Privacy
What is stored, and what is not
Written to be read rather than to be defensible. If anything below is unclear, that is a problem with this page and worth telling us about.
What we store
| What | Why |
|---|---|
| Your email, and your name if you gave one | To sign you in and to send a password reset |
| Your transactions, accounts, plans, funds, pledges and events | They are the product |
| Your observance and timezone settings | Yom tov length changes the dates and the budget; the timezone decides when a reminder waits |
| Bank connection and provider account identifiers, if you connect an account | So the server can ask Stripe Financial Connections for account updates |
| Session records — browser, IP, last seen | So you can see where you are signed in and end a session you do not recognise |
| A security audit log — sign-ins, key creation, bank connections | So a compromise can be reconstructed rather than guessed at |
What we never store
- Your bank password or login. Bank connections go through a provider that holds those credentials. They never reach us.
- Your card number. Payment details go directly to the payment processor. We store a customer reference and a subscription status.
- Your password. Authentication is handled by a dedicated service; we hold no password and no hash of one.
No tracking, and nothing to opt out of
There is no analytics script, no advertising pixel, no session recorder and no third-party tag on this site or in the application. The pages you are reading load one stylesheet and nothing else — which is also why they load instantly.
We keep server-side error logs and request logs, which record the request path and a request identifier. They do not record transaction contents.
We do not sell or share your data
Not to advertisers, not to data brokers, not to "partners". The subscription is the whole business model. The only third parties involved are the ones needed to run the service — the authentication and database host, the payment processor, and the bank-data provider if you connect an account — and each receives only what its job requires.
Your AI, if you connect one
When you connect your own assistant, it reads your data through a read-only key. What your assistant does with what it reads is governed by whoever provides it, not by us — worth knowing, because that conversation happens outside Kesef. Every request your assistant makes is recorded in your audit log, and you can revoke its key at any moment from Settings.
Leaving
Export. CSV export of your plan and transactions is in the app, works on every plan, and keeps working after a subscription lapses. Nothing is held back to make leaving harder.
Deletion. There is not yet a self-service deletion control. A deletion request is handled by the operator and includes the account's financial records, sessions and keys. Backup retention follows the database host's configured schedule. The current audit log remains attached to the account; it is not automatically anonymised after twelve months.
How long things are kept
- Your financial data: until you delete it. It is a record, and records are the point.
- Sessions: signing out revokes them immediately; expired and revoked rows are later removed by housekeeping.
- Request and error logs: according to the hosting deployment's configured retention.
- Security audit log: retained for the life of the account unless the operator processes an account-deletion request.
Changes to this page
If it changes in a way that affects what is collected or who sees it, we will say so by email before it takes effect — not by quietly updating a date at the bottom.
Last updated 3 September 2026.