Privacy policy
Last updated 2 September 2026
The short version
- We store your email, your name, a one-way hash of your password, and the records you create.
- We do not sell your data, advertise to you, or run third-party trackers.
- The people you record are never contacted, notified or invited by us.
- You can export everything, and you can delete your account and its data yourself.
What we collect
Account information
Your name, your email address, and your password stored as a salted scrypt hash. We never store the password itself and cannot recover it — a reset link is the only route back in.
The records you create
The names, amounts, dates, categories and notes you enter, plus any phone number or email you choose to add for someone so you can send them a reminder. Only you can see this. It is stored so we can show it back to you and sync it between your devices.
Please only record details about other people that you have a good reason to hold, and keep it proportionate — a name and an amount is usually enough.
Technical information
To keep sessions working and the service secure we store, for each active session, an approximate IP address, your browser's user-agent string, and when the session was created and last used. You can see your active sessions and sign them out from your account page.
Billing information
If you subscribe, card details go directly to our payment provider and never touch our servers. We keep a customer reference, your subscription status and renewal date, and the card brand and last four digits so you can recognise it.
What we do not do
- No advertising, no ad networks, no analytics that follow you around the web.
- No selling, renting or sharing of personal data with data brokers.
- No contacting the people in your records. No “your friend says you owe them” emails, ever.
- No bank connections and no access to your accounts.
- No reading of your records by staff except where you explicitly ask for support and give permission, or where the law requires it.
Cookies
We set two cookies, both strictly necessary and neither used for tracking:
- wom_sid — your signed-in session. HttpOnly, so scripts cannot read it. Expires after 30 days.
- wom_csrf — a token that proves a form submission came from our own pages, protecting you from cross-site request forgery.
Your theme preference is kept in your browser's local storage, not sent to us. Because we set no tracking cookies, there is no consent banner to click away.
How long we keep things
- Your records — until you delete them or delete your account.
- Sessions — 30 days from last use, or immediately when you sign out.
- Password reset links — one hour, and they are single-use.
- Billing records — as long as tax and accounting law requires, separate from your ledger.
Deleting your account removes your user record, your ledger, your sessions and your account history. Backups roll off on their own schedule shortly afterwards.
Your rights
Depending on where you live you may have the right to access, correct, export, delete or restrict the use of your personal data, and to object to processing or complain to a regulator. Most of these you can exercise yourself, immediately:
- Access and export — Settings → Backup (JSON) or Export CSV.
- Correction — edit any record, or your name and email on the account page.
- Deletion — Account → Delete account.
For anything else, contact [insert data protection contact].
Security
Passwords are hashed with scrypt and a per-user salt. Session tokens are random and stored hashed, so a copy of the database does not let anyone sign in as you. Requests that change data must carry a CSRF token. Sign-in, sign-up and reset attempts are rate limited. Serve the site over HTTPS in production so cookies are marked Secure.
No system is perfectly secure. If we discover a breach affecting your data we will tell you and the relevant regulator without undue delay.
Where your data is held
Your data is stored on servers operated by [insert hosting provider and region]. Our payment provider processes billing data under its own terms.
Children
The Service is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
Changes
If we change this policy in a way that materially affects you, we will tell you by email or in the app before it takes effect.