Privacy Policy
Last updated: August 15, 2026
1. Introduction
Welcome to ExpenseMate ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This privacy policy tells you how we look after your personal data, what your privacy rights are, and how the law protects you. It applies to all three places you can use ExpenseMate:
- our marketing website at expensemate.app (regardless of where you visit it from);
- the ExpenseMate web app at app.expensemate.app;
- the ExpenseMate mobile application for iOS.
We refer to the three together as our "Services". What we process is not identical across them, so wherever the marketing website, the web app and the mobile app differ — analytics and error reporting in particular — this policy says which one it is describing.
2. Data Controller
The controller responsible for your personal data is:
TK MEDIA S.à r.l.-S
13, In Bedigen
L-9283 Diekirch, Luxembourg
RCS Luxembourg: B306819
Email: contact@tkmedia.lu
For full company details, see our Legal Notice.
If you have any questions about this privacy policy, or if you wish to exercise any of your legal rights, please contact us at the email address above.
3. The Data We Collect
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data includes first name, last name, username or similar identifier.
- Contact Data includes email address and optionally telephone numbers.
- Financial Data includes expense records, receipt data, and payment information that you choose to share with the app.
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Services.
- Profile Data includes your username and password, your preferences, feedback, and survey responses.
- Usage Data includes information about how you use our Services.
- Image Data includes photographs of receipts you upload to the application.
- Subscription Data includes your ExpenseMate Premium subscription status, plan, and renewal or expiry dates, together with the anonymised purchase identifiers we receive from whoever sold you the subscription — the App Store if you bought it in the iOS app, Stripe if you bought it through our web checkout. We never receive or store your card or payment details: they go directly to Apple or to Stripe, and your billing country and any VAT are handled there too.
4. How We Collect Your Data
We use different methods to collect data from and about you including through:
- Direct interactions: You may give us your Identity, Contact, and Financial Data by filling in forms or by corresponding with us through the Services.
- Automated technologies or interactions: As you interact with our Services, we may automatically collect Technical Data about your equipment, browsing actions, and patterns.
- Third-party analytics providers: On our marketing website we use Google Analytics and PostHog (with your consent) and Vercel Analytics (cookieless, always active) to understand how visitors use the site. Vercel Analytics does not store personal data or set cookies, it collects only aggregated, anonymised metrics such as page views, referrer, device type, and approximate country. In the web app we use PostHog only if you accept analytics in the web app's own banner — nothing is loaded or sent before you answer it. In the mobile app we use PostHog to collect product-usage events (for example app opens, receipt scans, and which features you use) so we can understand how the app is used and improve it. This is first-party analytics and is not used to track you across other apps or services.
- Error reporting: When something goes wrong in the web app, an error report is sent to Sentry so we can find and fix it. Those reports carry the error itself and the page it happened on; we configure them to carry no name, email address, expense description or amount.
- How this is linked to you: In both the web app and the mobile app, the analytics identifier is your internal ExpenseMate account ID — not your name or email address, but a stable identifier for your account, and the same one our error reports carry. It means your activity on iOS and on the web is counted as one person's rather than two, and it is why this analytics is linked to you rather than anonymous.
- Buying Premium: When you buy or manage an ExpenseMate Premium subscription, the payment is processed by Apple if you bought it in the iOS app, or by Stripe if you bought it through our web checkout. Either way we are told, via RevenueCat, only that your subscription is active and which plan it is, so we can unlock Premium features for your account.
5. How We Use Your Data & Legal Basis
We only process your personal data where we have a valid legal basis under the GDPR (Regulation (EU) 2016/679). The table below sets out the purposes for which we process your data and the legal basis we rely on for each.
| Purpose | Data categories | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating your account and providing the Services (receipt scanning, expense tracking, group splitting) | Identity, Contact, Financial, Image, Profile | Performance of a contract, Art. 6(1)(b) |
| Managing your ExpenseMate Premium subscription and unlocking paid features | Subscription, Identity | Performance of a contract, Art. 6(1)(b) |
| Processing receipt images to extract items and amounts (AI-assisted OCR) | Image, Financial | Performance of a contract, Art. 6(1)(b) |
| Securing the Services, detecting fraud and abuse, and maintaining system integrity | Technical, Usage | Legitimate interests, Art. 6(1)(f) (running a secure service) |
| Marketing-website analytics and product improvement, on expensemate.app (Google Analytics and PostHog) | Technical, Usage | Consent, Art. 6(1)(a) |
| Product analytics in the web app, on app.expensemate.app (PostHog) | Usage, Technical, internal account ID | Consent, Art. 6(1)(a) |
| Product analytics in the iOS app, to understand usage and improve it (PostHog) | Usage, Technical, internal account ID | Legitimate interests, Art. 6(1)(f) (improving our app) |
| Detecting and diagnosing errors and crashes in the web app (Sentry) | Technical, Usage, internal account ID | Legitimate interests, Art. 6(1)(f) (keeping the web app working) |
| Aggregated, cookieless audience measurement (Vercel Analytics) | Technical (transient) | Legitimate interests, Art. 6(1)(f) (measuring website reach without identifying visitors) |
| Responding to support requests and legal-rights requests | Identity, Contact, any other relevant data | Legal obligation, Art. 6(1)(c) and legitimate interests, Art. 6(1)(f) |
| Complying with accounting, tax and other legal obligations | Identity, Contact, Financial (to the extent applicable) | Legal obligation, Art. 6(1)(c) |
6. Recipients and Sub-Processors
We do not sell your personal data. We share it only with a limited number of service providers (processors under GDPR Art. 28) who process it on our behalf and under our instructions in order to operate the Services:
| Provider | Purpose | Location |
|---|---|---|
| Google LLC (Firebase Authentication, Cloud Storage, Cloud Run) | Sign-in, receipt image and file storage, and a compatibility proxy for older app versions | EU / United States |
| Cloudflare, Inc. | Network routing, TLS termination and protection for our API; every request from the apps to our API passes through it | United States company, global network |
| Google LLC (Gemini API) | Receipt OCR / item extraction | United States |
| OpenAI, L.L.C. | Receipt OCR / item extraction (fallback) | United States |
| Vercel Inc. | Hosting for the marketing website and the web app; cookieless analytics on the marketing website only | United States (global edge) |
| PostHog Inc. | Product analytics for the marketing website, the web app and the mobile app; optional marketing-website session replay only after analytics consent | EU Cloud (Frankfurt) / United States company |
| Functional Software, Inc. d/b/a Sentry | Error and crash reporting for the web app | EU region (Frankfurt) / United States company |
| Apple Inc. | App Store subscription billing and management | United States / Ireland |
| Stripe, Inc. / Stripe Payments Europe, Ltd. (including Link) | Payment processing and billing for subscriptions bought through our web checkout; Stripe is the seller of record for those purchases and handles VAT | Ireland / United States |
| RevenueCat, Inc. | Subscription status and entitlement management | United States |
Receipt image content is sent to OCR providers only for the time needed to extract the data; we do not authorise them to use your content to train their models. We may additionally disclose personal data where required by law, court order, or a legitimate request from a public authority, or where necessary to protect our rights, the safety of our users, or the integrity of the Services.
Two points about the last two rows, because they are easy to state loosely. Cloudflare routes the traffic between your device and our API rather than storing your expenses: it necessarily sees the connection and its IP address, and it is on the path of every request the apps make. Sentry's ingest endpoint likewise receives your IP address at the network layer, but we configure Sentry not to store it in the error event. Error events do carry your internal ExpenseMate account ID, which is a persistent identifier for your account, so they are personal data even though they contain no name or email address.
7. International Data Transfers
Some of our sub-processors are established outside the European Economic Area (EEA), notably in the United States. When we transfer your personal data outside the EEA, we ensure an adequate level of protection using one or more of the following safeguards:
- Transfer to providers certified under the EU–US Data Privacy Framework (where applicable).
- Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision (EU) 2021/914), supplemented with technical and organisational measures where required.
- For Google services, Google's published cross-border transfer mechanisms.
To be precise rather than reassuring: your account and expense data is stored on a server in Luxembourg (section 8), our PostHog analytics is on PostHog's EU Cloud, and our Sentry project is on Sentry's EU region, so error reports are stored in the EEA. We do not claim that everything is hosted in the EU, because it is not — hosting, OCR and subscription management involve the United States providers listed in section 6, and Cloudflare operates a global network. The Location column in that table is the accurate per-provider answer.
You may request a copy of the safeguards in place for a given transfer by contacting us at the email address listed in section 2.
8. Infrastructure
Your account and expense data is stored in a PostgreSQL database on a server we operate in Luxembourg. Our API runs on that same server and is reached at api.expensemate.org through a Cloudflare Tunnel, so Cloudflare routes and secures every request the apps make; it does not store your expense data. We use Google Cloud Storage for receipt images and files and Firebase Authentication for sign-in. Google Cloud Run now hosts only a compatibility proxy for older versions of the mobile app; it stopped being our API host, and the Google Cloud SQL database was retired, in April 2026.
Our marketing website at expensemate.app and our web app at app.expensemate.app are both hosted on Vercel. On the marketing website, Vercel also provides cookieless, privacy-first analytics: it processes request metadata (such as IP addresses) transiently to derive aggregate country-level statistics, and IP addresses are not stored by Vercel Analytics. For more information, see Vercel's Privacy Policy.
With your analytics consent, we also use PostHog on the marketing website to measure product funnels such as app-store clicks, downloads, and join-link outcomes, and — again only with your consent, given separately in the web app — inside the web app to understand which features are used. We configure PostHog to avoid sending group IDs, expense descriptions or amounts, and session replay is switched off entirely in the web app. In the mobile app, PostHog is used to collect product-usage events tied to your account identifier so we can understand how the app is used and improve it.
The web app reports errors to Sentry, on Sentry's EU region, so that crashes we would otherwise never hear about get fixed. We configure it not to store your IP address in the error event and to drop the breadcrumbs that would record what you typed or what the app logged. Reports do carry your internal ExpenseMate account ID, so repeated errors can be recognised as one person's. Error reporting sets no cookie and is not part of the analytics consent choice — which is why the web app's banner tells you errors are always reported.
ExpenseMate Premium subscriptions bought in the iOS app are sold and billed by Apple through the App Store. Subscriptions bought through our web checkout are sold and billed by Stripe as merchant of record — its consumer-facing brand is Link, which is why the charge appears as LINK.COM* on a statement — and Stripe handles the billing country and VAT. We use RevenueCat in both cases to receive and manage your subscription status so the app can unlock Premium features for your account. We do not receive or store your payment-card details; the payment itself is handled entirely by Apple or by Stripe under their own terms.
9. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
10. Data Retention
We keep your personal data only for as long as reasonably necessary for the purposes set out in section 5, including to meet any legal, regulatory, tax, accounting or reporting requirements. Concretely:
- Account data (Identity, Contact, Profile): kept for as long as your account exists. On deletion, identifying fields are removed within 30 days.
- Expense and group data (Financial): kept while your account is active. When you delete your account, data that is strictly tied to you is deleted, and data that remains linked to shared groups or expenses of other users is anonymised (your identity is removed) rather than deleted, so that the expense history of other group members stays intact and the app continues to function correctly.
- Receipt images (Image): kept while linked to an expense; deleted when you delete the expense, the group, or your account.
- Technical and server logs: typically kept for up to 90 days for security, debugging, and abuse-prevention purposes.
- Google Analytics data: retained for 14 months by default at the GA4 level.
- PostHog analytics data: retained according to the PostHog project retention settings. On the marketing website and in the web app it is only collected after you accept analytics; in the iOS app it is collected to operate and improve the app, and you may object at any time under section 11.
- Error reports (Sentry): retained for the retention period configured on our Sentry project, after which the events are deleted automatically. They are kept only to diagnose the error they describe.
- Subscription data: kept while your account exists and for any period required to meet accounting and tax obligations. Payment and card data are handled by Apple or by Stripe, not by us.
- Accounting and tax records: retained for 10 years in accordance with Luxembourg accounting law where applicable.
Once anonymised, data is no longer considered personal data under the GDPR and may be retained for statistical and operational purposes.
11. Your Legal Rights
Under the GDPR, you have the following rights in relation to your personal data:
- Access (Art. 15): request a copy of the personal data we hold about you.
- Rectification (Art. 16): ask us to correct inaccurate or incomplete data.
- Erasure (Art. 17): ask us to delete your personal data, subject to the anonymisation approach explained in section 10.
- Restriction (Art. 18): ask us to limit the processing of your data in certain circumstances.
- Portability (Art. 20): receive your data in a structured, commonly used, machine-readable format.
- Objection (Art. 21): object to processing based on legitimate interests.
- Withdraw consent (Art. 7(3)): where processing is based on consent, withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Two of these you can exercise yourself, without asking us: delete your account in the iOS app under Settings, or in the web app under Settings, subject to the anonymisation approach explained in section 10; and withdraw analytics consent in the web app under Settings → Privacy, or on this website through the "Cookie Settings" link in the footer. For anything else, or if you would rather we did it, contact us at contact@tkmedia.lu. We will respond within one month of receiving your request.
12. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. In Luxembourg, the competent authority is the Commission nationale pour la protection des données (CNPD):
13. Children
Our Services are not directed at children under 16. Under Luxembourg law, the age of digital consent under GDPR Art. 8 is 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
14. Automated Decision-Making
Receipt OCR uses AI models to extract items and amounts from images. This is purely a data-extraction step; it does not produce decisions that have legal effects on you or similarly significantly affect you within the meaning of GDPR Art. 22. You remain in control of every expense you save in the app.
15. Cookies and Tracking
Our marketing website uses cookies and similar tracking technologies to distinguish you from other visitors. This helps us to provide you with a good experience when you browse the site and also allows us to improve it. You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.
The web app at app.expensemate.app works differently: it sets essentially no cookies of its own and instead uses your browser's local and session storage to keep you signed in, to remember your analytics choice, and to remember whether you prefer light or dark. Browser cookie settings do not govern that storage — you clear it by clearing site data for app.expensemate.app — and analytics can be switched off at any time in the web app under Settings → Privacy. Because the marketing website and the web app are separate origins, a choice made on one is not carried over to the other.
Our Cookie Policy covers both and lists the individual keys.
16. Changes to the Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
17. Contact Us
If you have any questions about this Privacy Policy, please contact us at contact@tkmedia.lu.