Skip to content
Chillar's

Legal

Privacy policy

Last updated

What we store

The financial data you enter: accounts, transactions, categories, tags, budgets, loans and planned payments, together with your settings (base currency, locale, theme, notification preferences and timezone).

Your account identity: the name, email address and avatar supplied by the account you sign in with — Google, GitHub or Facebook — or nothing at all if you use a guest account. We ask those providers for nothing else: not your contacts, not your repositories, and no permission to act on your behalf.

Operational records: a first-party event log of which screens are used and an error log of failures, both used to keep the app working. Neither contains transaction amounts or titles.

What we do not store

No passwords. We do not issue one, cannot accept one, and have no way to see the one you use with Google, GitHub or Facebook. Signing in happens on their site, and we receive only the result.

No banking credentials, because there is no bank connection to use them with.

No session-replay recordings, and no data sold or shared with data brokers. The service carries advertising, but your transactions, balances, categories and budgets are never used to select an ad and are never shared with an advertiser.

No location data. Your region is guessed once during onboarding from your browser's language preference to suggest a currency, and that guess is never stored as a location.

Who can read your data

You. Every row is isolated at the database level with row-level security, so a query issued on your behalf can only return rows belonging to your account.

Operators of the service can technically access the database for maintenance, as is true of any hosted application. Access is limited to what is needed to keep the service running.

Export and deletion

You can export everything at any time as JSON, which contains every row we hold for you and can be imported back. Filtered views also export to CSV, XLSX and PDF.

You can request account deletion from the settings page. Deletion takes effect after a seven-day grace period during which you can cancel it. After that, every row belonging to the account is permanently removed.

Why we are allowed to store it

We store everything in the first section to provide the service you asked for, since an expense tracker that does not keep your expenses is no tracker. Under the GDPR that is performance of a contract (Article 6(1)(b)); under India's DPDP Act it is processing for the purpose you gave the data for.

The error log rests on legitimate interest (Article 6(1)(f)): keeping the service working. It records what failed and where, never what you entered.

Notifications (the daily reminder and the email digest) stay off until you switch them on, and switching them off withdraws that consent at once.

How long we keep it

Your records stay until you delete them. There is no silent expiry: a transaction you entered five years ago is still there, because that is the point of a ledger.

Deleting your account removes every row after a seven-day grace period. Nothing is retained afterwards for analytics or backups beyond the rolling database backups, which age out within thirty days.

Error logs are kept for ninety days. Usage events are kept for as long as the account exists and are deleted with it.

Your rights

Access and portability: the JSON export gives you every row we hold, in a format that imports back. You do not have to ask anyone for it.

Correction: every figure in the app is editable by you, which is the same right exercised directly.

Erasure: request account deletion in settings. It completes after seven days and cannot be undone afterwards.

Objection, restriction and withdrawal of consent: switch off notifications, insights or usage analytics in settings. Nothing about the core ledger depends on them.

If you are in the EEA or the UK you may complain to your national supervisory authority. If you are in India you may complain to the Data Protection Board after raising the matter with us first.

Third parties

Signing in is handled by whichever provider you choose — Google, GitHub or Facebook. You authenticate on their site, not ours, and they tell us only that it succeeded, along with your name, email address and avatar. Their own privacy policy governs what they record about that visit, including the fact that you signed in to this service.

Exchange rates are fetched from a public exchange-rate feed. That request is made by the server, contains no information about you, and the response is stored once for all users.

Push notifications, if you enable them, are delivered through your browser vendor's push service. The notification payload is encrypted and contains no financial data.

The service runs on a hosting provider and a managed Postgres database. They process your data on our instructions only. No data broker sits in the chain.

Advertising is delivered by an ad provider. It receives what any web request carries — your IP address, browser and the page the ad appears on — and none of the financial data you entered. It is not given access to your account or your rows.

Because those providers run infrastructure in several regions, your data may be processed outside your own country. Where that is the case, the transfer relies on the provider's standard contractual clauses.

Cookies and what is stored on your device

Our own cookies are the ones that keep you signed in. The ad provider may set its own cookies on the pages that carry advertising; where the law requires consent for those, you are asked before they are set and you can withdraw it at any time.

The app also keeps things in your browser's own storage so it works offline: a copy of the data you have already loaded, a queue of changes made without a connection, and your theme choice. Signing out erases all of it.

No automated decisions about you

The insights the app shows (spending trends, subscription detection, a forecast, a health score) are arithmetic over your own rows, computed on our servers with fixed rules. There is no model, no profiling against other users, and no decision made about you that has any legal or similar effect.

Children

The service is not directed at children and is not intended for anyone under sixteen. We do not knowingly hold a child's data; if you believe a child has created an account, tell us and it will be removed.

Who is responsible, and how to reach us

The operator of the service is the data controller. The contact page carries the current route for privacy questions, correction requests and complaints.

A privacy question raised through that route gets an answer. If the answer does not satisfy you, the complaint routes in the rights section above remain open to you.

Changes to this policy

Material changes will be noted in the changelog and dated here. The version you are reading was last updated on the date shown above.