Privacy
A plain-English account of where your data lives, who can see it, and how to take it back.
What we store
Your account (name, email, and a hashed password if you don't use Google), and everything you enter: pay details, balance, the balances you've typed in over time, bills and their past prices, expenses, income, pay-later plans, payment history, savings goals, your categories, category budgets and display preferences.
Email. We only send account emails: a link to confirm your address when you sign up, one welcome email, and a password reset link when you ask for one. No newsletters, no marketing, and your email is never shared.
We do not collect analytics, behavioural tracking or advertising identifiers, and there are no third-party tracking scripts. You never give us bank logins; everything is entered by you.
Bank statements. If you import a CSV statement, the file is read and matched on your device. It is never uploaded. Only the lines you confirm are sent: their date, amount and description. They become ticked payments or one-off expenses, like anything else you enter.
Page speed.We measure how fast pages load using Vercel Speed Insights: load and response timings, the page's address with any details removed, and the kind of device and connection. It sets no cookies, uses no identifiers and never sees your budget.
Error logs. When something breaks, the server logs the kind of error and the page it happened on, with names, amounts and email addresses stripped out. Logs are kept by our host, Vercel, for a short time.
Where it lives
In Sydney.Your data is stored in a managed Postgres database (Neon) in the AWS Sydney region, and the app's servers run in Vercel's Sydney region. The database is encrypted at rest, and all traffic is encrypted in transit (TLS).
On your device, briefly.If you install the app, pages you've opened are cached so it still opens without a connection. Signing out clears that cache.
Who can see it
You. Every request is checked against your signed-in session, and the server only reads and writes budgets you belong to. No other user can see your budget unless you share it.
People you share a budget with.If you invite someone to a budget, or join theirs, everyone in it sees all of it: the balance, bills, plans, goals and payment history, plus each member's name and email and who ticked what. Viewers can see but not change anything. Your other budgets stay private. Invite links work once, for 7 days, and only a scrambled copy of each is stored.
The operator. Whoever runs the service has administrative access to the database, as the owner of any server does. Data is not browsed or analysed. For full control, self-host the app from its source.
Service providers, only for what they do: Neon (database), Vercel (hosting), Google (only if you choose Google sign-in), Resend (sends the account emails above; it receives your name, email address and the email itself, never your budget), and Frankfurter (exchange rates; it only ever receives currency codes, never your data).
Your controls
Export. Settings, then Data, then Export downloads everything in your budget as a JSON file you can import again later.
Clear budget. Settings, then Danger zone, then Clear all data empties your budget and keeps your account.
Delete account. Same place. This permanently deletes your login, your sessions and every budget you own, straight away.
A note on encryption
Data is encrypted at rest and in transit, but it is not end-to-end encrypted: someone with database access could technically read it. Optional client-side encryption may come later; the trade-off is that forgetting the passphrase would make your data permanently unreadable.
Questions
If something here is unclear or you want a specific guarantee, get in touch. This page changes when the architecture does.