Security
A concise view of the controls that protect your account and private records.
Last updated: August 4, 2026
No bank connection
ExpenseLense builds a private spending picture from the receipts, statements, emails, and purchases you choose to add. It does not connect to bank accounts, cards, payroll systems, or accounting APIs on your behalf.
Account and data access
ExpenseLense requires authenticated access and scopes records, files, recurring charges, email history, and Insight context to the signed-in account only. Each tenant is isolated behind the app-user identity, and source links are only created after an ownership check.
Processing safety
Uploads are limited and validated before processing. Files are checked for size and supported format. Images are decoded and re-encoded; PDFs receive structural validation and are retained unchanged. User files, text, email headers, filenames, merchant names, and amounts are treated as untrusted data when sent to AI services. This service does not provide a blanket malware scan for every upload; malformed or unsupported files are rejected.
Ownership and processing boundary
Viewing and downloading original files and viewing, editing, exporting, and deleting saved records do not require a paid plan. Limits apply only to new automated processing and reprocessing.
Original files, export, and deletion
Original receipt and statement files stay available for review, edits, and reprocessing. You can export records and source lists from Account > Privacy, and delete ExpenseLense data there if needed. Product-data deletion removes records immediately and performs file cleanup safely in the background.
Monitoring and providers
We use established providers with clear boundaries: Clerk handles sign-in and identity, Supabase stores your account-scoped records and private files, OpenAI receives extraction and Insight input only as needed, Resend handles inbound email, Vercel hosts the app, Stripe handles billing, and Sentry receives minimized, scrubbed error diagnostics. Private financial fields are not used for unrelated analytics.
Report a security issue
Email aiacobe@icloud.com with the subject "Security.". Describe the issue without attaching receipts, passwords, credentials, or full card numbers. No public service can guarantee perfect security, but we investigate credible reports and improve controls as the product changes.