Privacy Policy

Last updated 30 July 2026

This describes what Dinari collects, why, and what you can do about it — see the honest-limits note at the end of this page.

What we collect

  • Account information — your name, email address, and password (stored as a bcrypt hash, never in plain text).
  • Financial data you add— accounts, transactions, categories, budgets, assets, IOUs, and any notes or files you choose to import. This is the core of what the app is for, and it is only ever added by you or someone you've explicitly given access to an account.
  • Sharing information — if you invite a family member or friend, their name and email so the invitation and any shared-account access can work.
  • Basic technical data — things like IP address, used transiently for rate limiting and abuse prevention, not retained as a profile of your activity.

We do not collect more than the above. There is no advertising SDK, no analytics pixel, no data broker relationship.

How we use it

Solely to provide the app's features to you: showing your dashboard and reports, sending reminders you've opted into, detecting subscriptions and budget overruns, and letting you import/export your own data. We do not use your financial data for advertising, and we do not sell it to anyone, under any circumstances.

Who else can see it

Nobody, by default. The only ways another person sees any of your data:

  • You explicitly grant them access to a specific account (view-only or edit) — you control this and can revoke it at any time.
  • You record an IOU with someone and give them a portal link — they see only that shared balance and history, not your accounts.
  • If you enable AI-assisted categorisation or import, the specific merchant/transaction text or statement file involved is sent to the AI provider (Anthropic or Google) to generate a suggestion — this is opt-in and can be turned off in Settings at any time.

Where it's stored

On a managed Postgres database (Neon). Uploaded bank statement files are parsed in memory to extract transactions and are not retained afterward.

Your control over your data

  • Export— download your transactions at any time (CSV, QIF, OFX, or QFX) from Export & Data.
  • Delete— clear a single account, or permanently delete your entire account and all associated data, from the same page. Deletion is immediate and cannot be undone by us — we don't keep a hidden backup copy after you delete.
  • Correct — edit your name, email, categories, and any entry directly in the app at any time.

Children

Dinari isn't directed at or intended for use by children, and we don't knowingly collect data from anyone under the age of 16.

Changes to this policy

If this policy changes in a way that meaningfully affects how your data is handled, we'll update the date at the top of this page and, where practical, notify account holders directly.

Contact

Questions about this policy or your data — email dinarisupport@gmail.com.

Honest limits — please read this

This policy describes our actual, current practices in good faith. It is written by the person operating this app, with AI assistance, and is not a substitute for review by a qualified privacy lawyer — particularly regarding formal obligations under specific laws (such as GDPR, CCPA, or similar) that may apply depending on where you live and how widely this app is used. If Dinari grows beyond a small circle of trusted users, that legal review should happen before it does.