Privacy Policy

Your data stays on your device by default.

ExpensiFamily is built as a local-first app. In the current version, expense records are stored on your device unless you actively share information with support or choose to use Ask George.

Current version commitments

  • No account system and no cloud sync in the current release.
  • Expense records remain on your device unless you intentionally share details with support or use Ask George.
  • Support messages and attachments are used only to answer and resolve your request.
  • Support correspondence is normally deleted within 12 months after closure, unless longer retention is needed for legal or security reasons.
  • Ask George sends a limited set of recent expenses, optional budget targets, and an anonymous client ID to the ExpensiFamily server; the server may forward that data to OpenAI, the current external AI provider.
  • Ask George does not include expense or budget notes/descriptions, attached place metadata, or GPS metadata in the current version.
  • We do not sell personal data and we do not run advertising trackers on this site.
  • For privacy rights requests, contact support@expensifamily.com. We target a response within one month.
  • If cloud accounts, cloud sync, backups, or analytics are introduced, this notice will be updated before launch.

Current data model

The current release has no account system and no cloud sync. Expenses, categories, payees, budgets, notes, optional place metadata, and related timestamps are stored locally on your device.

What we process directly

Outside of on-device app storage, we process only what is needed to run this website, answer support requests, provide optional Ask George reports, and keep services secure.

Support and feedback

If you contact support, we process your email, message content, and any attachments you choose to send so we can respond and resolve issues.

Ask George

Ask George is optional. When you use it, the mobile app sends recent normalized expense data to the ExpensiFamily server. This can include local expense IDs, dates, amounts, currencies, categories, subcategories, payees, and recurring flags. If you have budgets, the app may also send budget targets such as category, amount, currency, and date range. The request also includes selected currency, locale, timezone, and a locally stored anonymous client ID. The server may forward the Ask George request data to OpenAI, the current external AI provider, to generate the report. The current data sent to Ask George does not include expense or budget notes/descriptions, attached place metadata, or GPS metadata, and the mobile app does not call OpenAI directly.

Sharing and tracking

Personal data is not sold. We do not use advertising trackers on this site.

Data portability

The app supports export formats for your records (JSON backup and CSV expense export), and import flows from supported sources.

GDPR notice (EEA/UK users)

This section provides the key information required by Articles 12 to 14 GDPR for current website and support processing activities.

Controller and scope

ExpensiFamily is operated by an independent individual developer (not a registered company at this stage), acting as controller for this website, support communications, and optional Ask George requests. Contact: support@expensifamily.com. The current version has no account system and no cloud sync; expense records remain on your device unless you actively share data with us or use Ask George.

Data categories and purposes

We process only data needed to operate the site, provide support, and maintain service security.

  • Contact and correspondence data you submit (such as email address and message content).
  • Files or screenshots you choose to attach to support requests.
  • Basic technical security/operational data (for example IP address, user agent, request metadata) processed by hosting and infrastructure providers.
  • If you use Ask George: recent normalized expense records, optional budget targets, selected currency, locale, timezone, and an anonymous client ID used for quota enforcement.
  • The current data sent to Ask George does not include expense or budget notes/descriptions, attached place metadata, or GPS metadata.

Legal bases (Article 6 GDPR)

Depending on the request, one or more legal bases apply.

  • Article 6(1)(b): contract steps or service delivery at your request.
  • Article 6(1)(f): legitimate interests (support operations, abuse prevention, service reliability).
  • Article 6(1)(c): compliance with legal obligations when required.
  • Article 6(1)(a): consent, where we specifically ask for it (you can withdraw at any time).

Recipients and international transfers

Data may be processed by service providers acting as processors (for example hosting, email, support tooling, and AI service providers for optional Ask George requests). OpenAI is the current external AI provider used by the server for Ask George. Where data is transferred outside the EEA/UK, transfers are based on approved safeguards (such as adequacy decisions or Standard Contractual Clauses with supplementary measures where required).

Retention

We keep personal data only for as long as necessary for the stated purposes, then delete or anonymize it. Retention depends on purpose, legal obligations, and security/dispute needs.

  • Support correspondence: targeted retention up to 12 months after closure, unless a longer period is required for legal or security reasons.
  • Security/operational logs: kept according to infrastructure provider retention settings and security requirements.

Your rights

You may request access, rectification, erasure, restriction, portability, or objection, and you may withdraw consent where processing is based on consent. To exercise rights, contact support@expensifamily.com. We may verify identity before fulfilling requests, and we target responding within one month.

Automated decision-making and children

We do not use personal data for solely automated decisions producing legal or similarly significant effects. The service is not directed to children under the age applicable in your jurisdiction for independent consent.

Complaints

You have the right to lodge a complaint with your local supervisory authority (Article 77 GDPR), without prejudice to any other administrative or judicial remedy.

If we add accounts, cloud sync, cloud backups, analytics, or materially change Ask George data handling, this notice will be updated before those changes are released.

Last updated: May 21, 2026