Privacy Policy

Last updated: 3 August 2026

1. Overview

Clockile - Expense Tracker ("we", "our", or "us") is a personal budget and expense management application operated at expenses.tomorrowly.co.za. This Privacy Policy explains what information we collect when you use our app, how we use it, and your rights regarding that information.

2. Information We Collect

We collect the following information when you use Expenses Tracker:

  • Google account information — your name and email address, provided when you sign in with Google. We do not receive your Google password.
  • Expense data — the income amounts, expense categories, and expense items you enter into the app.
  • Financial documents — bank statements you upload for automatic expense extraction.
  • WhatsApp information — your phone number and chat messages, collected when you interact with our WhatsApp bot.
  • Usage data — basic technical information such as your browser type and the time of your requests, collected automatically by our hosting infrastructure.

3. How We Use Your Information

We use the information we collect solely to provide and improve the app:

  • To authenticate you and associate your expense data with your account.
  • To store and display your monthly expenses and budget information.
  • To communicate with you and allow you to manage expenses via WhatsApp.
  • To provide AI-driven analysis and insights into your expenses.
  • To identify and fix technical issues with the app.

We do not sell your data, share it with third parties for advertising purposes, or use it for any purpose beyond operating this app.

4. Third-Party Services and Sub-processors

We use the following third-party services to provide certain features. Your data is shared with them strictly for the purpose of operating the app:

  • Meta (WhatsApp Cloud API): We use Meta's official API to power our WhatsApp bot. Messages you send to us via WhatsApp are routed through Meta's infrastructure.
  • Google Gemini AI: We use Google's Gemini AI to analyze your expense data and extract information from bank statements. We utilize the API under enterprise terms which ensure your data is processed securely and is not used by Google to train their foundational AI models.
  • Inngest: We use Inngest as our background job orchestrator. When you upload a document or trigger complex tasks, basic event metadata (such as internal IDs) is sent to Inngest to queue the job securely.
  • Resend: We use Resend to process inbound emails. If you forward a bank statement to our dedicated email address, it passes through Resend's servers before being securely stored in our database.

5. Google OAuth

We use Google OAuth 2.0 solely for authentication — to confirm your identity and create your account. We request only the minimum necessary scopes: your name and email address. We do not access your Google Drive, Gmail, contacts, or any other Google services. You can revoke our access at any time via your Google Account permissions.

6. Data Storage

Your data is stored securely in Supabase, a cloud database platform. Data is stored in the South Africa (af-south-1) region where available, or the nearest available AWS region. Supabase applies encryption at rest and in transit for all stored data. You can read Supabase's privacy practices at supabase.com/privacy.

7. Data Retention

We retain your data for as long as your account is active. Uploaded bank statements are deleted immediately after the relevant expense data has been extracted. If you wish to delete your account and all associated data (including expense records and WhatsApp chat history), please contact us at the email address below and we will action your request within 7 days.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and all associated data.
  • Withdraw consent for data processing at any time by deleting your account.

To exercise any of these rights, contact us at manakanejustin@gmail.com.

9. Cookies

We do not use cookies for tracking or advertising. Supabase uses a session token stored in your browser's local storage to keep you signed in between visits. This token is necessary for the app to function and contains no personally identifiable information beyond a reference to your account.

10. Children's Privacy

Clockile - Expense Tracker is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the app after changes are posted constitutes your acceptance of the updated policy.

12. Contact

If you have any questions about this Privacy Policy, please contact us at:
manakanejustin@gmail.com

© 2026 Tomorrowly. All rights reserved.Terms of ServiceBack to app