Privacy notice
Last updated 3 October 2026. In short: your finances are locked in your own browser with your passphrase, so nobody else can read them: not the person running the app, not the database, not the backups. What the server does keep is used only to run the app, is never sold, stays in the European Union: the database in Frankfurt, Germany, and the app in Belgium, and you can take it with you or delete it at any time.
Who is responsible
Finance is run by Gonçalo Rodrigues, who is the data controller under the GDPR. For anything about your data, write to goncalo.gr@proton.me.
Your finances are end-to-end encrypted
Everything you enter or import (transactions, categories, budgets, goals, accounts and balances) is locked in your browser before it leaves your device, with keys that only you hold. The server stores the locked copy and cannot open it. The app's pages are worked out in your browser from the unlocked copy. Bank statements you import are read in your browser and never sent to the server.
Your keys are protected by your passphrase and by a recovery key shown once when you start. Nobody can reset them: if you lose both, your data cannot be recovered by anyone.
What the server keeps, and why
| Data | Why | Legal basis |
|---|---|---|
| Your email address, when you created the account, last logged in and accepted these terms | To log you in with an emailed link and to know which data is yours | Needed to provide the service you asked for (GDPR article 6(1)(b)) |
| Your finances, locked: a scrambled copy only your devices can open, its size, and when it last changed | So your data is kept safe and the same on all your devices | Needed to provide the service (article 6(1)(b)) |
| Your keys, locked: your public key, and your private key locked with your passphrase and with your recovery key | So you can unlock your data on a new device | Needed to provide the service (article 6(1)(b)) |
| The names of your spaces and the people you share them with | So shared spaces work | Needed to provide the service (article 6(1)(b)) |
| Your internet address and browser details in short-lived server logs, and a count of login emails asked for | To keep the app secure and stop abuse, such as floods of login emails | Legitimate interest in security (article 6(1)(f)) |
Nobody but you and the people you share a space with can read a space's data. The advice in the app is worked out automatically in your browser from your own numbers; it has no legal or similar effect on you and is not financial advice.
Cookies
Two cookies, both needed for the app to work: one keeps you logged in (for 30 days), the other remembers which space you are in. Your browser also keeps your unlocked keys for this device, in a form that cannot be copied out, until you log out, and your choice of light or dark theme. There are no advertising, tracking or analytics cookies, so there is nothing to consent to.
Who helps run the app
These companies process data only on the app's behalf and under contracts that the GDPR requires:
- Google Cloud runs the app, in Belgium.
- Neon stores the database, in Frankfurt, Germany.
- Resend sends the login emails. It is based in the United States, so your email address goes there, protected by the European Commission's standard contractual clauses. The emails never contain figures.
- GitHub keeps nightly backups for 30 days. They hold your finances only in their locked form, and are encrypted again before they leave the app's systems.
Your data is never sold, and never shared with anyone else unless the law requires it.
How long it is kept
- Your account and data: until you delete them. You can delete your account from the Account page at any time; it is removed straight away, and from backups within 30 days.
- If you do not log in for 12 months, you get an email; if you still do not log in within 30 days, the account and its data are deleted.
- Login links: they stop working after 15 minutes and are erased after a day. Server logs are kept for up to 30 days.
Your rights
You can see and download all your data (Export, on the dashboard; the file is made in your browser), correct it, delete it (Account page), and object to or ask to limit how it is used. For anything the app does not let you do yourself, write to goncalo.gr@proton.me; you will get an answer within a month. You can also complain to a data protection authority, in Portugal the CNPD, or the one where you live.
If something goes wrong
A breach of the server or the backups exposes only locked data, email addresses and space names. If there is a breach that puts your data at risk, the data protection authority is told within 72 hours, and you are told directly if the risk to you is high.
Changes
If this notice changes in a way that matters, you will be asked to read it again when you next log in.