Privacy Policy

Spens is a personal pocket ledger: you record your transactions, budgets, savings goals, debts and accounts in it. This data is sensitive by nature, and this policy explains in plain terms what we collect, why, and what we never do with it.

1. Who is responsible for your data

Spens is published by David Dossou, acting as an individual. For any question about your data or to exercise your rights, write to djidenou@hey.com.

2. What we collect

Today, the only cookies set are those strictly required for your session: Spens currently uses no third-party analytics and no advertising trackers. If we introduce measurement or advertising cookies in the future (for example to run campaigns on Facebook or other platforms), they will only be set with your prior consent, collected through a cookie banner you can accept, decline or change at any time. This policy will be updated accordingly. In any case, your financial data will never be shared with advertising networks.

3. Why we process it (legal bases)

Your data is never sold or rented, and your financial data is never used for advertising.

4. Shared spaces

If you join a shared space (for example with your family), the transactions and budgets of that space are visible to its members. You choose what you record in a shared space; your personal spaces remain private.

5. Where your data lives

Your data is hosted on Hetzner servers located in Germany (European Union). Transactional emails (sign-in codes, invitations) are sent through Brevo, a provider based in France. We do not transfer your data outside the European Union.

6. How long we keep it

7. Your rights

Under the GDPR and applicable data protection laws (including, for users in Côte d'Ivoire, law no. 2013-450 on the protection of personal data), you have the rights of access, rectification, erasure, portability, restriction and objection over your data.

To exercise them, write to djidenou@hey.com. You can also delete your account yourself from your profile, which erases all your data. You also have the right to lodge a complaint with your supervisory authority (the CNIL in France, the ARTCI in Côte d'Ivoire).

8. Security

Connections are encrypted (HTTPS), sign-in is passwordless with one-time codes, and server access is restricted. No system is infallible, so if an incident ever affects your data we will notify you without delay, as required by law.

9. Changes to this policy

This policy may evolve, in particular when new features (such as voice dictation) launch. If a significant change is made, you will be informed in the app or by email.