Back to home

Legal

Privacy Policy

Effective date: February 20, 2026

We only collect what we need to run Yitra, secure your account, and improve the product.

Data we collect

  • Account info like your name and email address.
  • Login and session details used to keep your account secure (for example, session records, IP address, and device/browser info).
  • Budget data you add, like budgets, accounts, categories, payees, transactions, amounts, currencies, and memos.
  • Your newsletter preference if you opt in.
  • Basic app usage and error data to keep Yitra reliable.

How we use data

  • Provide core budgeting features.
  • Sign you in and protect your account.
  • Send account emails (like sign-in and verification).
  • Send optional newsletter updates when you subscribe.
  • Fix bugs, monitor performance, and improve the app.

Services we use

  • PostHog for product analytics and website usage trends.
  • Sentry for error and performance monitoring.
  • Resend for account emails and newsletter delivery.
  • PostgreSQL to store application data.

We share data with these providers only when needed to run Yitra.

How we encrypt your data

Sensitive budgeting text is encrypted before storage. This includes items such as budget names, account names, category names, payee names, and transaction memos.

We use industry-standard AES-256-GCM encryption with a unique random value for each encrypted record. Encryption keys are derived from a server-side master key and are not exposed in the browser.

Cookies

  • Session cookies are used to keep you signed in securely.
  • A short-lived signed cookie may be used during sign-in to carry newsletter preference.
  • Analytics tools like PostHog may use cookies or browser storage for measurement.

Retention

We keep account and budgeting data while your account is active. We also keep limited operational logs for reliability and security.

Your choices

  • You can update your account details and preferences.
  • You can opt in or out of newsletters.
  • You can request account and data deletion.
  • In some shared-budget cases, you may need to leave shared budgets first before full deletion.

What we do not do

We do not sell your personal data.

Updates and contact

We may update this policy from time to time. For privacy questions or requests, use the contact page.