ExpenseAI Privacy Policy

Last updated: September 27, 2026

ExpenseAI is an expense logging app. You log an expense by saying it out loud, typing one line, or snapping a receipt. We designed ExpenseAI to work without an account and to keep your data on your device.

Data We Collect

ExpenseAI minimizes data collection. By default, everything you log never leaves your device.

Data We Do Not Collect

Permissions

All permissions can be revoked at any time in iOS Settings › ExpenseAI.

Third-Party AI Services

Cloud AI is optional and off by default. Requests travel directly from your device to the provider you select; ExpenseAI's developer does not receive their contents or responses.

OpenAI

Destination: api.openai.com

Data sent and how: Text you type, on-device voice transcription, or on-device receipt OCR text, together with your category names and today's date, plus your OpenAI API key as request authentication. Sent only after you select OpenAI and tap “Agree & Use OpenAI.” If you later choose “Send receipt image” and accept its separate disclosure, a compressed JPEG copy of each receipt you select — including anything visible such as merchant, amount, date, address, or payment details — is sent instead of OCR text.

Use: Process the submitted text and return an expense draft. See OpenAI's API privacy information.

Alibaba Cloud Model Studio (Qwen/DashScope)

Destination: dashscope.aliyuncs.com

Data sent and how: Text you type, on-device voice transcription, or on-device receipt OCR text, together with your category names and today's date, plus your Alibaba Cloud API key as request authentication. Sent only after you select Qwen and tap “Agree & Use Qwen.” If you later choose “Send receipt image” and accept its separate disclosure, a compressed JPEG copy of each receipt you select — including anything visible such as merchant, amount, date, address, or payment details — is sent instead of OCR text.

Use: Process the submitted text and return an expense draft. See Alibaba Cloud's Privacy Policy.

The selected provider processes these requests under the agreement and privacy terms associated with the API key you supply. These providers state that they apply technical and organizational safeguards to customer data. We require every third party with which ExpenseAI shares user data to provide the same or equivalent protection described in this policy and required by applicable App Store guidelines.

You can stop future receipt-image sharing by changing Receipt reading back to On-device text; enabling image sharing again requires fresh permission. You can stop all cloud sharing by choosing Revoke under Cloud AI permission. ExpenseAI immediately returns to Apple Intelligence and requires fresh permission before any cloud provider can be used again. You can also clear an API key in Settings. Requests already processed by a provider are subject to that provider's retention and deletion terms and controls; use the links above or your provider account to manage them.

Data Sharing

We do not sell your data or use it for advertising or cross-app tracking. Expense text is shared with OpenAI or Alibaba Cloud only when you explicitly enable that provider. A compressed receipt image is shared only when you grant the additional image permission described above. ExpenseAI also sends the first-launch analytics event and More Apps request described above; those requests go to services operated for the developer and are not used for third-party advertising or cross-app tracking.

Data Retention & Deletion

Your expenses, photos, and settings remain on your device until you delete them in the app or uninstall ExpenseAI. Uninstalling the app removes local data, so we recommend using the CSV export in Settings to move your ledger to a new phone. Cloud AI requests are retained or deleted by the provider under the terms associated with your API account; ExpenseAI's developer does not receive or retain those requests. We retain first-launch analytics and standard server logs only as long as reasonably necessary for aggregate app analytics, security, and service operation. To ask about deletion of developer-held data, contact us using the address below; because ExpenseAI has no account, we may need information such as your IDFV to identify a record.

Children's Privacy

ExpenseAI is not directed to children under 13, and we do not knowingly collect data from children.

Changes to This Policy

If we make changes, we will update this page with a new "Last updated" date.

Contact

For privacy questions, contact: hswillg@gmail.com

Terms of Use