Legal · Privacy

PrivacyPolicy

We believe transparency is the foundation of trust. This policy explains exactly what data we collect, how we use it, and the rights you have over it.

Last updated: April 12, 2026Version 2.0Applies to: expenseai.in

Information We Collect

We collect information you provide directly and data generated as you use ExpenseAI. This data is essential to deliver our AI-powered financial tracking features.

Minimal Data Principle

We only collect data that is necessary to operate ExpenseAI effectively. We do not sell your personal information to third parties.

Account Information

  • Full name
  • Email address
  • Password (encrypted)
  • Profile picture (optional)
  • Date of birth (optional)

Financial Data

  • Transaction records (income & expenses)
  • Budget configurations
  • Category labels & folder names
  • Spending patterns & history
  • Connected account details (Phase 2)

Device & Usage Data

  • IP address & approximate location
  • Browser type & OS version
  • Session timestamps & duration
  • Feature usage & navigation patterns
  • Crash reports & error logs

We may also collect data from third-party services (e.g., Google Sign-In) with your explicit authorization. You can review and manage this data at any time from your profile settings.

How We Use Your Information

Your data powers the core features of ExpenseAI. We use it for the following clearly-defined purposes:

Service Operation

Process transactions, sync data, and provide your personalized expense dashboard.

AI-Powered Insights

Analyse spending patterns to generate smart budget recommendations and financial insights.

Notifications & Alerts

Send budget alerts, spending limit warnings, and account security notifications.

Analytics & Improvement

Aggregate anonymised usage stats to improve features and fix bugs.

Security & Fraud Prevention

Monitor for suspicious activity, detect unauthorized access, and protect your account.

Communications

Send product updates, feature announcements, and support responses (opt-out available).

No Selling, Ever

We never sell, rent, or trade your personal data to advertisers or data brokers. Your financial information is yours alone.

Data Sharing & Disclosure

We do not share your personal information except in the limited circumstances described below. All sharing is governed by strict data processing agreements.

Service Providers

We share data with trusted vendors who help us operate ExpenseAI — cloud hosting (e.g., AWS/Vercel), email delivery, and analytics. These providers are contractually bound to use your data only for the services they provide to us.

Cloud infrastructureEmail service providersError tracking tools

Legal Requirements

We may disclose your information when required by law, court order, or governmental authority, or when necessary to protect the rights, property, or safety of ExpenseAI, our users, or the public.

Court ordersRegulatory complianceLaw enforcement requests

Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the business. We will notify you before your data is subject to a different privacy policy.

Mergers & acquisitionsAsset sales

With Your Consent

We may share your data with third parties when you explicitly authorise us to do so — for example, when you use a third-party integration or share a folder report via public link.

Public folder sharingThird-party integrationsExport features

We Never Share With

  • Advertisers or ad networks
  • Data brokers or marketing firms
  • Social media platforms
  • Other ExpenseAI users (without your consent)
All third-party service providers are vetted for security compliance and are prohibited from using your data for their own purposes.

Data Retention

We retain your data only as long as necessary to provide services and comply with legal obligations. The retention periods below apply after account deletion unless otherwise stated.

Active Account Data(While your account is active)
Retained indefinitely
Transaction Records(For financial compliance)
5 years after deletion
Usage & Analytics(Anonymised after 12 months)
24 months
Communication Logs(Support tickets & emails)
12 months
Security Logs(Login & device activity)
90 days

Account Deletion

When you delete your account, we begin purging your personal data within 30 days. Some aggregate, anonymised analytics data may be retained indefinitely as it cannot identify you.

We may retain certain data longer if required by applicable law (e.g., the Information Technology Act, 2000 and its amendments) or to resolve pending disputes.

Your Rights & Choices

You have full control over your personal data. These rights are available to all ExpenseAI users regardless of location.

👁️

Access

Request a copy of all personal data we hold about you in a portable format.

Download from Profile → Settings → Export Data

✏️

Correction

Update or correct any inaccurate personal information we hold.

Edit in Profile → Personal Information

🗑️

Deletion

Request complete deletion of your account and associated personal data.

Profile → Account Management → Delete Account

📦

Portability

Export your financial data in CSV or JSON format at any time.

Dashboard → Export → Choose Format

🔕

Opt-Out

Unsubscribe from marketing emails and disable non-essential notifications.

Profile → Notifications → Preferences

🚫

Withdraw Consent

Withdraw consent for data processing where consent was the legal basis.

Contact us at support@expenseai.in

Response Time

We respond to all data rights requests within 30 days. Complex requests may take up to 60 days, in which case we will notify you of the extension.

If you are located in the European Economic Area (EEA), you also have the right to lodge a complaint with your local data protection authority. For Indian users, rights are governed under the Digital Personal Data Protection Act, 2023.

Cookies & Tracking Technologies

We use cookies and similar technologies to operate ExpenseAI, remember your preferences, and understand usage patterns. Here is a full breakdown:

Essential Cookies

Always Active

Authentication tokens, session management, CSRF protection. Required for the app to function.

auth_tokensession_idcsrf_token

Preference Cookies

Optional

Remember your settings like currency, theme preferences, and display options.

theme_prefcurrency_preflocale

Analytics Cookies

Optional

Understand how users interact with ExpenseAI to improve features and fix issues.

_gaanalytics_sessionfeature_flags

Security Cookies

Always Active

Detect and prevent fraudulent sessions, bot activity, and unauthorized access.

device_fingerprintrisk_score

Managing Cookies

You can control optional cookies through your browser settings. Note that disabling essential cookies will prevent you from logging in and using core features.

We do not use third-party advertising cookies. Our analytics are limited to first-party data to understand product usage. Local storage may also be used for performance caching.

Security Measures

We implement enterprise-grade security to keep your financial data safe. However, no system is 100% immune — we encourage you to use a strong password and enable all security features in your account.

AES-256 Encryption

All financial data is encrypted at rest using AES-256, the same standard used by banks.

TLS 1.3 in Transit

All data transmitted between your device and our servers is protected via TLS 1.3.

Multi-Device Session Control

Monitor all active sessions and remotely revoke access from any device at any time.

Anomaly Detection

Real-time monitoring detects suspicious logins or unusual activity and alerts you instantly.

Secure Password Hashing

Passwords are hashed using bcrypt with per-user salts — we never store plain-text passwords.

Regular Security Audits

We conduct periodic security reviews and vulnerability assessments to proactively address threats.

Report a Vulnerability

If you discover a security issue, please disclose it responsibly to support@expenseai.in. We take all reports seriously and aim to respond within 72 hours.

Contact Us

Have questions about this Privacy Policy or how we handle your data? We are here to help. Reach out through the appropriate channel below.

Prefer a contact form?

Use our website contact form for general privacy inquiries.

Contact Form

Registered Address: ExpenseAI, India. This Privacy Policy is effective as of April 12, 2026 and supersedes all prior versions. We reserve the right to update this policy — changes will be notified via email or an in-app banner.

© 2026 ExpenseAI. All rights reserved.

Privacy Policy — ExpenseAI | ExpenseAI