1. Introduction
Welcome to Spend by RevExOS ("Spend," "we," "our," or "us"). We are committed to protecting your privacy and your financial data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Telegram bot and web dashboard for expense tracking.
By using Spend, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect the following types of information:
2.1 Telegram Data
- Telegram user ID and username
- Messages you send to our bot (expense entries)
- Images you send (receipts, invoices)
- Chat interaction timestamps
2.2 Expense Data
- Expense amounts and currencies
- Merchant names and categories
- Transaction dates and descriptions
- Receipt and invoice images
- Extracted data from receipts (items, totals, vendor info)
2.3 Account Information
- Email address (if provided for web dashboard access)
- Preferred currency and settings
- Subscription status
2.4 Automatically Collected Data
- Device information when accessing the web dashboard
- IP address and browser type
- Usage analytics (pages visited, features used)
3. How We Use Your Information
We use your information to:
- Process and categorize your expense entries
- Extract data from receipt and invoice images using AI
- Provide spending analytics and insights
- Display your expense history in the web dashboard
- Send you expense summaries and notifications via Telegram
- Process subscription payments
- Improve our AI models for better expense categorization
- Respond to your support requests
- Detect and prevent fraud or abuse
4. Data Security
We take the security of your financial data seriously and implement robust security measures:
- Encryption at Rest: All stored data, including expense records and receipt images, is encrypted using industry-standard AES-256 encryption
- Encryption in Transit: All data transmitted between your device, Telegram, and our servers uses TLS 1.3 encryption
- Secure Infrastructure: Our servers are hosted on secure cloud infrastructure with regular security audits
- Access Controls: Strict access controls ensure only authorized personnel can access system infrastructure
- Regular Backups: Your data is regularly backed up with encrypted backups stored securely
5. Data Sharing and Disclosure
We do not sell your personal or financial data. Ever.
We may share your information only in the following limited circumstances:
- Service Providers: We use trusted third-party services for payment processing (e.g., Stripe), cloud hosting, and AI processing. These providers are bound by strict data protection agreements.
- Legal Requirements: We may disclose your information if required by law, court order, or government request.
- Business Transfers: In the event of a merger, acquisition, or sale, your data may be transferred. We will notify you before your data is subject to a different privacy policy.
- With Your Consent: We may share information with your explicit consent.
6. AI and Receipt Processing
When you send receipt or invoice images, our AI processes them to extract relevant information:
- Images are processed securely and encrypted during transmission
- Extracted data is stored with your expense records
- Original images may be stored for your reference (Pro plan)
- We do not use your receipt images to train AI models without explicit consent
- You can request deletion of stored images at any time
7. Data Retention
We retain your data as follows:
- Active Accounts: Your expense data is retained for as long as your account is active
- Deleted Accounts: Upon account deletion request, we delete your data within 30 days, except where retention is required by law
- Financial Records: Some financial records may be retained for up to 7 years to comply with tax and legal requirements
- Backups: Deleted data may persist in encrypted backups for up to 90 days
8. Your Rights
You have the following rights regarding your data:
- Access: Request a copy of all your stored data
- Export: Export your expense data in CSV or PDF format
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and all associated data
- Restriction: Request restriction of certain data processing
- Portability: Receive your data in a portable format
To exercise these rights, contact us at privacy@revexos.com or use the /delete command in the Telegram bot.
9. Telegram Integration
Spend operates as a Telegram bot. Please note:
- We only receive messages you send directly to our bot (@spendntypebot)
- We cannot access your other Telegram chats or contacts
- Telegram's own privacy policy also applies to your use of Telegram
- You can stop using Spend at any time by blocking the bot
10. Children's Privacy
Spend is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
11. International Data Transfers
Your data may be processed and stored in countries outside your country of residence. We ensure appropriate safeguards are in place for any international transfers, including standard contractual clauses where required.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Sending a message through the Telegram bot
- Posting a notice on our website
- Updating the "Last updated" date at the top of this page
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us: