← Back to Aurefi

Privacy Policy

Last updated: July 2026

Overview

Aurefi is built with privacy as its foundation. This policy explains what data we collect, how we use it, and your rights.

Data We Collect

  • Account data: Email address and name (if you create an account via Google OAuth or email/password)
  • Financial data: Transactions, budgets, goals, and recurring entries you enter into the app
  • Billing data: Payment information is handled entirely by Lemon Squeezy — we never see or store your credit card details
  • Usage data: Anonymous page view analytics via Vercel Analytics (no personal data collected)

End-to-End Encryption

All financial data synced to our servers is encrypted end-to-end using AES-256-GCM with a key derived from your email via PBKDF2 (600,000 iterations). We cannot read your transaction data — it is encrypted before it leaves your device and decrypted only on your authorized devices.

Data Storage

Your encrypted data is stored on Neon (PostgreSQL) servers hosted on AWS. Unencrypted data (email, name, billing info) is stored in the same database but is kept to the minimum necessary to operate the service.

Third-Party Services

  • NextAuth.js — authentication (Google OAuth)
  • Lemon Squeezy — payment processing and subscription management
  • Neon / AWS — database hosting
  • Vercel — application hosting and analytics
  • Google Gemini API — AI-powered financial assistant (only if you opt in; data sent is not stored)

Data Retention

We retain your data for as long as your account is active. You can delete your account and all associated data at any time by contacting us. Upon deletion, all encrypted financial data is purged within 30 days.

Your Rights

You have the right to access, correct, export, or delete your data at any time. Since your financial data is end-to-end encrypted, we cannot read it — but we can delete it upon request.

Contact

For privacy inquiries, contact nimashmendis.dev@gmail.com.