AI Receipt Processing

When you scan a receipt, the image is sent through our secure backend proxy to Google's Gemini AI service for text extraction. Our backend does not store the images—they are processed and immediately discarded. Google's Gemini API (paid tier) does not use your data to train their AI models. However, data may be temporarily cached by Google for processing purposes and may be logged for abuse monitoring in accordance with Google's policies.

4. Third-Party Services

We use the following third-party services:

5. Data Sharing

We do not sell your personal data. We may share your information only in the following circumstances:

6. Data Retention

We retain your account and expense data for as long as your account is active. Locally stored data remains on your device until you delete it or uninstall the App. If you enable sync, cloud-stored data is retained until you delete your account. When you delete your account, all associated data is permanently removed from our servers within 30 days.

7. Your Rights

7.1 All Users

You have the right to:

7.2 European Economic Area (EEA) Residents – GDPR Rights

If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR):

Our legal basis for processing your data is: (a) contract performance (to provide our services), (b) legitimate interests (to improve our services), and (c) your consent (for optional features like analytics).

7.3 California Residents – CCPA Rights

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

8. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS/SSL) and at rest, secure authentication, and regular security assessments. However, no method of electronic transmission or storage is 100% secure.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your residence, including the United States. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your data during such transfers.

10. Children's Privacy

The App is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the App and updating the "Effective Date" above. Your continued use of the App after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at:

BoringSoft

Email: support@boringsoft.org

For EEA residents: You may also contact your local data protection authority.