spendklaroLast updated 29 September 2026
This notice describes how spendklaro handles personal information in the current product. It reflects present behaviour in the software, not a certification, audit, or legal opinion. It has not been reviewed by counsel. A complete privacy policy addressing applicable law, including the GDPR and the CCPA where they apply, will be published before a public launch.
spendklaro is a personal finance application. You upload account statements; we parse them, store analysed transactions against your account, and show insights, budgets, goals, and activity so you can understand your spending. We act as the controller of personal information processed in a spendklaro instance that we operate.
We collect the following categories of information:
We do not collect payment card numbers as a payment processor, and we do not connect directly to your bank. You choose which files to upload.
We process personal information only to:
We do not sell personal information. We do not use your financial information for advertising. We do not share it with other spendklaro users. We do not send statement contents to third-party analytics, advertising, or AI services. Parsing and categorisation run on the application server that hosts your spendklaro instance. Original statement files, when kept, are stored with a cloud object-storage provider as described below.
If you set a spending cap, we store the label, monthly amount, and optional category you choose so we can compare it with your analysed expenses for the month, quarter, or year you are viewing, and so we can show progress on Overview and Budgets, and related cards on Insights. If a cap is over, or on pace to go over that stretch, we also show a notice on Overview and Budgets.
Caps are stored with your account. We do not use them for advertising or share them with other users. You can change or remove a cap at any time on Budgets. Removing a cap stops that comparison going forward and does not delete transactions. Account deletion removes caps with the rest of your data.
If you set a goal, we store the kind (save a monthly amount, or spend less in a category than the previous stretch), the amount or percent you choose, and the optional category, so we can compare it with your analysed income and expenses for the period you are viewing, and so we can show progress on Overview and Budgets, and related cards on Insights.
Goals are stored with your account. We do not use them for advertising or share them with other users. You can change or remove a goal at any time on Budgets. Removing a goal stops that comparison going forward and does not delete transactions. Account deletion removes goals with the rest of your data.
When you open Overview, we calculate a score for the month, quarter, or year you are viewing. The score uses analysed pay, spending, bank fees, and the gap between payday and must-pay bills. If you have set spending caps or goals, those comparisons are included. Parts we cannot measure from the file are left out of the average.
We calculate the score for display. We do not store it as a separate record. We do not use it for advertising or share it with other users. Days of cover in the score are estimated from the uploaded file, with the running balance starting at zero for that period. They are not your bank’s official balance.
There is no setting to turn the score off. You can change or remove caps and goals at any time on Budgets, which changes those parts of the score. Deleting a statement or your account removes the transactions the score uses. While those statements remain, opening Overview calculates the score again.
When you open Overview or Insights, we compare the charges in the month, quarter, or year you are viewing with the other transactions in your uploaded statements. We look for a charge that is much larger than your usual amount at that place, a merchant name that has not appeared in an earlier month, and a week where spending is faster than usual.
We calculate these notes for display. We do not store them as a separate record. We do not use them for advertising or share them with other users. They are a comparison inside your own file, not a fraud alert from your bank.
There is no setting to turn these notes off. Deleting a statement or your account removes the transactions the comparison uses. While those statements remain, opening Overview or Insights calculates the notes again.
Account and financial records are stored in a database associated with your user account. Access in the product is scoped to the signed-in account. Original statement files are stored in a private object-storage bucket under object keys scoped to your account, unless you turn that off in Settings. Objects are not published at a public URL; spendklaro reads and deletes them only from the application server. Passwords are stored as one-way hashes, not in plain text. Passkey public keys are stored with your account and cannot be used to reconstruct a biometric.
When you create an account, we keep the original statement file after it has been parsed so we can re-process it later. Files are stored in private cloud object storage (an S3-compatible bucket), not in the application database. This setting is on for every account, including accounts created before this became the default, unless you turn it off. We also tell you this when you register, on Overview before your first upload, and on Upload.
You can change this at any time in Settings by checking or unchecking “Keep original statement files after parsing”. That change is saved immediately. Unchecking deletes stored original files, and we do not keep new ones. We keep the file checksum described above so a later upload of the same file updates the existing statement. Turning this off does not undo parsing that already occurred; analysed transactions remain until you delete the statement, the retention period removes it, or you delete your account. You may turn the setting back on at any time; that applies to files you upload after you turn it on.
While original files are kept, we may re-read them when we change how statements are parsed, so analysed records stay consistent. We do not send statement files to third-party analytics, advertising, AI, or OCR services. The object-storage provider processes the file bytes only to store, retrieve, and delete them on our instructions.
You may set how long we keep analysed statements in Settings (between 30 and 3,650 days; the default is 365). The period is measured from the date we stored the statement (the upload), not from the dates printed on the transactions inside it.
When that period is saved, and when you use the product while signed in, we delete statements older than the period you chose. Deleting a statement removes its analysed transactions, parse history, and any stored original file for that statement. This cannot be undone. Shortening the period can remove existing statements as soon as the new period is saved. Lengthening the period does not restore statements that were already deleted.
We apply this period when you use spendklaro, including when you change it in Settings. The new period is saved when you finish editing the number. We do not currently run a separate deletion job while you are signed out. You can change this setting at any time. You can also delete an individual statement or delete your account.
We use cookies that are necessary to keep you signed in and to protect your session. These are required for the service to function. Signing out ends your session. We do not use advertising cookies.
When you use spendklaro on our hosted deployment, we collect anonymized page views and basic navigation events, and we collect performance measurements such as load times and Core Web Vitals. We process this through Vercel Analytics and Vercel Speed Insights so we can operate the site and improve speed and reliability.
Those tools receive URLs and technical data about your browser and device. They do not receive statement contents, transaction details, or other financial information from your account. We do not sell this usage or performance data. There is no separate opt-out in Settings; if you do not want this collection, do not use the hosted website.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
If you choose to sign in with Google, Google processes your sign-in under Google’s own privacy policy. We use the account details Google returns only to authenticate you. You can stop using Google sign-in by signing out. To remove the information we hold, delete your account in Settings. Managing connected apps in your Google account is described by Google.
When you register with email, or when you ask us to send another verification link, we send your email address and that link to an email delivery provider so it can deliver the message. We use that provider only to send the verification email. We do not use it for marketing. Until that provider is configured, a local development server shows the link in the app instead of sending it.
The systems that host spendklaro necessarily store the information described in this notice in order to run the product. That includes the application host, the database host, and a cloud object-storage provider for original statement files (when you keep them). Those providers process information only to store it and operate the service. We do not use them for advertising or for analytics of your financial information.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. You can exercise the access, correction, export, deletion, and consent-withdrawal controls described above in the product, principally in Settings and Activity.
Withdrawing consent does not affect processing that was lawful before withdrawal. Account deletion is irreversible.
This section describes rights commonly recognised under data protection law. It does not mean spendklaro has completed a GDPR, CCPA, or similar compliance programme, and it is not legal advice.
spendklaro is not directed at children under 16, and we do not knowingly collect personal information from children. If you believe a child has created an account, delete it in Settings or contact us as described below.
We will revise this notice when our practices change. The date at the top of this page is the effective date of the current version.
You can exercise the controls in this notice in Settings after you sign in. A dedicated privacy contact address will be published before public launch. Use of spendklaro is also described in our Terms.