Privacy Policy
Last updated: October 4, 2026 · Version 1.2
This Privacy Policy explains what information Expense, LLC ("Expense", "we", "us") collects, how we use it, and the choices you have. It covers:
- the Expense browser extension (the "Extension"),
- the Expense websites and web application — expense.cash, app.expense.cash, and our API at api.expense.cash (together, the "Sites"),
collectively, the "Service". The Service is offered only in the United States (Section 9).
The short version: Expense is a price-comparison tool. We collect the minimum we need to run it — an email address and password for your account, the product information needed to run a comparison, and affiliate order data that tells us a purchase came from Expense. We run no advertising and no tracking cookies, and we do not sell or share your personal information with data brokers or advertisers. Our websites use only Cloudflare's cookie-free, aggregate page analytics, and the Extension has no analytics at all.
1. Information We Collect
1.1 From the Extension
The Extension's job is to recognize a product page and show you a price comparison. To do that:
- Product-page detection runs on your device. The Extension's detection code runs on pages you visit and reads the product's name, price, currency, and category — usually from structured data the storefront itself publishes (schema.org markup or the store platform's own product object), and on stores that publish neither, from the page's heading and the visible text around it. It never reads what you type. A small script also runs on each page to recognize which store platform it is and to notice when a single-page store changes route; apart from the product details described in the next point, nothing these scripts read leaves your browser. On roughly ninety large marketplace sites we deliberately exclude, and on any page it does not recognize as offering a product for sale, no comparison is shown and nothing is sent to us.
- Comparison requests. When a product page is detected and you are signed in, the Extension asks our API for comparisons; it makes no automatic requests otherwise. The request contains: a search string derived from the product's name (and category), your results-limit setting, and optionally the page price and your minimum-discount setting — never the page's address. It is sent over HTTPS with your sign-in token, and it is the only API call the Extension makes to our servers. When results are displayed, product images load directly from AliExpress's image servers (see Section 3).
- Apart from your sign-in token, the Extension sends only details of the product you are viewing — its name, its category if the store lists one, and its price — with your results-limit and minimum-discount settings. It never transmits the address (URL) of the page, which sites you visit, page screenshots, images, or any other page content, and pages and sites that do not offer a product for sale have nothing transmitted at all. The detected currency is used only locally and is not transmitted.
- Stored on your device (browser extension storage, never synced to other devices by us): your sign-in token (a token issued by app.expense.cash that identifies your account, includes the email address it was issued to, and is valid for up to 90 days), your settings (results limit, minimum discount, AliExpress pop-up preference, result sort order), and install/sign-in timestamps. The token leaves your device only as authentication on the API request described above.
- Connecting the Extension to your account: when you sign in on app.expense.cash, and again each time you open a page there while signed in, the web app hands the Extension your sign-in token through a browser messaging channel restricted to app.expense.cash. Your password is never given to, stored by, or visible to the Extension.
- The AliExpress pop-up decluttering feature (optional, on by default) hides nuisance overlays on AliExpress pages using a local stylesheet plus a local scan that tags promotional overlays so the stylesheet can hide them. Nothing it reads leaves your browser, it sends no data, and it is designed never to hide cookie- or privacy-consent prompts.
1.2 When You Create an Account
Registration is invite-only and collects exactly: your email address, a password, and the invite code you redeem. We store your password only in a form we cannot read. We also keep your email-verification status (verification, one-time sign-in, and password-reset codes are single-use and expire within minutes), your account creation date, your active session identifiers, and a record of which invite code your account redeemed and when (that record includes your email address). We also record that you accepted the Terms & Conditions and this Policy (which versions, and when) and confirmed you are at least 18.
We do not ask for and do not store your name, postal address, phone number, date of birth, or payment details. We have no payment processing at all — the Service is free.
1.3 Purchase Attribution (How Our Affiliate Funding Works)
Expense is funded by affiliate commissions from AliExpress. When you are signed in, outbound AliExpress links we show you include an attribution tag — a pseudonymous identifier derived one-way from your account. It is not your email, name, or anything readable, and it cannot be traced back to you by anyone but us. The tag appears only on comparison results we render in response to a product page or search of yours: Expense never rewrites, appends to, or replaces links or affiliate codes already on the pages you visit, never sets or modifies shopping or affiliate cookies, and never applies codes in the background — an affiliate link is used only when you click it.
If you complete a purchase after clicking such a link, AliExpress reports the order to our affiliate account — including the product, the order's status and timestamps, the amount paid, and the commission we earned — together with the attribution tag we attached to the link, which is how we attribute the purchase to your account. AliExpress does not share your name, address, phone number, or payment details with us.
1.4 Collected Automatically
- IP addresses. Your IP address (provided by our network provider, Cloudflare) is used solely for rate limiting and abuse prevention; our network provider also uses it to keep the Service to the United States (Section 9). It is held in short-lived counters that expire within at most an hour, and is never added to your account records or joined to your search activity.
- Session cookie. Loading a page on app.expense.cash sets one strictly-necessary session cookie, including before you sign in (see Section 5).
- Server logs. Like nearly every online service, our servers keep short-lived operational logs for debugging and security; log lines record request details as they are processed, which can include search text. Logs are overwritten in rotation and are not used to build profiles.
- Search queries are not kept. Searches you run are processed to return results and are not saved to any database or linked to your account in any stored form. On the web app, a search also places the query and your filters in the page's address so results can be reloaded or shared; loading such an address sends them to us like any page request, and they are still not stored.
1.5 What We Do Not Collect
For clarity, the Service has no advertising, no tracking cookies or tracking SDKs, no data-broker relationships, and no analytics beyond our websites' cookie-free, aggregate page analytics (Section 3). The Extension has no analytics; it does not collect the addresses of the pages you visit, which sites you visit, keystrokes, form entries, page screenshots, or precise location; it sends nothing from pages and sites that do not offer a product for sale; it does not read or set cookies; and it contains no code that fingerprints you or your device.
2. How We Use Information
We use the information above only to:
- provide the Service's single purpose: detecting product pages and showing price comparisons;
- create, secure, and operate your account (authentication, email verification, password reset);
- attribute affiliate purchases to accounts and collect the commissions that fund the free Service;
- protect the Service (rate limiting, abuse and fraud prevention);
- improve the Service using the minimum data needed to do so; and
- comply with legal obligations.
3. How We Share Information
We do not sell personal information, and we do not share it for advertising. Information is shared only with:
- Cloudflare, Inc. — our network and security provider. All traffic to the Sites and API passes through Cloudflare's network (this is how your IP address reaches us). Our sign-in, registration, verification, and password-reset flows use Cloudflare Turnstile, which verifies you are human; that verification shares your IP address and the challenge result with Cloudflare, and the Turnstile script loads only on the web app's sign-in, registration, email-verification, and password-reset pages. Our websites (expense.cash and app.expense.cash) also use Cloudflare's cookie-free, aggregate page analytics: when one of their pages loads, your browser reports to Cloudflare the page viewed, the referring site, your browser, operating system, and device type, and how quickly the page loaded, and we see only aggregate statistics (page views and load performance, broken down by page, referring site, country, browser, operating system, and device type). It sets no cookies and stores nothing in your browser. The Extension has no analytics.
- AliExpress (Alibaba Group) — to run a comparison, our servers send AliExpress only the product identifiers needed to retrieve listings, under Expense's own credentials; your search text is never sent to AliExpress, and neither are your email, name, or account identity. Comparison results — in the Extension and the web app alike — display product images served directly from AliExpress's image servers, so your browser requests those images when results are shown; AliExpress sees your IP address and which images were fetched, nothing more. If you click through to AliExpress, your browser carries the pseudonymous attribution tag described in Section 1.3, which only we can connect to an account; from that point AliExpress's own privacy policy governs.
- Proton, our email delivery provider — the transactional email the Service requires (verification links, one-time sign-in codes, password resets) is sent through Proton Mail's SMTP relay over an encrypted connection. These emails contain only your email address and the relevant code or link.
- Google Fonts — our web pages load their fonts from Google Fonts. When a page loads, Google receives the ordinary web-request data — your IP address and browser details — and serves the font files; it receives nothing else about you.
- Google (Chrome Web Store) — if you install the Extension from the Chrome Web Store, Google processes the installation under its own privacy policy; we do not control or receive that data.
- Authorities or successors when required — if the law requires disclosure, or if Expense's assets are transferred in a merger or acquisition. In an asset transfer this Policy continues to apply to your information until changed as described in Section 12 — and information the Extension collects from the Chrome browser or from web pages is transferred only after we obtain your explicit prior consent, as the Chrome Web Store's Limited Use requirements demand.
4. Chrome Web Store — Limited Use Statement
Expense's use of information received from the Chrome browser and from web pages you visit will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. In plain terms: that data is used only to provide and improve the Extension's single, user-facing purpose — price comparison. We do not sell it. We transfer it to third parties only where necessary to provide or improve that single purpose, to comply with applicable law, to protect against fraud, malware, or abuse, or — with your explicit prior consent — as part of a merger, acquisition, or sale of assets. We never use or transfer it for advertising, for credit assessment or lending, or to data brokers, and we do not permit humans to read it except with your consent, for security and abuse prevention, or where the law requires.
5. Cookies and Local Storage
- app.expense.cash sets one strictly-necessary session cookie. We set it on your browser when you load a page on our site, including before you sign in. It holds a randomly generated identifier that keeps your visit consistent from page to page and expires after 14 days or when you sign out. It is HTTP-only, sent only over HTTPS, and is not used for tracking, so no cookie-consent banner is required for it.
- Your search preferences on the web app (result limit, price cap, sort order) are kept in your browser's local storage; they also appear in the page's address alongside your query so a search can be reloaded or shared (Section 1.4).
- The Extension keeps its settings and your sign-in token in browser extension storage on your device (Section 1.1). The Extension itself sets no cookies and reads none.
- Cloudflare may set its own cookies on our domains for security purposes (for example bot filtering); these are governed by Cloudflare's policies. Its page analytics on our websites (Section 3) set no cookies.
6. Extension Permissions, Explained
The Extension requests the minimum permissions its purpose needs:
- "Read and change all your data on all websites" — product pages exist on millions of independent store domains, so no fixed site list can cover them; this permission lets the detection described in Section 1.1 run where you shop. Reading happens locally; data leaves your device only as described there.
- Storage — keeps your settings and sign-in token on your device.
- AliExpress pages — the same website access above is what lets the optional pop-up decluttering feature (Section 1.1) run there; it is presentation-only and makes no network requests.
The Extension also declares a messaging channel that only app.expense.cash can use; it exists solely so the web app can hand the Extension your sign-in token (Section 1.1).
7. Data Retention
- Account data — kept for as long as your account exists, then deleted when your account is deleted.
- Sessions — expire after 14 days (server-side session data is deleted on expiry or sign-out).
- Extension sign-in token — valid for up to 90 days from issue. It is stored on your device, and a copy lives inside your server-side web session until that session expires (see Sessions above); the device copy is removed when you sign out from the Extension's pop-up, uninstall the Extension, or when our API rejects it. While you are signed in to the web app, visiting any page of app.expense.cash in the same browser signs the Extension back in, so sign out of the web app before you sign out of the Extension. Signing out of the web app does not by itself remove a token the Extension already holds.
- Rate-limit counters (IP) — expire automatically within at most one hour.
- Affiliate purchase records — retained as business/tax records for as long as the law and ordinary bookkeeping require. They contain no name or contact details (Section 1.3).
- Server logs — short-lived and overwritten in rotation.
8. Security
We take proportionate, real measures. Our current measures include: all traffic between you and the Service is encrypted in transit (TLS); your password is stored only in a form we cannot read; one-time sign-in codes, password-reset links, and email-verification links are single-use and expire within minutes; sign-in tokens are cryptographically signed so they cannot be forged; registration is invite-gated and CAPTCHA-protected; and the credentials our own services use are kept in an encrypted store, separate from code. If a breach affects your personal information, we will notify you and any regulator required by law without undue delay. No online service can promise perfect security, but we design so that a breach exposes as little as possible.
9. Your Rights and Choices
- Access, correction, deletion. You can delete your account yourself at any time from the web app's Settings page (an account that was never email-verified can also be deleted from the sign-in flow). To request a copy of the personal information we hold about you, or to correct it, email support@expense.cash from your account's address. Account deletion removes your account record; a sign-in token already issued to the Extension stops working when it expires (Section 7), and affiliate transaction records retained for bookkeeping contain no name or contact details. To remove the Extension's sign-in token from your device as well, sign out from its pop-up after you delete your account.
- Disconnecting the Extension. Sign out of the web app first, then sign out from the Extension's pop-up to remove your sign-in token from your device: while you are signed in to the web app, visiting any page of app.expense.cash in the same browser signs the Extension back in. Or uninstall the Extension and your browser removes everything it stored. Without a token the Extension cannot retrieve comparisons and makes no requests to our API.
- "Do Not Sell or Share" / Global Privacy Control. We do not sell or share personal information for cross-context behavioral advertising, and we do not collect "sensitive personal information" as the CCPA defines it, so there is nothing for a GPC or "do not sell" signal to opt out of. When you click through to AliExpress your browser carries the attribution tag described in Section 1.3; we do not treat this as a "sale" or "share" — you are choosing to interact with AliExpress directly, the tag identifies the referral rather than you, and the commission is paid for the referral, not for data. California residents may exercise the access, deletion, and correction rights above at any time; we do not discriminate for doing so.
- Outside the United States. The Service is offered only in the United States, to people located in the United States, and is not directed to anyone elsewhere. We do not offer or market it to, and do not knowingly collect personal information from, individuals in the European Union, the United Kingdom, or any other country. If you are outside the United States, do not use the Service. Any information we nonetheless receive from outside the United States is processed in the United States under this Policy.
10. Children
The Service is not directed to anyone under 18, and you must be 18 or older to use it. We do not knowingly collect personal information from anyone under 18; if you believe we have, email support@expense.cash and we will delete it.
11. Third-Party Sites
Product pages, storefronts, and AliExpress are operated by third parties with their own privacy practices. Once you leave the Service — including by clicking a comparison result — the destination's policies apply, not this one.
12. Changes to This Policy
We may update this Policy from time to time. The "Last updated" date and version number above always reflect the current revision, and the current version is always published at www.expense.cash/privacy; previous versions are available on request. If we make a material change — such as collecting new categories of data or using data in a new way — we will notify you before it takes effect, by email if you have an account and/or by a notice in the Extension or web app. Your continued use of the Service after a change takes effect constitutes acceptance of the revised Policy. If you do not agree, stop using the Service and delete your account.
13. Contact
Expense, LLC — operated from North Carolina, United States.
Privacy and legal inquiries: support@expense.cash