Privacy Policy
Home Terms of Service
Back

Last updated: 1 August 2026

1. Introduction

Safe-to-Save ("the Service", "we", "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

The Service is a personal finance tracker. It is not a commercial product — there are no ads, no analytics services, and no data monetization of any kind.

2. Information We Collect

When you use Safe-to-Save, we collect the following information:

  • Account information: A synthetic email address and password you choose for authentication. These are not real email addresses and are stored by Supabase Auth.
  • Transaction data: Amounts, categories, notes, dates, and types (income or expense) that you manually enter.
  • Recurring transaction data: Templates for repeating income or expenses, including frequency and schedule.
  • Balance check-ins: Bank balances you enter, along with calculated values (average daily spend, floor amount, safe-to-save amount).
  • Settings and preferences: Runway days, starting daily estimate, monthly budget, default dashboard view, custom categories, theme preference, and transaction color preference.

We do not collect: real names, real email addresses, physical addresses, phone numbers, bank account numbers, or any data from your financial institutions.

3. How We Store Your Data

All data is stored in a Supabase PostgreSQL database. Supabase provides encryption at rest and in transit (TLS). Database access is governed by Row-Level Security (RLS) policies that restrict each user to their own data — you can only see and modify your own records.

Authentication tokens are stored as HTTP-only cookies managed by Supabase Auth.

4. How We Use Your Data

Your data is used solely to provide the Service's features:

  • Calculating the "safe to save" amount based on your spending patterns
  • Displaying spending charts and transaction history on your dashboard
  • Projecting month-end balances based on recurring items
  • Syncing your data across your own devices when you sign in
  • Exporting your data in CSV or JSON format when you request it

We do not use your data for any other purpose. There is no automated decision-making or profiling beyond the calculations you explicitly request.

5. Data Sharing

We do not sell, rent, trade, or share your data with any third party. Your data stays in the Supabase database and is accessible only to you through the Service's authenticated interface.

The Service relies on Supabase as a data processor. Supabase's privacy practices are governed by their own privacy policy and data processing agreement. No other third-party services receive your data.

6. Cookies and Tracking

The Service uses one essential cookie: the Supabase authentication session token. This cookie is necessary for the Service to function — it keeps you signed in.

We do not use: analytics cookies, advertising cookies, tracking pixels, fingerprinting, or any form of user behavior tracking. There are no third-party scripts beyond the Supabase client library and Chart.js (loaded from CDN for chart rendering).

7. Data Retention

Your data is retained as long as your account exists. If you delete your account or request data deletion, your records will be removed from the database.

You can export all your transaction data at any time from the Settings page in CSV or JSON format.

8. Your Rights

You have the right to:

  • Access: View all your data through the Service's interface or export it from Settings.
  • Correct: Edit or delete individual transactions at any time.
  • Delete: Request deletion of your account and all associated data by contacting us.
  • Portability: Export your data in a structured, machine-readable format (CSV or JSON) from Settings.

9. Data Security

We take reasonable measures to protect your data, including:

  • Row-Level Security on every database table, ensuring you can only access your own records
  • TLS encryption for all data in transit
  • Encryption at rest provided by Supabase
  • No administrative backdoors — the Service creator cannot view your data through the application

No method of electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

10. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal data, please contact us.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be noted in the "What's New" section within the Service. Continued use after changes constitutes acceptance of the updated policy.

12. Contact

For questions about this Privacy Policy or to request data deletion, contact: javanmyna.dev@gmail.com