Last updated: July 2026
Aurefi is built with privacy as its foundation. This policy explains what data we collect, how we use it, and your rights.
All financial data synced to our servers is encrypted end-to-end using AES-256-GCM with a key derived from your email via PBKDF2 (600,000 iterations). We cannot read your transaction data — it is encrypted before it leaves your device and decrypted only on your authorized devices.
Your encrypted data is stored on Neon (PostgreSQL) servers hosted on AWS. Unencrypted data (email, name, billing info) is stored in the same database but is kept to the minimum necessary to operate the service.
We retain your data for as long as your account is active. You can delete your account and all associated data at any time by contacting us. Upon deletion, all encrypted financial data is purged within 30 days.
You have the right to access, correct, export, or delete your data at any time. Since your financial data is end-to-end encrypted, we cannot read it — but we can delete it upon request.
For privacy inquiries, contact nimashmendis.dev@gmail.com.