privacy · updated September 2026
What we hold, and what we don't
Written to be read. If anything here ever stops being true, the page changes the same day the practice does.
What we hold
Your ledger. The statement files you drop in become one ledger file per person, stored on our server (hosted on Railway, with daily encrypted backups to a private storage bucket). We never ask for, receive, or store your bank credentials — you download statements from your bank yourself.
Your account. Email, a hashed password (or your sign-in provider's id), and billing status. Payments are processed by Stripe; your card number never touches our server.
Product counts. We record that events happened — "an import completed," "a rule was taught" — as counts tied to your account, so we can see where the product fails people. Never the contents: no amounts, no merchant names, no transactions in analytics.
What leaves the box
One thing. When the engine proposes categories, it sends masked merchant names only to a language-model API — never amounts, balances, dates, account numbers, or your identity. Masking strips personal tokens before anything is sent. If you turn the engine off in Settings, nothing leaves at all.
What we will never do
Sell or share your data. Show ads. Ask for bank credentials. Train anything on your ledger. Use your data for anything except running the product you pay for. There is no version of the business where your transaction history is the inventory — you pay us; that's the model.
The two doors
Export — download your entire ledger, any tier, any time, from Settings. Delete — remove your account and every byte of your data, any time, no questions, effective immediately (backups age out within 30 days). Both doors work on the free tier, forever. Neither is ever behind the paywall.
Cookies
One session cookie, to keep you signed in. No trackers, no pixels, no third-party analytics scripts on the app.
Questions
Write to the maker — the address is on your receipt. You'll get a human.