Privacy Policy
1. Overview
Oweize ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains what personal information we collect, how we use and disclose it, your rights, and how to contact us.
Oweize is a personal finance application that helps users track shared expenses, split bills, and manage budgets. The app does not process payments, move money, or act as a financial institution. Users record payments that occur through external services (e.g., Venmo, Zelle, bank transfers, cash).
By using Oweize, you consent to the practices described in this policy. If you do not agree, do not use the app.
2. Information We Collect
2.1 Information You Provide Directly
- Account information: Full name, email address, phone number (with country code), preferred currency -- used for account creation, authentication, notifications, and friend matching.
- Profile information: Gender (optional), profile avatar (optional) -- used for avatar generation and user identification.
- Authentication data: Google ID (if using Google Sign-In), Apple ID (if using Apple Sign-In) -- used for social login.
- Financial information (user-entered): Expense descriptions, amounts, categories, income sources, settlement records, payment method handles (e.g., Venmo username, Zelle phone/email, CashApp handle, UPI ID, bank transfer details) -- used for expense splitting, budget tracking, and displaying payment information to friends.
- User-generated content: Receipt images, bank/credit card statements (CSV or PDF), expense notes, group names -- used for receipt parsing, expense verification, and budget analysis.
- Contacts (optional): Phone numbers and email addresses from your device contacts -- used for finding friends already on Oweize.
- Communications: Support requests, feedback, survey responses -- used for customer support and product improvement.
2.2 Information Collected Automatically
- Device and technical data: Device type, operating system version, device name, device push token (Expo), platform (iOS/Android/Web), IP address -- used for session management, push notifications, rate limiting, and security.
- Usage and analytics data: Page views, browser information, interaction data, app usage patterns -- collected via Segment for analytics and product improvement.
- Financial data (via Plaid): Bank account names, types, balances, credit limits, transaction history (up to 730 days), merchant names, amounts, dates, and locations -- used for budget tracking dashboard and automated expense categorization.
2.3 Information from Third Parties
- Google: Google user ID, email, name, profile picture URL -- received during Google Sign-In.
- Apple: Apple user ID, email -- received during Apple Sign-In.
- Plaid: Bank account and transaction data (see Section 2.2) -- received for the Budget feature.
3. How We Use Your Information
We use your personal information for the following purposes:
- Provide and operate the service: Account creation, authentication, expense splitting, budget tracking, friend matching, notifications.
- Communicate with you: Transactional emails (login OTP, welcome emails, account notifications), SMS OTP verification, support responses.
- Improve the product: Analytics, usage analysis, feature development, bug fixes.
- Security and fraud prevention: Rate limiting, session management, detecting unauthorized access.
- Legal compliance: Responding to legal requests, complying with applicable laws and regulations.
We do not sell your personal information to third parties.
4. How We Disclose Your Information
4.1 Service Providers
We share personal information with the following third-party service providers to operate the app:
- Plaid: Bank account connection and transaction retrieval. Data shared: internal user ID, country codes. Plaid receives bank credentials directly from you.
- Twilio: SMS OTP verification. Data shared: phone number and OTP message content.
- SendGrid: Transactional and marketing emails. Data shared: email address, name, OTP codes, promotional codes.
- Expo: Push notifications. Data shared: device push token, notification content.
- AWS S3: File storage for profile avatar images and receipt images.
- AWS Bedrock (Claude AI): AI-powered data extraction from receipts and bank statements. Data shared: receipt images, bank/credit card statement content.
- Google: Google Sign-In authentication.
- Apple: Apple Sign-In authentication.
- Segment: Web analytics. Data collected: IP address, browser info, page views, usage patterns.
- Vercel: Hosting, backend API, scheduled tasks.
4.2 Other Disclosures
We may also disclose your personal information:
- With your consent: For example, when you choose to share payment method handles with friends.
- To protect rights and safety: If we believe disclosure is necessary to prevent fraud, protect our rights, comply with law, or respond to legal process.
- Business transfers: In connection with a merger, acquisition, or sale of assets, subject to appropriate privacy protections.
5. AI-Powered Processing of Financial Documents
Oweize uses AI (Claude Sonnet 4.5 via AWS Bedrock) to extract data from receipt images and bank/credit card statements (CSV or PDF), including merchant names, amounts, categories, dates, and line items.
- Financial documents containing sensitive data are processed by AI within the configured AWS region.
- AI extraction may be inaccurate. You should review and verify all extracted data.
- You can use Oweize without uploading receipts or statements, but certain features may be limited.
- You can delete uploaded documents and extracted results through the app or by contacting us.
6. Data Retention
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, or as required by law.
- Active user account data: Retained while your account is active.
- Deleted user audit record: Name, email, phone, signup method, currency, signup date, and deletion date retained for fraud prevention, legal compliance, and dispute resolution.
- Plaid access tokens: Deleted when you disconnect your bank or delete your account; revoked on Plaid servers upon account deletion.
- Split expenses (user-created): Soft-deleted on account deletion to preserve shared records for other participants.
- Split expenses (as participant): Your user ID anonymized; expense retained for other participants.
- Settlements: Anonymized for active groups; hard-deleted for deactivated groups.
- OTP data: Auto-expires after 1 hour.
- Imported bank statements: Stored until you request deletion.
- Receipt images: Stored in AWS S3; deleted when associated expense is deleted, subject to backup retention.
When you delete your account, we delete or anonymize your personal information as described above. Some information may remain where necessary to preserve shared records for other users, prevent fraud or abuse, comply with legal obligations, resolve disputes, or maintain security and accounting records.
7. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information, subject to legal and operational exceptions.
- Portability: Request a copy of your data in a structured, commonly used format.
- Restriction: Request that we limit how we use your personal information.
- Objection: Object to certain processing activities.
- Withdraw consent: Withdraw consent for optional processing (e.g., marketing emails).
To exercise your rights, contact us at support@oweize.com. We will respond within 30 days, or as required by applicable law. We may need to verify your identity before processing your request.
If you have a privacy complaint, you may contact us directly. You also have the right to file a complaint with the Office of the Privacy Commissioner of Canada or your local privacy regulator.
8. Security
We implement reasonable technical and organizational measures to protect your personal information, including encryption of financial tokens at rest (AES-256-GCM), password and OTP hashing, JWT-based authentication, API rate limiting, CORS allowlisting, HTTPS everywhere, session management with remote revocation, and time-limited access to stored files.
No security measure is perfect. We cannot guarantee absolute security, and you use the service at your own risk.
9. Children's Privacy
Oweize is not intended for children under 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us, and we will take steps to delete it.
10. Cross-Border Data Transfers
Your personal information may be transferred to and processed in countries other than your own, including the United States and Canada. These countries may have different privacy laws than your country of residence. We implement appropriate safeguards, such as contractual agreements, to protect your data during transfer.
11. Cookies and Analytics
Our website and web application use analytics services (Google Analytics and Segment). These services collect page views, browser information, IP addresses, and usage patterns. We request your consent before loading analytics cookies. You can manage your preference through the cookie consent banner or your browser settings. Disabling cookies may limit certain features.
12. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by updating the date at the top of this page, posting an in-app notice or banner, or sending an email notification. Your continued use of Oweize after changes constitutes acceptance of the updated policy.
13. Additional Disclosures
California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information is collected, used, shared, or sold; to delete personal information (subject to exceptions); to opt-out of the sale or sharing of personal information (we do not sell or share personal information as defined by CCPA); and to non-discrimination for exercising privacy rights. Contact us at support@oweize.com.
European Union (GDPR)
If you are in the EU, you have the right to access, correct, delete, or restrict processing of your personal information; data portability; objection to processing; withdrawal of consent; and to lodge a complaint with a supervisory authority. Our legal basis for processing includes consent, contract performance, legitimate interests, and legal obligations.
Canada (PIPEDA)
If you are in Canada, you have the right to access your personal information, challenge its accuracy, and request correction or deletion (subject to legal and operational exceptions). You may file a complaint with the Office of the Privacy Commissioner of Canada.
14. Contact
If you have questions or concerns about this privacy policy or your personal information, please contact our Privacy Officer:
- Privacy Officer: Parth Patel, Founder
- Email: support@oweize.com
- Address: Kitchener, Ontario, Canada