Spendella
Русская версия Home
Legal

Privacy Policy

What we collect, why, who else touches it, where it lives and what you can do about it.

Effective 17 September 2026
Contents
1. Who we are 2. What we collect 3. Why, and on what legal basis 4. AI features and your data 5. Who we share data with 6. Where data is processed 7. Shared budgets 8. How long we keep data 9. Security 10. Your rights 11. Cookies 12. Age limit 13. Changes 14. Contact

This Privacy Policy explains how Spendella (spendella.com and the Spendella apps) collects, uses and protects your personal data. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR and Russian Federal Law 152-FZ on personal data. If you are in Russia, the Russian version is the binding text; this English version is provided for everyone else and for convenience.

Section 1

Who we are

The data controller is Maksim Andreevich Pokhilchuk, a sole proprietor registered in the Russian Federation (INN 744885116877, OGRNIP 324745600190376), based in the Chelyabinsk Region, Russia. In this Policy we say "we" and "Spendella".

For any question about your data, write to info@spendella.com. This is also the address for exercising the rights described in section 10.

This Policy covers the website spendella.com, the web app and the Spendella app for Android, in every edition we publish: the build from our website, and the builds distributed through RuStore, AppGallery and Google Play.

Section 2

What we collect

When you sign up:

  • A name or nickname
  • Your email address
  • Your password, stored only as a cryptographic hash
  • If you sign in with Yandex ID, VK ID, HUAWEI ID or Google: the name and email address you allow that provider to share. We do not receive your contacts, friends or anything else from those accounts

Financial data you enter yourself:

Every financial figure in Spendella comes from you. We do not connect to your bank and we never see your card number, account number or online banking credentials.

  • Amounts of income and expenses, their dates and descriptions
  • Names of accounts, categories and transactions
  • Budgets, goals, loans, subscriptions and cashback rules

Files, photos and voice you send for recognition:

  • Bank statements you import (CSV, Excel, PDF or a screenshot). Card and account numbers, phone numbers and balances are removed from the lines before anything is sent for recognition
  • Photos of receipts, payment screenshots and screenshots of your bank's cashback screen
  • Voice entries. The recording is sent for speech recognition and is not kept; what we keep is the recognised text as your transaction
  • Messages you type to the AI assistant

Device notifications (Android only, optional, off by default):

If you turn on automatic entry from bank notifications, the app reads notifications only from the apps you pick in the settings and sends the payment lines to our server to create a draft transaction for you to confirm. The original notification text is not stored. You can turn this off at any time in the app or in Android settings.

Technical data:

  • IP address
  • Browser type, operating system, device model and app version
  • Date and time of requests to the Service
  • Session history, so you can see and end active sessions
  • A push token and an installation identifier, so notifications can reach your device
  • Cookie data (see section 11)
  • Crash and error reports, collected on our own server

Payments: the amount, purpose and status of each payment, and the email address the receipt goes to. Card details are entered on the payment provider's page and never reach our servers.

Shared budgets: when you invite someone, we receive their email address. Until they accept, it is used only to send the invitation.

Support: the type and subject of your request and the messages we exchange. Subjects and messages are stored encrypted on our servers and are not passed to any AI provider.

App lock: the four-digit code is stored only on your device. If you enable fingerprint or face unlock, the biometric check is done by your phone's operating system; the app only learns whether it passed. No biometric data ever reaches us.

What we do not collect: your full legal name, home address, phone number, identity documents, precise or approximate location, your contacts, other apps installed on your device, an advertising identifier, or card and bank account details.

Section 3

Why we use your data, and on what legal basis

Under the GDPR every use of personal data needs a legal basis. Here is what we do and why we are allowed to.

Purpose What it involves Legal basis
Providing the ServiceAccounts, transactions, budgets, goals, loans, subscriptions, analytics and everything else you signed up forPerformance of a contract, Art. 6(1)(b)
Sign-in and securityAuthentication, two-factor codes, session history, fraud and abuse preventionContract, Art. 6(1)(b); our legitimate interest in keeping the Service secure, Art. 6(1)(f)
AI featuresAutomatic categorisation, insights, reports, the assistant, voice entry, receipt and statement recognition (see section 4)Contract, Art. 6(1)(b). We also record your consent the first time you use an AI feature
Payments and tax receiptsTaking payment for a plan or a pack of AI operations, issuing the receipt the law requires, keeping payment recordsContract, Art. 6(1)(b); legal obligation under Russian tax law, Art. 6(1)(c)
NotificationsBudget overruns, goals reached, reports, security alerts. Each event and channel can be switched off in the settingsContract for service notifications, Art. 6(1)(b); your consent for optional channels such as Telegram, Art. 6(1)(a)
SupportAnswering your requests, and a copy to your email if you asked for oneContract, Art. 6(1)(b)
Usage analyticsUnderstanding which features are used, so we can improve them (Yandex Metrica on the website, AppMetrica in the app)Your consent, Art. 6(1)(a). Without it no analytics runs
Improving the ServiceAnalysis of anonymised, aggregated figuresLegitimate interests, Art. 6(1)(f)
Legal requestsResponding to a court order or a lawful request from a public authorityLegal obligation, Art. 6(1)(c)

We do not use your data for advertising, we do not build advertising profiles and we do not sell personal data to anyone.

Section 4

AI features and your data

All AI features run on Yandex Foundation Models, Yandex SpeechKit and Yandex Vision OCR (Yandex LLC, Russia, INN 7736207543), on servers in Russia. Yandex is the only AI provider we use and it processes data on our instructions only.

What is sent to the AI provider:

  • Amounts and descriptions of transactions, names of categories and accounts
  • Aggregate figures, such as total income and spending for a period
  • Receipt photos and screenshots, for recognition
  • Voice recordings, for speech recognition
  • Statement lines during import, after card numbers, account numbers, phone numbers and balances have been removed
  • Messages you send to the assistant, including a first pass that works out whether the message is a question, an entry or a request for a summary

Free and Basic plans: these plans include no AI operations, so nothing is sent to the AI provider, with two exceptions: a one-off reading of your answers during the initial setup, and the trial period, during which the full feature set is available.

Automated decisions. Categories, insights and suggestions are produced automatically, but none of them has a legal effect on you or anything similarly significant: they are suggestions about your own figures, you can change any category and ignore any suggestion, and no decision about you is taken on that basis. We do not profile you for advertising.

Section 5

Who we share data with

We do not sell personal data and we do not share it for anyone else's marketing. To run the Service we rely on the providers below. Each one receives only what its job needs.

Provider What for What it receives
Yandex Foundation Models, SpeechKit, Vision OCR (Yandex LLC, Russia)All AI featuresSee section 4
Robokassa (ROBOKASSA LLC, Russia, INN 5047063929)Payments on the website and in the Android app downloaded from our site; it also issues the tax receipt for each paymentAmount and purpose of the payment, your email address for the receipt. Card details are entered on Robokassa's page and never reach us
YooKassa (YooMoney LLC, Russia)Payments made earlier and payment methods already saved thereSame as above
RuStore (VK LLC, Russia)In-app purchases and push notifications in the RuStore editionPurchase token; device push token
Huawei (Huawei Services (Hong Kong) Co., Limited; Aspiegel SE, Ireland, for the EU)HUAWEI ID sign-in, in-app purchases and push notifications in the AppGallery editionName and email you allow HUAWEI ID to share; purchase token; device push token
Google (Google LLC, USA)Google sign-in, Google Play billing and Firebase Cloud Messaging in the Google Play editionName and email you allow Google to share; purchase token; device push token
Yandex ID and VK ID (Yandex LLC and VK LLC, Russia)Sign-in for users in RussiaName and email you allow to share
AppMetrica (Yandex LLC, Russia)Usage analytics in the Android app, only after your consent at sign-upAnonymous usage events, device model, OS version, screen size, network type, an installation identifier. No advertising identifier, no location
Yandex Metrica (Yandex LLC, Russia)Website analytics, only after you accept cookiesPage views and interactions on the website
Telegram Messenger Inc.Notifications in Telegram, only if you connect it yourselfThe text of the notifications you chose to receive
Timeweb (Russia)Email deliveryYour email address and the content of the email
AdminVPS (Russia)HostingAll Service data is stored on servers in Moscow, Russia

Country detection at sign-in involves no third party. To show the sign-in options that work in your region, the Service looks up the country of your IP address in a database stored on our own server. The IP address is not sent anywhere, not stored and not logged for this purpose. We use the IP to Country Lite database by DB-IP, licensed under CC BY 4.0.

We may disclose data to public authorities where the law obliges us to, for example under a court order or a lawful request from a competent authority.

Section 6

Where your data is processed

Our servers, our database and our AI provider are in the Russian Federation. Whatever country you use Spendella from, your data is stored and processed in Russia.

If you are in the EU, the EEA, the UK or Switzerland, please read this carefully. Russia is not covered by an adequacy decision of the European Commission or the UK government, which means your data does not enjoy the same legal protection there that it has at home, and Russian public authorities may be able to access data on grounds that differ from those in your country. By creating an account you transfer your data to Russia yourself, and we rely on your explicit consent to that transfer (Art. 49(1)(a) GDPR), given when you accept this Policy at sign-up. You can withdraw it at any time by deleting your account; withdrawal does not affect processing that already took place.

Some of the providers listed in section 5 are outside Russia: Huawei (Hong Kong, and Ireland for EU users), Google (USA) and Telegram. They process the small amount of data described there under their own terms and safeguards, and only for the edition of the app you actually use.

We have no representative in the EU or the UK. Contact us directly at info@spendella.com.

Section 7

Shared budgets

  • The owner of a shared budget enters the email address of the person they invite. Until the invitation is accepted, the address is used only to send it
  • By accepting an invitation, a participant agrees to this Policy
  • Participants see each other's transactions in the shared budget. Accepting the invitation means agreeing to that
  • An export of a shared budget includes the transactions of all its participants
  • When a participant deletes their account, their membership ends. Transactions they created in the shared budget stay, without an author. When the owner deletes their account, the shared budget is deleted entirely

If you enter someone else's data, for example an email address in an invitation, you confirm that you are allowed to do so.

Section 8

How long we keep data

Data Kept for
Account and everything you enteredUntil you delete your account
Technical logs (IP addresses, sessions)Up to 1 year
Payment recordsUp to 5 years, as Russian tax and accounting law requires
Support conversationsWhile your account exists; deleted with it
Records of your consentFor as long as we need to be able to demonstrate it
Data of a deleted accountRemoved, except what the law obliges us to keep for the periods above

You can delete your account yourself in the profile settings; deletion is confirmed by email.

Section 9

Security

  • Every connection is encrypted with HTTPS/TLS
  • Passwords are stored as cryptographic hashes; account names, transaction titles, descriptions and notes are stored encrypted
  • Access to data is restricted by roles
  • Active sessions are visible in your settings and any of them can be ended
  • Two-factor authentication with an authenticator app or an email code
  • Regular backups

If a breach happens, we will notify the competent supervisory authority within 72 hours where the GDPR requires it, notify Roskomnadzor within 24 hours as Russian law requires, and tell the people affected without undue delay.

Section 10

Your rights

Under the GDPR, the UK GDPR and Russian law you have the right to:

  • Access the data we hold about you and get a copy of it
  • Rectify inaccurate data, in the settings or by writing to us
  • Erase your data by deleting your account in the profile settings, with email confirmation
  • Restrict processing while a dispute about your data is being resolved
  • Port your data: export your transactions in CSV or Excel at any time
  • Object to processing based on our legitimate interests
  • Withdraw consent at any time, for analytics, notification channels or AI features, without affecting what was done before
  • Not be subject to a decision based solely on automated processing that has legal or similarly significant effects. We make no such decisions
  • Complain to a supervisory authority: the data protection authority of your country in the EU or EEA, the Information Commissioner's Office in the UK, or Roskomnadzor in Russia. We would appreciate the chance to resolve the matter first

To exercise any of these rights, write to info@spendella.com from the email address of your account. We answer within 10 working days and never later than one month. We may ask you to confirm your identity before releasing data.

Other regions. If your local law gives you additional rights, for example under the California Consumer Privacy Act, we honour them on the same terms. We do not sell or share personal data for advertising in any region.

Section 11

Cookies

The website uses cookies for three things:

  • Necessary: sign-in and security. These cannot be switched off
  • Functional: remembering your language and theme
  • Analytics: Yandex Metrica, to understand how the website is used. It loads only after you press "Accept" in the cookie notice

You can choose "Necessary only" and use the Service without analytics. Your choice is stored in your browser's local storage with no expiry. To choose again, clear the site data in your browser and open the Service anew; this also signs you out in that browser.

You can also manage cookies in your browser settings. Blocking necessary cookies may prevent you from signing in.

Section 12

Age limit

The Service is for people aged 18 and over. By signing up you confirm that you are at least 18. If we learn that a minor has created an account, we will delete the account and all data linked to it.

Section 13

Changes to this Policy

We may update this Policy. If a change matters to you, we will tell you by email or with a notice in the Service. A new version takes effect when it is published here, and the effective date at the top always tells you which version you are reading.

Section 14

Contact

For anything about your personal data:

  • Email: info@spendella.com
  • Controller: Maksim Andreevich Pokhilchuk, sole proprietor, Chelyabinsk Region, Russian Federation
  • Website: spendella.com

Related documents (in Russian): Public offer, Terms of service, Consent to personal data processing

© 2026 Spendella. All rights reserved.
Home Русская версия Terms of service info@spendella.com