Privacy policy · draft
Privacy, in plain English
Your household's records are yours. Here is what we hold, why, and who can see it.
What we collect
- Account details you give us: your name, email, phone number, and household name.
- Records you add or connect: documents, statements, bills, properties, entities, policies, and accounts.
- Basic technical data: sign-in times, device and browser type, and IP address, used for security.
How we use it
- To run your household ledger and show it back to you.
- To let Diana read your records and draft summaries, follow-ups, and records for you to confirm.
- To keep your account secure, including two-factor sign-in and fraud checks.
- We do not sell your personal information. We do not use your records to advertise to you.
Who can see it
- You, and the people you invite to your household, in the roles you choose.
- Advisors see only what an owner shares, and only until the share expires.
- Service providers that help us run the product (hosting, storage, email, text messages, AI processing, bank linking, payments) under contracts that limit their use of your data.
- Authorities when the law requires it. We will tell you when we are allowed to.
How we protect it
- Documents are encrypted at rest with a key per household. Sessions use secure, HTTP-only cookies.
- Two-factor sign-in is required. Sensitive actions are recorded in an audit log you can read.
- Diana is read-only: she cannot send money, send mail, or file anything on her own.
Your choices
- You can see, correct, export, or delete your records. Deleting your household removes its data from active systems; backups age out on a fixed schedule.
- You can disconnect a bank, cloud folder, or email source at any time.
- Contact us through the Talk to us page with any privacy request.
Changes
- If we change this policy in a way that matters, we will tell you in the app or by email before it takes effect.