← Back home

Privacy Policy

docs/legal/privacy-policy.md

Draft — not legal advice.This is a working draft pending review by a qualified lawyer before it's treated as final.

[Company Legal Name] (“we,” “us,” “TwoPurse”) operates TwoPurse, a household budgeting, expense-tracking, and debt-management application (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By creating an account, you agree to the collection and use of information as described here.

1. Information we collect

Account information — email address, display name, and authentication data, handled by our authentication provider (Supabase Auth).

Household financial data — anything you or a household member enters into the Service: income amounts, budget categories and limits, individual expenses (amount, date, category, note, payment method), loans and EMI details, credit card bill entries, and opening balances. This data is provided entirely by you and your household members — we do not connect to your bank or pull financial data from any external source.

Billing information — if you subscribe to a paid plan, our payment processor (Razorpay) collects and processes your payment card or UPI details directly. We do not store your full card number or bank credentials on our servers.

Usage and technical data — device/browser type, IP address, pages visited, and general usage patterns, collected via our analytics provider. Error and crash reports, which may include technical context (e.g. the page you were on and a stack trace), collected via Sentry.

2. How we use your information

We do not sell your personal or financial information to third parties, and we do not use your household's financial data for advertising.

3. How data is shared within a household

This is core to how the product works, so it's worth stating plainly: any financial data entered into a household — income, expenses, budgets, loans, balances — is visible to every member who has accepted an invitation to that household. Household membership is managed under Settings; removing a member revokes their access to that household's data going forward.

4. Third parties who process data on our behalf

ProviderPurposeWhat they see
SupabaseDatabase, authentication, real-time syncAll account and household financial data (encrypted at rest and in transit)
VercelApplication hostingRequest/traffic metadata
RazorpayPayment processingBilling/payment details — not your household financial data
SentryError monitoringTechnical error context; configured to avoid capturing financial field values where possible
[PostHog / Plausible]Product analyticsUsage/behavioral data, not financial data entered into the app

We do not permit these providers to use your data for their own purposes beyond providing their service to us.

5. Data retention and deletion

We retain your account and household data for as long as your account is active. If you delete your account (Settings → danger zone), we will delete your personal account data and, where you are the sole member of a household, that household's data, within [X days], except where retention is required for legal, tax, or fraud-prevention purposes. To request deletion or export of your data, contact us at [privacy@yourdomain.com].

6. Data security

Data is encrypted in transit (TLS) and at rest. Access to household data is enforced at the database level via Postgres Row-Level Security, scoped to accepted household members only — no application code path can read across households. No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to the Service.

7. Children's privacy

The Service is not directed to individuals under 18. We do not knowingly collect information from children.

8. International data transfers

Your data is hosted in [Supabase region, e.g. ap-south-1 / Mumbai]. If you access the Service from outside that region, your data will be transferred to and processed there.

9. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Contact us at [privacy@yourdomain.com] to exercise these rights.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice before they take effect.

11. Contact us

[Company Legal Name]
[Address, if applicable]
[privacy@yourdomain.com]