SpendWhy — Privacy Policy

Last updated: 2026-06-24

SpendWhy ("the app", "we", "us") is a personal finance application operated by ZYNTHYR OÜ, a company registered in Estonia. This policy explains what data the app handles, why, where it is stored, and the choices you have.

If you have questions, contact us at privacy@spendwhy.com.


1. Summary

2. Data we collect and why

Account data. When you create an account we store your email address to authenticate you. Sign-in is handled by Supabase Auth.

Financial data you enter. Transactions, accounts, categories, budgets and notes you create are stored in an encrypted local database on your device.

Receipt images. If you scan a receipt, the photo is processed on your device using on-device text recognition (Google ML Kit) to extract amounts and text. The image itself is not transmitted to us.

Bank synchronisation data (optional). If you connect a bank, we use Enable Banking, a licensed PSD2 account-information service. With your consent, it provides read-only access to your account details and transaction history. We store, in our backend:

Device security data. If you enable the biometric app lock, it is handled by your device's secure hardware (via the operating system). Biometric data never leaves your device and is never sent to us.

Diagnostics (optional). The app may send anonymised crash reports (Sentry) and product-usage analytics (PostHog) to help us fix bugs and improve the app. These contain technical information (e.g. error traces, device model, app version), not your financial records. Where required, this is governed by your in-app/OS choices.

3. Where your data is stored

4. Third parties we use

ProviderPurposeData
Enable BankingOpen-banking aggregator (PSD2)Bank account & transaction data, with your consent
SupabaseAuthentication & backend hosting (EU)Account email, bank-sync data
Google ML KitOn-device receipt text recognitionRuns locally; no data sent to us
Sentry (optional)Crash reportingTechnical diagnostics
PostHog (optional, EU)Product analyticsAnonymised usage events

We do not sell your data and do not share it for advertising.

5. Bank connections and consent

Connecting a bank is entirely optional. When you do:

6. Data retention and deletion

Your local data stays on your device until you delete the app or the data. You can request deletion of your account and the data we hold in our backend by contacting privacy@spendwhy.com; we will delete it within 30 days, subject to any legal retention obligations.

7. Security

8. Your rights

Under the GDPR you can request access to, correction of, or deletion of your personal data, and you may object to or restrict certain processing. Contact privacy@spendwhy.com to exercise these rights. You may also lodge a complaint with your local data-protection authority.

9. Children

SpendWhy is not directed at children under 16 and we do not knowingly collect their data.

10. Changes to this policy

We may update this policy; the "Last updated" date above reflects the latest version. Material changes will be communicated in the app.

11. Contact

ZYNTHYR OÜ — privacy@spendwhy.com