Data Privacy Policy v1.2

Privacy Policy

Effective Date: September 1, 2026 • Last Reviewed: September 2, 2026

1. Information We Collect

As a dedicated financial ledger platform, we collect only information that you explicitly submit or configure:

  • Account Credentials: Email address, hashed password credentials (stored using salted Argon2/bcrypt), and user profile name.
  • Financial Records: Transaction dates, payee/merchants, currency codes, debit/credit amounts, and custom category tags.
  • Supporting Documents: Receipt images and PDF attachments uploaded for automated OCR expense extraction.
  • Workspace Configurations: Budget targets, financial goal progress, and recurring transaction rules.

2. Zero Third-Party Sale Commitment

We do NOT sell, lease, or monetize your financial data to third-party advertisers, brokers, or external analytics firms.

Your financial records are collected exclusively to render your private dashboards, execute analytics computations, and generate personal financial reports.

3. Technical Subprocessors & Third-Party AI Services

To provide intelligent automation, secure authentication, and support ticketing, EXPENX integrates with authorized service providers:

  • Google Gemini API: When you use Ask Expendi, request AI financial insights, or upload receipt images for OCR extraction, relevant prompt context and images are transmitted via encrypted HTTPS to Google Gemini for real-time inference. Under standard enterprise API terms, this data is processed in-memory and not used to train public foundation models.
  • Google Identity Services: If you choose Continue with Google, your Google Account identifier and verified email are used to establish your session.
  • n8n Support Automation: When submitting concerns via our Support Desk, ticket metadata and descriptions are dispatched to our internal support automation workflow to deliver emails to support@expenx.virenesis.com.

4. Tenant Isolation & Cryptographic Security

All stored records are partitioned using strict Multi-Tenant Isolation boundaries in PostgreSQL. Financial records associated with one workspace cannot be queried or accessed by users belonging to another workspace.

5. User Control, Data Portability & Right to Erasure

You retain full ownership over your financial records:

• Export: You can download a complete JSON archive of all your accounts, transactions, and categories at any time from Settings > Privacy.

• Deletion: You can permanently wipe your entire account and all associated ledger records directly via the Danger Zone in your dashboard settings.

6. Privacy Contact & Inquiries

For data protection questions or inquiries, contact our team at:
support@expenx.virenesis.com