This Privacy Policy explains how Expentomy ("we", "us", "our") collects, uses, and protects your information when you use our personal finance scheduling service at expentomy.com. Please read this carefully.
1. Information We Collect
1.1 Information You Provide
- Account information — name, email address, password (stored as a one-way Argon2ID hash; never in plaintext)
- Financial data — account names, types, balances, expenses, income items, debt information, and repayment schedules you manually enter
- Billing information — your selected plan and billing cycle. Payment card details are processed directly by Stripe and never stored on our servers
- Support communications — emails you send to our support team
1.2 Information Collected Automatically
- Log data — IP address, browser type, pages visited, timestamps
- Session data — authentication tokens stored in secure HttpOnly cookies
1.3 Bank Account Data (Plaid — Pro & Family Plans Only)
If you choose to connect a bank account via Plaid:
- We receive and store your account balances from linked institutions
- We do NOT receive or store your bank login credentials — entered directly into Plaid's secure interface
- We do NOT receive or store full account numbers or routing numbers
- Plaid access tokens are encrypted with AES-256-GCM before storage — never stored in plaintext
Bank account connection is optional and can be revoked at any time from your account settings. Your use of Plaid is also subject to Plaid's Privacy Policy.
2. How We Use Your Information
- Provide, operate, and improve the Service
- Authenticate your identity and maintain account security
- Process subscription payments via Stripe
- Sync bank account balances via Plaid (if enabled)
- Send transactional emails: 2FA codes, email verification, password resets, receipts, payment failure notices
- Send balance alert emails when your balance deviates from your schedule (Pro/Family, if enabled)
- Respond to support requests
- Detect and prevent fraud and security incidents
- Comply with legal obligations
We do not use your financial data to serve ads. We do not sell your personal information. We do not use your data to train AI or machine learning models.
3. How We Share Your Information
We do not sell or rent your personal information. We share data only with the following trusted service providers:
We may also disclose information when required by law, court order, or government authority. We will notify you of such requests where legally permitted.
4. Data Security
- All data in transit encrypted with TLS/HTTPS
- Passwords hashed with Argon2ID — irrecoverable even by us
- Plaid tokens encrypted with AES-256-GCM before database storage
- Two-factor authentication (2FA) enabled by default
- Login lockout after 5 failed attempts
- HttpOnly, Secure, SameSite=Strict session cookies
- All admin actions logged in an immutable audit trail
If you believe your account has been compromised, contact security@expentomy.com immediately.
5. Data Retention
We keep your spending history for as long as your account is active — intentionally longer than most banks make it visible in online banking — so you can look back across your transactions and itemized receipts over time. You remain in control: you can export or delete individual transactions, individual receipts, or your entire history at any time, and everything is permanently purged when you close your account.
- Account data — retained while active and for 90 days after deletion
- Transaction & receipt history — retained for the life of your active account so your spending history stays available to you; you can export or delete any of it at any time
- Financial data — permanently deleted within 30 days of account closure
- Billing records — retained for 7 years (tax compliance)
- Audit logs — retained for 2 years
6. Data Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Notify affected users by email within 72 hours of confirming the breach
- Describe the nature of the breach and what data was affected
- Explain what steps we are taking to address the breach and prevent recurrence
- Provide guidance on steps you can take to protect yourself
- Report to relevant authorities as required by applicable state and federal law
7. Your Rights & Choices
You have the right to:
- Access — request a copy of the personal information we hold about you
- Correct — update inaccurate or incomplete information
- Delete — request deletion of your account and associated data
- Export — download your data in CSV format directly from the Service
- Restrict processing — request that we limit how we use your data
- Withdraw consent — revoke consent for optional processing (e.g., bank sync, balance alerts) at any time via your account settings. Withdrawal does not affect the lawfulness of prior processing
To exercise these rights, contact privacy@expentomy.com. We will respond within 30 days for general requests and within 45 days for CCPA requests, as required by law.
8. California Privacy Rights (CCPA)
California residents have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To submit a CCPA request, email privacy@expentomy.com with subject line "CCPA Request." We will respond within 45 days.
9. International Users
The Service is operated in the United States and is intended for users located in the United States. We do not currently target or market to users in the European Union or European Economic Area. If you access the Service from outside the United States, you do so at your own initiative and are responsible for compliance with local laws. By using the Service, you consent to your information being transferred to and processed in the United States.
10. Children's Privacy
The Service is not directed to children under 18. We do not knowingly collect information from children. If you believe a child has provided us with personal information, contact privacy@expentomy.com and we will delete it promptly.
11. Cookies
We use a single session cookie (EXPENTOMY_SESSION) to maintain your authenticated session. It is HttpOnly, Secure, SameSite=Strict, and expires after 2 hours of inactivity. We do not use advertising cookies, analytics cookies, or third-party tracking.
12. Legal Basis for Processing
We process your personal information on the following legal bases:
- Contract performance — to provide the Service you subscribed to (account management, schedule generation, billing)
- Legitimate interest — to maintain security, prevent fraud, and improve the Service
- Consent — for optional features like bank account sync and balance alerts (revocable at any time)
- Legal obligation — to comply with tax, financial, and regulatory requirements
13. Sub-Processors
Our service providers (Stripe, Plaid, Postmark, DreamHost) may use their own sub-processors to deliver their services. Their use of sub-processors is governed by their respective privacy policies linked in Section 3 above.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by email at least 30 days before material changes take effect.
15. Contact Us
Questions about this Privacy Policy? Contact us at: