Privacy Policy

Last updated: August 2026
SpendLens is private by default.

SpendLens ("the App") is built on a simple principle: your finances are nobody's business but yours. This policy explains what information the App handles and — crucially — what it does not.

Summary in one paragraph

SpendLens has no accounts, no analytics, and no ads. Everything you enter stays on your iPhone — and in your own private iCloud container. One optional feature — Smart Parsing — sends message text for processing, and is described in full below. It is off until you turn it on; when it is off, nothing you enter is sent anywhere by SpendLens except to your own iCloud. Because Smart Parsing can transmit transaction text when enabled, SpendLens declares this in its App Store privacy label rather than claiming "Data Not Collected."

Data storage

All data you enter into SpendLens — expenses, categories, notes, receipt images — is stored locally on your device using Apple's Core Data framework. The data lives inside the App's secure sandbox managed by iOS and is encrypted at rest by the operating system.

If you use Smart Parsing, captured items are stored the same way. So that you can see what a transaction came from and correct a bad parse, SpendLens keeps the original text of each captured message — the SMS body, or the text read from a screenshot — alongside the transaction it produced, on your device and in your private iCloud container. You can delete any captured item, or wipe everything, from within the App.

Data we do not collect

SpendLens does not collect, transmit, or store any of the following:

iCloud sync

When you are signed in to iCloud, your expense data syncs across your Apple devices using Apple's CloudKit framework. This data is stored in your private iCloud container — the same one that backs apps like Reminders and Notes. SpendLens has no access to this data. It is encrypted in transit and at rest by Apple, and if you switch on Apple's Advanced Data Protection, it becomes end-to-end encrypted so that not even Apple can read it.

Sync is controlled by iOS, not by us. You can stop it at any time in iOS Settings → [your name] → iCloud → Apps Using iCloud, or by signing out of iCloud. Doing so does not delete your local data. Removing the App from a device removes its local data on that device.

Camera access (optional)

SpendLens Pro includes an optional receipt scanning feature that uses your iPhone's camera. Camera access is only requested the first time you tap "Scan receipt" and is shown via the standard iOS permission prompt. All text recognition happens on-device using Apple's Vision framework — no images are uploaded or transmitted anywhere. The captured receipt image is stored only inside the linked expense in your local database. You can revoke camera access at any time via iOS Settings → Privacy → Camera.

Currency exchange rates

SpendLens fetches currency exchange rates through our own endpoint, which sources them from ExchangeRate-API. The rate table is refreshed once a day and cached, so the App works offline against the last rates it fetched. These requests ask for a list of currency rates only — they carry no expense data, no user data, no device identifiers, and no tracking information. The rate provider never sees anything about you or your spending.

In-app purchases

SpendLens uses Apple's StoreKit framework for one-time Pro unlocks and optional tip purchases. All payment processing is handled entirely by Apple under Apple's privacy policy. SpendLens never receives or stores your payment details, full name, or billing address.

Notifications

SpendLens uses local notifications for the recurring expense reminders you set up, and to let you know when a captured transaction is waiting for review. These notifications are scheduled and delivered entirely on your device and do not involve any external push notification server. No notification data leaves your device.

Siri, Shortcuts & App Intents

SpendLens exposes App Intents to Siri and the Shortcuts app so you can voice-log expenses or check totals. When you use Siri, voice processing follows Apple's Siri privacy practices. SpendLens itself only receives the parsed parameters (e.g. amount, currency, merchant) and creates the expense locally on your device.

Smart Parsing — bank SMS and screenshots (optional, off by default)

Smart Parsing is the one feature in SpendLens that uses the internet to process your content. It is opt-in and disabled until you turn it on.

How it works. You create a Personal Automation in Apple's Shortcuts app that fires when a message arrives from a sender you choose. The Shortcut passes the message text to SpendLens through a published App Intent. SpendLens sends that text to our processing endpoint, which forwards it to Google's Gemini model to extract the amount, merchant, date, and currency. The structured result comes back and the transaction appears in your Expenses timeline for one-tap approval.

Screenshots work the same way. If your bank sends push notifications instead of SMS, you can share a screenshot to SpendLens. The image is read on your device using Apple's Vision framework, and only the extracted text is sent for parsing — the image itself never leaves your iPhone, and it is deleted as soon as the text has been read.

What we do with that text. We keep none of it. Our processing endpoint is stateless — it holds the message only long enough to return a result, and it never writes message content to a log or a database. Your text is not used to train any AI model.

What goes with the request. No account, no name, no device identifier, and no location — SpendLens has none of those to send. The request is authenticated with an app-level token shared by all copies of the App, not tied to you or your Apple ID. As with any web request, your IP address is visible to our endpoint; we use it only to rate-limit abuse, and we do not log it against your messages or build any profile from it.

Sub-processors for this feature. Cloudflare (request routing) and Google Cloud (Gemini via Vertex AI). Each receives the message text in order to produce a parse result, and handles it under its own privacy terms — neither is given any information about who you are.

iOS never gives any app direct access to your SMS, and SpendLens does not read your messages. Only the specific messages your automation forwards are ever processed. You can turn Smart Parsing off, or delete the automation in Shortcuts, at any time — and when it is off (the default), no message text is sent anywhere. Manual entry never touches the network.

Your consent. Smart Parsing is processed on the basis of your explicit consent, given by turning it on and withdrawable at any time by turning it off in Settings → Auto-Capture from SMS.

Children's privacy

SpendLens is not directed at children under 13 and does not knowingly collect any data from children. SpendLens has no accounts and gathers no personal information from any user, so there is nothing for us to hold about a child.

Third-party services

These are all of the third parties involved in running SpendLens:

Cloudflare and Google Cloud are the only parties that ever receive transaction text, and only when Smart Parsing is enabled.

SpendLens uses no advertising SDKs, no analytics SDKs, no crash reporters linked to your identity, and no third-party trackers of any kind.

Your rights

Because SpendLens does not collect or store any personal data on our side, traditional data-subject rights (access, deletion, portability) are exercised directly within the App: you control your data 100%. You can:

Changes to this policy

We may update this privacy policy if the App's functionality changes. Any updates will be reflected on this page with a new "Last updated" date. If a change materially affects how your data is handled, we will say so plainly rather than quietly editing the page.

Contact

If you have questions about this privacy policy, write to businessforzeeshan@gmail.com. We are a solo developer team and respond to every email personally.

The short version: Your spending stays on your device. The only thing that can ever leave is the text of a bank message you choose to capture — and only if you turn on Smart Parsing, only for as long as it takes to pull out the amount and merchant. We never log it, never store it, never sell it, and it is never used to train a model.