Privacy Policy
This policy explains how Spendly handles personal data when you visit the website, create an account, connect providers, or contact support.
Last updated: 22 July 20261. Who is responsible for your data
Spendly is operated by Denis Efremov, a self-employed service provider established in Portugal. For privacy questions or requests, email mail [at] denisefremov.com. Full operator details are available on the Legal page.
2. Scope and roles
Spendly acts as a data controller for account administration, security, support, website operation, and billing records. When a business customer adds employees, provider accounts, projects, or AI usage records, Spendly generally processes that information on the customer's instructions. The customer remains responsible for having an appropriate legal basis to provide that information.
3. Data we process
- Account data: email address, authentication identifiers, display name, language, and workspace role.
- Business workspace data: company settings, employees, teams, projects, budgets, alerts, and preferences.
- Provider data: provider account identifiers, encrypted credentials supplied by the customer, usage records, transactions, model names, quantities, currencies, costs, and synchronisation status.
- Technical and security data: request metadata, timestamps, rate-limit records, error logs, security events, and essential session cookies.
- Support data: messages and information you choose to send when requesting help.
- Billing data: subscription status, customer and transaction identifiers, invoices, and tax information when paid plans are activated. Payment card details are handled by the payment provider, not stored by Spendly.
4. Why we process data
| Purpose | Legal basis |
|---|---|
| Provide accounts, dashboards, synchronisation, reports, budgets, and support | Performance of a contract |
| Protect accounts, prevent abuse, diagnose failures, and maintain service reliability | Legitimate interests in operating a secure service |
| Issue invoices and retain required accounting records | Legal obligation and performance of a contract |
| Send essential service and security messages | Performance of a contract and legitimate interests |
| Use optional analytics or marketing technologies | Consent — none are currently active |
5. Service providers and recipients
Data may be shared only where needed to operate Spendly, including:
- Supabase for authentication and managed database services;
- Cloudflare for DNS, security, and encrypted traffic delivery;
- Google when you choose Google authentication;
- AI service providers when you ask Spendly to connect to and synchronise a provider account;
- Stripe and PayPal when paid subscriptions are activated and you choose to pay through them;
- professional advisers or authorities where required by law or necessary to establish or defend legal claims.
Spendly does not sell personal data.
6. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism. Customers should also review the transfer terms of each AI provider they connect.
7. Retention
- Account and workspace data is kept while the account is active and for a limited period needed for recovery, security, or dispute handling after closure.
- Provider credentials are retained until the connection or workspace is deleted.
- Operational and security logs are kept only as long as reasonably needed for security and diagnostics.
- Invoices and tax records are retained for the period required by Portuguese law.
- Support correspondence is kept while the request is active and afterwards where reasonably required to document its resolution.
8. Security
Spendly uses access controls, row-level database security, encryption in transit, restricted administrative access, and encrypted storage for provider credentials. No online service can promise absolute security, so customers should use unique passwords, limit provider-key permissions, and remove unused connections.
9. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may withdraw consent where processing relies on consent. Send a request to mail [at] denisefremov.com. Identity verification may be required before a request is completed.
You may also complain to Portugal's supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD).
10. Cookies, children, and changes
Spendly currently uses only essential cookies and local storage. See the Cookie Policy. Spendly is a business service and is not intended for children. Material changes to this policy will be announced in the service or by email where appropriate.