Savenello Privacy Policy
Preview version. Savenello is in early testing. These terms may change before general release, and we will notify users of material changes.
Effective date: October 8, 2026
Last updated: October 8, 2026
1. About this policy
1.1. This Privacy Policy explains how Savenello ("we", "us" or "our") collects, uses, shares and protects information when you use the Savenello website (the "Service") at https://savenello.com. It should be read together with our Terms of Service at https://savenello.com/terms.
1.2. The Service is a personal finance website for households. A household is a shared account: the person who signs up becomes its owner, and other adults may later be invited as members. Information added to a household can be seen by every member of that household.
1.3. The short version: we collect what we need to show your household its money, we use it to run the Service, we do not sell your personal information, and we do not use your bank data for advertising.
2. Information we collect
2.1. Account information you give us.
- Your name, email address and time zone.
- Your second factor settings: an encrypted secret for your authenticator app, and hashed one-time recovery codes. If text message codes are offered and you choose them, your mobile phone number.
- Your notification settings, such as whether the weekly recap email is on and its day and time.
- Billing details, once paid plans begin. Card payments are handled on Stripe's hosted pages. We receive limited information such as subscription status and payment history, but not your full card number.
2.2. Household information.
- The household's name and plan status.
- Who belongs to the household and their role (owner, and later member or view-only member).
2.3. Bank and card data received through Plaid. When you link an account, we receive from your financial institution, through Plaid:
- the institution's name and the accounts you choose to share (checking, savings and credit cards), including account names, types and current balances with the date of each balance;
- transaction history, including date, amount, description, merchant, and whether a transaction is pending or posted, plus later corrections and removals made by the institution;
- connection details, such as connection health and when the last update happened; and
- an access token from Plaid that lets us retrieve updates. This token is encrypted when stored and is never sent to your browser.
We do not receive your bank username or password, and we do not request or store full account numbers or routing numbers. We do not link investment or retirement accounts through Plaid.
2.4. Information you create in the Service. Categories, clean merchant names, rules, transaction approvals, edits, splits and notes, transfer matches, budgets and budgeted amounts, savings goals and entries, manual assets and their values (for example home equity, vehicles or precious metals), net worth snapshots and report settings.
2.5. Device, session and log information.
- Session records: a hashed session token, a short description of your device and browser, when the session was last active and when it expires. You can see these on the Sessions page.
- Sign-in records: hashed single-use sign-in link tokens with a short expiry, and counters of sign-in and code attempts (by account and by IP address) used to stop guessing and abuse.
- Technical information that our hosting provider, Cloudflare, processes when your browser connects to the Service, such as IP address, browser type, the pages requested and the time of the request. This may appear in service and security logs. Sign-in links are kept out of these logs.
- An email log that records which email was sent to whom and when, without the email's content or links.
2.6. Activity log. The Service keeps a log of changes made in your household: who made the change, when, and the values before and after. It also records security events, such as sign-ins, second factor changes, recovery code use, bank connections added or removed, exports and deletion requests. This lets you see what happened to your data and supports security investigations. Security-sensitive values (such as tokens and secrets) are never copied into the log.
2.7. Communications. If you contact us, we keep your message and our reply.
2.8. Cookies. The Service uses only cookies that are necessary to sign you in and keep you signed in securely. We do not use advertising cookies or third-party analytics.
3. Plaid
3.1. We use Plaid Inc. ("Plaid") to connect the Service to your financial institutions. When you link an account, you use Plaid's own window (Plaid Link), and Plaid collects information from you, your device and your financial institution, including your bank sign-in details, to make the connection.
3.2. Plaid's handling of your information is governed by Plaid's End User Privacy Policy: https://plaid.com/legal/#end-user-privacy-policy. By linking an account, you acknowledge that your information will be handled by Plaid as described in that policy. Plaid is not controlled by us, and this policy does not cover Plaid's practices.
3.3. You can remove a connection in the Service at any time (see Section 9). Plaid also offers its own tools for viewing and managing connections you have made through Plaid, described in its policy.
4. How we use information
We use information to:
- create and secure your account, send sign-in links, check your second factor, and keep sessions safe (including idle time-outs and signing out other devices);
- retrieve and update balances and transactions from the accounts you link, and tell you when a connection needs to be reconnected;
- provide the Service's features: the review queue, categories and merchant suggestions, rules, transfer and card payment matching, budgets, goals, savings rate, net worth, reports, the monthly wrap-up and CSV exports;
- send the emails you need (sign-in links, security and account notices, reconnect notices, billing notices) and the weekly recap if you keep it on;
- keep the activity log so your household can see who changed what;
- make nightly backups and restore data if something goes wrong;
- protect the Service, our users and us, including limiting sign-in attempts, investigating suspicious activity and preventing fraud and abuse;
- provide support when you ask for it;
- process payments and manage subscriptions, once paid plans begin;
- find and fix errors and keep the Service running well, using error and performance information (we do not use third-party analytics); and
- comply with law and enforce our Terms.
5. What we do not do
5.1. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5.2. We do not use your bank or transaction data for advertising, and we do not show ads in the Service.
5.3. The Service does not move money or make payments from your accounts.
6. How we share information
We share information only as follows:
6.1. Within your household. Everything in a household is visible to its members, according to their role.
6.2. Service providers who process information for us to run the Service, under terms that limit their use of it:
- Cloudflare, Inc.: hosts and runs the Service, including the application, the database and the storage for our nightly encrypted backups.
- Plaid Inc.: connects to your financial institutions (see Section 3).
- Resend: sends sign-in links, notices and the weekly recap.
- An SMS provider, when texted codes are offered: will send text message sign-in codes to people who choose that option.
- Stripe: will process subscription payments, once paid plans begin.
6.3. Legal and safety reasons. When we believe in good faith that disclosure is required by law, subpoena or court order, or is needed to protect the rights, property or safety of our users, the public or us, or to investigate fraud or security issues.
6.4. Business transfers. If we are involved in a merger, acquisition, financing, formation of a company to operate the Service, or sale of assets, information may be transferred as part of that change. We will require the recipient to honor this policy or notify you before your information becomes subject to a different policy.
6.5. With your direction or consent. For example, when you export your data and share the file yourself.
7. How we protect information
We use reasonable administrative, technical and physical safeguards designed to protect your information. They include:
- No passwords. Sign-in uses a single-use email link plus a second factor (an authenticator app code, with text message codes possibly added later). Sign-in link tokens are stored only in hashed form and expire after a short time.
- Hashed sessions and recovery codes. Session tokens and recovery codes are stored only in hashed form. Sessions end after a period of inactivity and also have a maximum lifetime.
- Encryption. Plaid access tokens and authenticator secrets are encrypted at rest and are never sent to your browser. The Service is only available over encrypted HTTPS connections. Nightly backups are encrypted before they are stored, in private storage that is not publicly accessible.
- Household separation. Every household's data is tied to that household and access is checked on each request. This is tested with separate test households.
- Data minimization. We do not store bank usernames, passwords, full account numbers or routing numbers.
- Backups and recovery. Data is backed up every night, and restores are tested.
- Review. The design has had a security review, and a full security review is planned before the Service handles real bank data.
- Limited access. Access to production data is limited to the people who operate the Service, is used only to provide support you ask for, keep the Service secure, or comply with law, and each access is recorded.
No system is completely secure, and we cannot guarantee that information will never be accessed, used or disclosed without permission. Please also protect your email account, your authenticator device and your recovery codes (see our Terms). Remember that emails, including the weekly recap, are stored in your email account and are only as secure as that account.
8. How long we keep information (archive versus delete)
8.1. While your household is active. We keep your household's information while the household exists, so your history and reports stay complete. In normal use, records you remove (such as categories, merchants or bank connections) are archived, not permanently deleted, and the activity log keeps a history of changes. When you remove a bank connection, we stop retrieving data from it and ask Plaid to end the connection, and you choose whether its past transactions are kept or archived.
8.2. When a household is deleted. Deleting a household is a true deletion. When the owner deletes a household, we:
- end the household's bank connections with Plaid;
- permanently delete the household's data from our live database, including transactions, balances, accounts, budgets, goals, assets, activity log entries, email log entries and sessions, within 30 days of a verified deletion request; and
- let copies in our encrypted backups expire on their normal schedule. Backups are kept for 35 days, so deleted data is fully removed from backups within 35 days after it leaves the live database.
We keep a minimal record that the household was deleted, when and by whom, with no financial data, and records we are required to keep by law (such as billing and tax records) for as long as applicable law requires.
8.3. Other retention periods.
- Activity log: entries are kept for 2 years, then deleted.
- Email log: 90 days.
- Expired sessions and sign-in links: 90 days after they expire.
- Service and security logs: 30 days.
- After a subscription is cancelled and not renewed: the household stays available for export for 30 days, then is deleted as described in Section 8.2, except what the law requires us to keep.
8.4. Plaid's retention. Plaid keeps information under its own policy. Ending a connection through the Service asks Plaid to end its access for us, and Plaid's policy describes how it then handles your data.
9. Your choices and rights
9.1. In the Service, you can:
- Access and export: view your household's information at any time, and (as the owner) export it as CSV files.
- Correct: edit transactions, categories, merchant names, notes, budgets, goals, assets and your own profile. Bank-provided data can be recategorized or annotated, and errors at the source must be corrected by your financial institution.
- Unlink banks: remove any bank connection in Settings.
- Manage emails: change the time of, or turn off, the weekly recap. Sign-in, security, billing and other service emails cannot be turned off while you have an account.
- Manage sessions: see your active sessions and sign out other devices.
- Delete: as the owner, delete the whole household (see Section 8.2). A member who is not the owner can ask us at privacy@savenello.com to delete their own login and personal details. The household's data stays with the household, and the member's name may remain in existing activity log entries until those entries expire.
9.2. You can also contact us at privacy@savenello.com to ask for access, a copy, correction or deletion of your personal information. We will need to verify your identity, usually through your signed-in account, before acting. We will respond within 30 days, or any shorter period required by law.
10. Data breach notification
10.1. If we learn of a breach of security that affects your personal information, we will investigate, take steps to contain it, and notify affected people as required by law.
10.2. Consistent with Florida Statute 501.171, we will notify affected Florida residents as quickly as possible and no later than 30 days after we determine that a breach has occurred, or have reason to believe one has occurred, unless a delay is requested by law enforcement or otherwise allowed by that law. When required, we will also notify the Florida Department of Legal Affairs (for breaches affecting 500 or more Florida residents) and consumer reporting agencies (for breaches affecting more than 1,000 people). We will notify residents of other states as their laws require, and we intend to give all affected users notice on the same timeline.
10.3. Notices will be sent to the email address on your account, and may also appear in the Service.
11. Federal financial privacy law
To the extent the federal Gramm-Leach-Bliley Act applies to Savenello, we will handle your nonpublic personal information as that law requires and will provide any additional notice it requires. We do not share your nonpublic personal information with non-affiliated third parties except as described in this policy and as permitted by law.
12. Children
The Service is only for adults. People under 18 may not create an account or be added to a household. We do not knowingly collect personal information from anyone under 18, including children under 13. If we learn that we have, we will delete it. Contact us at privacy@savenello.com if you believe a child has provided information to us.
13. Your state privacy rights
13.1. Depending on where you live, you may have rights under state privacy laws, such as the right to know what personal information we collect, use and disclose, to access, correct and delete it, to get a portable copy, to opt out of the sale or sharing of personal information or of targeted advertising, and not to be discriminated against for using these rights. As stated in Section 5, we do not sell personal information or share it for targeted advertising.
13.2. Some state laws may not apply to us, or may not apply to financial information covered by federal law. Even so, we will honor requests to know, access, correct, export and delete personal information from any user, wherever they live in the United States, as described in Section 9.
13.3. To make a request, contact us at privacy@savenello.com. We will verify your identity before responding. You may use an authorized agent where state law allows, and we may ask the agent for proof of authority. If we deny your request, you can ask us to reconsider by replying to our response.
14. Where information is stored
The Service is offered only in the United States. Our service providers store and process information in the United States and may also do so in other countries where they operate.
15. Changes to this policy
We may update this policy from time to time. If we make material changes, we will tell you by email or in the Service at least 30 days before they take effect, unless a faster change is required by law. The "Last updated" date at the top shows when it last changed. We will not use information in a materially different way than described when it was collected without your consent where the law requires it.
16. Contact us
Questions or requests about this policy or your information:
Savenello
Email: privacy@savenello.com (all other questions: support@savenello.com)
Mailing address: available on request at support@savenello.com