CashCove

Privacy Policy

Effective 11 August 2026

How CashCove collects, uses, and protects your data — in plain language. Your financial data is yours; we never sell it or use it for advertising.

1. Who we are

CashCove (“we”, “us”) is a personal money-management tool. For the personal data described here, we act as the data controller. You can reach us about privacy at privacy@cashcove.app.

2. What we collect

  • Account data — your email address and authentication details, so you can sign in and we can secure your account.
  • Financial data you enter — transactions, budgets, accounts, loans, goals, bills, categories, tags, and notes. This is the data the Service exists to organize; it is never used for advertising.
  • Optional inbound data — if you enable email or Telegram capture, the messages you forward, solely to draft transactions for your review. Android SMS capture is described separately below.
  • Android SMS messages — only if you install the Android app and switch SMS capture on. The app requests SMS permission after you sign in, never before, and two things use it:
    • Capture reads messages arriving from the moment you opt in — never your existing history. Each one is checked on your phone first, and only messages that look like bank or payment transaction alerts are sent to us. Everything else is discarded on the device and never leaves it. What we receive becomes a draft you review; nothing is ever posted to your books automatically.
    • Sender discovery reads your SMS inbox on the device so the app can suggest which bank sender IDs to link to an account. This runs entirely on your phone. Message bodies from that scan are never uploaded, stored, or turned into drafts — only the sender ID reaches us, and only when you explicitly link one.
    We keep the original message text for 7 days, then erase it automatically, retaining only a digits-masked preview so a draft can still be traced to its source. You can switch capture off at any time, and signing out disables it on that device.
  • Technical & diagnostic data — limited error and performance data for security and reliability (IP address is not stored with error reports).
  • Analytics data — only if you accept analytics cookies (see section 6): usage events and, via Microsoft Clarity, anonymized session behavior. Your financial data is never sent to analytics.

3. Why we use it and our legal basis

  • To provide the Service (store and show your data, authenticate you) — legal basis: performance of a contract.
  • To keep the Service secure and working (error monitoring, abuse and fraud prevention) — legal basis: legitimate interests.
  • Analytics and product improvement — legal basis: your consent, which you can withdraw at any time.
  • To meet legal obligations (e.g. keeping limited security/audit records) — legal basis: legal obligation or legitimate interests.

4. Who we share it with (processors)

We do not sell your data. We use a small set of service providers who process data on our behalf to run CashCove:

  • Supabase — database, authentication, and backend functions (hosting region: India).
  • Netlify — application hosting and delivery.
  • Cloudflare — DNS and network security.
  • Sentry — error monitoring (personal identifiers disabled).
  • Resend — transactional and summary email delivery.
  • Google (Analytics / Tag Manager) and Microsoft (Clarity) — analytics, only with your consent.

5. Where your data is processed

Your data is hosted in India, and some of our service providers process data in the United States and elsewhere. If you have questions about where your data is processed, contact us using the details below.

6. Cookies and analytics consent

Essential cookies needed to run the Service and keep you signed in are always on. Analytics cookies (Google Analytics via Tag Manager, and Microsoft Clarity) load only after you accept them in the cookie banner. If you reject, none are loaded. You can change your choice at any time using the “Cookie preferences” link in the footer, or under Configure › Privacy & data in the app.

7. How long we keep it

We keep your account and financial data for as long as your account is active. When you delete your account, we permanently erase your data from our live systems, and it is removed from routine backups within a limited backup-retention window. We keep minimal security and audit records for a limited period afterwards to protect the Service and meet legal obligations, then purge them.

8. Your rights

Depending on where you live, you have rights over your personal data, including to:

  • Access and export your data — export it as JSON or CSV any time from Configure.
  • Erase your data — delete your account from Configure, which permanently removes your data as described above.
  • Rectify inaccurate data — edit it directly in the app.
  • Object to or restrict certain processing, and withdraw consent for analytics.
  • Lodge a complaint with your local data protection authority.

To exercise any right we can’t self-serve in the app, email privacy@cashcove.app.

9. How we protect it

Access to your data is scoped to your account through row-level security, the database is encrypted at rest, and connections are encrypted in transit. We do not apply a separate layer of end-to-end encryption, so staff with database access could in principle read your records; access is restricted and audited. No system is perfectly secure, but we work to protect your data.

10. Children

CashCove is not intended for children. You must be old enough to form a binding contract in your jurisdiction to use the Service.

11. Changes to this notice

We may update this notice as the Service evolves. When we make material changes we will update the effective date above and, where appropriate, notify you.

12. Contact

Questions about your privacy? Reach us at privacy@cashcove.app.

← Back to home© 2026 CashCove