Privacy Policy | LiveSpend
Effective date: July 13, 2026
LiveSpend ("LiveSpend," "we," "us," or "our") provides a service that helps you track spending using (a) transaction alert emails read via the Gmail API with your permission, and (b) transactions you enter manually (the "Service").
This Privacy Policy explains what information we collect, how we use it, and the choices you have. If you have any questions, contact us at support@livespend.app.
1) Information we collect
A. Account information
When you create an account, we collect and store:
- Email address (required)
- Account identifiers, including a Clerk user identifier and internal identifiers used to connect your account with LiveSpend features and billing
Authentication and account profile details are handled through Clerk.
B. Transaction information
LiveSpend stores only the transaction details needed to provide the Service. This may include:
- Merchant name
- Transaction amount
- Currency
- Transaction date
- Category (if assigned)
- Transaction source (e.g., Gmail sync, manual entry)
- Spending source/card nickname (if you set one with multiple cards)
- Creation and deletion status for transaction records
You can provide transaction information in the following ways:
- Gmail API connection (optional): You connect a Gmail account and authorize LiveSpend to read messages using the Gmail API. LiveSpend checks new messages to identify bank transaction alerts and extracts transaction details from alerts it recognizes. The Gmail access, temporary processing, storage, and automated extraction involved are described in Sections 1D, 1E, and 1F below.
- Manual entry: You can manually enter transactions with similar fields.
C. Spending targets, preferences, and notifications
LiveSpend also stores information you create or configure in the Service, such as spending targets, cycle settings, categories, category rules, spending sources/card nicknames, time zone, onboarding status, notification preferences, generated insights, and app progression state.
If you enable notifications, LiveSpend may store notification preferences, sent notification records (including the recipient, subject, message, destination link, provider, and delivery identifier), browser push subscription details, iOS/device push tokens, and related delivery information.
D. Gmail API data (Gmail connection only)
If you choose to connect Gmail, LiveSpend accesses your Gmail data through the Gmail API after you grant permission. LiveSpend is designed to minimize persistent storage, but the ongoing sync path may need to inspect a newly added message before it can determine whether the message is a bank transaction alert the Service can use.
-
Permission: LiveSpend requests the Gmail
gmail.readonlypermission. This allows LiveSpend to read messages but does not allow it to send, edit, or delete email. - What we temporarily process: For a message being checked, LiveSpend may fetch the full Gmail API message and hold its headers, timestamp, snippet, and decoded text or HTML body in application memory while determining whether it is a transaction alert and extracting transaction details. A regular catch-up sync narrows messages by configured bank sender domains. During ongoing Gmail history/watch sync, LiveSpend may fetch any newly added message before determining that it is unrelated. Unrelated message content is discarded after that check.
- What we store about the Gmail connection: We store the connected Gmail address, an encrypted OAuth refresh token, whether synchronization is enabled, last-sync timestamps and status, the latest sync error and its timestamp, a Gmail history cursor, and watch-expiration information.
- What we store for each processed message: We retain the Gmail message ID, a one-way SHA-256 hash derived from the connected Gmail address, processing status (pending, non-transaction, or transaction created), and record timestamps. This minimal tracking record is retained even when a message is determined to be unrelated, so LiveSpend can avoid reprocessing the same message and keep sync reliable.
- What we store for a transaction alert: If a message produces a transaction, we store the extracted transaction information described in Section 1B and link it to the message's tracking record.
- What we do not persist: LiveSpend's database does not store email bodies, subjects, senders, recipients, full headers, snippets, or attachments from Gmail. It does not retain the content of unrelated email after the temporary check described above.
E. OAuth tokens (Gmail connection only)
LiveSpend stores only an encrypted refresh token, which is used to obtain temporary access tokens when needed. Access tokens are not stored persistently and are generated and used only transiently during synchronization. You can revoke LiveSpend's access at any time through your Google account settings, which will invalidate the refresh token and prevent further access. Disconnecting Gmail inside LiveSpend removes the Gmail account address and encrypted refresh token from LiveSpend's active Gmail connection record.
F. Automated parsing, categorization, and insights
LiveSpend uses the OpenAI API for limited, user-facing features:
- Ambiguous bank alerts: If a message comes from an authenticated sender at a bank LiveSpend works with, but LiveSpend's standard parser cannot confidently interpret it, LiveSpend may send OpenAI the bank name, email subject, email date, and up to 12,000 characters of extracted body text to determine whether it is a transaction alert and, if so, extract the amount, direction, date, and merchant.
- Merchant categorization: LiveSpend may send a transaction's merchant name and your category names to suggest a reusable merchant rule and category.
- Weekly insights: LiveSpend may send an aggregated weekly metrics brief containing period dates, spending totals and counts, merchant and category summaries, time-of-day and weekday/weekend patterns, comparisons with recent periods, and budget context. The brief does not contain raw individual email messages or a list of raw transaction records.
LiveSpend does not separately save the raw OpenAI prompt or raw response in its database. It does store the resulting transaction, category or rule, and generated insight needed to show these features in the Service. OpenAI may temporarily retain API inputs and outputs according to LiveSpend's API configuration and OpenAI's applicable data policies. LiveSpend does not opt in to using this data to train generalized AI models. For current provider retention details, see OpenAI's API data controls.
G. Billing and subscription information
If you subscribe to LiveSpend Pro, billing and subscriptions depend on the platform where you subscribe. LiveSpend Pro subscriptions purchased in the iOS app are processed through Apple In-App Purchases. LiveSpend Pro subscriptions purchased on the web are processed through Stripe. Apple or Stripe, as applicable, will collect and process your payment information directly.
We do not collect or store your credit card number, CVV, or full payment credentials.
We may receive and store limited billing-related information from Apple or Stripe, such as:
- Subscription status, such as active, cancelled, past due, expired, refunded, or revoked
- Apple or Stripe customer, subscription, transaction, or receipt identifiers
- Plan, billing period, purchase or expiration dates, cancellation status, and related entitlement status
- Apple billing verification data needed to validate and manage iOS subscriptions
This information is used solely to manage your account and provide the Service. For details on how Apple or Stripe handle payment data, see Apple's applicable payment and privacy terms and Stripe's Privacy Policy.
H. Support communications
If you email us for support, we will receive and store the contents of your message and your contact information (such as your email address) to respond and help resolve your issue.
I. Technical, usage, and analytics data
We may collect technical and usage data such as IP address, device/browser information, timestamps, page views, referral source, UTM parameters, diagnostic events, and limited product or website interaction events for security, abuse prevention, troubleshooting, analytics, and product improvement.
We use PostHog for limited website and product analytics. On our public landing page, we configure PostHog in cookieless mode, so PostHog is not intended to store analytics identifiers in cookies, local storage, or session storage. PostHog may collect page views, referral and campaign information, and interactions such as clicks on download, sign-up, or other call-to-action buttons.
Product and backend analytics sent to PostHog are limited to high-level funnel and status events, such as whether an account was created, onboarding steps were completed, Gmail was connected, a spending source was added, a spending target was set, or a first transaction was received. For signed-in users, these analytics events may be associated with Clerk and internal account identifiers, the account creation time, plan, app environment, and relevant high-level event status. We do not send PostHog Gmail message content, email subjects, email bodies, raw transaction descriptions, merchant names, transaction amounts, bank or payment credentials, or other sensitive financial details.
Landing-page PostHog analytics is configured so PostHog is not intended to store its analytics identifiers in cookies, local storage, or session storage.
J. Information we do not collect
LiveSpend is designed to avoid collecting sensitive banking and payment credentials. We do not collect or store:
- Bank logins, passwords, or credentials
- Access to your bank account portal
- Full card numbers
- CVV codes
- Payment card expiration dates
2) How we use information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Create and manage your account
- Process and display your transaction history and summaries
- Create and manage spending targets, categories, category rules, spending sources, preferences, insights, and notifications
- Sync transactions from your connected Gmail account (if enabled)
- Temporarily inspect newly added Gmail messages to identify bank transaction alerts the Service can process and avoid processing the same message twice
- Use OpenAI for the user-facing transaction parsing, merchant categorization, and weekly insight features described in Section 1F
- Manage subscription status, billing records, and Pro account access
- Send notifications if you enable them
- Respond to support requests and communicate with you about the Service
- Protect the security and integrity of the Service (e.g., preventing abuse and troubleshooting)
- Measure landing page performance, understand which sources and campaigns lead to downloads or sign-ups, improve onboarding, and understand high-level product funnel drop-off
We do not sell your personal information. We do not use your data for advertising. We do not use Gmail-derived content for advertising, resale, surveillance, credit or lending decisions, or training generalized AI/ML models. We use limited third-party analytics as described in this Privacy Policy, but we do not use analytics data for advertising or sell analytics data. Some service providers may process basic operational, security, diagnostic, analytics, or delivery data under their own policies.
3) How Gmail syncing works
If you connect Gmail, LiveSpend uses read-only Gmail API access to check new messages for bank transaction alerts it can use and extract transaction details. This feature can be disabled by you. As explained in Section 1D, an ongoing sync may temporarily inspect a newly added message before determining that it is unrelated.
Most bank alerts LiveSpend can use are handled by its standard parsers. Some ambiguous alerts from authenticated bank senders may be analyzed through the OpenAI API as described in Section 1F.
- You control whether Gmail sync is enabled.
- You can revoke LiveSpend's Gmail access at any time in your Google account permissions.
- If access is revoked or expires, syncing may stop until you reconnect.
- Disconnecting Gmail inside LiveSpend stops future Gmail syncing and removes the active Gmail address and OAuth token. It does not automatically delete transactions already imported or the minimal per-message tracking records described in Section 1D.
Google API Limited Use
LiveSpend's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements. LiveSpend uses Gmail-derived data only to provide or improve user-facing transaction tracking features that you authorize.
4) Sharing of information
We do not sell your personal information.
We may share information only in the following limited circumstances:
A. Service providers (to operate the Service)
We use trusted third parties to run LiveSpend, such as:
- Clerk (authentication)
- Apple (iOS subscription billing through In-App Purchases)
- Stripe (web subscription billing and payment processing)
- Resend (email notification delivery)
- Apple Push Notification service and browser push providers (push notification delivery)
- Railway (hosting and database infrastructure)
- Google (Gmail API access, only if you connect Gmail)
- OpenAI (limited transaction-alert parsing, merchant categorization, and weekly insight generation as described in Section 1F)
- PostHog (limited website and product analytics, including high-level funnel events; session replay is disabled)
These providers process data as needed to provide their services to us and support operation, security, analytics, and reliability of the Service. OpenAI may temporarily process or retain the limited data described in Section 1F in accordance with LiveSpend's API configuration and OpenAI's applicable data policies. Gmail-derived content is not used by LiveSpend for advertising, resale, surveillance, credit or lending decisions, or training generalized AI/ML models. We do not share Gmail message content, raw transaction details, transaction amounts, merchant names, bank credentials, or payment credentials with PostHog.
B. Legal and safety
We may disclose information if we believe it is reasonably necessary to:
- Comply with applicable law, regulation, or legal process
- Protect the rights, safety, and security of LiveSpend, our users, or others
- Detect, prevent, or address fraud, abuse, or security issues
C. Business changes
If LiveSpend is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. If that happens, we will take reasonable steps to ensure your information remains protected.
5) Data retention
We keep information only as long as necessary to provide the Service and for legitimate operational needs (such as security, dispute resolution, and compliance).
- Transactions and account data are retained while your account exists unless deleted or changed through the Service, subject to limited retention for legal/security purposes. Deleted transactions may be removed from active views while some records are retained for operational integrity.
- Spending targets, categories, rules, preferences, spending sources, insights, and notification records are retained while your account exists unless deleted or changed through the Service.
- Gmail API sync: LiveSpend does not persist full Gmail message content in its database. The Gmail connection data, extracted transactions, and per-message tracking records described in Section 1D are retained while your LiveSpend account exists. Disconnecting Gmail removes the active Gmail address and encrypted refresh token, but does not delete imported transactions or the per-message tracking records. Deleting your LiveSpend account deletes those records from LiveSpend's primary application database, subject to the limited exceptions described below.
- OpenAI processing: LiveSpend does not separately save raw prompts or raw responses in its database. OpenAI may temporarily retain API inputs and outputs according to LiveSpend's API configuration and OpenAI's applicable data policies.
- Billing data (subscription status and Apple or Stripe identifiers) is retained as long as your account exists and for a reasonable period after account deletion as required for accounting, tax, and dispute resolution purposes.
- Analytics data is retained only as long as reasonably needed for analytics, product improvement, security, and troubleshooting, or according to our analytics provider settings. Session replay is disabled.
6) Your choices and rights
A. Account deletion
You can delete your account. Account deletion cancels an active web subscription, attempts to revoke the Gmail connection, and deletes the account's transactions, Gmail message tracking records, settings, and other associated user records from LiveSpend's primary application database. Limited billing, security, webhook, analytics, or provider-held records may remain where reasonably necessary for legal compliance, accounting, dispute resolution, fraud or abuse prevention, or under the applicable provider's retention settings. Deleting your LiveSpend account does not cancel an Apple In-App Purchase subscription; that subscription must be cancelled through your Apple account or App Store settings. You may also withdraw Gmail access without deleting your LiveSpend account by disconnecting Gmail or revoking access through Google.
B. Access and correction
You can access and update certain account details through your account settings. If you need help accessing, correcting, or deleting information, contact us at support@livespend.app.
C. Gmail access revocation
If you connected Gmail, you can disconnect it inside LiveSpend or revoke access in your Google account settings. After revocation, LiveSpend will no longer be able to sync Gmail messages unless you reconnect. Revoking access through Google does not by itself delete LiveSpend's local Gmail connection record, imported transactions, or per-message tracking records. Disconnecting inside LiveSpend removes the active Gmail address and token, but imported transactions and per-message tracking records remain until your LiveSpend account is deleted.
D. Subscription cancellation
You can cancel your Pro subscription at any time according to the platform where you subscribed: through your Apple account or iOS App Store subscription settings for subscriptions purchased through Apple In-App Purchases, or through your account settings or the Stripe customer portal for subscriptions purchased on the web. Upon cancellation, you will retain access to Pro features until the end of your current billing period, after which your account will revert to the free tier. Your transaction data and account information will not be deleted upon subscription cancellation.
E. Notifications
You can enable or disable email and push notifications in your account settings. You can also control push notifications through your browser or device settings.
F. Website analytics choices
On our landing page, we configure PostHog analytics in cookieless mode, so PostHog is not intended to store its analytics identifiers in cookies, local storage, or session storage. Session replay is disabled. You can limit or block website analytics by using browser privacy settings, browser extensions, or other tools that block analytics scripts. If we provide additional analytics opt-out controls, you may also use those controls. Blocking analytics scripts may prevent analytics features from working, but should not prevent you from viewing the landing page.
G. Data export
Data export is not currently available, but may be added in the future.
7) Security
We use reasonable administrative, technical, and organizational safeguards designed to protect your information. However, no method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
8) International users
LiveSpend is currently operated from Canada. If you access the Service from outside Canada, your information may be processed and stored in locations where our service providers, including hosting, analytics, authentication, billing, and automated model providers, operate. By using the Service, you understand that your information may be transferred to and processed in other jurisdictions.
9) Children's privacy
LiveSpend is not intended for children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact support@livespend.app.
10) Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make changes, we will update the "Effective date" above. If changes are material, we may provide additional notice within the Service or by email.
11) Contact us
If you have questions about this Privacy Policy or our privacy
practices, contact us at:
support@livespend.app