Privacy
In plain language: what we receive, what we store, who else sees it, and how to delete all of it.
We never ask for your bank password
We don't use banking aggregators and we don't ask for your bank username or password. We can't see your balance, your statements or your history, and we can't move money. All we receive are the notification emails you choose to forward to us.
You decide what reaches us
During setup you create a Gmail filter that forwards only the emails coming from your bank, to a personal address of yours on our server. No other mail in your inbox is ever sent to us.
That filter is yours and lives in your Gmail. If you delete it, we stop receiving mail that same instant — you don't have to ask us or wait for us to do anything.
What we store
- Your email address and your password, stored as an Argon2id hash (we can't read it).
- The last 4 digits of each card, plus whatever label you give it. Never the full number — the bank's emails don't include it.
- For each transaction: merchant, amount, currency, date and assigned category.
- Your categories, rules and budget amounts.
What we don't store: your balance, your passwords, your full card number, or any of your other email.
The original email is deleted
When an email arrives from your bank we read it, extract the transaction, and delete the email body immediately. All that remains is the transaction.
The exception: if an email has a format we can't read yet, we keep its content for up to 30 days so we can add support for that bank. After that it is deleted automatically.
Who else sees your data
We use these providers, and no others:
- Postmark (part of ActiveCampaign, United States) — receives the emails you forward and delivers them to us; it also sends our confirmation and password emails. Being US-based, laws such as the CLOUD Act apply to it. We set its retention to the minimum they offer.
- Telegram — only if you enable alerts. In that case the merchant name and amount are sent to Telegram's servers. If you don't enable it, Telegram receives nothing.
- Our server provider, where the application and database run.
We don't sell your data, we don't run ads, and we use no third-party trackers or analytics.
What the developer can see
We'd rather say it than hide it: when an email arrives in a format the app can't read, it shows up in an internal panel where I (the developer) can open its content to add support for that bank. It's the same notification email you already received, and it's deleted after 30 days.
Emails that are processed successfully never go through there: their content has already been deleted.
Encryption
All traffic goes over HTTPS. The email bodies we do keep (the ones we couldn't read) are stored encrypted in the database, which protects backups and disks, but this is not end-to-end encryption: the server holds the key so it can read them. See the security page.
Delete everything
From Your account you can download all your data as JSON and delete your account. Deletion is immediate and permanent: your transactions, cards, categories, rules, budgets and forwarding address are all removed. We keep no copies.
Contact
Email me at [email protected] if you have questions or want to report a security problem.
Last updated: 2026-07-25