This Privacy Policy explains how BanyanTree Consulting LLC ("we", "us", or "ExpenseLogify") collects, uses, shares, and protects the personal information of users of the ExpenseLogify application and website (collectively, the "Service"). It also describes your legal rights and how to exercise them.
1. Who we are
ExpenseLogify is operated by BanyanTree Consulting LLC, a company incorporated in the United States. In this policy, "we", "us", and "our" refer to BanyanTree Consulting LLC. If you are located in the European Economic Area (EEA), the UK, or California, additional rights apply as described in Section 9.
2. Information we collect
We collect only the data you provide, plus a minimal amount required to operate the Service:
Account information
- Email address (used as your account identifier and for authentication)
- Display name
- Encrypted password (hashed with bcrypt; we never see or store the plaintext)
- Optional profile: home address, family composition (adults / children counts)
Financial & behavioral data (that you enter)
- Transactions: amount, category, date, description, retailer, quantity, source (manual, receipt scan, voice, email)
- Budgets, goals, and recurring transaction templates you set up
- Receipt images you upload (compressed to WebP and stored as base64 in the database)
- Voice recordings you submit for AI transcription (used transiently — see Section 5)
- Item mappings you create for the smart shopping list
Technical & session data
- IP address (captured at login for security alerting; not shared with third parties)
- User-Agent string (parsed into device / browser / OS labels for the sessions panel)
- Session timestamps: creation, last-active, expiration
- Usage logs: which features you used and when (e.g., "receipt_scan called at 12:03") — used for admin analytics and rate limiting
What we do NOT collect
- We do not collect bank account, card, or payment information.
- We do not track you across other websites.
- We do not use advertising cookies or third-party analytics trackers.
- We do not require or verify your legal name; you can use an alias.
3. How we use your information
We use the information above solely to:
- Provide and operate the Service (dashboard, reports, budgets, shopping list, etc.)
- Authenticate you and detect suspicious sign-ins
- Generate personalized financial insights via the AI Financial Coach (see Section 5)
- Convert receipts and voice into transactions using AI (see Section 5)
- Enforce security limits (e.g., login rate limiting, expensive-endpoint quotas)
- Communicate with you about your account (support, security alerts if any, policy updates)
We do not use your data to train third-party AI models, target ads, or profile you for marketing.
4. Legal basis for processing (GDPR)
If you are in the EEA or UK, our legal bases under Article 6 GDPR are:
- Contract (Art. 6(1)(b)): to provide the Service you signed up for
- Legitimate interests (Art. 6(1)(f)): to keep the Service secure and prevent abuse
- Consent (Art. 6(1)(a)): for optional features you explicitly enable (e.g., voice transcription, receipt scanning, AI coaching)
5. Third-party AI processing
ExpenseLogify offers three AI-powered features. Enabling any of them causes the specific data listed below to be transmitted to a third-party AI service for processing. You control whether to use these features.
| Feature | Provider | What is sent | Purpose |
|---|---|---|---|
| Voice transcription | OpenAI (Whisper API), via Emergent LLM proxy | The raw audio blob you record | Convert speech → text so we can parse it into a transaction |
| Receipt scanning | Google (Gemini 2.5 Flash), via Emergent LLM proxy | The compressed receipt image | Extract line items, retailer, date, total, and category suggestions |
| Financial Coach & item-name suggestions | Google (Gemini 2.5 Flash), via Emergent LLM proxy | Aggregated, non-identifying financial summary: first name only, monthly income/expense totals, category breakdowns, budget vs. actual, top retailers by spend | Generate personalized money advice; suggest clean product names from cryptic receipt descriptions |
How these providers handle your data
Per our contract with Emergent Labs (our LLM proxy provider), requests are relayed to OpenAI and Google under their standard API terms, which prohibit training on customer data by default:
- OpenAI: API inputs and outputs are not used to train OpenAI models (see OpenAI API Data Usage Policies).
- Google (Gemini API): Content sent through the paid Gemini API is not used to improve Google's models (see Gemini API Additional Terms of Service).
Both providers may retain request data briefly for abuse monitoring per their public policies. We do not authorize any secondary use.
Opting out
You can use ExpenseLogify entirely without invoking any AI features by entering transactions manually. The AI features are opt-in per use — clicking "Scan receipt", "Record voice", or "Refresh coach" is the point of consent.
6. Data storage & security
- Your data is stored in a managed MongoDB database with encryption at rest.
- All traffic between your device and our servers is encrypted with TLS 1.2+.
- Passwords are hashed with bcrypt (cost factor 12).
- Sessions use short-lived JWTs (24-hour expiry) and can be individually revoked from the profile "Security & Active Sessions" panel.
- We rate-limit login attempts (10/5min/email, 30/5min/IP) and expensive AI endpoints to prevent abuse.
- Search inputs are escaped against ReDoS / NoSQL injection.
- CSV exports are sanitized against formula-injection attacks.
- The application applies standard security response headers: X-Content-Type-Options, X-Frame-Options: DENY, Referrer-Policy, Permissions-Policy, and HSTS.
7. Data retention
We retain your account and financial data for as long as your account is active. If you delete your account, we permanently erase all of your data across every database collection within a reasonable technical window (typically immediately; never more than 30 days including automated backup rotation). Aggregate, anonymized statistics used for internal capacity planning may be retained indefinitely because they contain no personal information.
Rate-limit records auto-purge after 1 hour. Session records auto-purge on expiry (24 hours from creation).
8. Data sharing & sales
We do not sell your personal information and have never done so, as defined by the California Consumer Privacy Act (CCPA) and similar laws. We share data only with:
- The AI providers listed in Section 5, and only for the AI features you invoke
- Our infrastructure provider (Emergent Labs) for hosting and platform services
- Legal authorities when required by valid legal process (subpoena, court order); we notify you unless legally prohibited
9. Your rights (GDPR / CCPA)
Regardless of your location, we voluntarily extend the following rights to every user:
- Right to access & portability: Download a complete JSON export of every piece of data we store about you. Available in-app at Profile → Privacy & Your Data → Download.
- Right to erasure ("right to be forgotten"): Permanently delete your account and all associated data. Available in-app at Profile → Privacy & Your Data → Delete…. Requires password + typed confirmation. Effect is immediate and irreversible.
- Right to rectification: Edit or update any incorrect data directly in the app.
- Right to restrict / object to processing: Simply stop using AI features to restrict processing; delete your account to fully object.
- Right to withdraw consent: AI features are consent-per-use. Stop using them to withdraw consent going forward.
- Right to lodge a complaint: EEA/UK users may complain to their local Data Protection Authority. California users may contact the California Attorney General's Office.
We respond to written requests (see Section 13) within 30 days as required by law.
10. International data transfers
ExpenseLogify is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to, processed, and stored in the U.S. Where personal data of EEA/UK users is transferred, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission with our sub-processors.
11. Children's privacy
ExpenseLogify is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us personal data, please contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top and, for material changes, notify you via the in-app interface or by email. Continued use of the Service after a change constitutes acceptance of the revised policy.
13. Contact us
For questions about this policy, or to exercise any of the rights above, contact:
BanyanTree Consulting LLC
Attn: Privacy Officer
Email: privacy@expenselogify.com
This document is provided for informational purposes and does not constitute legal advice. If you need a policy tailored to a specific jurisdiction (e.g., additional state-specific disclosures for Virginia, Colorado, or Texas privacy statutes), please consult qualified legal counsel.