EasyExpense

Privacy, in plain words.

Effective September 24, 2026

This policy covers EasyExpense Budget & Ledger and this support website, provided by BrightEng (Sihan Teng). Contact: contact@brighteng.org.

Your ledger

Expenses, budgets, wallet names, rules, and saved receipts are stored on your device. If you enable personal iCloud sync, your personal ledger is synchronized through your private iCloud database. The app does not send your ledger to a separate BrightEng server.

A family ledger uses Apple CloudKit sharing. Participants you authorize can read shared entries and receipts; those with edit permission can change them. Your personal workspace remains separate. The owner controls invitations and removal.

Invitations and identifiers

Family invitation lookup uses CloudKit’s public database to store the family name, invitation code, CloudKit share link, zone identifiers, and creation metadata. These records support finding and accepting an invitation; they do not contain your expense amounts, merchant names, or receipt images. Do not place sensitive information in the family name or share invitation codes publicly. Ledger access still requires Apple’s share authorization.

Sign-in and subscriptions

Sign in with Apple is optional. The app stores the identifier and any name or email Apple provides on your device. Apple handles authentication and App Store payments; EasyExpense does not receive your Apple password or payment-card details. StoreKit provides verified subscription entitlements so the app can enable paid features.

Apple Family Sharing of a purchase is separate from CloudKit ledger access. A subscription does not automatically give another person access to your personal or family transactions.

Photos, camera, and exchange rates

Receipt recognition uses Apple Vision on your device. Saved receipt photos are included in the chosen ledger and can sync or be shared with that ledger. Camera or photo access is used when you choose to scan or attach an image.

Automatic exchange-rate requests use Frankfurter. Requests contain currency codes and, where needed, a rate date. They do not contain your transaction amount, merchant, notes, or receipt. Like other network services, the provider receives connection information such as an IP address.

Diagnostics and contact

The app does not contain advertising or third-party analytics SDKs, and does not track you across other companies’ apps or websites. Diagnostics are exported only when you request them; they contain versions, sync status, and counts, not ledger contents or account identifiers. If you email support, we receive your email address and the information you choose to send. We use it to answer your request and resolve the issue.

Retention, deletion, and your choices

You control whether personal sync is enabled, which ledger receives an expense, and who can access your family ledger. Deleting an entry removes it from that ledger; synchronization and retained deletion markers help prevent deleted entries from reappearing. Exported files and copies already saved by other people remain under their control.

In the app, open Settings → Data & Tools → Account & Data Deletion to delete saved Apple profiles and, if selected, the personal ledger. Personal ledger deletion includes saved receipts, splits, wallets, budgets, bills, and rules. If personal iCloud sync is enabled, deletions propagate when the app reconnects; when sync is disabled, manage existing cloud copies separately in iCloud settings. Family records are separate: use Family Ledger to delete shared entries, leave, or end sharing as owner.

You can remove app data from your device through iOS Settings and manage stored iCloud data through your Apple Account settings. Removing a local app installation does not by itself delete existing iCloud data. Apple Account settings also let you stop using Sign in with Apple. Deleting app data does not cancel an App Store subscription.

For assistance with a privacy or deletion request, email contact@brighteng.org. We do not sell personal information. We retain support messages only as needed to handle the request and any applicable recordkeeping obligations.

This website

This static website is hosted on Cloudflare Pages. It has no analytics scripts, advertising, forms, or tracking cookies added by BrightEng. Cloudflare may process technical request information to deliver and protect the site. See Cloudflare’s privacy policy. Linked services have their own privacy terms.

Changes

We will update this page when data handling changes and show the revised effective date. Material changes will also be reflected in the app or its App Store information where appropriate.