Last updated: June 23, 2026 ยท We take your privacy seriously
Your privacy is fundamental to Xpenvo. This app exists to help you manage your finances โ not to profit from your data. This Policy explains exactly what we collect, why, and how we protect it. It applies to all users worldwide and covers every feature of the Xpenvo web and mobile application. By using Xpenvo you agree to the practices described here.
Account Information: When you create an account we collect your name, email address, and a hashed (never plain-text) password. We also store your subscription plan, onboarding status, and any referral or affiliate code you used to sign up.
Financial Data: All financial information you enter โ transactions (amount, title, category, date, notes, type), budgets, savings goals, debts, subscriptions, wallets, invoices, bill calendar entries, and custom categories โ is stored securely in your account and is used only to provide the Xpenvo service to you.
AI Interaction Data: Your messages to Zara and her responses are stored as your chat history. Usage counts (AI actions per day, receipt scans per day) are logged to enforce plan limits. We log which features you use (chat, context buttons, reports, insights) but never the content for any purpose other than providing the service.
Automatically Collected Data: When you use the app we collect your IP address and country code (for geo-detection), your browser user-agent (for login security alerts), error and diagnostic data via Sentry (linked to an anonymised user ID), and session activity timestamps processed in-memory on your device only for the 30-minute automatic logout feature โ this activity data is never transmitted to our servers.
Future Financial Features: Xpenvo may expand its financial tools over time (e.g. tax tracking, investment tracking, additional wallet types). Any new categories of personal data collected by future features will be processed under the same principles described in this Policy. We will notify you of any material changes before they take effect.
To Provide the Service: Your financial data powers your dashboards, budgets, goals tracking, reports, health score, cash flow, net worth, and every other feature of the app. We cannot provide these features without processing this data.
To Power AI Features: Your data and chat messages are sent to Anthropic's Claude API to generate Zara's personalised coaching responses, proactive insights, AI reports, and web-search results (Pro). See Section 4 for full detail.
To Authenticate You and Secure Your Account: Your email and user-agent are used to detect suspicious logins and send you security alerts. Sessions expire after 30 minutes of inactivity to protect your financial data.
To Enforce Plan Limits and Manage Subscriptions: We track daily AI action counts and receipt scan counts per user to enforce Free, Beta, and Pro plan limits. Subscription status is updated via webhook events from Dodo Payments.
To Prevent Fraud and Abuse: We use anonymised device characteristics to detect fraudulent use of our affiliate programme. We do not use these signals to track you across other apps or websites.
To Improve the Service: We analyse aggregated, anonymised usage patterns (never your personal financial data) to understand which features are used and to improve them. We use Sentry error reports (anonymised) to fix bugs.
To Communicate With You: We send transactional emails (account changes, security alerts, subscription events) and push notifications you have opted into. We do not send marketing emails without your explicit consent.
How Zara Works: When you send a message to Zara or trigger an AI feature, the relevant text and a summary of your financial context (spending totals, budget status, goal progress) are sent over an encrypted connection to Anthropic's Claude API. The response is returned to you and stored in your chat history.
Receipt Scanner: When you scan a receipt, the image is converted to an encrypted data string on your device and transmitted to our backend, which forwards it to Anthropic's API for extraction. The extracted fields (merchant, amount, date, category) are returned and stored as a transaction. The raw image is never stored on Xpenvo's servers.
Voice Input: Voice-to-text is processed entirely by your device's built-in browser or OS speech recognition engine. Only the resulting text transcript is sent to our servers โ raw audio is never transmitted or stored by Xpenvo.
Automated Decisions: We do not make fully automated decisions that have legal or significant financial effects on you. All AI outputs are informational and require your own review and action.
Anthropic's Data Handling: As of the effective date of this Policy, Anthropic does not use API customer data to train their models without explicit consent. Anthropic's privacy policy applies to the processing of your data by their API: anthropic.com/privacy.
Camera: The Receipt Scanner requests camera access only when you activate the scan feature. Camera permission is used solely for capturing receipt images. You may deny camera permission and use the file-upload alternative instead. Camera access is never used to capture images in the background.
Microphone: Voice input features request microphone access only when you tap the voice button. Speech processing occurs on your device. Xpenvo does not record, store, or transmit raw audio at any time. You may deny microphone access without affecting any other feature of the app.
These permissions can be revoked at any time through your browser or device settings.
Encryption in Transit: All data between your device and our servers is encrypted using TLS 1.3 โ the same standard used by major financial institutions.
Encryption at Rest: Your data is stored on Supabase infrastructure which applies AES-256 encryption at rest across all storage layers.
Row-Level Security: Supabase Row Level Security (RLS) policies are enforced at the database level, ensuring that your data is cryptographically inaccessible to other users โ even in the event of application-level errors.
Password Security: Passwords are hashed using bcrypt by Supabase Auth and are never stored in plain text. Xpenvo staff cannot read your password.
Session Security: Sessions expire after 30 minutes of inactivity. Login security alerts are sent to your registered email on new sign-ins. API keys and secrets are stored as server-side environment variables and are never exposed in client-side code.
Breach Notification: In the event of a data breach likely to risk your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law โ within 72 hours for GDPR-covered incidents.
We do not sell, rent, or trade your personal or financial data to any third party. We share data only with the providers listed below, each bound by a data processing agreement:
Supabase (Database & Auth): All your account and financial data is stored on Supabase's infrastructure (hosted on AWS). Supabase is SOC 2 Type II certified. Privacy: supabase.com/privacy
Anthropic (AI Processing): Your chat messages and financial context are processed by Anthropic's Claude API to generate Zara's responses. Privacy: anthropic.com/privacy
Dodo Payments (Billing): When you subscribe to a paid plan, your email is passed to Dodo Payments to create a checkout session. We do not store or handle your payment card details โ these are handled exclusively by Dodo Payments. Privacy: dodopayments.com/privacy
Sentry (Error Monitoring): Crash and error reports including an anonymised user ID and technical diagnostic data are sent to Sentry to help us fix bugs. Sentry is SOC 2 Type II certified. Privacy: sentry.io/privacy
Cloudflare (CDN & Infrastructure): All traffic passes through Cloudflare's global network for DDoS protection, performance, and geo-detection (country code via IP). Privacy: cloudflare.com/privacypolicy
Push Notification Services: Push notifications are delivered via Google Firebase Cloud Messaging (Android) and Apple Push Notification Service (iOS/Web). We transmit your notification subscription token to these services only to deliver the notifications you have opted into.
Subscriptions are processed securely by Dodo Payments. When you initiate a purchase you are redirected to a Dodo Payments-hosted checkout page. Xpenvo never receives, stores, or processes your payment card number, bank details, or other payment credentials.
Dodo Payments notifies Xpenvo of subscription events (activation, renewal, cancellation, expiry) via digitally signed webhooks. We verify the cryptographic signature of every webhook before updating your account.
Your Dodo Payments customer ID and subscription ID are stored in your Xpenvo account solely to manage your subscription status.
Essential Only: We use your browser's localStorage to cache your profile (for faster loading) and to store your Supabase authentication session. A session preference (xpenvo_visited) is stored to determine your entry screen on repeat visits.
No Advertising Cookies: We do not use advertising cookies, third-party tracking pixels, or any cookies for behavioural advertising โ ever.
Service Worker: Our Progressive Web App uses a service worker and browser cache to enable offline access to the app shell. This data is stored locally on your device.
You can clear cookies and local storage at any time through your browser or device settings. Clearing auth storage will sign you out.
Xpenvo is a global service. Your data is stored and processed by our providers' infrastructure, which may be located in the United States, European Union, or other countries.
For EEA & UK users: Where data is transferred outside the EEA or UK to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) or the UK IDTA approved by the relevant authorities. You may request a copy of these safeguards by emailing [email protected].
For users in Ghana, Nigeria, South Africa, and other jurisdictions: We take reasonable steps to ensure that international transfers comply with your local data protection law, including the Ghana Data Protection Act 2012, Nigeria's NDPA 2023, and South Africa's POPIA.
Account & Financial Data: Retained for the duration of your account. After account deletion, personal data is permanently removed within 30 days. Anonymised aggregated data (not linked to you) may be retained for service improvement.
AI Chat History: Retained for 2 years from each message date, then automatically deleted.
AI Usage & Action Logs: Retained for 13 months for usage tracking and billing verification.
Error Reports (Sentry): Retained for 90 days.
Push Notification Tokens: Retained until you revoke notification permission or delete your account.
Backup Copies: System backups may persist for up to 90 days before being fully purged from all backup storage.
All Users: You may access, correct, or export your financial data directly from the app. You may delete your account and all associated data from Settings โ deletion is permanent and takes effect within 30 days.
EEA, UK & Swiss Users (GDPR / UK GDPR): You have the rights to access, rectify, erase, restrict, and port your personal data, and to object to processing. You may also withdraw consent at any time. To exercise these rights contact us at [email protected] โ we will respond within 30 days. You also have the right to lodge a complaint with your national Data Protection Authority.
California Users (CCPA / CPRA): You have the right to know, delete, and correct personal information, and to opt out of the sale or sharing of personal information (we do not sell or share it). Contact us with "California Privacy Rights" in the subject line.
Ghana, Nigeria, South Africa, Canada, Australia & Other Jurisdictions: You have equivalent rights under your applicable local law including the Ghana DPA 2012, NDPA 2023, POPIA, PIPEDA, and the Australian Privacy Act. Contact [email protected] to exercise these rights.
We will respond to all verifiable data rights requests within 30 days (or as required by applicable law).
Xpenvo requires users to be at least 16 years old. In the United States, users aged 13โ15 may use the service with verifiable parental consent in compliance with COPPA. In some EU member states the minimum age may be higher than 16.
We do not knowingly collect personal information from children below the applicable minimum age. If you are a parent or guardian and believe your child has created an account, please contact us immediately at [email protected] and we will delete the account and all associated data promptly.
Xpenvo operates a SaaS affiliate programme that allows participants to earn commissions by referring new paying subscribers. If you participate in the affiliate programme, we collect and store your affiliate identifier, your linked Xpenvo account (if applicable), referral click and conversion data, and payout information required to process commission payments.
Affiliate tracking uses privacy-respecting link parameters and anonymised conversion signals. We do not track affiliate referrals using persistent cross-site cookies. Affiliate data is retained for the duration of the affiliate relationship and for a reasonable period thereafter for audit and payout purposes.
The affiliate programme is governed by a separate Affiliate Programme Agreement. Participation is voluntary.
We may update this Privacy Policy as the service evolves, to reflect new features, changes in law, or changes in how we operate. When we make material changes we will notify you via email to your registered address or via an in-app notice at least 14 days before the changes take effect.
The "Last updated" date at the top of this page always reflects the most recent revision. Your continued use of Xpenvo after the effective date of the revised Policy constitutes your acceptance of the changes.
For questions about this Policy or to exercise any of your rights, contact us at [email protected].
Global Compliance: This Policy is written to comply with GDPR (EU/UK), CCPA/CPRA (California), COPPA (USA), PIPEDA (Canada), Privacy Act 1988 (Australia), Ghana Data Protection Act 2012, NDPA 2023 (Nigeria), POPIA (South Africa), and other applicable data protection laws. To exercise your rights under any of these laws, contact us at [email protected].