Privacy Policy
Last updated: 27 July 2026This Privacy Policy explains what information CashLedger ("CashLedger", "we", "us") collects, how we use it, and the choices you have. CashLedger is a personal and family expense-tracking application available at
cashledger.chaitanyalakamsani.com. By creating an account or using the application, you agree to this policy.1. Information you provide
When you register and use CashLedger, you provide:
- Account details — your email address, first and last name (optional), an optional phone number, and a password. Passwords are handled and stored by our authentication provider (Supabase Auth) as salted hashes; we never see your plaintext password.
- Profile picture — an avatar image, if you choose to upload one.
- Financial records you enter — transactions (amount, date and time, type, description, notes, classification), categories and subcategories, merchants, accounts (including a name, opening balance and, if you enter one, an institution name and a masked account number), payment modes, tags, locations, and budgets.
- Family workspace data — a family/workspace name, its membership, and invitations you send (the invited email address and an invitation token).
- Preferences — theme, currency, timezone, default account and payment mode, and your favorite categories/subcategories.
- Saved searches — filters you choose to save.
2. Information from Google Sign-In
If you choose "Continue with Google", Google shares your email address and basic profile information with us so we can create or access your account. We do not receive your Google password.
If your Google account has a profile picture, we make a copy of it in our own storage once, when your account is created, and serve that copy. We do not link to the image on Google's servers, so viewing CashLedger does not send a request to Google for your picture.
3. Your profile picture is not public
Avatar images are held in private storage. They are not publicly accessible and cannot be reached by guessing a URL. When the application needs to display your picture it generates a temporary link that expires after 24 hours and grants access to that one image only. If you replace your picture, the previous image is deleted immediately and any link to it stops working straight away.
4. Information collected automatically
- Authentication & session data — session cookies set by Supabase Auth to keep you signed in, and the time of your most recent sign-in.
- Usage analytics — Google Analytics 4, but only on our public pages and, in some countries, only with your consent. See section 5.
- Country — our hosting provider tells us the two-letter country your request comes from. We use it for one purpose only: to decide whether we must ask for your analytics consent before loading analytics. It is stored in a cookie that is deleted when you close your browser, and it is never sent to anyone else.
- Server logs — our hosting provider (Vercel) processes standard request information (such as IP address and user-agent) to serve and secure the application.
5. Analytics — public pages only
Analytics never runs inside your account. Google Analytics is loaded only on our public pages — the home, sign-in, sign-up, forgot-password, Privacy Policy and Terms pages. It is not loaded on any page of the signed-in application, nor on invitation, password-reset or sign-in-callback pages.
As a result, no financial information ever reaches Google Analytics: no transaction, budget, account or other record identifier, no amounts, no email address, no user or family identifier, and no invitation token. Page addresses we do report are stripped of any query string, and any identifier-shaped part of an address is replaced before it is sent. We send only page views of those public pages — no custom events.
We have also switched off Google's advertising features for this property in code — not merely in a settings panel — so your usage cannot be combined with advertising profiles or used for ad personalisation.
If you are in the EU, the EEA or the United Kingdom, we ask for your consent before loading Google Analytics at all. Until you accept, no Google script is requested, no analytics cookie is set, and no data leaves your browser. If you decline, analytics is never loaded and CashLedger works exactly the same. If we cannot determine which country you are in, we ask for consent rather than assume it. Elsewhere, analytics loads without a banner. Your choice is stored on your device only and is never sent to us.
You can change your mind at any time. "Cookie Preferences" in the footer of every public page lets you withdraw consent or grant it again, and takes effect immediately. Your choice — whether you accepted or declined — is remembered for 12 months, after which we ask again rather than assuming a decision you made a year ago still holds.
6. How we use your information
- To provide the application — authenticate you and store and display your records.
- To enable family sharing — members of your family workspace can view shared records.
- To generate the reports, analytics and exports you request.
- To secure the service — including rate limiting and abuse prevention.
- To understand aggregate usage of our public pages, as described in section 5.
We do not sell your personal information, and we do not use your financial records for advertising.
7. Family workspaces and sharing
CashLedger is designed for shared use within a family workspace. Records you add to a family are visible to other members of that family. Each family has exactly one Owner, who can manage the family's shared data, membership and invitations. The Owner can hand ownership to another member, after which they become an ordinary member. Only share a workspace with people you trust.
8. Invitations
To invite someone, you create an invitation link. If you address the invitation to a specific email address, that address is stored so we can validate who accepts it, and it is shown to anyone opening the link only in masked form (for example
c•••a@gmail.com). The name of the person who sent the invitation and the family name are shown in full — that is the point of an invitation, but it does mean anyone you forward an invitation link to can see who invited them and to which family. Treat invitation links as confidential.Invitations follow a fixed lifecycle, applied automatically by a daily job:
- 7 days — an invitation is valid for seven days, after which it expires and can no longer be accepted.
- 30 days — once an invitation has been accepted, declined, revoked or expired, the invited email address is erased from it thirty days later.
- 180 days — the invitation record itself is deleted permanently after one hundred and eighty days.
An Owner can revoke a pending invitation at any time.
9. Service providers
We rely on the following providers to run CashLedger:
- Supabase — database, authentication, and file storage (your account, financial records, and avatar images).
- Vercel — application hosting and delivery.
- Google — Google Sign-In (optional authentication) and Google Analytics (public pages only, as described in section 5).
- Cloudflare — DNS for our domain.
These providers process data on our behalf under their own terms and privacy policies. We use no payment processor, no email or SMS provider, no error-tracking service and no push notification service. Fonts are served from our own servers, not from Google Fonts.
10. Cookies and browser storage
This is the complete list of what CashLedger stores in your browser.
- Essential cookies — Supabase Auth session cookies, which keep you signed in. The application cannot function without them.
- Preference cookie — remembers your light/dark theme.
- Country cookie — a two-letter country code used only to decide whether to ask for analytics consent (section 5). Deleted when you close your browser.
- Analytics cookies — Google Analytics
_gacookies, set only on our public pages, and in the EU/EEA/UK only after you accept. - Local storage — your theme and sidebar preference, whether you have installed or dismissed the app-install prompt, and your analytics consent choice (the decision plus the date you made it, so we know when to ask again).
- Session storage — while you are accepting an invitation, the invitation token and the invited email address, for the current browser tab only. It is discarded when you close the tab, when you sign out, or after 30 minutes.
No financial data is stored in your browser. CashLedger is not an offline application; your records are fetched from the server each time you use it. Pages containing your data are marked as not cacheable, so they are not written to disk or kept for the browser's back button, and signing out clears the application's local data and cache. Your analytics choice is intentionally kept when you sign out, so we do not re-ask a decision you have already made; you can change it from "Cookie Preferences" in the footer at any time.
11. Data retention
We retain your information while your account remains active. When you delete a record it is soft-deleted — hidden from the application but retained in the database so financial history is not lost accidentally, and so it remains available to the other members of a shared family workspace. Certain information may be retained for operational, security, backup, or legal reasons.
Invitations are the one category with an automatic schedule, described in section 8. Financial records have no automatic deletion schedule. You can export your data at any time, and you can delete your account as described below.
12. Your choices and rights
- Access & portability — you can export your transactions and related data at any time as CSV, Excel, or PDF from within the application.
- Correction — you can edit your profile, preferences, and records directly in the application.
- Analytics — where we ask for consent, you can decline, and analytics is never loaded.
- Deletion — see section 13.
13. Deleting your account
You can have your account deleted. Contact us at the address in section 17 and we will carry it out. When an account is deleted:
- your identifying information is erased — email address, first and last name, phone number, profile picture and personal preferences are removed from your profile;
- your profile picture is deleted from storage, and any temporary link to it stops working;
- your sign-in account is anonymised too — the email address held by our authentication provider is replaced with an unrecoverable random value, and the name and profile picture supplied by Google (if you signed in that way) are erased. Your access is revoked immediately and the account can no longer be signed in to. Because the address is genuinely gone, you are free to register again with the same email later;
- pending invitations you sent, and pending invitations addressed to you, are revoked;
- if you were the last member of a family workspace, that workspace is removed with you;
- if you were the Owner of a workspace that still has other members, you must first transfer ownership to one of them, so their shared records are not left without an administrator.
What is kept: the financial records in a shared family workspace are retained for the remaining members, and are no longer associated with your name or email address. This is because those records belong to the workspace as a whole — deleting them would erase the other members' own financial history. If you were the only member, the workspace and its records are removed with your account.
14. Security
Data is transmitted over HTTPS. Access to your family's data is enforced at the database level by row-level security, so one family cannot access another's data. We apply a Content Security Policy, strict security headers, application-level rate limiting, and validation of uploaded images (an upload is checked by its actual file content, not its claimed type). Avatar storage is private and reachable only through expiring links. No method of transmission or storage is completely secure, but we take reasonable measures to protect your information.
15. International processing
Your account and financial data are stored and processed by Supabase in the Mumbai, India region (ap-south-1). Our hosting provider (Vercel) serves the application from its global network, and Google processes the limited analytics described in section 5 on its own infrastructure. By using CashLedger, you consent to this processing.
16. Children
CashLedger is not directed to children, and we do not knowingly collect information from children. If you believe a child has provided us data, contact us and we will remove it.
17. Changes and contact
We may update this policy as the application evolves. Material changes will be reflected by updating the "Last updated" date at the top of this page. See also our Terms & Conditions.
Questions, requests, or account deletion:
hello@chaitanyalakamsani.com.