Last updated: 2026-06-24
SpendWhy ("the app", "we", "us") is a personal finance application operated by ZYNTHYR OÜ, a company registered in Estonia. This policy explains what data the app handles, why, where it is stored, and the choices you have.
If you have questions, contact us at privacy@spendwhy.com.
Account data. When you create an account we store your email address to authenticate you. Sign-in is handled by Supabase Auth.
Financial data you enter. Transactions, accounts, categories, budgets and notes you create are stored in an encrypted local database on your device.
Receipt images. If you scan a receipt, the photo is processed on your device using on-device text recognition (Google ML Kit) to extract amounts and text. The image itself is not transmitted to us.
Bank synchronisation data (optional). If you connect a bank, we use Enable Banking, a licensed PSD2 account-information service. With your consent, it provides read-only access to your account details and transaction history. We store, in our backend:
Device security data. If you enable the biometric app lock, it is handled by your device's secure hardware (via the operating system). Biometric data never leaves your device and is never sent to us.
Diagnostics (optional). The app may send anonymised crash reports (Sentry) and product-usage analytics (PostHog) to help us fix bugs and improve the app. These contain technical information (e.g. error traces, device model, app version), not your financial records. Where required, this is governed by your in-app/OS choices.
| Provider | Purpose | Data |
|---|---|---|
| Enable Banking | Open-banking aggregator (PSD2) | Bank account & transaction data, with your consent |
| Supabase | Authentication & backend hosting (EU) | Account email, bank-sync data |
| Google ML Kit | On-device receipt text recognition | Runs locally; no data sent to us |
| Sentry (optional) | Crash reporting | Technical diagnostics |
| PostHog (optional, EU) | Product analytics | Anonymised usage events |
We do not sell your data and do not share it for advertising.
Connecting a bank is entirely optional. When you do:
Your local data stays on your device until you delete the app or the data. You can request deletion of your account and the data we hold in our backend by contacting privacy@spendwhy.com; we will delete it within 30 days, subject to any legal retention obligations.
Under the GDPR you can request access to, correction of, or deletion of your personal data, and you may object to or restrict certain processing. Contact privacy@spendwhy.com to exercise these rights. You may also lodge a complaint with your local data-protection authority.
SpendWhy is not directed at children under 16 and we do not knowingly collect their data.
We may update this policy; the "Last updated" date above reflects the latest version. Material changes will be communicated in the app.
ZYNTHYR OÜ — privacy@spendwhy.com