How we handle your data
Draft. This document is a working draft and has not been reviewed by a lawyer. It needs checking before the site or the app goes live.
The privacy policy is the binding version, and it is written to be precise. This page is the same thing said honestly, in the order you would actually ask.
You are handing over your entire financial picture. Why should you?
That is the right question, and most finance apps answer it with a badge. Here is the real answer, including the parts that do not flatter us.
What we hold
Your email address, the name you pick, and your ledger: accounts, transactions, budgets, assets, debts, property records, and any receipt photos you attach.
That is it. Not your bank login, because there isn’t one. Not your location. Not your contacts. Not what else is on your phone.
What we do with it
We store it, and we sync it between your devices and the people in your household. Nothing else happens to it.
No advertising. No selling. No sharing with a data broker. No “anonymised insights” sold to anyone. No profiling. There is no analytics SDK and no crash-reporting SDK in the app at all, and if we ever add crash reporting, this page will say so before the version ships.
What we cannot promise
It is not end-to-end encrypted. Your data is encrypted in transit and at rest, and each household is isolated from every other by database-level policies. But the technical ability to read what is stored exists on our side. Building a shared, multi-device, searchable ledger with true end-to-end encryption is a genuinely different product. We would rather tell you that here than let you assume otherwise.
We are small. There is no security team. There is one person, standard platform infrastructure, and a written plan for what happens if something goes wrong.
If either of those is disqualifying for you, that is a reasonable conclusion and we would rather you reached it now.
Getting your data out
One tap: Settings, then Export my data. You get a complete copy of your ledger in an open format, immediately, without asking us and without waiting for anyone to approve it. There is also a transactions-only CSV that opens in Excel or Numbers.
Two gaps, stated plainly. The export lists every receipt and property image and where it is stored, but does not include the image files themselves. And it is your ledger rather than your account details. Ask and we will send either.
One more thing worth knowing, because it is the sort of detail people discover at the worst moment: the import side of the app does not yet read back everything the export writes. Assets, liabilities and property records are in your file, but “Replace all data from file” does not restore them yet.
Leaving
Settings, then Account, then Delete my account. It happens immediately, from inside the app. You do not have to email anyone.
What that does depends on one thing:
- You are the only person in your household. Everything goes. The whole ledger, every image, the login. Permanently. If an image cannot be removed at that exact moment, it is made unreachable immediately and deleted by hand.
- Somebody else is still in it. Your login goes, and you lose access. The ledger stays with them, because it is their financial history too and it isn’t ours to take from them.
There is no bin, no grace period and no undo. Deleted data survives only in encrypted backups until those age out, and we cannot search those for you. Export first. The delete screen offers you that first.
Where it lives
On Supabase’s infrastructure, in {{TODO: region}}. The full list of companies that touch your data is on the subprocessors page, and it is three names long.
If something goes wrong
You get told. Not “eventually”, and not buried in a status page. You are notified directly, and the relevant regulator is notified too where the law requires it. What we would do, and in what order, is written down before we need it rather than improvised on the day.
Questions, or anything here that reads as evasive? Tell us. That’s a bug in this page and worth fixing.