The Spenze app is developed and operated by Mehnic, a company that owns a portfolio of mobile applications. For the purposes of applicable privacy laws (including Brazil's LGPD, the EU GDPR, and California's CCPA), Mehnic is the data controller for your personal information.
Data Protection Officer (DPO) / Privacy Contact:
Email: fabio.almcosta@gmail.com
This data is stored on our secure servers (Azure PostgreSQL) and is visible only to you.
When you use the voice transaction feature, your audio is transmitted to Microsoft Azure Cognitive Services Speech-to-Text for transcription. Audio is not permanently stored on our systems after processing. The transcribed text is then used only to extract transaction details.
If you sign in with Google, Facebook, or Apple:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Create and maintain your account | Name, email | Performance of contract |
| Provide the financial management service | Transactions, budgets, categories | Performance of contract |
| AI features (insights, chat assistant) | Transactions, history | Legitimate interest / Consent |
| Voice-to-transaction feature | Audio (temporary, not stored) | Consent |
| Social authentication | Name, email from provider | Performance of contract |
| Subscription management | Plan status | Performance of contract |
| Customer support | Email, reported issue data | Legitimate interest |
| Security and fraud prevention | Technical logs | Legitimate interest / Legal obligation |
We do not use your financial data for advertising, profiling for third parties, or any purpose other than delivering and improving the Spenze service.
We do not sell, rent, or share your personal data with third parties for commercial or advertising purposes. We share data only with infrastructure providers necessary to run the service:
| Provider | Purpose | Country | Privacy Policy |
|---|---|---|---|
| Microsoft Azure | API hosting, database (PostgreSQL), Speech-to-Text, OpenAI (AI features) | USA / Global | View |
| RevenueCat | Subscription management | USA | View |
| Social login (OAuth) | USA | View | |
| Facebook / Meta | Social login (OAuth) | USA | View |
| Apple | Sign in with Apple (OAuth), App Store | USA | View |
All providers act as data processors under contracts that include appropriate data protection clauses compliant with LGPD, GDPR, and applicable laws.
Some of our providers are located outside Brazil and the European Union (primarily in the United States). We ensure such transfers are made with adequate safeguards, including Standard Contractual Clauses (SCCs) and compliance programs (e.g., EU–U.S. Data Privacy Framework), as required by LGPD Art. 33 and GDPR Chapter V.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at fabio.almcosta@gmail.com. We respond within 15 business days.
We implement technical and organizational measures to protect your data:
No system is completely immune to security threats. In the event of a data breach that affects your personal data, we will notify affected users and relevant authorities as required by applicable law.
Spenze is intended for users 18 years of age or older. We do not knowingly collect personal data from children under 13 (or under 16 in the EU). If we become aware that a minor's data has been collected, we will take immediate steps to delete it. If you believe a child has provided us personal data, please contact us at fabio.almcosta@gmail.com.
Spenze is a mobile application and does not use cookies. We do not use advertising trackers, cross-app tracking, or behavioral profiling for third-party purposes.
With your permission, we may send push notifications for financial alerts and reminders. You can revoke this permission at any time in your device settings or in the app under Settings → Notifications.
In compliance with Apple App Store requirements, here is a summary of our data practices:
We may update this Privacy Policy from time to time. When we do:
This Privacy Policy is governed by the laws of Brazil, in particular Law No. 13.709/2018 (LGPD). For users in the EU, GDPR applies to the extent applicable. The courts of São Paulo, Brazil have jurisdiction for any disputes.