Skip to main content

Last updated: September 30, 2026

This Privacy Policy explains how The Bearded Coder LLC ("we", "us", or "our") collects, uses, shares, and protects personal information when you use Whittle, our expense-tracking application, and related websites (the "Service"). For the personal data you enter into your account, The Bearded Coder LLC is the data controller. If you have any questions, contact us at thebeardedcoderco@gmail.com.

Information we collect

  • Account & profile data: your name, email address, password (stored only as a secure hash), and (where you provide them) your business or organization name, business mailing address, and profile picture.
  • Financial records you enter: expenses, income (the date, who paid you, the amount, and any notes for each payment you record), budgets, mileage, and the receipt or document images you upload. Uploaded files are private and are served only through an authorized request that verifies you own them; they are not exposed at public URLs.
  • Imported transactions: when you use the import feature, the bank or card transactions you upload (transaction date, description, and amount), which you can match to existing expenses or turn into new ones.
  • Billing data: handled by our payment processor, Stripe. We never store full card numbers; we retain only your Stripe customer and subscription identifiers and limited card metadata (brand and last four digits) needed to display and manage your subscription.
  • Team data: if you create or join an organization account, we store membership and role information and the email addresses you invite, so we can send and manage invitations. In an organization, owners and admins can see the income that members record in it, in the Net profit tile and the income CSV.
  • AI usage records: when an AI feature runs for your account, we record which feature ran and how much it used (such as token counts) so we can enforce your plan's usage quotas.
  • Feedback & support messages: the feedback you submit through the app and the messages you send us for support, so we can respond and improve the Service.
  • Technical & usage data: your IP address, your browser and device type (user-agent), the essential cookies that keep you signed in and protect form submissions (session and CSRF), your most recent sign-in time, and your email preferences (such as whether you have opted out of product-update emails). We also keep audit logs of sensitive actions (see Activity & security logs below), and our application error logs can contain an IP address; we use them only to troubleshoot problems.
  • First-party page-view analytics (only with your consent): if you choose "Accept all" in our cookie notice, we record which of our public pages are viewed (never your activity inside the app), the referring website (if any), campaign tags in the link you followed (utm parameters), and a randomly generated visitor identifier stored in a first-party cookie (see Cookies below). We collect this ourselves, server-side; it is stored only in our own database, contains no name, email, or other personal details, and is never shared with or sent to any third party.
  • Account milestones: separately from page-view analytics, and whatever you choose in the cookie notice, we record a small set of events tied to your account: signing up, verifying your email, logging your first expense, your first receipt scan, starting checkout, subscribing or changing plans, your trial ending, and requesting a free-tool email. We use them to run billing (for example, the "your price since" line on your subscription page) and to understand how people sign up. They are stored only in our own database, include the analytics visitor identifier only if you have accepted analytics cookies, and are deleted after 25 months.
  • Free-tool emails: if you use one of our free tools (such as the self-employed tax estimator or the mileage deduction calculator) and ask us to email your results, we store the email address you enter and which tool it came from, and we record that a tool email was requested (see Account milestones). The figures you type into a calculator are used only to write that email: they wait in our outgoing mail queue until it is sent and are not kept once it goes out. If a send fails, the queued message (your email address and those figures) stays in our failed-mail log until we clear it. You receive that single email; we do not add you to any mailing list. Tool email addresses are deleted automatically after 24 months, or sooner if you ask us to remove yours.

How we use it

We use this information to provide and secure the Service, create and manage your account and team, process payments and subscriptions, send transactional email (such as account verification, password resets, team invitations, budget alerts, trial reminders, and payment-failure notices), respond to support requests and feedback, understand how the Service is used (through our own first-party analytics, which never leave our database), and comply with our legal obligations. We may also send occasional product-update emails, which you can opt out of at any time using the unsubscribe link in each message. Where your plan includes AI features, we also process your receipts and expense data to read receipts, suggest categories, answer your questions, and generate insights (see AI features below). We do not sell your personal data, and we use no advertising or third-party tracking cookies.

AI features

Some features use artificial intelligence to save you data entry: receipt scanning, automatic categorization, quick-add (describing an expense in a sentence), the "ask your expenses" assistant, monthly insights, and the one-line takeaway on your Snapshot. The content each one needs (for example, a receipt image, the sentence you typed, or the expense data required to answer your question or build your insights) is sent to our AI provider, Google Cloud (Vertex AI, using Google's Gemini models), to process on our behalf. Google handles this data as our subprocessor under its enterprise terms and does not use it to train its models. No AI feature reads your income log.

Some of this happens when you ask for it: tapping Scan or Suggest, using quick-add or the assistant, or generating insights. On plans that include the feature involved, and during a free trial, some of it also happens automatically:

  • When you pick a receipt while adding an expense, or on the mobile capture screen, it is scanned right away (once per page).
  • When you open your Snapshot, a one-line takeaway is written from summary figures: your totals, your top categories, and your budget status.
  • On the 1st of each month, a summary of the previous month is sent to build your monthly insights: category totals, budget figures, and the descriptions and amounts of budget entries you did not log as expenses, including entries added from imported bank transactions.
  • When you create an expense or a budget entry from an imported transaction, its description is sent to pick a category.

If your plan does not include AI features, none of this runs on your account. Receipt photos are re-encoded before they are sent, which removes hidden photo metadata such as camera details and location. PDF receipts are sent as uploaded, so any document properties embedded in the file (for example an author name or the tool that created it) are included in what Google processes on our behalf. If you prefer, upload a photo of the receipt instead. If you use voice dictation with quick-add, the speech-to-text step is performed by your browser, not by Whittle. In most browsers the recording is sent to the browser maker's own speech service (Google for Chrome, Microsoft for Edge, Apple for Safari) and handled under that company's privacy terms; some newer browsers can transcribe on your device instead. The audio itself never reaches Whittle or our AI provider; we receive only the final text you submit. Dictation is optional, and typing works the same everywhere. AI output can be wrong or incomplete, so you should review and confirm it before relying on it, and it is not professional tax, accounting, or financial advice (see our Terms of Service).

Legal bases (GDPR)

Where the EU/UK GDPR applies, we process personal data on these bases: performance of a contract (to deliver the Service you sign up for), legitimate interests (to secure, maintain, and improve the Service and prevent abuse), legal obligation (such as tax and accounting record-keeping), and consent (where we ask for it, for example optional communications, which you can withdraw at any time).

Cookies

We use a small number of first-party cookies only:

  • Essential cookies: a session cookie to keep you signed in, a CSRF token to secure forms, and a small cookie that remembers your cookie choice itself.
  • An optional analytics cookie (whittle_vid), set only if you choose "Accept all" in our cookie notice: a randomly generated identifier that lets us count how many people visit our public pages (such as the home and pricing pages, but never your activity inside the app). It contains no personal information and is not derived from anything about you; the page-view data it is tied to lives only in our own database and is never shared with anyone. It expires after about 13 months, and the data it collects is deleted on the schedule described under Data retention. If you choose "Essential only", this cookie is not set and no page views are collected at all.

You can change your choice at any time via the Cookie preferences link in the page footer. We don't use advertising cookies, third-party analytics, or tracking pixels, and no outside analytics service ever sees your visit. The content-delivery networks listed under Sharing & subprocessors do receive a request each time your browser loads a file from them.

Browser storage

Separately from cookies, a few things are kept by your own browser on your own device. None of it is a cookie, so none of it is sent to us with your requests, and none of it is ever transmitted anywhere:

  • An unfinished receipt capture. While you are filling in the mobile capture page, what you have typed or had scanned (description, business purpose, amount, category, date, miles, and the itemized notes read off the receipt) is held in your browser's session storage, so an incoming call or an accidental tap does not lose it. The receipt photo itself is never stored. It is cleared when you save the expense, when you discard it, and automatically when you close the tab. It is also removed if a different person or a different account is using the browser.
  • Your light or dark theme choice, so the right one is applied before the page paints rather than flashing the wrong one.
  • Whether you dismissed the trial banner, remembered per account so it does not reappear on every page, though it returns when the trial is nearly over.
  • An offline page. The app's service worker keeps a single page in your browser's cache, the "you are offline" notice, so it can show it when you lose your connection. It contains no personal information.

You can clear all of it at any time through your browser's "clear site data" or "clear browsing data" controls, and doing so has no effect on your account or your expenses.

Sharing & subprocessors

We share data with the providers that help us operate the Service. These are bound by a data-processing agreement and may use the data only on our instructions:

  • Stripe: payment processing and subscription billing.
  • Mailgun: delivery of transactional and operational email.
  • Bluehost: hosting of the application and storage of your data and uploaded files.
  • Google Cloud (Vertex AI / Gemini): AI processing for receipt scanning, categorization, the assistant, insights, and the Snapshot takeaway, including the automatic steps described under AI features (not used to train Google's models).

A few other services also receive limited data, without a data-processing agreement with us:

  • Google (Gmail): our support inbox. It receives the emails you send us and the feedback you submit in the app.
  • Content-delivery networks: jsDelivr (Bootstrap), Google Hosted Libraries (jQuery), and Fonticons (the Font Awesome icon kit) serve the open-source code and icons that load on every page, and Google Fonts supplies a font stylesheet that some email apps load when you open one of our emails. Like any site your browser contacts, they receive your IP address and browser details, and may count requests, under their own privacy terms. We send them nothing else.

We may also disclose information if required by law or valid legal process, to protect the rights, safety, or property of our users or the public, or as part of a merger, acquisition, or sale of assets, in which case we will continue to protect your information and notify you of any change in control or applicable policy.

International transfers

We and our providers are based in, or process data in, the United States. If you access the Service from outside the United States, your information will be transferred to and processed there. Where required, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) for these transfers.

Activity & security logs

To keep accounts secure and meet our compliance obligations, we keep a log of sensitive actions, including: successful and failed sign-ins, viewing of receipts, audit-binder views, tax exports and income exports, AI feature usage, transaction imports and import reviews, budget entries made from imports, expense submissions, approvals, rejections, and reimbursements, feedback submissions and our handling of them, membership and ownership changes, billing and payment events from Stripe, data exports and deletions, and any staff access to your account. Each entry records the account, who performed the action (where known), their IP address and browser details, the time, the record affected, and details that can include an email address, a file name, a plan, or a Stripe reference and amount. These logs are used only for security, troubleshooting, and compliance, and are automatically deleted after 12 months. If you delete your account, these log entries are kept for the remainder of that 12 month window in a de-identified form: they are unlinked from your user record, and stored IP addresses, browser details, and personal details such as email addresses are erased. What remains is an anonymous record that an action of a given type happened at a given time.

Data retention

We keep your data while your account is active. Receipts, financial records (including your income entries), and imported transactions are retained for as long as you keep them; when you delete a record, it is removed from the live Service promptly. We may retain limited records where the law requires it. Activity & security logs are kept for 12 months. First-party analytics data is deleted automatically on a rolling schedule: individual page views after 13 months, and account milestone records after 25 months. Email addresses captured by our free tools are deleted after 24 months.

When you delete your account, we permanently remove your data from the live Service promptly, with these exceptions. Security log entries are retained in the de-identified form described under Activity & security logs until they expire at 12 months. Records you added inside an organization you do not own belong to that organization and stay with it. Stripe keeps its own records of your past payments under its legal obligations. Our database backups are rotated on a schedule, and the oldest is deleted after about 31 months, so deleted data ages out of them within that time. Uploaded files, such as receipts, are also covered by our hosting provider's own backups, which it rotates on its own schedule.

Security

We protect your data with industry-standard measures: all traffic is encrypted in transit over HTTPS/TLS, passwords are stored only as secure hashes, each account's data is isolated from others, and uploaded receipts and profile images are accessible only through authorized requests rather than public links. We log sensitive actions as described above. No system can be guaranteed perfectly secure, but we work to safeguard your information and to address issues promptly.

Your rights (GDPR / CCPA)

Depending on where you live, you may have the right to access, export, correct, delete, restrict, or object to our processing of your data, to data portability, to withdraw consent, and to lodge a complaint with your local data-protection authority. We do not discriminate against you for exercising these rights. You can act on the main ones directly:

  • Sign in to export or delete your data, or email us to make a request.

For any other request, email us and we will respond within the timeframe required by applicable law.

Children

The Service is intended for users aged 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version here with a new "Last updated" date and, for material changes, notify you by email or in-app. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.

Contact

Questions or requests: thebeardedcoderco@gmail.com. See also our Terms of Service.