Privacy Policy
How Spentlo handles your information
Last updated: August 21, 2026
This policy explains what Spentlo collects, why it is needed, how it is protected, when it may be shared, and the choices available to you. It is written for Australian users and is intended to support the Australian Privacy Principles and applicable Consumer Data Right obligations. The Terms of Service explain the rules for using Spentlo.
Privacy at a glance
Purpose
Spentlo uses information to provide the planning, forecasting, household, security and support features you request.
Control
You decide what to add and whether to connect a provider. You can disconnect, reset, export or delete through available controls.
Security
Passwords are hashed, production sessions are protected, and sensitive server records are encrypted at rest.
1. Information we collect
Spentlo collects information you provide, information created when you use requested features, and limited technical information needed to operate and protect the service.
- Account information: name, email, optional phone number, birthday, optional profile details, password hash, verification status, two-step verification settings and passkey records. Your birthday confirms age eligibility, can personalise an in-app birthday moment when you enable that preference, and can calculate private age milestones when you separately enable retirement planning.
- Household information: members, roles, invitations, linked people and access approvals.
- Information you add for planning: income, spending, accounts, assets, investments, loans, goals, bills, uploaded transaction records, notes and forecast preferences.
- Optional connected data: consent details, connected account metadata, balances and transactions supplied by an enabled bank-data provider after you choose to connect.
- Support information: the name, email, topic and message you submit through the public contact form, plus in-app feedback, ratings, attachments and whether you agree to follow-up.
- Technical and security information: browser and device details, request times, IP address, session records, failed sign-in attempts, security events and error diagnostics.
2. How we use information
Spentlo uses information to:
- create, authenticate and protect your account;
- provide the household planning, calculations, reports and connected features you choose to use;
- manage consent, verification, recovery and household permissions;
- respond to support requests and improve reliability;
- send product messages only where you have chosen to receive them; and
- meet security, fraud-prevention, legal and regulatory obligations.
3. Calculations and optional AI features
Spentlo can calculate forecasts, savings rates, goal capacity, loan projections, interest estimates and other planning insights from information available in your workspace. If you enable retirement planning, Spentlo uses your saved birthday locally to estimate your age at loan payoff and retirement milestones using assumptions you control. These outputs are informational and are not financial, tax, legal or investment advice.
If you submit a question to an externally configured AI feature, Spentlo sends only the reduced household summary and question needed to generate the response. Your raw birthday and bank login credentials are never included. Derived retirement results are included only when you choose that option in the planner. If an external provider is unavailable, Spentlo may use a local rules-based response instead.
4. Optional bank linking and Yodlee
Bank linking is optional. Where enabled, Spentlo uses Yodlee, an Envestnet company, to present the connection and consent experience and to retrieve the account information you authorise. Spentlo does not ask for or store your internet banking password.
For supported Australian Open Banking connections, you choose the accounts, data and consent period presented in the provider flow. Available controls let you review or revoke a connection. Yodlee also processes information under its own privacy and security terms.
5. How information is stored and protected
Spentlo uses safeguards designed to protect information, including HTTPS in production, password hashing, HttpOnly session cookies, sign-in rate limits, optional two-step verification, role-based household access, restricted administrator access and server-side encryption for sensitive stored records.
No internet service can guarantee complete security. Use a strong unique password, enable two-step verification where available, sign out on shared devices and keep your device software current.
6. When information may be shared
Spentlo does not sell personal information. Information may be disclosed only as reasonably needed to:
- service providers that host, store, secure, monitor, email or otherwise operate Spentlo;
- a bank-data provider when you choose to connect an account;
- members of your household according to the roles and approvals you choose;
- professional advisers, insurers or authorities where reasonably necessary; or
- another party with your consent or where required by law.
Public contact-form messages are sent to Spentlo's fixed support inbox through the configured email provider. They are not added to your household finance workspace, although the provider and support mailbox may retain the message as needed to deliver and answer it.
7. Overseas processing
Some service providers may process information in Australia or overseas. The locations depend on the providers enabled for hosting, email, monitoring, bank data and optional AI features. Spentlo aims to use reputable providers with appropriate contractual and technical safeguards.
8. Cookies and browser storage
Spentlo uses an HttpOnly cookie for the signed-in server session and limited browser storage for interface preferences, release notices and temporary app state. The logged-out page does not contain your private workspace. Blocking cookies or browser storage may prevent account access or preferences from working correctly.
9. Access, correction, connection controls and deletion
You can update many profile details, manage household access and disconnect supported providers from within Spentlo. A workspace reset clears eligible planning information while keeping login and security details. Full account deletion removes the account and saved workspace data, subject to limited retention needed for backups, security, fraud prevention, legal or accounting obligations.
For help accessing or correcting information, email support@spentlo.com.
10. Retention
Spentlo keeps information only for as long as needed for the purposes in this policy, an active consent, support correspondence, security and recovery, or applicable legal obligations. Connected-data retention settings may be shorter than general account retention. Backups are removed through their normal secure rotation schedule.
11. Children
Spentlo is intended for people aged 18 or older. People under 18 should not create an account.
12. Questions and complaints
Send privacy questions, correction requests or complaints to support@spentlo.com. Spentlo will aim to respond within a reasonable period. If you are not satisfied, you may contact the Office of the Australian Information Commissioner.
13. Changes to this policy
This policy may be updated as Spentlo and its providers change. The latest version and update date will remain available on this page.