Privacy Policy
Last updated: 3 September 2026
This policy explains what the My Passbook app and website collect, why, and the choices you have. The data controller (data fiduciary) is My Passbook, contactable at developerpb07@gmail.com.
The short version
Used as a guest, the app keeps everything on your device. We receive nothing.
Create an account and your ledger plus your email are stored on our hosted backend so they can sync across your devices.
No ads. No third-party advertising or analytics trackers.
Email is used only to run your account — never for marketing.
What we collect
Ledger data you enter. Accounts, transactions, transfers, categories, tags, budgets, recurring items, and the people and debt records you create. As a guest this stays only in local storage on your device. With an account, a copy is stored on our backend to enable backup and multi-device sync.
Account credentials. If you create an account: your email address and a securely hashed password, handled by our authentication provider (Supabase). Guests are issued an anonymous identifier with no personal details attached.
Technical data. When the app or website contacts our backend, standard request metadata (such as IP address and timestamps) is processed by our infrastructure providers to deliver and secure the Service. We do not build advertising or behavioural profiles.
What we do not collect
No advertising identifiers, no ad networks.
No third-party analytics or session-recording SDKs in the app.
No access to your contacts, photos, camera, or location.
No bank connections — figures are only what you type in.
How we use it
To store and sync your ledger across your devices when you have an account.
To authenticate you and let you reset your password.
To operate, secure, debug, and improve the Service.
To comply with legal obligations and enforce our Terms of Service.
Where the law asks us to identify a legal basis: running your account is performance of our contract with you (the Terms of Service); security, debugging, and improvement rely on our legitimate interests in operating a reliable Service; some processing is to meet legal obligations. Where consent is required, we ask for it and you can withdraw it.
Email
We send transactional email only: password-reset codes and, if enabled, account-confirmation messages. Delivery is handled by our email provider, Resend. We do not send newsletters or promotional email.
Who we share it with
We do not sell your personal data and we do not share it for advertising. We share it only with the providers that run the Service on our behalf, under agreements that limit them to processing it for us:
Supabase — hosted database and authentication.
Resend — transactional email delivery.
Vercel — hosting for this website.
We may also disclose data if required by law, to protect our rights or users' safety, or as part of a business transfer (you would be notified).
Where it is processed
Our providers may process and store data on servers outside your country, including in the United States and the European Union. Where a transfer needs a safeguard under Indian, EU, UK, or other law, we rely on appropriate measures such as standard contractual clauses and the providers' own compliance programmes.
How long we keep it
Guest data lives on your device until you delete entries or remove the app. Account data is kept while your account exists. Signing out of a device deletes that device's local copy and returns it to a fresh guest ledger. To delete your account and the data stored on our backend, email developerpb07@gmail.com — we action deletion requests within 30 days, subject to any legal retention we are required to observe.
Your rights
Depending on where you live — for example under India's Digital Personal Data Protection Act, 2023, the EU/UK GDPR, or similar laws — you may have the right to access, correct, complete, update, export, or erase your personal data, to withdraw consent, to nominate someone to exercise your rights, and to complain to a data-protection authority. Most ledger data is already visible and editable inside the app; for anything else, contact developerpb07@gmail.com. If you are in the EU/UK you may also object to or restrict certain processing.
Security
Data in transit is encrypted (HTTPS/TLS). Account data on our backend is isolated per user by row-level security so one account cannot read another's. Passwords are stored only as salted hashes. No system is perfectly secure, so we cannot guarantee absolute security; tell us at developerpb07@gmail.com if you spot a problem.
Children
The Service is not directed to, and not intended for, anyone under 18. We do not knowingly collect their personal data; if we learn we have, we will delete it.
Changes
We may update this policy. The current version is always on this page with its “last updated” date; where a change is significant we will make reasonable efforts to highlight it in the app or by email.
Contact
Privacy questions or requests: developerpb07@gmail.com.
© 2026 My Passbook · Terms · Privacy
developerpb07@gmail.com