Last updated: see your deployment date.
Your account (name, email, username, hashed password — never your plain-text password), and whatever you choose to add: documents and their metadata, bank account and transaction records, reminders, budgets, and personal info entries. Uploaded files are stored outside the public web root and are only ever served back to the account that uploaded them.
Solely to run the app for you — computing balances, showing your dashboard, sending you in-app reminders. We don't sell your data, and we don't use it to serve ads.
Only you. Every record is scoped to your account at the database level; other users of this app cannot see your documents, transactions, or any other data you store.
Passwords are hashed (bcrypt), sessions use HTTP-only cookies, and every action is recorded in an audit log. See README §6 (“Security notes”) for the full list of protections this build ships with.
You can edit or delete individual records (documents, transactions, reminders, etc.) yourself at any time from within the app. Self-service full account deletion isn't built yet — to request your account and all its data be deleted, contact support; this is currently a manual process.
See our Terms of Service.