Privacy Policy
1. Who is responsible for your information
[REGISTERED ENTITY NAME] ("we") is the responsible party for the personal information described here, as that term is used in the Protection of Personal Information Act 4 of 2013 (POPIA).
- Information Officer: [NAME], [EMAIL]
- Address: [ADDRESS]
- Information Regulator (South Africa): you may complain to the Regulator at any time — [email protected]
2. What we do with your statement file
We never write your statement file to disk. You upload a PDF, we read it in memory, we extract the transactions, and the file is gone when the request ends. We never have a copy of a statement we could read. There is no folder of PDFs anywhere in this system.
The one exception is a statement laid out in a way we cannot read yet. We keep one encrypted copy of that file in our database, not linked to your account, so that we can add support for that layout. It is deleted 30 days after it was uploaded. Nothing from it is added to your transactions.
3. What we do keep
From each statement we keep the transaction rows — the date, the description your bank printed, the amount, and the running balance — together with the category each row was put in and any category you corrected by hand.
We keep your categorising rules with your statements, in our database. A rule is the text it matches, the category you chose and, if you limited it to one account, which account — nothing else. They follow your sign-in, so they are the same on every device, and the Rules page lists and deletes them.
We keep your account number, encrypted. We read it off the statement — you never type it in — and we keep it so that the account can be named on screen: two accounts at the same bank are often both called "Private Bank Account", and without the number there is nothing to tell them apart. It is stored scrambled (AES-256-GCM) under a key that is not held in the same database as the number, and it is deleted when the rest of your statements are. We also keep which bank the statement came from.
4. How long we keep it
If you do not have an account: thirteen months from your last visit, rolling. Every time you come back the clock restarts. When it does run out, everything is deleted automatically by a job that runs daily at 03:15 — not archived, not anonymised, deleted.
Thirteen months is deliberate: a budgeting product that compares this month to the same month last year cannot forget you between visits.
If you do have an account, that clock does not apply. Your data is kept for as long as the account exists, and goes when you delete it.
5. Your account, if you create one
You can use the whole product without an account. If you create an account we store your email address and a hash of your password.
We never keep the password itself. It is put through PBKDF2-HMAC-SHA256 at 210,000 iterations with a random salt per user, and only the result is stored. Nobody here can read it, including us.
We use your email address to identify you when you sign in, and to reach you if something goes wrong with your data. We do not send marketing, and there is no mailing list.
6. The cookie
One cookie joins one visit to the next so that your statements are still there when you come back. It holds an identifier and nothing else — no name, no email, no transaction data.
Clearing your browser clears it. Without an account, a cleared cookie means we can no longer connect you to your previous uploads, and that data will be deleted at the end of its thirteen months.
7. What we learn across users
We count how often a shop lands in a category across everybody who uses the product, so that the next person's "WOOLWORTHS PLACE 4021" is categorised correctly without them having to fix it.
These counts are a merchant name and a number. They carry no link to you, no amount and no date, and they are not reversible into a person.
8. Who else sees it
Nobody. Nothing leaves our servers.
- No third-party analytics, advertising or tracking.
- No AI model sees your transactions. Categorisation runs on rules on our own server, which is also why there is no transborder transfer to disclose under POPIA s 72.
- We have never sold personal information and will not.
The only exception is one we hope never to use: if we are compelled by law, we will comply, and we will tell you unless we are forbidden to.
9. Your rights under POPIA
You may, at any time:
- Ask what we hold about you (s 23) and get it back in a usable form.
- Correct or delete anything that is wrong, irrelevant, excessive or out of date (s 24).
- Withdraw your consent and stop using the product; withdrawal does not undo processing that was lawful before it.
- Object to processing (s 11(3)).
- Complain to the Information Regulator (s 74).
You can download and delete your data yourself, on the Account page, linked from the menu on every page: Download my data gives you everything we hold as a file, and Delete my data (or Delete my account) removes all of it at once. This works with or without an account.
For anything else: email [EMAIL]. We answer within 30 days.
10. Keeping it safe
Your data sits in a South African-hosted SQL Server database with access limited to the application's own service identity. Passwords are hashed as described in section 5. Statement files never reach storage, so they cannot leak from it.
Gap, declared deliberately: [budget.netdentity.net] is served over HTTP today, not HTTPS. Until that is fixed this section cannot honestly claim transport security, and the policy should not go live before it is. See the gap list.
11. Children
The product is not intended for anyone under 18, and we do not knowingly hold a child's information.
12. Changes
If we change how we handle your data we change this page and date it. When the change is material we will say so on the page rather than hope you re-read it.
Last updated: [DATE OF PUBLICATION]