The short version
Aartha never connects to your bank. It stores only what you type in. It runs no advertising trackers and no third-party analytics. Your financial records are not sold, rented, or shared with advertisers - not in aggregate, not anonymised, not ever.
What is collected
Account information
- Your email address, used to sign in and to send verification and reset codes.
- Your display name, if you provide one.
- A one-way hash of your password. The password itself is never stored and cannot be recovered from the hash - only reset.
Financial information you enter
All of it is information you type in yourself: salary amount and payday, expenses, recurring bills, savings goals, investments, budget rules, and the names and balances of bank accounts and credit cards you choose to track.
Note what this list does not include. Aartha has no bank integration, so it never receives or stores account numbers, card numbers, IFSC codes, UPI IDs, net banking credentials, or any other means of moving money. An account balance in Aartha is a number you typed, not a live connection.
Technical information
- A single session cookie,
sf_session. It is httpOnly (not readable by scripts), SameSite=Strict (not sent from other sites), and served only over HTTPS in production. It holds a signed session token - no financial data. - Standard server logs kept by the hosting provider, which include IP addresses, for security and abuse prevention.
What is not collected
There are no advertising cookies, no tracking pixels, no session recorders, and no third-party analytics. The application’s Content Security Policy restricts network connections to its own origin, so the pages you view cannot quietly report to anyone else.
How your information is used
- To calculate and display your daily safe-to-spend figure and related summaries.
- To sign you in and keep you signed in across devices.
- To send transactional email - verification codes and password resets. No marketing email is sent without you asking for it.
- To keep the service secure, including rate limiting and abuse prevention.
Your data is not used to train machine-learning models, is not profiled for advertising, and is not enriched with information bought from data brokers.
Who else can see it
Aartha relies on a small number of service providers to operate. Each receives only what its function requires:
- Database hosting - stores your account and financial records so they persist between sessions.
- Email delivery - receives your email address and the message body in order to deliver verification and reset codes.
- Application hosting - runs the service and keeps standard access logs.
Beyond these, your information is disclosed only where the law requires it, and only to the extent required.
The public demo
The “Explore live demo” button signs you into a shared demonstration account containing entirely fabricated data. That account is public: every visitor sees the same one, and anything entered there is visible to other visitors and is periodically erased and rebuilt. Do not enter real personal or financial information into the demo.
How long it is kept
Your records are kept for as long as your account exists. Items you delete move to the recycle bin, where you can restore them until you empty it. When you delete your account, the associated financial records are removed. Backups and server logs may persist for a short additional period before rotating out.
Your rights over your data
You can view and edit every record from within the app, export your data, and delete individual records or your entire account. Depending on where you live, you may also have statutory rights to access, correct, port, or erase your personal data, and to complain to a data protection authority. To exercise any of these, write to smit@aartha.app.
Security
Passwords are hashed, sessions are signed and carried in a hardened cookie, traffic is served over HTTPS with strict transport security, and the application sets a restrictive Content Security Policy. No system is perfectly secure, so please use a unique password and tell us promptly if you suspect a problem with your account.
Children
Aartha is not directed at children and should not be used by anyone under 18. If you believe a child has created an account, contact us and it will be removed.
Changes to this policy
If this policy changes in a way that materially affects how your information is handled, the date at the top of this page will change and, where appropriate, you will be notified in the app or by email.
Contact
Questions about this policy, or about your data, can go to smit@aartha.app.
This policy describes how the software actually behaves, but it has not been reviewed by a lawyer. Before launching publicly - and particularly before handling users in the EU, the UK, or under India’s DPDP Act - have a qualified practitioner check it against the obligations that apply to you.