1. Who we are
Sora (sora.rinzai.dev) is a free money planner run by rinzai, an individual developer ("we", "us"). We decide how the personal data described here is used, so we are its controller under the UK and EU GDPR and its Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
Contact for anything in this policy, including requests and complaints: [email protected]. This address is also our grievance contact under the DPDP Act.
2. What we can't see
Everything you put into Sora (amounts, categories, dates, notes, budgets, loans, goals, your currency, your theme and profile picture) is encrypted in your browser with a key made from your password, before it leaves your device. We store only the encrypted result, padded so its size doesn't reveal how much you've entered.
Your password never reaches us: your browser sends a separate key derived from it. We therefore cannot read, analyse, share or recover your financial data. If you lose both your password and your recovery key, it can't be recovered by anyone.
3. What we collect
| Data | Why |
|---|---|
| Email address | Your account: signing in, confirming your address, password-reset emails. |
| Sign-in credentials: a key derived from your password (stored hashed by our auth provider), passkeys (public key, the name you give it, when it was added and last used) | Signing you in securely. |
| If you sign in with Google: your Google account's email, name, profile picture link and account ID, as Google shares them | Linking Google sign-in to your Sora account. We only ask Google for your basic profile and email. |
| Your encrypted data and encrypted copies of its key (one per recovery key and passkey) | Storing your data so you can reach it from any device. We can't decrypt it. |
| Technical data: IP address, browser, times and pages requested, in our providers' security and request logs | Keeping the service secure and working, and investigating abuse. |
| Emails you send us | Replying to you and handling your requests. |
We don't collect anything else: no analytics or advertising trackers, no location, no contacts. Exchange rates come from the European Central Bank via our server; no information about you is sent to get them.
4. Why we're allowed to use it
- To provide the service you asked for (UK/EU GDPR Art. 6(1)(b), contract): your account, sign-in and storing your encrypted data.
- Legitimate interests (Art. 6(1)(f)): security logs, preventing abuse and keeping the service running.
- Consent under the DPDP Act: by creating an account you consent to the processing described here, for these purposes only. You can withdraw consent at any time by deleting your account; this doesn't affect processing already done.
- Legal obligations, where the law requires us to keep or disclose something.
5. Cookies and storage on your device
- Session cookie (
sb-…-auth-token): keeps you signed in, for up to 30 days. It's strictly necessary, httpOnly (page scripts can't read it) and only sent to Sora. Signing in with Google or resetting a password briefly sets a similar cookie to complete that step securely. - Local storage: if you choose "Not now" on the passkey suggestion, we remember that on this device for 30 days. Nothing else.
- App cache: if you install Sora, it keeps its icons and an offline page on your device. Never your data.
We don't use analytics, advertising or third-party cookies, so there's nothing to opt out of.
Your encryption keys exist only in your browser's memory while Sora is open and unlocked. They're never written to storage, cookies or logs.
6. Who processes data for us
We use a few providers to run Sora. They process data only on our instructions, under data processing terms with appropriate safeguards.
| Provider | What for | Where |
|---|---|---|
| Supabase | Accounts, sign-in and the encrypted database | Tokyo, Japan |
| DigitalOcean | Hosting the app | Singapore |
| SMTP2GO | Sending account emails (confirmation, password reset) | Global |
| Cloudflare | Domain name (DNS) and forwarding emails to our contact address | Global |
| Only if you choose to sign in with Google | Global |
International transfers. These locations may be outside your country. Where UK or EU law requires it, transfers rely on an adequacy decision (Japan has one from the EU and UK) or on the providers' standard contractual clauses. Under the DPDP Act, transfers are made to countries not restricted by the Government of India. Your financial data is encrypted end to end wherever it's stored.
We don't sell, rent or share your personal data, and we never use it for advertising or profiling. Under US state laws such as the CCPA: we do not sell or share personal information.
7. How long we keep it
- Your account and encrypted data: until you delete your account or ask us to.
- After deletion: removed from our systems within 30 days; copies in our providers' backups expire on their normal cycle, typically within a further 30 days.
- Security and request logs: kept by our providers for their standard periods, usually days to a few weeks.
- Emails with us: as long as needed to deal with your request.
If an account is never confirmed or is unused for a long time, we may delete it after giving notice to its email address where we can.
8. Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you, and get a copy (UK/EU: in a portable format).
- Correct anything inaccurate or incomplete.
- Delete your account and data (erasure).
- Object to or restrict processing based on legitimate interests (UK/EU).
- Withdraw consent (DPDP Act): delete your account.
- Nominate someone to exercise your rights if you die or become unable to (DPDP Act).
Email [email protected] from the address on your account (so we know it's you). We'll reply within 30 days, and we don't charge for this. Your financial data is readable only in the app, with your password: we can give you the encrypted copy, but only you can open it.
Complaints
Please contact us first; we'll try to put things right. You can also complain to:
- India: the Data Protection Board of India, after using our grievance contact above.
- UK: the Information Commissioner's Office (ico.org.uk).
- EU/EEA: the data protection authority where you live or work.
9. Security
Beyond end-to-end encryption (Argon2id to derive keys from your password, AES-256-GCM for your data), Sora uses strict content security policies, secure httpOnly cookies, HTTPS everywhere and per-user database access controls. No system is perfectly secure; if a breach affecting your personal data happens, we'll tell you and the relevant authorities as the law requires.
10. Children
Sora is for adults. You must be 18 or older to create an account. If we learn that someone under 18 has an account, we'll delete it.
11. Changes
If we change this policy, we'll update the date at the top. For significant changes we'll tell you by email or in the app before they take effect. The Terms cover your use of Sora.