1. Scope and Controller
This Privacy Policy describes how Allospend Technologies LLC ("Allospend," "we," "us," or "our") collects, uses, discloses, and retains personal information ("Personal Information" or "PI") in connection with the Allospend consumer brand, the Allospend iOS mobile application (the "App"), the website at https://allospend.app (the "Site"), Dummii NFC stickers, and related services (collectively, the "Service").
For purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and the UK GDPR, where applicable, the data controller is Allospend Technologies LLC. Our Data Protection Officer can be reached at privacy@allospend.app.
EU/UK/Switzerland notice. The Service is not currently directed to users located in the European Economic Area, the United Kingdom, or Switzerland, and we do not actively market to those regions. If we extend the Service to those regions, we will update this Policy and provide GDPR (Art. 13/14) disclosures before processing.
2. Information We Collect
We collect only the Personal Information reasonably necessary to operate the Service. Categories include:
2.1 Account and Identity Data
- Name, email address, phone number, date of birth, country, and state.
- Login credentials (hashed) and authentication metadata.
- Government-issued ID images when you complete Stripe Identity or Plaid Identity Verification for withdrawals or high-value transactions.
2.2 Transaction and Financial Data
- Wallet balance, funding source tokens (e.g., tokenized card via Stripe, Plaid-linked bank account last-four), transaction history, split-group activity, instant-withdrawal instructions, and NFC tap-to-pay routing metadata.
- We do not store full bank-account numbers on our servers. Tokenized identifiers are stored by our processors (Stripe, Plaid).
2.3 Receipt and Image Data
- Receipt photographs and OCR output produced on-device using Apple Vision framework.
- Uploaded images are transmitted to AWS S3 for processing and storage.
- When a receipt is hard to read and the on-device parser cannot confidently produce line items and totals, we offer an optional text-repair fallback. The receipt photo stays on your device. We send only the OCR text (and confidence + bounding-box geometry) — never the image — to OpenAI under OpenAI's Modified Abuse Monitoring (MAM) retention setting. You can opt out at any time from the receipt scanner; opt-out users continue to use the on-device parser.
2.4 Biometric Data
- Face ID / Touch ID templates and Passkey (WebAuthn) public keys. These are stored in the iOS Secure Enclave and the device's iCloud Keychain; we do not collect or store raw biometric images. See Section 7 for our BIPA / CUBI / RCW 19.375 disclosures.
2.5 AI and Smart Notes Data
- Prompts, drafts, and outputs of Smart Notes, expense-categorization, and related AI Features. Processed by OpenAI, Anthropic, or Google under their respective Data Processing Addenda. We instruct those processors not to use your inputs to train their foundational models.
- Receipt text-repair inputs and outputs, when you choose to use the feature. See §8.1 for the dedicated disclosure (what leaves the device, what stays, retention posture, and opt-out).
2.6 Device, Usage, and Telemetry Data
- IP address, device identifiers (IDFV, advertising identifier only with consent), iOS version, crash logs, and in-app analytics from OneSignal, Vercel Web Analytics, and our own logs.
2.7 Communications Data
- In-app messages, support tickets, and emails to support@allospend.app or compliance@allospend.app.
2.8 SMS Communications Data
When you opt in to receive transactional SMS from Allospend (via the public opt-in page at https://allospend.app/sms-notifications or in-app at Settings → Notifications → SMS), we collect:
- Your mobile number in E.164 format (e.g.
+15551234567). - The version of the Terms of Service and Privacy Policy you agreed to at the moment of consent.
- A one-way SHA-256 hash of the IP address that submitted the form.
- A one-way SHA-256 hash of the User-Agent that submitted the form.
- The timestamp of consent and the source surface (web opt-in page, in-app, or admin import).
Raw IP addresses and User-Agent strings are never stored. The hashed values exist only to support fraud and dispute investigation, and they are excluded from routine analytics exports.
3. Purposes and Legal Bases
We process Personal Information for the following purposes (with the corresponding GDPR legal basis):
- Provide and operate the Service (Art. 6(1)(b) contract performance; Art. 6(1)(f) legitimate interest).
- Verify identity, prevent fraud, and comply with anti-money-laundering ("AML") and Bank Secrecy Act ("BSA") obligations (Art. 6(1)(c) legal obligation; Art. 6(1)(f) legitimate interest).
- Process payments, instant withdrawals, and Premium subscriptions (Art. 6(1)(b)).
- Provide AI Features and Smart Notes (Art. 6(1)(b); Art. 6(1)(f)).
- Provide the optional receipt text-repair fallback when the on-device parser cannot confidently produce line items or totals for a hard-to-read receipt (Art. 6(1)(b); Art. 6(1)(f)). Always opt-in from the receipt scanner and revocable at any time.
- Send transactional SMS notifications (payment reminders, withdrawal confirmations, security alerts) (Art. 6(1)(b); Art. 6(1)(f)).
- Provide customer support (Art. 6(1)(b)).
- Improve security and prevent abuse (Art. 6(1)(f)).
- Comply with legal process (Art. 6(1)(c)).
- Marketing (Art. 6(1)(a) consent in regions requiring it, otherwise Art. 6(1)(f) with opt-out).
4. How We Share Personal Information
We do not sell Personal Information for money or other valuable consideration, and we do not "share" Personal Information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act of 2018 (Cal. Civ. Code §§ 1798.100 et seq.) ("CCPA") as amended by the California Privacy Rights Act of 2020 ("CPRA").
We share Personal Information with:
- Payment processors: Stripe, Inc.; Plaid Inc.; Block, Inc. (Cash App); PayPal, Inc. (Venmo, PayPal); Apple Pay.
- Identity verification providers: Stripe Identity, Plaid Identity Verification.
- Infrastructure providers: MongoDB Atlas (database), Amazon Web Services S3 (file storage), Vercel Inc. (hosting), OneSignal (push), Resend (transactional email), SendGrid / Twilio SendGrid (transactional email backup).
- AI processors: OpenAI, L.L.C.; Anthropic PBC; Google LLC — acting as processors under Data Processing Addenda.
- Receipt text-repair: when you opt in, receipt text (and confidence + bounding-box geometry only — never the receipt image, your geolocation, your contact list, or your device fingerprint) is sent to OpenAI, L.L.C. under OpenAI's Modified Abuse Monitoring (MAM) retention setting described in §8.1.
- SMS sub-processor: Twilio Inc. — when you opt in to transactional SMS, your mobile number is shared with Twilio solely to deliver the messages described in §13 below. We do not share your mobile number with any other third party for their own marketing purposes.
- Professional advisors and auditors under confidentiality.
- Law enforcement and regulators when compelled by valid legal process.
- Acquirers in a merger, acquisition, or sale of assets.
Each sub-processor is bound by data-protection terms no less protective than those in this Policy. A current list is available at https://allospend.app/legal/subprocessors.
5. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know the categories and specific pieces of Personal Information collected, the categories of sources, the business or commercial purposes, and the categories of third parties with whom we share it (Cal. Civ. Code § 1798.110, § 1798.115).
- Delete Personal Information we collected from you, subject to statutory exceptions (§ 1798.105).
- Correct inaccurate Personal Information (§ 1798.106).
- Opt out of the sale or sharing of Personal Information. We do not sell or share; nevertheless, you may submit a request and we will honor it (§ 1798.120).
- Limit the use and disclosure of Sensitive Personal Information ("SPI") to that which is necessary to perform the services requested (§ 1798.121).
- Non-discrimination for exercising your rights (§ 1798.125).
- Designate an authorized agent to act on your behalf.
To exercise these rights, email privacy@allospend.app or use the in-app "Do Not Sell or Share" toggle. We will verify your identity before responding.
6. Other U.S. State Privacy Rights
We honor rights requests from residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states that have enacted comprehensive consumer-privacy laws, including the right to access, correct, delete, port, and opt out of targeted advertising, sale, and profiling.
7. Biometric Data; BIPA / CUBI / Washington
Allospend processes biometric data only as strictly necessary to provide biometric authentication (Face ID, Touch ID, Passkey) and only with your separate, written, informed consent captured at the moment you enable the feature. We do this in compliance with:
- The Illinois Biometric Information Privacy Act, 740 ILCS 14 ("BIPA") — we obtain written consent before collection, we do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information, and we retain biometric identifiers for the shorter of (a) the duration of your account relationship or (b) three (3) years after your last login, after which they are destroyed.
- The Texas Capture or Use of Biometric Identifier Act, Tex. Bus. & Com. Code § 503.001 ("CUBI") — we provide notice and obtain consent before capture and do not sell biometric data.
- The Washington biometric statute, RCW 19.375 — we provide notice, obtain consent, and do not sell biometric data.
Raw biometric templates (Face ID vectors, Touch ID templates) remain on your device in the iOS Secure Enclave; Allospend does not receive or store them. Passkey public-key material is stored by Apple's iCloud Keychain under your Apple ID.
8. AI / Smart Notes
When you use Smart Notes, expense categorization, or other AI Features, the prompts, drafts, and outputs are transmitted to OpenAI, Anthropic, or Google under their respective Data Processing Addenda for the purpose of generating the response. We instruct these processors not to use your inputs to train, fine-tune, or improve their foundational or general-purpose models, and not to retain inputs beyond the period required to provide the response. See our AI Terms for full disclosures under the EU AI Act (Regulation (EU) 2024/1689) and the Colorado AI Act (Colo. Rev. Stat. § 6-1-1701 et seq.).
8.1 Receipt Text Repair (Optional, Off by Default)
When the on-device parser returns a below-confidence result for a hard-to-read receipt, we offer a text-only repair by a third-party AI. This feature is off by default, opt-in per scan, and revocable at any time from the receipt scanner.
What leaves your device (only when you opt in):
- The OCR text your iPhone already extracted from the receipt (item names, prices, totals).
- The per-line confidence score and bounding-box geometry so the model can reason about layout.
- A redacted summary of what the on-device parser saw.
What does not leave your device:
- The receipt photograph itself.
- Your geolocation, your contact list, your device fingerprint, your advertising identifier, or any other category not listed above.
- Full text from other apps on your device.
What we redact on your iPhone before sending:
- Email addresses.
- US-format phone numbers.
- Card-like numeric strings (13+ digits, with optional spaces or dashes).
- The redactor is a safety net, not a guarantee. It catches the common patterns but it cannot catch every possible personal detail. If your receipt has a name, address, or other detail you would rather not share, leave the feature off.
Where the data goes and how long it stays:
- The redacted text is transmitted over TLS to OpenAI, L.L.C. and processed under OpenAI's Modified Abuse Monitoring (MAM) retention setting: OpenAI may hash inputs to detect abuse but does not retain the plain-text bodies after the response is returned.
- Allospend does not log, store, or back up the receipt text on our servers. We log only a minimal per-call event record (no receipt text) for metering, billing, abuse detection, and audit. The receipt text itself never hits our disk.
- We enforce per-call timeouts, per-user caps, and global caps on this feature so a single user cannot generate unbounded traffic.
- We can disable the feature on the server, on your device, or both, without an app release.
Zero Data Retention (ZDR). We have not enabled OpenAI's ZDR setting today. The default MAM setting is paired with the compensating controls above. If we enable ZDR, we will update this Policy and the App Store privacy labels.
Your choices:
- Turn it on for one scan — the in-app scan flow asks the first time it would route to the third-party repair.
- Turn it off forever — the receipt scanner's privacy settings. The on-device parser keeps working; you can still scan, split, assign, and pay. The on-device parser delivers a slightly lower success rate on the hardest receipts, by design.
- Withdraw consent — the receipt scanner's privacy settings remove the per-scan grant. You can re-enable later.
Why we offer this. Hard-to-read receipts are the difference between "we did the math in two minutes" and "we spent twenty minutes arguing about who had the side salad." We want the math to be right without making you re-type it. You lead. We handle the rest.
9. Children's Privacy
The Service is not directed to children under 13 and is not available to anyone under 18. We do not knowingly collect Personal Information from children under 13 in violation of the Children's Online Privacy Protection Act (15 U.S.C. §§ 6501–6506) ("COPPA"). If we learn that we have collected Personal Information from a child under 13, we will delete it within thirty (30) days of discovery. If you believe a child has registered, contact privacy@allospend.app.
10. International Data Transfers
The Service is operated from the United States. If you use the Service from outside the United States, you understand that your Personal Information will be transferred to, stored in, and processed in the United States. Where required, we use Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for transfers from the EEA / UK / Switzerland to the United States.
11. Security
We employ administrative, technical, and physical safeguards designed to protect Personal Information, including encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls, audit logging, and intrusion detection. No system is 100% secure; we cannot guarantee absolute security.
12. Retention
We retain Personal Information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods:
- Account and transaction data: while your account is active, plus seven (7) years for AML / tax / financial-record purposes (31 CFR § 1010.430(d)).
- Biometric identifiers: three (3) years after last login.
- AI prompts and outputs (Smart Notes): ninety (90) days from creation.
- Receipt text-repair data: Allospend does not retain the receipt text. OpenAI processes it under the Modified Abuse Monitoring (MAM) setting described in §8.1 and does not retain plain-text bodies after the response. Allospend retains only the minimal per-call event record described in §8.1 (no receipt text) for the same seven (7) year period as other transactional records for tax / fraud / audit purposes.
- Support tickets: three (3) years from closure.
- Marketing suppression: indefinitely, or until you opt back in.
13. SMS Communications
This section explains the SMS communications Allospend sends and your choices.
SMS is an optional notification channel. Opting in to receive SMS is never a precondition for creating an Allospend account, completing any transaction, or using any other Allospend feature. You can decline on the public opt-in page, decline in the iOS app, change your preference at any time in Settings → Notifications, or opt out later by replying STOP to any Allospend SMS. Declining has no effect on your ability to use Allospend.
13.1 What you will receive
When you opt in via the public opt-in page at https://allospend.app/sms-notifications (or in the iOS app at Settings → Notifications → SMS), Allospend sends transactional text messages only in the following categories:
- Payment reminders — a reminder before a group expense is due.
- Withdrawal confirmations — a confirmation when an organizer withdrawal completes.
- Security alerts — a one-time alert when a chargeback or dispute is filed on your account.
We do not send marketing, promotional, or non-transactional SMS from this opt-in. We do not send SMS to a phone number you have not opted in to receive them on.
13.2 The consent screen
The public opt-in page at https://allospend.app/sms-notifications presents an unchecked consent box, a phone number input, and two equally visible buttons:
- "Yes, opt me in" — enabled only after you check the box and provide a valid phone number.
- "No thanks, skip" — always enabled. Writes a decline audit record and shows a "No problem. We won't send you SMS" acknowledgement. Returns you to the rest of the site.
Inside the Allospend iOS app at Settings → Notifications → SMS, the same unchecked consent box is shown with an explicit "Skip" button alongside "Enable SMS notifications"; the SMS toggle is OFF by default.
Both surfaces link to this Privacy Policy and to the Terms of Service; both surface the message-frequency, "message and data rates may apply", and "we do not share your mobile number" disclosures before any consent can be recorded.
13.3 Frequency
Message frequency varies by use. Payment reminders are sent at most once per group per day. Withdrawal confirmations are sent per payout event. Security alerts are sent per dispute event. You may receive multiple transactional messages on the same day across different groups and events.
13.3 Message and data rates
Message and data rates may apply. Allospend does not charge you to receive SMS, but your mobile carrier may charge messaging or data fees. Contact your carrier for details.
13.4 We do not share your mobile number
Allospend does not share your mobile number with third parties for their own marketing purposes. We share your mobile number with our SMS sub-processor, Twilio Inc., solely to deliver the transactional messages described in this section. Twilio is bound by a Data Processing Addendum; see our Sub-Processor List §3.9 for the DPA reference.
13.5 How to opt out
You may stop receiving SMS from Allospend at any time by replying STOP, UNSUBSCRIBE, CANCEL, END, or QUIT to any Allospend SMS. We will send a one-time confirmation and no further non-security messages will be sent to that phone number. You may also disable SMS notifications from Settings → Notifications in the iOS app, or by emailing privacy@allospend.app.
Account-security exception — under 47 CFR §64.1200(a)(9), account-security messages (Verify OTP at login, withdrawal confirmation, dispute notification) may continue after a STOP reply because they are not "marketing or promotional." You may disable these messages in Settings → Notifications at any time, or by contacting us.
13.6 Help
Reply HELP to any Allospend SMS for support options, or email privacy@allospend.app, or visit https://allospend.app/help.
13.7 Where to verify and consent
You can read the current consent screen and submit opt-in at https://allospend.app/sms-notifications. The consent version is recorded against each consent record so that future policy revisions can be cross-checked.
14. Your Rights and How to Exercise Them
Depending on your jurisdiction, you may have the right to: access, correct, delete, port (data portability), opt out of sale/sharing/targeted advertising/profiling, limit use of SPI, and appeal a denial. Submit requests to privacy@allospend.app or via the in-app privacy controls. We will respond within forty-five (45) days (or such longer period as permitted by law). California residents may also use our "Do Not Sell or Share" mechanism in the App.
15. DMCA
If you believe content hosted by Allospend infringes your copyright, send a takedown notice under 17 U.S.C. § 512(c) to dmca@allospend.app, our designated agent registered with the U.S. Copyright Office. The notice must include the elements required by 17 U.S.C. § 512(c)(3).
16. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide at least thirty (30) days' prior notice by email and/or in-app notification. The "Last Updated" date reflects the most recent revision.
17. No Sale of Personal Information
We do not sell Personal Information. We do not share Personal Information for cross-context behavioral advertising. We do not knowingly sell or share the Personal Information of consumers under 16.
Contact Information
- Privacy / Data Protection Officer: privacy@allospend.app
- Customer Support: support@allospend.app
- Legal: legal@allospend.app
- General Information: info@allospend.app
- Compliance / AUP reports: compliance@allospend.app
- Disputes: disputes@allospend.app
- DMCA designated agent: dmca@allospend.app
- App Store: https://apps.apple.com/app/allospend-group-finances/id6795749022
- Domain: https://allospend.app
- Sub-processor list: https://allospend.app/legal/subprocessors
Allospend Technologies LLC
725 Kingsland Avenue, Suite 100
St. Louis, MO 63130
USA
© 2026 Allospend Technologies LLC. All rights reserved.