Expense Lens

Privacy Policy

Last updated: July 27, 2026

What we collect

Only what it takes to run the app — but that is more than it was a year ago, so here it is in full:

  • Account data — email address, display name, and which sign-in methods you use (password, Google, Sign in with Apple, passkey). If you turn on two-factor authentication we store the secret needed to verify your codes.
  • Expense data — receipt images, amounts, merchants, categories, tags, dates, currencies, notes, projects and budgets.
  • Mileage data — trip start, destination and distance, and on iPhone the GPS track of a recorded trip.
  • Voice audioiPhone only, and only while you have deliberately started a voice session with the hands-free assistant: the microphone audio you speak, and the text transcripts of both sides of that conversation. The microphone is off at every other moment, and iOS asks for your permission before it is ever used. The audio is streamed live to our AI provider rather than recorded — we do not write it, or the transcript, to our database or storage.
  • Content from services you connect — if you connect Google Drive or Gmail, the files and messages we read from the folder and label you choose. If you use an inbound receipt address, the whole email that arrives: sender, subject, body and attachments.
  • Chat messages — what you ask the assistant, plus the expense records assembled to answer it.
  • Billing data — plan, subscription status and history. Card numbers go to Stripe or Apple and never reach us.
  • Technical data — the server and error logs produced while handling your requests (IP address, timestamp, user agent), plus AI extraction results and any correction you make to them, which we keep to measure accuracy.
  • Usage data — pageview analytics on this marketing site (Google Analytics 4 via Google Tag Manager), and, only if you accept the consent prompt inside the app, in-app analytics (also Google Analytics 4). Decline it and no analytics storage is used in the app.

Why we collect it

  • To provide and improve the expense tracking service
  • To power AI receipt extraction, categorization and the chat assistant
  • To calculate budgets, analytics, forecasts and recurring-charge detection (plain arithmetic on your own data)
  • To send transactional email, budget alerts, the weekly digest and scheduled reports
  • To generate reports and exports for you, and to push expenses to accounting software you connect
  • To process payments via Stripe on the web and Apple in-app purchase on iPhone (we never see or store your card number)
  • To keep accounts secure — two-factor authentication, passkeys, abuse and error investigation

Where your data is stored

Plainly, because it matters and we have not said it before: your data is stored in the United States, while the servers that process it run in the European Union.

  • Database (Firestore) — Google Cloud nam5, United States multi-region
  • Receipt images (Cloud Storage)US-CENTRAL1, United States
  • Application servers and background jobseurope-west1, Belgium

Several of the processors listed below are US companies, or process data in the US regardless of where it is stored: Google (including the Gemini API), xAI, Apple (including Apple Maps), Stripe, Resend — and Intuit or Dropbox if you connect them.

Google, Stripe, Intuit, Dropbox and Resend are certified under the EU-U.S. Data Privacy Framework. xAI and Apple are not certified under it, and the safeguard that applies to those two transfers is still being confirmed.

AI processing

Expense Lens uses third-party AI models to read receipts, answer questions and — on iPhone — talk with you. That means content leaves our servers:

  • Receipt images — sent to Google Gemini for extraction. If that call fails, to xAI. PDFs take the same path.
  • Emails forwarded to an inbound receipt address — the message body is sent to Google Gemini, with xAI as fallback.
  • Chat assistantboth providers receive chat content, and they receive different things. Every message goes first to Google Gemini to work out what you asked, carrying your question, the last few turns of the conversation, your category and project names, and up to 30 of your recent merchants with their descriptions. The answer is then written by xAI, which additionally receives the amounts behind the answer. What that contains depends on what you asked: for an expense look-up it is the totals, a per-category breakdown, your top merchants and, when the result set is 15 expenses or fewer, the individual expense lines (merchant, amount, currency). Other kinds of question assemble a different summary. If xAI is unavailable, Gemini writes the answer instead — and in that case it receives that same amount-level context, not just the intent-parsing context above.
  • Voice assistant (iPhone only) — when you start a hands-free session, your microphone audio is streamed live from your iPhone straight to xAI, along with the transcripts xAI produces of what you and the assistant said. The audio does not pass through our servers: all we do is mint a five-minute token that lets your phone open the connection, so our own API key never leaves our infrastructure. We never write the audio or the transcript to our database or storage; the transcript you see on screen is held in memory only, kept to the last 60 lines, and cleared when you start your next session. During the session the assistant can act on your data, within a fixed and deliberately narrow set of mileage actions: start and stop live GPS trip tracking, save the trip it just recorded as a mileage expense, log a trip that already happened from two addresses and a date, and look up an address to confirm with you (that lookup goes to Apple Maps, not to xAI). Saving a trip does write a mileage expense to your account — that is the point of the feature, and it is the same record you would get by filling the form in yourself. The result of each action is sent back to xAI over the same connection, so the assistant can read it out and carry on the conversation. That means xAI also receives the trip's distance and duration, the resolved start and end addresses, the amount and currency of a trip it saved, and — for an address lookup — the candidate addresses together with their latitude and longitude. It cannot read, change or delete your receipts, your other expenses, your budgets or your account settings.

We name providers rather than specific model versions: the exact model is a deployment setting and changes without a code release. Categorization and tagging happen inside the same extraction call — no extra transfer. Budgets, analytics, forecasts and recurring detection are ordinary arithmetic on your own data: no model is involved and nothing is sent anywhere.

Both providers state in their API terms that content submitted through the API is not used to train their models — Google under the paid-tier Gemini API terms that apply to us, and xAI under its API terms, under which API inputs and outputs are deleted within 30 days. We are still confirming that the realtime voice connection is covered by those same terms.

Who can access your data

  • Other users see only a project you deliberately shared with them, as an editor or a viewer.
  • Receipt images have no public URLs. They are served through an authenticated proxy.
  • Expense Lens is a hosted service. Our server-side code runs with administrative access to the database by design, and the people who operate the service can reach that infrastructure to run, debug and support it. We do not browse your expenses, sell your data or use it for advertising — but we are not going to claim it is technically impossible for us to read it.
  • AI extraction results and the corrections you make to them are logged so we can measure and improve accuracy.

What we don't do

  • We never sell your data to third parties
  • We never use your expense data for advertising
  • We don't require bank account connections
  • We don't track you across other websites
  • We don't record your screen or session

Third-party services

Everyone who touches your data, and what each one receives.

ServiceWhat it receives
Google Firebase / Google CloudAuthentication, database, storage, server functions and push delivery — all account and expense data, and your receipt images
Google Gemini APIReceipt images, forwarded email bodies, and every chat message — with recent conversation turns, your category and project names, and up to 30 recent merchants with their descriptions. If xAI is unavailable, also the amounts and expense lines
xAIChat messages plus the matching amounts, category breakdown, top merchants and — for result sets of 15 or fewer — individual expense lines. Also the same receipt images and forwarded email bodies as the extraction fallback, whenever the Gemini call fails. And, on iPhone, the live microphone audio of a voice session — streamed direct from your phone, not through us — plus the transcripts of both sides and the result of every action the assistant takes, which is sent back over the same connection: the trip's distance and duration, the resolved start and end addresses, the amount and currency of a trip it saved, and candidate addresses with their latitude and longitude. In that session the assistant can start and stop GPS trip tracking, save the recorded trip as a mileage expense, log a past trip, and look up an address; it reaches nothing else in your account
Resend (outbound)Recipient address and content of transactional email, budget alerts, the weekly digest and scheduled reports, including attachments
Resend (inbound)The full contents of every email forwarded to an inbound receipt address — sender, subject, body and attachments
StripeEmail, name, payment method, billing address and subscription history. Card numbers go to Stripe directly and never reach us
AppleiOS purchase and subscription lifecycle, Sign in with Apple identity, push notification delivery
Open Exchange RatesDates and currency codes only — no amounts, no identifiers
Google Maps Platform (web)On the web only: mileage start and end coordinates, the addresses you type into the trip form, and the map shown on a mileage expense. The iPhone app does not call Google for any of this — see the row below
Apple Maps / MapKit (iPhone)On iPhone the whole mileage map stack is Apple's, not Google's: the address text you type into the trip form — sent as you type, to power autocomplete — the suggestion you then pick, the start and end coordinates sent to work out the driving route, and the first and last coordinates of a recorded trip, which are reverse-geocoded into a city and country. The trip map itself is drawn from Apple's map tiles. The voice assistant's address lookup goes through the same service
Google Tag Manager / GA4Pageviews and events on this marketing site, and the same in the app if you accept the in-app consent prompt
Intuit QuickBooksExpenses you push to a company you have connected — including the receipt image itself, uploaded to Intuit and attached to the record
DropboxScheduled report files. The app only uploads; it makes no calls that read your Dropbox
Google Drive / GmailThe files and messages you ask the app to read from the folder and label you choose, and report files written back to Drive

Connecting Google Drive and Gmail uses a single Google authorization covering drive.readonly, drive.file, gmail.readonly and gmail.labels. Two are read-only but broad — Google grants read access to your entire Drive and entire mailbox, even though the app only ever reads the one folder and the one label you selected. The other two allow limited writes: files the app itself creates, and label management. You can revoke the grant at any time in your Google account settings. The tokens behind every connection you authorize — Google, Dropbox and QuickBooks — are stored encrypted at rest, in server-only storage.

Data retention and deletion

  • Account data — kept while your account is active
  • Receipt images — kept until you delete the expense or your account

Deleting your account (Settings → Delete Account) runs immediately, not on a 30-day timer, and it is thorough. It removes your expenses and pending expenses, categories, projects, report schedules, AI accuracy logs, project invitations, merchant rules, your subscription entitlement record, every third-party integration token (Google, Dropbox, QuickBooks and the sync records that go with them), your WebAuthn tokens and any waitlist entry. It then recursively deletes your user document, which takes your two-factor secret, passkey credentials, mileage trips, notifications, recurring-expense records and push tokens with it. Your receipt images and pending uploads are removed from storage, and your login is deleted. There is no undo.

What stays behind is deliberately non-personal: a shared exchange-rate cache keyed by date, a payment-webhook ledger keyed by provider event id (clearing it would let a replayed webhook reprocess), date-keyed markers recording that a scheduled job ran, and hashed 24-hour throttle counters for unknown inbound senders. None of it identifies you.

Billing history is a separate matter. Stripe is the payment processor and the system of record for your invoices and payments, and retains them under its own legal obligations; we delete our derived copy. Ask Stripe, or us, for what they hold.

One narrow gap, stated plainly: files staged temporarily while importing from Google Drive or Gmail are deleted once the import succeeds, and deleting your account now sweeps that staging area too — but a failed or abandoned import can leave a staged file sitting there until your account is deleted. Email hello@expense-lens.com and we will clear it sooner.

Your rights

You can at any time:

  • Unsubscribe from emails (link in every email)
  • Export your data — CSV, XLSX and PDF of your expenses on the web, or PDF, Excel, CSV and a full export from the iPhone app, plus a Download my data button in Settings → Privacy on the web that hands you a CSV of your expenses
  • Correct anything the AI or you got wrong, directly in the app
  • Delete your account from Settings → Delete Account
  • Request a copy, correction or deletion of your data by email
  • Complain to your local data protection authority

For any privacy request, email hello@expense-lens.com.

Cookies and analytics

Google Tag Manager and GA4 run on this marketing site. On the home page they load only after you accept the cookie banner — decline there and they never run. On every other page of this site, including this one, they currently load as soon as the page opens, before you have been asked. That is a gap rather than a design choice, and closing it is tracked as issue #18. Until it is closed, assume analytics loads on arrival anywhere except the home page.

Inside the app, cookies are used for authentication. In-app analytics (GA4) is consent-gated: analytics storage is denied by default, and GA4 loads only if you accept the consent prompt in the app. The separate product-analytics service we used to run in the app has been removed entirely. We do not use advertising cookies anywhere, and we do not use a third-party error-monitoring service.

Changes

If we make significant changes to this policy, we'll notify you by email. Minor clarifications may be made without notice.