Kesef

Privacy

What is stored, and what is not

Written to be read rather than to be defensible. If anything below is unclear, that is a problem with this page and worth telling us about.

What we store

WhatWhy
Your email, and your name if you gave one To sign you in and to send a password reset
Your transactions, accounts, plans, funds, pledges and events They are the product
Your observance and timezone settings Yom tov length changes the dates and the budget; the timezone decides when a reminder waits
An encrypted bank access token, if you connect an account To fetch new transactions. Encrypted with a key held outside the database
Session records — browser, IP, last seen So you can see where you are signed in and end a session you do not recognise
A security audit log — sign-ins, key creation, bank connections So a compromise can be reconstructed rather than guessed at

What we never store

  • Your bank password or login. Bank connections go through a provider that holds those credentials. They never reach us.
  • Your card number. Payment details go directly to the payment processor. We store a customer reference and a subscription status.
  • Your password. Authentication is handled by a dedicated service; we hold no password and no hash of one.

No tracking, and nothing to opt out of

There is no analytics script, no advertising pixel, no session recorder and no third-party tag on this site or in the application. The pages you are reading load one stylesheet and nothing else — which is also why they load instantly.

We keep server-side error logs and request logs, which record the request path and a request identifier. They do not record transaction contents.

We do not sell or share your data

Not to advertisers, not to data brokers, not to "partners". The subscription is the whole business model. The only third parties involved are the ones needed to run the service — the authentication and database host, the payment processor, and the bank-data provider if you connect an account — and each receives only what its job requires.

Your AI, if you connect one

When you connect your own assistant, it reads your data through a read-only key. What your assistant does with what it reads is governed by whoever provides it, not by us — worth knowing, because that conversation happens outside Kesef. Every request your assistant makes is recorded in your audit log, and you can revoke its key at any moment from Settings.

Leaving

Export. CSV export of your plan and transactions is in the app, works on every plan, and keeps working after a subscription lapses. Nothing is held back to make leaving harder.

Deletion. Ask and we delete your account and everything owned by it — transactions, accounts, plans, funds, events, pledges, sessions and keys — within thirty days. Backups age out on their own schedule, at most thirty-five days. The security audit log is retained for twelve months with the account identifier removed, because a log that can be deleted by whoever caused the entry is not an audit log.

How long things are kept

  • Your financial data: until you delete it. It is a record, and records are the point.
  • Sessions: until they expire or you sign out. Signing out deletes the record.
  • Request and error logs: thirty days.
  • Security audit log: twelve months.

Changes to this page

If it changes in a way that affects what is collected or who sees it, we will say so by email before it takes effect — not by quietly updating a date at the bottom.

Last updated 30 July 2026.