Privacy policy
Short version: your financial data is stored so it can sync to your devices, it is never sold or shared for marketing, there are no analytics or tracking scripts anywhere in this app, and you can export or delete all of it yourself in one click. The specifics follow.
Last updated: August 5, 2026
1. Who this is about
The FWF Ledger app (app.financewithoutfluff.com) is operated by Kaivora LLC, a U.S. limited liability company, which is the controller of the data described here. This policy covers the app only. The static site at financewithoutfluff.com stores its calculator data in your own browser and has its own, shorter policy.
2. What we store
Your account. Your name, your email address, and a cryptographic hash of your password — never the password itself. If you turn on two-factor authentication, the authenticator secret and your backup codes are stored encrypted. Each active sign-in also records a session token, the IP address, and the browser user agent it was created from, which is what lets you see and end sessions you don't recognise.
What you enter. Account names and types, balances and the dates they apply to, any notes you attach, debt details (APR, minimum payment, due day, payment plans), savings goals, budget percentages, and — if you use income smoothing — the income figure and tax set-aside you entered.
What your bank sends, if you connect one. Through Plaid: account names, types and balances, and the name of the institution. Where the transactions feature is switched on for your account, we also store each transaction's date, amount, description, merchant name, and Plaid's category for it. We store a Plaid access token so we can refresh balances; it is encrypted at rest with AES-256-GCM under a key that is not in the database.
Optional extras. If you enable push notifications, the push endpoint and keys your browser generates. If you invite someone to a household, the email address you typed.
3. What we don't store
We never receive your bank username or password — those are entered inside Plaid's own window and never touch our servers. We don't collect your Social Security number, date of birth, physical address, or phone number, and we don't pull the identity details Plaid could give us. We don't store card numbers; if you subscribe, your payment details are entered with and held by Stripe, our payment processor — they never touch our servers. We don't read the holdings inside an investment account — only its total value.
4. No analytics, no trackers
There is no analytics package, no telemetry, no advertising pixel, no session recorder, and no third-party script of any kind in this app. That is why you have never seen a cookie banner here: there is nothing to consent to beyond the one cookie that keeps you signed in. We don't build a profile of you, and we don't do anything with your data that would need one.
5. Cookies and what's in your browser
One cookie: better-auth.session_token, which is what keeps you signed in. It's HTTP-only, marked secure in production, restricted to same-site requests, and expires after seven days. It is strictly necessary — without it the app can't tell it's you.
The app also keeps a few things in your browser's own storage, which never leave your device: your light/dark preference, whether you dismissed the install prompt, which payoff approach you last picked on the debt page, and any balance you entered while offline (held until it syncs, then cleared). The offline service worker caches the app's own icons and code — never your financial data, and never an authenticated page.
6. Who else touches your data
We use vendors to run the app. They process data on our instructions and are not permitted to use it for their own purposes. That's the honest version of “we don't share your data” — not that nobody ever sees a byte, but that nobody is ever sold one.
- Neon — hosts the database, so it holds everything in section 2.
- Vercel — hosts and serves the app, so it processes your requests and server logs.
- Plaid — only if you connect a bank. Plaid receives an internal account identifier from us and returns your balances; your bank credentials go to Plaid directly and never to us. Plaid's own privacy policy is shown to you before you connect, and it governs what Plaid does.
- Resend — sends our email, so it processes the recipient address and the message. Weekly check-in emails contain figures like your net worth and total debt, which is worth knowing before you turn them on.
- Your browser's push service — only if you enable push notifications. Whoever makes your browser (Apple, Google, Mozilla) relays the message; the contents are encrypted so they can't read it.
We do not sell your data, share it for advertising, or hand it to data brokers or lead generators — as committed on the promises page. We would disclose data if legally compelled to, and we'd tell you unless we were prohibited from doing so.
7. Email and notifications
The weekly check-in is off until you turn it on, and only sends when something has actually changed. Our emails are plain text with no tracking pixels, so we can't tell whether you opened one. Every check-in ends with an unsubscribe link that works without signing in and takes one click. Emails we send regardless of that setting are the ones you asked for by acting: verifying your address, signing in by link, and household invitations.
8. Keeping it, and deleting it
We keep your data while your account exists, because a tracker with no history isn't a tracker. Nothing is aged out or deleted behind your back — the free tier's twelve-month view hides older history from the chart, it doesn't erase it, and your export always contains everything.
Deleting your account takes one confirmation and happens immediately: your accounts, balances, history, goals, budget settings, sessions, and login are removed from the live database in that moment, and we sever any bank connection at Plaid before the data goes. There is no thirty-day recovery window, no retention offer, and no support ticket. Five honest caveats:
- If Plaid can't be reached at the moment you delete — their systems are down, or the call times out — everything of yours still goes right then. Your deletion doesn't wait on somebody else's uptime. The single thing we hold on to is the encrypted key that severs the bank connection, kept on its own with nothing attached to it: no name, no email, no account, nothing that points back to you. A daily job keeps trying that key until the connection is actually cut, and then the key is deleted too. We keep it because the alternative is worse — a link to your bank left open with nobody able to close it.
- If you share a household with other people, deleting your account removes your accounts and your membership, but data that belongs to them stays theirs.
- Routine encrypted database backups kept by our hosting provider age out on their own cycle rather than instantly, which is a property of how backups work everywhere.
- Expired email verification and sign-in tokens tied to your address may linger briefly before they are cleared; they contain no financial data.
- A household invitation you sent and then revoked keeps the email address you typed, marked revoked, until your account or the household is deleted — at which point it goes with them.
9. Household sharing
If you join a household, the other members see only the accounts and goals you have marked household-visible. Anything left private stays private to you, on every screen and in every total they see. You choose this account by account, and can change it whenever you like.
10. Security
Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form. Plaid access tokens are encrypted with AES-256-GCM using a key held outside the database, and two-factor secrets and backup codes are encrypted too. Two-factor authentication is available by authenticator app — and never by SMS, which is a deliberate choice, because a phone number is the easiest thing about you to steal. No system is perfectly secure, and we won't pretend otherwise; if a breach affected your data we would tell you what happened and what to do.
11. Your rights
You can see everything we hold by exporting it — full JSON or CSV, one click, no request form and no waiting period. You can correct anything by editing it directly, including backdated history. You can delete everything from settings. We extend these to everyone rather than checking where you live first, and we will never charge for them or make you talk to someone to exercise them. If something you want isn't covered by a button, email us and we'll do it.
12. Children
This app isn't intended for anyone under 16, and we don't knowingly collect their data. If you believe a child has created an account, tell us and we'll remove it.
13. Changes, and contact
If this policy changes in a way that affects what happens to your data, we'll say so rather than quietly editing the page and moving the date. Questions, requests, or a correction to something here: support@kaivorallc.com. The terms of use cover the rest of the relationship.