SpendTrail Privacy Notice
Effective date: 2026-09-10
Central policy: SentiDawn Privacy Policy
SpendTrail is a SentiDawn product. This SpendTrail Privacy Notice supplements the SentiDawn Privacy Policy (https://www.sentidawn.com/privacy) with details about data in SpendTrail. Where this notice is more specific, it governs that data; where it is silent, the SentiDawn Privacy Policy applies. This notice does not take away any right given by that policy.
1. Information SpendTrail records
Sign-in identity, account and role data, and operational logs are covered by the SentiDawn Privacy Policy (https://www.sentidawn.com/privacy). The following records are specific to SpendTrail, and each is held for the account that recorded it.
- Documents you upload — images of bank transfer or payment slips, and PDF credit-card statements — together with the file name, size and a content hash used to detect the same file being uploaded twice. Files are kept in SpendTrail's file store; where the object store is in use, each file is sealed with an encryption key specific to your account.
- What is read off a slip — the transaction reference, whether it was a transfer or a payment, the paying and receiving account numbers and names as printed on the slip, the date, time, amount and fee, the bank, a merchant reference, the memo, the contents of the slip's QR code, and whether it was marked as an e-donation. A slip names the other side of a transfer; SpendTrail records what is printed on the document you upload.
- What is read off a credit-card statement — the masked card number, billing period, statement total, reward-points balance and expiry, and for each line its dates, description, amount and currency. A statement is held as a staged reading until you confirm the import; only then does it become records.
- Sources of fund — the bank accounts and cards you create, with the identifier, display name and bank you enter for each.
- How you organise your records — categories, tags, classification rules, the category overrides and tags you apply by hand, card groups, billing-cycle settings, and which model reading produced each record.
- Transactions you enter by hand — the transaction reference, transfer or payment type, the paying and receiving account numbers and names, date, time, amount and fee, bank, merchant reference and memo, whether it was an e-donation — plus a remark.
- Statement passwords you choose to save, so that password-protected statements can be opened for you. Saving one is optional. They are stored encrypted (AES-256-GCM) and are used only to open your own statement PDFs.
- Which of your files are in Trash, and when they were put there.
2. How SpendTrail uses this information
- To read your documents: SpendTrail sends the slip image, or the text extracted from a statement PDF, to an AI model that reads the fields listed above off it. The administrator sets which model is used by default; you can choose a different one for a given reading. The model's reading is an aid; the records it produces are yours to review.
- To recognise a document uploaded twice, by its content hash, and a slip already recorded from another file, by its transaction reference together with the paying and receiving account numbers.
- To classify your records into expense, non-expense and donation using the categories, rules, overrides and tags you set, and to show you summaries of your spending by period, account, card and category.
- To send reminders about uploading slips through SentiDawn's notification service. Reminders are on unless an administrator turns them off, and an administrator sets their schedule. To send one, SpendTrail passes your email address, the date of your last upload and the number of days since it to that service.
3. Who can see what
- You see your own documents and records. No other account can see them: there is no sharing between accounts in SpendTrail, and nothing an account records is visible to another.
- Administrators manage accounts, system settings, the AI model and prompt configuration, and storage maintenance. SpendTrail gives administrators no screen for browsing another account's documents or records.
- You can connect an AI assistant to your account through MCP, from the Connect page; the connection is set up through SentiDawn's identity service. Everything the assistant does is done in your account, with your records only. SpendTrail passes the assistant's credential to the identity service to check it on each call and does not keep it.
4. How long SpendTrail keeps it
Account data and operational logs follow the retention rules in the SentiDawn Privacy Policy (https://www.sentidawn.com/privacy). Within SpendTrail:
- A file you move to Trash can be restored by you. Trash has no expiry: nothing in it is purged on a schedule.
- A statement reading becomes records when you confirm the import. Reading the statement again replaces its current reading — including records already confirmed from it, which are removed and staged again until you confirm.
- A saved statement password stays until you remove it.
5. Your rights
Your data rights and how to exercise them are set out in the SentiDawn Privacy Policy (https://www.sentidawn.com/privacy).
6. Contact
For questions about this SpendTrail Privacy Notice, contact SentiDawn at [email protected].
7. Changes to this notice
The current version of this notice and its effective date are published on this page. The SentiDawn Privacy Policy (https://www.sentidawn.com/privacy) also applies.