Last updated: 26 July 2026
This policy covers spendly.app (this website) and live.spendly.app (the Spendly app). Spendly is operated by Telora Labs.
We’ve written this in plain language. Where something is a limitation rather than a feature, we’ve said so rather than burying it.
What we collect
When you create an account: your email address, and optionally your first and last name. That’s the whole account record — there is no phone number, date of birth, address or demographic profile.
What you put into Spendly: the financial information you choose to enter — accounts, balances, transactions, categories, budgets, goals, debts, investments and their values. This is the substance of the product. You decide what goes in; we don’t acquire it from anywhere else.
Authentication data: a bcrypt hash of your password (never the password itself), and if you enable them, your encrypted two-factor secret and backup codes, or your registered passkey credentials.
Sign-in attempts: we log the IP address and username used for sign-in attempts, successful and failed, in order to detect and block brute-force attacks. These records are retained for a limited period and used only for that purpose.
Technical data: standard server logs, and error reports when something breaks.
What we don’t collect
- We don’t buy, enrich, or import data about you from third parties.
- We don’t build advertising profiles, and we don’t run advertising.
- We don’t sell your data. There is no arrangement under which any third party receives your financial data for their own purposes.
- We don’t track you across other websites.
Analytics on this website
This marketing site uses Umami, a self-hosted, cookieless analytics tool running on our own infrastructure. It records aggregate page views and referrers. It does not set cookies, does not use device fingerprinting, and does not follow you to other sites. No data goes to a third-party advertising network.
We previously used Google Analytics on this site and have removed it.
Who processes your data
We use a small number of third-party providers (“subprocessors”) to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, storage | AWS regions |
| Amazon SES | Sending transactional email (password resets, weekly summaries) | us-east-1 (United States) |
| Sentry | Error and exception monitoring | Sentry infrastructure |
Transactional email is sent via AWS SES in the United States, which means email content — for example a password reset link, or a weekly summary of your spending totals — is processed in the US. If you are in the UK or EU, this is an international transfer and we rely on the relevant standard contractual safeguards.
Sentry receives error reports, which can incidentally include technical context about a failing request. We do not deliberately send financial data to Sentry.
How long we keep it
While your account is open, we keep your data so the product works.
When you delete your account, we immediately revoke every active session and remove your access. Your records are then marked as deleted.
Records are then purged on our normal retention cycle, and backups age out on theirs. If you need confirmed immediate erasure rather than deletion and revocation, email [email protected] and we’ll carry it out and confirm.
Your rights
If you’re in the UK or EEA, the UK GDPR / EU GDPR give you the right to:
- Access the personal data we hold about you
- Correct anything inaccurate
- Delete your data
- Export your data in a portable format
- Object to or restrict certain processing
- Complain to your data protection authority
Two of these you can exercise yourself, immediately, without asking us:
- Export — Settings → export, in the app. Produces CSV files of your accounts, budgets, categories, investments and transactions.
- Deletion — Settings → account.
For anything else, email [email protected] and we’ll respond within the statutory period.
Export scope: the CSV export covers accounts, budgets, categories, investments and transactions. For savings goals, sinking funds, envelopes, commitments and debts, ask us and we’ll extract them for you.
Legal basis for processing
- Performance of a contract — to provide the service you signed up for
- Legitimate interests — securing the service against attack, monitoring errors, and aggregate analytics
- Consent — for optional email such as the weekly summary, which you can unsubscribe from at any time
Cookies
The app sets one essential cookie: your authentication session. It is httpOnly, Secure and SameSite=Strict. It exists solely to keep you signed in, and there is no way to use an authenticated product without it.
This marketing website sets no tracking cookies.
Children
Spendly is not directed at children under 16, and we don’t knowingly collect their data. If you believe a child has created an account, contact us and we’ll remove it.
Changes
If we make a material change to this policy, we’ll update the date at the top and, where the change actually affects you, tell account holders by email rather than relying on you to re-read this page.
Contact
Questions, requests, or complaints: [email protected]
Security vulnerabilities: [email protected]