REXO Privacy

Privacy Policy

REXO is built as a privacy-focused finance product. The app supports optional AI features, but it is designed to minimize transmitted user data and to avoid collecting financial account authentication secrets.

Optional AI onlyNo banking credentials collectedDelete account in app
Quick summary
  • Users control whether remote AI analysis is enabled.
  • OpenAI and DeepSeek are used only for user-invoked AI requests.
  • Subscription state is handled through RevenueCat and the App Store.
  • Cloud sync is tied to sign-in rather than silent background collection.
Product

REXO: AI Expense Tracker

Effective Date

June 10, 2026

Support

support@rexo.app

AI is optional

Receipt scan, transaction categorization, and AI insights run only when the user explicitly chooses those features.

No bank credentials

REXO does not request or transmit online banking usernames, passwords, PINs, CVV values, or bank authentication secrets.

Delete account in-app

Signed-in users can delete their cloud account and synced finance data from Settings inside the iOS app.

1. Information REXO handles

REXO is a personal finance app. Depending on how you use it, we may handle profile details for sign-in, manually entered transactions, account names, balances, subscription records, savings goals, receipt images, OCR text, device-level settings, and product diagnostics.

  • Core finance data is created directly by the user.
  • Cloud data is only used when the user signs in and chooses synced features.
  • Subscription status is handled to unlock paid app features and restore purchases.

2. How we use information

We use information to operate the product, sync the user account across devices, restore subscriptions, generate receipt drafts, categorize transactions, improve reliability, prevent abuse, and respond to support issues. We do not use transaction content for advertising.

3. Third-party processors and infrastructure

REXO uses specialized processors only for the parts of the service they support. These providers receive only the data reasonably required for that task.

  • Supabase: authentication, account session management, and optional cloud sync.
  • RevenueCat: subscription state, entitlement status, and restore-purchase handling.
  • OpenAI and DeepSeek: optional AI-assisted categorization, receipt extraction, and finance insight generation.
  • PostHog or similar analytics tooling: privacy-scrubbed product telemetry for stability and feature quality.

4. AI Services and Data Processing

REXO uses third-party AI services to provide optional receipt analysis, spending insights, smart categorization, and AI coaching. Before any third-party AI request is sent, REXO presents an in-app disclosure and requires the user to agree. When a user invokes an AI feature, limited data needed for that request may be securely sent through REXO backend services to OpenAI and/or DeepSeek.

  • Information shared may include receipt images or text, merchant name, transaction amount, currency, date, category, notes, and summarized spending patterns.
  • This information is shared only to provide the specific AI-powered feature requested by the user.
  • REXO does not send bank login credentials, card numbers, passwords, Apple ID, or payment authentication information to AI providers.
  • Users can decline consent or revoke it at any time from Settings > AI & Privacy. Third-party AI requests remain blocked while consent is disabled.
  • AI provider credentials remain server-side. REXO applies authentication, consent checks, data minimization, and rate limiting before provider requests.

5. What REXO does not collect for AI

REXO does not support bank-linking credentials and does not request or transmit bank usernames, bank passwords, card numbers, CVV values, ATM PINs, or other financial account authentication secrets for AI processing.

6. Analytics and minimization

REXO is designed to minimize transmitted financial content. Product analytics are configured to avoid raw amounts, merchant names, free-form notes, balances, passwords, phone numbers, and email content whenever those fields are not required for the event.

7. Retention and deletion

Finance data stored only on the device remains local until the user edits, deletes, or removes the app. When cloud sync is used, synced records remain in the backend until the user deletes them, deletes the cloud account in-app, or requests support assistance. Subscription and audit records may be retained for billing integrity, fraud prevention, legal compliance, and support operations.

8. User controls

Users can review or change notification settings, subscription status, privacy links, and AI preferences inside the app. Signed-in users can also delete their cloud account from the Settings screen. Users can contact support for privacy questions or operational deletion requests.

9. Security

REXO uses reasonable technical and organizational safeguards intended to protect account access, synced data, and service operations. No internet-based service can guarantee absolute security, so users should also secure their device, operating system, and sign-in credentials.

10. International transfers

Because infrastructure or service providers may operate in multiple countries, user information may be processed outside the user’s home jurisdiction. Where applicable, REXO uses contractual and operational measures intended to protect data during those transfers.

11. Changes to this policy

We may update this Privacy Policy when the product, legal requirements, or operational practices change. The effective date at the top of this page will be updated when material revisions are published.

12. Contact

For privacy questions, support requests, or operational deletion assistance, contact support@rexo.app.

Hosted policy for App Store disclosure and in-app privacy access.Terms of Use