Privacy
Privacy Policy
This policy describes the information ExpeFi collects and how it is used to provide expense tracking, exports, billing, and support.
Information we collect
ExpeFi may collect account details such as your email address, authentication identifiers, subscription status, workspace settings, account labels, categories, budgets, bills, cash entries, transactions, export settings, and support messages. Payment card details are handled by Stripe and are not stored by ExpeFi.
How we use information
We use information to provide the app, protect account access, save finance records, process subscriptions, generate exports, respond to support requests, improve reliability, prevent abuse, and comply with legal, tax, security, and payment obligations.
Clerk authentication
Clerk handles authentication and may process account identifiers, email addresses, session metadata, device/browser details, verification events, and security logs needed to create and protect your ExpeFi account.
Manual finance data
Manual entries may include cash expenses, cash holdings, account labels, categories, budget amounts, bill names, bill dates, notes, and settings you choose to save. You control the accuracy of this information and can remove or update it inside the app where supported.
Connected account data
When you connect an institution, Plaid may collect the information needed to authenticate with that institution and provide data you authorize. ExpeFi receives normalized account details, institution name, account type, masked account digits, cached balances, transaction dates, amounts, currencies, merchant descriptions, categories, pending status, and provider identifiers used to synchronize changes. ExpeFi does not receive or store your bank password, full account number, or routing number. Plaid processes information under its own end-user privacy policy and consent experience. ExpeFi records the consent version, acceptance time, authorized Transactions purpose, and protected session/account references before issuing a Plaid Link token. ExpeFi also requires a recent Clerk first-factor sign-in and an ExpeFi authenticator or single-use recovery code for each Plaid Link action.
Stripe billing data
Stripe processes card details and may provide ExpeFi with customer identifiers, subscription status, invoices, payment status, billing email, and limited payment metadata. ExpeFi uses that information to activate Pro access, show billing status, and support payment questions.
Google Sheets™ add-on data
If you use ExpeFi for Google Sheets™, the add-on works only with the active spreadsheet and performs a one-way manual export from ExpeFi. ExpeFi may process the spreadsheet name, a hashed workbook identifier, selected export scope, masking choice, row counts, connection status, and sync timestamps. Access tokens are delivered once and stored by ExpeFi only as hashes. The add-on does not request access to all files in Google Drive.
MCP and AI connection data
When you authorize an approved MCP client, ExpeFi records the client, granted read scopes, resource, issue and last-use times, revocation state, and pseudonymous operational audit events. ExpeFi does not store raw MCP access or refresh tokens. Returned data excludes bank credentials, full account and routing numbers, MFA material, raw provider IDs, and internal database IDs. You can revoke grants from Settings.
Google account security events
When Google Cross-Account Protection is enabled, Google may send signed account-security events associated with Google sign-in. ExpeFi stores a keyed hash of the Google account identifier and minimal event metadata to revoke sessions or temporarily block access after a high-risk event. Raw security-event tokens and raw Google account identifiers are not stored.
Cloudflare infrastructure
ExpeFi uses Cloudflare as an infrastructure provider to deliver and protect the service and store application data.
Currency and market data
ExpeFi may retrieve currency-rate and market-cap data from external data providers to sort, display, and convert supported currencies. These data requests are not intended to include your private transaction descriptions, account numbers, or bank login details.
Service providers and sharing
ExpeFi relies on service providers including Clerk for authentication, Stripe for billing, Plaid for optional financial-account connectivity, Google for the optional Sheets add-on and account-security events, Cloudflare for hosting and persistence, and other infrastructure tools needed to operate the product. We do not sell personal information, and providers process information as needed to support ExpeFi.
Local storage, cookies, and consent
The app uses browser storage for preferences such as theme, selected workspace options, sidebar state, table density, and temporary UI choices. Authentication and payment providers may use cookies or similar technologies to keep sessions secure.
Retention and deletion
We keep account and finance information while your account is active or as needed for security, billing, dispute handling, and legal obligations. Disconnecting a financial institution immediately disables it in ExpeFi. ExpeFi retries temporary provider revocation failures and removes the encrypted connection token within seven days at the latest. Previously synchronized transactions remain in your ExpeFi history until deletion is requested. Authenticator assurances and rate-limit data expire quickly; operational sync records are retained for up to 90 days, and security/consent audit records are generally retained for up to one year unless a longer period is legally required. Signed-in users can start account-data deletion from Settings, or contact [email protected].
Security
ExpeFi uses HTTPS, protected routes, server-side access checks, encrypted sync secrets where applicable, application-level AES-256-GCM encryption for Plaid access tokens and local authenticator seeds, one-use hashed recovery codes, rate limits, and trusted providers for authentication, infrastructure, and payments. No internet service can be guaranteed perfectly secure, but we design around reasonable safeguards.
Contact
Questions, deletion requests, export requests, or privacy concerns can be sent to [email protected].Mailing address: 99 WALL ST #884, NEW YORK, NY 10005, USA. This address is for business correspondence. Customer support is fastest by email.