Privacy Policy

Last updated: see your deployment date.

Template notice: this is a starting-point privacy document generated for this build, not legal advice. Have a qualified lawyer review it against where you actually host the app and store data (see README §7/§9) before relying on it for real users — requirements differ by region (e.g. GDPR, UAE PDPL) and by what a hosting provider does with data on your behalf.

1. What we store

Your account (name, email, username, hashed password — never your plain-text password), and whatever you choose to add: documents and their metadata, bank account and transaction records, reminders, budgets, and personal info entries. Uploaded files are stored outside the public web root and are only ever served back to the account that uploaded them.

2. How it's used

Solely to run the app for you — computing balances, showing your dashboard, sending you in-app reminders. We don't sell your data, and we don't use it to serve ads.

3. Who can see it

Only you. Every record is scoped to your account at the database level; other users of this app cannot see your documents, transactions, or any other data you store.

4. Security

Passwords are hashed (bcrypt), sessions use HTTP-only cookies, and every action is recorded in an audit log. See README §6 (“Security notes”) for the full list of protections this build ships with.

5. Your data, your control

You can edit or delete individual records (documents, transactions, reminders, etc.) yourself at any time from within the app. Self-service full account deletion isn't built yet — to request your account and all its data be deleted, contact support; this is currently a manual process.

See our Terms of Service.