Expensy
Effective Date: December 1, 2025
BoringSoft ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and share information when you use Expensy ("the App").
We use your information to:
Your expense data is stored locally on your device by default. Receipt images are always stored locally on your device and are never uploaded to our servers, regardless of whether cloud synchronization is enabled.
If you enable sync, only your transaction data (amounts, categories, dates, merchant names, and notes) is uploaded to Supabase servers. This is text data only. Receipt images are never uploaded—they remain exclusively on your device. Supabase provides secure, encrypted cloud storage for your synced transaction data.
When you scan a receipt, the image is sent through our secure backend proxy to Google's Gemini AI service for text extraction. Our backend does not store the images—they are processed and immediately discarded. Google's Gemini API (paid tier) does not use your data to train their AI models. However, data may be temporarily cached by Google for processing purposes and may be logged for abuse monitoring in accordance with Google's policies.
We use the following third-party services:
We do not sell your personal data. We may share your information only in the following circumstances:
We retain your account and expense data for as long as your account is active. Locally stored data remains on your device until you delete it or uninstall the App. If you enable sync, cloud-stored data is retained until you delete your account. When you delete your account, all associated data is permanently removed from our servers within 30 days.
You have the right to:
If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR):
Our legal basis for processing your data is: (a) contract performance (to provide our services), (b) legitimate interests (to improve our services), and (c) your consent (for optional features like analytics).
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS/SSL) and at rest, secure authentication, and regular security assessments. However, no method of electronic transmission or storage is 100% secure.
Your data may be transferred to and processed in countries outside your residence, including the United States. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your data during such transfers.
The App is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the App and updating the "Effective Date" above. Your continued use of the App after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at:
BoringSoft
Email: support@boringsoft.org
For EEA residents: You may also contact your local data protection authority.