Skip to content

No policy has been written yet, because nobody has an account and no personal data is being collected. What is already true about how this is built:

  • A household owns the data, not a person

    Every account, transaction, category, budget and goal belongs to a household. Deleting a person nulls their authorship and leaves the household's money intact, because a partner's history is not theirs to erase.

  • The database itself enforces the boundary

    Postgres row-level security is switched on and forced for every table that carries a household, and the application connects as a least-privilege role it applies to. A query that forgets its filter returns nothing rather than another family's money.

  • Bank access never touches your browser

    Bank connections run server-side, through Salt Edge: you sign in at your own bank, and no bank credential is ever handled by this app. The permission is read-only, and disconnecting a bank revokes it at the provider.

  • Your data leaves as easily as it arrives

    Transactions export as CSV today, on every plan, and the export imports straight back. That is a design commitment, not a feature to be gated later.

The actual policy

Phase 26 · #30
Lawful basis, retention periods, sub-processors, the consent wording for bank access and for AI processing, data export and erasure mechanics, and a cookie notice. Written by a professional before the first account opens, and versioned so acceptance can be recorded against it.