Legal

Privacy Policy

Effective February 27, 2026

What’s Your Balance? is currently in a private beta. This policy explains what we collect, how we use it, and how you can control it. It will be updated before a public launch.

1. What we collect

To run the service for you, we store the following in our database:

  • Account information: your email, a hashed password, and (optionally) your name and Google profile picture if you sign in with Google.
  • Cash-flow data you enter: funding-account labels and balances, bills, income sources, pending charges, debts, and any notes you add.
  • App preferences: onboarding status, cushion thresholds, monthly-summary opt-in, and role (user or admin).
  • Subscription state: trial status, subscription status, Stripe customer/session identifiers. Payment card details are stored by Stripe, not by us.
  • Feedback you submit through the in-app widget: message text, category, the page you were on, and your email address so we can follow up.
  • Basic operational logs (request timestamps, error traces) needed to keep the service running.

2. What we do NOT collect

  • Your bank credentials. The service does not connect to your bank; you enter balances manually.
  • Full credit card numbers. Payments run through Stripe, which handles card data under its own compliance.
  • Your Social Security number, tax records, or government IDs.
  • Location data, contacts, or files from your device.

3. How we use your data

  • Run the app: show your dashboard, pay-period forecasts, bills, and monthly outlook.
  • Authenticate you and protect your account.
  • Bill you through Stripe if you subscribe.
  • Respond to feedback or support requests you send us.
  • Fix bugs and improve the product based on aggregated, non-personal patterns.

We do not sell your data. We do not run ads. We do not share your cash-flow entries with third parties.

4. Who processes your data

These are the third parties involved in running the service:

  • Cloud hosting — runs the app servers and database on our behalf.
  • MongoDB — stores your data at rest.
  • Stripe — processes subscription payments. We only receive non-sensitive identifiers (customer id, session id, subscription status).
  • Google — if you choose Google sign-in, Google authenticates you and shares your email, name, and profile picture with us.

Each of these providers has its own privacy policy governing what they do with the data they handle.

5. Security

  • Passwords are stored as bcrypt hashes — the plain password is never saved.
  • Sessions use httpOnly cookies over HTTPS, so JavaScript running in the browser cannot read the token.
  • All traffic between your browser and our servers is encrypted with TLS.
  • Data is stored per-user; user records are scoped and filtered by user id on every query.

No system is 100% secure. If we ever become aware of a breach affecting your account we will notify you promptly.

6. Cookies

We use only the cookies needed to keep you signed in: an access token cookie and a refresh token cookie (both httpOnly). We do not use tracking or advertising cookies.

7. Your choices & rights

  • Access & export — you can view all of your data inside the app. Request an export at any time by emailing us.
  • Correct or update — edit any bill, income, funding source, or account setting directly in the app.
  • Delete — email us to close your account and remove your data. We will confirm and then delete within 30 days, except records we must retain for tax or fraud reasons (payment history, minimal audit logs).
  • Opt out of the monthly summary email — via the toggle in Settings.

8. Retention

We keep your data as long as your account is active. If you close your account, we remove your app data within 30 days. Payment records that we’re legally required to keep may be retained longer.

9. Children

The service is intended for adults managing their own money. It is not directed to children under 13, and we do not knowingly collect data from them.

10. Changes to this policy

We may update this policy as the product evolves — for example when a new integration is added. Material changes will be notified inside the app or by email before they take effect.

11. Contact

Privacy questions, data-export requests, or account-deletion requests? Email admin@whatsyourbalance.com.