Privacy Policy

Last updated September 11, 2026

This policy describes how Expense Agent, a private personal-finance application operated by Chris Lew, accesses and uses data. Expense Agent is not offered as a public service.

Information the application accesses

Expense Agent may access the following information when authorized by the owner:

How information is used

The application uses this information only to import transactions, identify duplicates and transfers, categorize expenses, maintain monthly expense records, and calculate personal spending summaries.

Gmail access is read-only. The application limits its Gmail search to messages from Venmo and extracts only information needed to record a transaction. It does not modify or send email.

Storage and processing

Expense Agent runs on the owner's computer. Transaction records, identifiers, configuration, and authorization tokens are stored locally. Categorized transaction information is written to Google Sheets selected by the owner.

When a transaction cannot be categorized by a local rule, limited fields such as the merchant or transaction description, amount, direction, and allowed category list may be sent to the OpenAI API solely to suggest a category. Google authentication credentials and complete email messages are not sent to OpenAI.

Sharing and sale of information

Information is not sold, used for advertising, or shared with data brokers. Information is disclosed only to service providers necessary to perform the functions described above, including Google, Plaid, and OpenAI.

Retention and deletion

Information remains in the owner's local database and selected spreadsheets until the owner deletes it. The owner can delete local records, spreadsheet records, and stored authorization tokens at any time.

Google API data

Expense Agent's use and transfer to any other application of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Security and access control

Access is restricted to the application's owner. Credentials and tokens are kept out of the public website and source-control history. No method of electronic storage or transmission is guaranteed to be completely secure.

Your choices

The owner may revoke Google access through the Google Account connections page, disconnect linked Plaid accounts, or stop running the application.

Changes

This policy may be updated when the application's data practices change. The revision date at the top of this page will identify the latest version.