Your household's money is personal. This policy describes what Spendhog collects, where it is stored, and what control you keep over it.
01The short version
Spendhog is a tool for seeing your own money clearly. We ask for as little as possible, we never sell your data, we run no trackers and no analytics, and the AI assistant is off until you turn it on.
02Who we are
The data controller is Valentino Baptista, Tösswiesenstrasse 35, 8413 Neftenbach, Switzerland. Spendhog is operated personally, not by a company. For any data question: info@spendhog.com.
03What we collect
Only what Spendhog needs to work for your household:
- Account data: your email and, if you sign in with Google, the name on that account, plus the members you invite. The language you signed up in is kept with your login, so that your starting categories are named in it whichever device you confirm on.
- The financial data you enter: accounts, transactions, budgets, categories, members, tags and goals. You enter or import this yourself; Spendhog does not connect to your bank.
- People in your household who have no account, children included: you can add them as members, give them names and attribute spending to them. Their names and the spending attributed to them are part of your data and are kept like the rest of it, so record only what you are entitled to record about them. If you switch on the assistant, their names travel in its summary (see section 12).
- Your interface preferences: language, theme, text size, date and number formats, the dashboard's layout and the ledger's columns. They are stored with your account on our database, so they follow you from one device to another.
- Messages you send through the Feedback form, along with your account email, and any files you choose to attach: up to three per message, PNG, JPG or WebP images or PDF, up to 5 MB each. A screenshot shows everything that was on the screen, your figures included, so attach only what you want us to see. Before they leave your device, images are redrawn, which strips their metadata, such as where a photo was taken; a PDF goes as it is. The files are kept at Supabase, in Ireland, like the rest of the data, in a private space only the operator can open: once sent, neither you, nor another account, nor the app itself can read them.
- Subscription: if you subscribe, payment is handled by Paddle (merchant of record), which collects your name, address and payment details; we receive only the subscription status, never the card.
- Error reports. We run no usage analytics. If the app fails, it records the error so we can fix it: the message, the technical trace of where in the code it happened (the stack trace), the page, the app version and the browser identification, linked to your account so we can tell whether a fault reached one person or many. Never the contents of your ledger. They are deleted after 90 days, by a clean-up that runs every day.
- Server logs. The server that delivers the app's pages, and the proxy in front of it, keep standard access logs of each request: IP address, time, the address requested and the browser identification. They are used only to run and protect the service, and only the operator can read them.
- Exit answer (optional). If you delete your account, you can tell us why. The account is deleted either way. The answer is stored with no link to your account, your email or your household: the reason you chose, the note you write (up to 500 characters), the account's age as a range (for example, 8 to 30 days), whether there were entries in a household you belonged to, the plan (trial, free or paid) and the month. The note is free text, so please do not write anything in it that identifies you. Legal basis: legitimate interest in improving the service, from a voluntary answer. We keep these answers for 24 months and then delete them.
- The logos you choose for accounts and goals are loaded by your browser straight from the address you give; that server sees your IP address, as with any image on the web.
- Where you came from: if you arrive from an ad, the campaign tags (utm) and the click identifier the ad network adds to the address: Google (gclid, gbraid, wbraid), Meta (fbclid), Microsoft (msclkid), TikTok (ttclid) or LinkedIn (li_fat_id). Stored once, with your signup, so we know which campaign brought you. They do not follow your browsing and are never sent to the ad network or to anybody else, and the click identifiers are deleted after 90 days.
- Account-level counts: to support you and to run billing, the operator's admin screen shows, for each account, its email, when it signed up and last signed in, its plan, the size of its household, how many entries, accounts, budgets and goals it holds and the date of its latest entry. Never what those entries say.
- Notices to the operator: at most every ten minutes, the operator gets one email saying only how many new signups and how many new error reports there have been, so he can write to each new household in its first days and fix a failure before anybody has to report it. That email carries no personal data: no email addresses, no names and no error text. To count the errors, the database gathers the reports into groups (kind, page and message, with numbers and identifiers taken out), without the account they came from and without the stack trace.
04Legal bases
These reasons apply under both the EU's GDPR and the Swiss Federal Act on Data Protection (FADP): the contract with you (account, financial data and preferences), your consent (the AI assistant) and legitimate interest (feedback, the optional answer when leaving, invites, error reports, server logs, backups, the account-level counts used for support and billing, abuse prevention and measuring which campaign brought a signup, and the notices to the operator about new signups and errors). To create an account we need your email address; everything else you enter is your choice.
Automated decisions: the app works out assessments of your financial situation for you, such as the Financial health score, the notifications and the assistant's answers. They exist only to inform you and your household. We make no decision about you that has legal effects or a similarly significant effect on you, based on them or by any other automated means. The only thing the app applies by itself is the subscription terms: one free 30-day trial per mailbox and the conditions of the founder price. If you think they were applied wrongly in your case, write to us and a person will review it.
05Where it is stored
In a Postgres database managed by Supabase, on servers in the European Union (AWS region eu-west-1, Ireland). Data always travels over an encrypted connection (TLS) and is encrypted at rest. Isolation between accounts is enforced by the database itself (Row-Level Security): no user can read or modify another user's data. Once a week we also take a full copy of the database and keep the latest eight, about two months, on our own server in Switzerland, where only the operator can reach them. They exist to restore the service if the database or the hosting account is ever lost.
06In your browser
We store your session and a copy of your interface preferences, so the app opens in your language and theme before you sign in. Undo and redo history lives in sessionStorage and disappears when you close the browser.
The texts the assistant writes for you (the conversation, the Financial health assessment, the Simulation summaries and the monthly brief) and, beside each answer, the totals the app computed for it, the questions the assistant asked the app and the web searches it made are kept in the browser and copied to your account. They stay on the device after you sign out, shown only to the account they belong to, until you clear the chat, tighten what is sent (which deletes the conversation) or turn the assistant off, which deletes them on the device and in your account. While the assistant waits for you to accept a new description of what it sends, they are kept as they are.
When you sign up, the device briefly holds your acceptance of these documents and, if you arrived from an ad, the campaign tags (and, for a Google sign-up, the language you signed up in), tied to the account being created. Your account takes them over the first time it opens; otherwise they expire after three days, or thirty minutes for a Google sign-up. The browser also keeps a few technical markers with nothing from your ledger in them, for example how long the last start-up took.
07We do not sell or share
Your data is never sold, rented or shared with third parties for advertising. We use no trackers and no analytics tools, and we do not use your individual transactions for advertising. We may disclose data if the law requires it.
08Third-party services and transfers abroad
Some of these services are outside Switzerland. For each one we say which country it is in and what protects your data there. Switzerland recognises the countries of the EU and the EEA and the United Kingdom as protecting personal data adequately, and the EU recognises Switzerland and the United Kingdom; no further safeguard is needed for them. The United States counts as adequate only for companies certified under the Data Privacy Framework: the EU-U.S. framework for data coming from the EU, and the Swiss-U.S. framework for data coming from Switzerland, which Switzerland has recognised since 15 September 2024. Where the country is not recognised, and unless a service below says otherwise, the transfer relies on the European Commission's standard contractual clauses in the service's data processing agreement; for data coming from Switzerland, the FDPIC, the Swiss data protection authority, recognises those clauses with the adaptations to Swiss law. We checked the official list of certified companies on 28 September 2026.
These are everyone who touches anything, what they get, and where they are:
- Supabase: hosting, database and sign-in. The contract is with Supabase Pte. Ltd., in Singapore. The database is in Ireland (AWS eu-west-1), and the functions that run on the server execute in the Supabase region nearest to whatever calls them, your browser or another server. When Supabase or its subprocessors handle data outside Europe, from Singapore or from another country on the subprocessor list Supabase publishes, the transfer relies on the standard contractual clauses in its data processing agreement, with the Swiss addendum. Supabase is not certified under the Data Privacy Framework.
- Google: only if you choose to sign in with Google. For people in Europe that is Google Ireland, under Google's own privacy policy.
- Frankfurter and the ECB: exchange rates, the European Central Bank's reference rates delivered by the Frankfurter service. Your browser asks for the rates, so the service sees the request and your IP address, as any website does, and never your data. The service is delivered through Cloudflare and states that it logs neither IP addresses nor requests; we could not confirm which country it is hosted in.
- Paddle: payments, as merchant of record, with its own privacy policy. Paddle (Paddle.com Market Limited) is in the United Kingdom, which Switzerland and the EU recognise as adequate.
- Resend: the app's emails, for example invites and password resets. Resend is a US company and processes data mainly in the United States, where its primary operations are; our emails are sent from its European region (Ireland). Resend is certified under the EU-U.S. Data Privacy Framework, which covers data coming from the EU; it does not hold the Swiss certification, so for data coming from Switzerland the transfer relies on the standard contractual clauses in its data processing agreement, with the adaptations to Swiss law.
- Namecheap: hosts the info@spendhog.com mailbox, where the emails you send us arrive. Namecheap is a US company, and its mail service (Private Email) runs only on its servers in the United States (Phoenix, Arizona). It is not certified under the Data Privacy Framework. Its data processing agreement contains the EU and UK standard contractual clauses but not the adaptations to Swiss law, so for data coming from Switzerland it does not yet have a safeguard recognised by the FDPIC.
- Have I Been Pwned: when you set or change a password, checks whether it appeared in public breaches, receiving only a 5-character fragment of its hash, never the password. It is run from Australia, keeps its data on servers in the United States and is served through Cloudflare. We have no contract with it: your browser asks it directly, so it sees your IP address and the fragment, and nothing else.
- Cloudflare Turnstile: protection against bots on the sign-in, sign-up, password reset, confirmation resend and password change forms. The contract is with Cloudflare, Inc., in the United States. Your browser loads it from challenges.cloudflare.com only on those forms, and it receives your IP address, characteristics of your browser and device, and how you interact with the check, never your account data. The legal basis is our legitimate interest in keeping accounts safe. Cloudflare is certified under the EU-U.S. and the Swiss-U.S. Data Privacy Framework, and its data processing addendum is part of its terms. It sets no cookie on our domain.
- Anthropic: only if you switch on the AI assistant. The contract is with Anthropic Ireland, Limited; the data is stored in the United States, and, according to Anthropic's documentation, requests may be processed in the United States, Europe, Asia and Australia, and, for internal processes such as safety reviews, in other countries where Anthropic or its affiliates operate. It is not certified under the Data Privacy Framework; the transfer relies on the standard contractual clauses in its data processing agreement, with the Swiss addendum. See the AI assistant section.
- Brave Search: only when the assistant looks up a published statistic, and receives only the search phrase, from Anthropic and not from you. A US company, working for Anthropic under Anthropic's data processing agreement. See the AI assistant section.
- Our own server in Switzerland: it delivers the app's pages and holds the weekly backups (sections 3 and 5).
09Household members
Members you invite see the household data according to their role (owner, editor or viewer). Everyone in a household works on the same ledger, so if the owner deletes their account, the household and its whole ledger are deleted with it, for every member; the other members keep their own logins, each with a new, empty household of their own. If anybody else leaves the household or deletes their account, the entries they recorded stay in it, because they are the household's history.
10Your rights
You can export your household's financial data at any time (Settings, Data): one file with the accounts, transactions, categories, tags and the groups they sit in, budgets, goals, upcoming bills, scenarios, your answers about fixed expenses, members and settings, including your own preferences and the assistant's memory notes. What that file does not hold, for example your account's email and name, your household membership and roles, pending invitations, the assistant's texts, the totals kept beside its answers, the questions it asked the app and the web searches it made, your feedback messages and the files attached to them, the record of which campaign brought you, your subscription status and your error reports, we send you on request. You can permanently delete your account and everything in it (Settings, Account, Danger zone). You also have the rights of access, rectification, erasure, restriction and objection: just write to us, and we answer free of charge within 30 days at most. You also have the right to lodge a complaint with a data protection authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch), in the EU your country's authority. In Switzerland you can also enforce your rights before the civil courts.
11Retention
We keep your data for as long as the account exists, with these exceptions: error reports are deleted after 90 days, and the advertising click identifiers (gclid and the others listed in section 3) are deleted after 90 days, because past that they can no longer answer the question they were kept for. The campaign tags (utm) identify nobody and stay. Files attached to feedback are deleted 90 days after they were sent, or sooner if the operator deletes the message. The error groups the database keeps to count the errors (kind, page, message and counts, without the account they came from or the stack trace) are deleted 90 days after the error last happened. When you delete your account, it is removed from the database immediately and irreversibly, and if you are the household's owner the household's whole ledger goes with it (see section 9). Four things survive: feedback messages you sent may remain, no longer linked to you, but without the files you attached to them, which are deleted within a day of the account; error reports from before the deletion stay, no longer linked to your account, until their 90 days are up; the answer you gave on the way out, if you gave one, with no link to your account, for 24 months; and a fingerprint (a cryptographic digest) of your email address, not the address itself. Separately, the weekly backups (section 5) are a copy of the database as it was that day, so anything deleted since, whether a deleted account, error reports or click identifiers past their 90 days, stays in them until they are replaced, at most about eight weeks later. They are used only to restore the service after a loss. The backups are of the database and do not include the files attached to feedback.
The fingerprint serves one purpose: knowing that this mailbox has already had the free 30-day trial, so that deleting the account and signing up again does not restart it. It cannot be read back as your address, but someone who already knows an address can check whether it matches. It cannot be used to contact you or to link you to any financial data, which is deleted in full. Legal basis: legitimate interest (abuse prevention).
12AI assistant (optional)
The AI assistant is off by default; nothing is sent without your explicit consent, given on the assistant's own page and, for the monthly brief, additionally on its card at the end of the month's cards in What's new or in the assistant's settings. When you switch it on and ask a question, we send Anthropic (provider of the Claude model), over an encrypted connection, an aggregated summary of your data: monthly totals, totals per category and per person, balances, budgets, goals and the fixed expenses the app recognises (what they are, what they cost and how often), what you have free per day, your months of cover, what is owed and the balance projection, together with your question. The same is sent when you ask for a Financial health assessment, and when Simulation writes a scenario's summary, which it does by itself once per scenario on each device and again whenever you press its button. If you switch on the monthly brief, once a month, the first time you open the app after a month has closed, until that month's cards have been closed in What's new on that device (and, if that fails, once more later while those cards have not been closed on a device), we send Anthropic a smaller summary of that month: its income, its spending and the difference between them, and its spending by category and by title, each beside the average of up to three months before it, with figures worked out from those same totals (differences, percentages and shares). It is written once per month and person, and you can switch it off in the assistant's settings. The financial health score and the areas behind it travel with every question. The summary uses the names you have given to people, children included, and to accounts, categories, budgets and goals, so that the assistant can answer about them. Individual transactions, emails and credentials are never sent. The titles and notes you write on entries travel as vocabulary: the word, what it cost in total and how often it appears, never tied to an entry or a date. So a title you have used only once carries what that one purchase cost, rounded. A note only travels if it is short and you have written it at least three times. You can change this in the assistant's settings: share every short note (a note written once then carries its purchase's rounded cost, like a title), only the ones you repeat, or none at all, in which case the note field never leaves your device, not even as a total.
When a question needs a figure the summary does not hold, the assistant can ask the app for an exact total over a slice it chooses: a period, a category, an account, a person, a title or a word in the notes. The app works it out and sends back only that total and how many entries it covers, never the entries themselves; over a narrow enough slice, a single day and title for example, that total is one entry's amount. A search for a word looks through every note, not only the repeated ones, unless you share no notes, in which case the notes are not searched at all.
When the assistant writes the summary of a scenario in Simulation, it is also sent that scenario's name and its assumptions: the labels you wrote for them, with their amounts, percentages and months and the category, goal or account each one applies to, together with the scenario's projected results.
Anthropic acts as a processor, under the data processing addendum that forms part of its commercial terms: those terms forbid it from using this data to train models. Per its documentation, requests and responses are deleted from its systems after about 30 days, except where flagged by its automated safety systems or where the law requires it to keep them. During that period they may be accessed by Anthropic for safety and security purposes. The conversation, the Financial health assessment, the Simulation summaries, the monthly brief and, beside each answer, the totals the app computed for it, the questions the assistant asked the app and the web searches it made stay in your browser and are copied to your account, so a thread you started on your laptop is there when you open your phone; they go nowhere else and we do not use them for anything. You can clear the conversation whenever you like with the button on the assistant's page; tightening what is sent (Settings, AI) deletes it too, because earlier answers may quote your notes; and turning the assistant off deletes all of them, on the device and in your account. Where Anthropic keeps this data, and what protects it there, is in section 8. You can withdraw consent at any time on the page itself, after which nothing further is sent.
Looking up published figures. When your question needs a figure the app does not hold, for example what a typical household in your country spends, the assistant can look it up on the internet. It is instructed to search only when the question is about finances, to prefer official sources such as statistics offices and central banks, and to name the source and the year of any figure it uses. What leaves is a search phrase written by the model, run by Anthropic through Brave Search. Each call to the model can run at most three searches; answering one question can take several calls, when the assistant also asks the app for totals or a search runs long, so one question can lead to more than three searches. Your ledger does not go into the search: transactions, balances, budgets and notes are not sent. The model is also instructed never to write anything identifying you into a search, such as your amounts, account or bank names, shops you bought from, or your address.
Assistant memory: if you choose to save notes for the assistant, those notes are stored in your account's database and sent along with each question. The full list is visible on the assistant's page, where you can delete any note at any time; the assistant may suggest a note, but nothing is saved without your confirmation.
13Changes to this policy
As Spendhog is in early access, this policy may change as the product grows. We will update the date at the top and, for material changes, let you know inside the app.
14Contact
For any privacy question, write to info@spendhog.com or use the Feedback form inside the application. Postal address: Valentino Baptista, Tösswiesenstrasse 35, 8413 Neftenbach, Switzerland.
Questions about this page? Reach us any time and we'll walk you through it. info@spendhog.com