Privacy Policy

Last updated

Qirsh is a manual personal-finance tracker. It never connects to your bank, so the only financial data it holds is what you type in yourself. Your name and email are encrypted in the database, your password is hashed and cannot be recovered by anyone, and nothing is sold, rented, or used for advertising. You can export everything or delete your account permanently at any time from Settings.

1. Who we are

Qirsh (“Qirsh”, “we”, “us”) is a personal-finance application operated as a sole trader by Zaid Haddadin, based in Amman, Jordan. For the purposes of the EU and UK General Data Protection Regulation that individual is the data controller for the personal data described below.

You can reach us about anything in this policy at privacy@qirsh.app.

2. What we collect

Everything below is either something you typed in, or something the service had to record to keep your account working and secure. There is no third category.

Account details

DataHow it is stored
Display nameEncrypted at rest (AES-256-GCM)
Email addressEncrypted at rest, plus a one-way keyed hash used to look up your account at sign-in
PasswordHashed with bcrypt. Hashing is one-way — we cannot read, recover, or tell you your password
Two-factor secret and recovery codesEncrypted at rest; only present if you turn 2FA on
PreferencesCurrency, default account, notification settings

Financial data you enter

Accounts and cards you add (name, type, last four digits if you choose to enter them, balances, credit limits, interest rates), transactions, transfers, statement periods and payments, loans and their terms, installment plans, budgets, goals, tags, recurring rules, and saved templates.

We never connect to your bank. Qirsh has no open-banking integration, no card-network access, and no import from any financial institution. It cannot see any account you have not typed in yourself, and it can never move money.

Technical and security data

DataPurpose
IP addressRecorded against sign-in attempts, rate-limited actions, and document downloads, to detect brute-force and abuse
Sign-in attemptsThe email attempted, whether it succeeded, and when — so repeated failures can be throttled
Error reportsAn error message, the route it happened on, and a stack trace. Your user ID is attached where known so we can tell whether a bug affected one person or everyone
Feedback you sendStored with the message you wrote
Push subscriptionsOnly if you enable notifications: the browser push endpoint, its keys, and your browser’s user-agent string

Cookies

Qirsh sets two cookies, authToken and refreshToken. Both are HTTP-only, meaning no script on the page can read them, and both exist purely to keep you signed in. They are strictly necessary: the app cannot function without them, so no consent banner is required for them.

There are no advertising cookies, no tracking pixels, and no third-party cookies of any kind. Our analytics are configured to store nothing at all on your device — no cookie, no local storage — so there is no analytics identifier following you between visits.

Product analytics

We use PostHog (EU-hosted) to understand which screens are used and where the app breaks. It is configured deliberately narrowly:

  • We identify you to PostHog by a random internal ID only. Your name and email are never sent.
  • Session replay masks every input and every piece of text on the page, so recorded sessions show layout and interaction, not your balances, payees, or amounts.
  • Analytics requests are proxied through our own domain, so they are first-party and are not shared with an ad network.
  • Automatic capture of the text of buttons and links you click is switched off, and query strings are stripped from recorded page addresses — so a search you ran, or a payee name, is never sent.
  • Nothing is stored on your device: no analytics cookie, no local storage.

3. Why, and our legal basis

Under the EU/UK GDPR we must state a lawful basis for each purpose. Ours are:

PurposeLegal basis
Running your account and storing the finances you enterPerformance of a contract — this is the service you signed up for
Sign-in throttling, abuse prevention, error monitoringLegitimate interests — keeping the service secure and working, balanced against your rights
Product analyticsLegitimate interests, minimised as described above. You may object at any time
Transactional email (verification, password reset, alerts you asked for)Performance of a contract
Push notificationsConsent — off unless you enable it, withdrawable in Settings or your browser

4. What we never do

  • We do not sell your personal data. We never have, and there is no mechanism in the product to do so.
  • We do not share it with advertisers, data brokers, or credit-reference agencies.
  • We do not use your financial data to train AI models.
  • We do not profile you or make automated decisions with legal or similarly significant effects.
  • We do not connect to your bank or hold credentials for any financial institution.

5. How it is protected

  • All traffic is served over HTTPS only.
  • Your name and email are encrypted at rest with AES-256-GCM, so a stolen database file or backup does not yield a readable directory of who uses Qirsh.
  • Your password is hashed with bcrypt — a one-way function. Nobody, including us, can reverse it.
  • Two-factor authentication is available, and its secret is encrypted at rest.
  • Sessions use short-lived, HTTP-only tokens that are invalidated on sign-out, password change, and password reset.
Being straight with you about the limits. Encryption at rest protects against someone obtaining the database or a backup. It is not end-to-end encryption: Qirsh holds the key, so our systems can decrypt your name and email in order to sign you in and email you. Your financial entries — amounts, payees, balances — are stored unencrypted in the database, protected by access controls rather than by cryptography. Anyone who tells you a cloud app with a “forgot password” link is zero-knowledge is not being straight with you.

6. Who else processes it

We use a small number of infrastructure providers (“sub-processors”). Each is bound by a data-processing agreement and may use your data only to provide their service to us:

ProviderRoleRegion
VercelApplication hosting and deliveryFrankfurt, EU
NeonPostgreSQL databaseFrankfurt, EU
ResendTransactional email (verification, password reset, alerts)EU/US
PostHogProduct analytics, as minimised aboveEU

We will also disclose data where we are legally required to — a binding court order or a valid request from a competent authority — and we will tell you when we are permitted to.

7. Where it is stored

Your account and all financial data are stored in the European Union (Frankfurt). Email delivery may route through our email provider’s infrastructure outside the EU; where that happens, the transfer relies on the European Commission’s Standard Contractual Clauses.

8. How long we keep it

DataRetention
Account and financial dataUntil you delete your account
Sign-in attempt recordsShort-lived; kept only long enough to throttle abuse
Error reports and feedbackUntil resolved and no longer diagnostically useful
Session and reset tokensExpire automatically; reset tokens are single-use

Deleting your account is real deletion. It permanently removes your accounts, transactions, statements, loans, installment plans, budgets, goals, tags, recurring rules, templates, push subscriptions and sessions. It is irreversible, and we cannot restore it afterwards — export first if you want a copy.

9. Your rights

Wherever you live, you can:

  • Access your data — export it from Settings at any time: a full JSON file, or a CSV of your transactions.
  • Correct it — your accounts, transactions and other entries are all editable in the app. Your name and email address are not yet editable in-app; email us and we will change them for you.
  • Delete it — Settings → delete account, which erases your account and everything listed in section 8. A small number of security records (sign-in attempts, rate-limit counters) are keyed to an internal identifier rather than to your account, and age out on their own schedule.
  • Take it elsewhere — the JSON export is a machine-readable file you own.
  • Object to or restrict processing based on legitimate interests, including analytics.
  • Withdraw consent for notifications, without affecting anything before that.

Most of these you can exercise yourself, immediately, without asking us. For anything else, email privacy@qirsh.app; we respond within 30 days. We do not charge for this, and exercising a right will never degrade your service.

10. Regional rights

European Union and United Kingdom

You have the rights in Articles 15–22 GDPR, as summarised above. You also have the right to lodge a complaint with your supervisory authority — your national data-protection authority in the EU, or the Information Commissioner’s Office in the UK — and you may do so without contacting us first.

United States

If you live in California, the CCPA/CPRA gives you the right to know what is collected, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined, and we do not process it for cross-context behavioural advertising — so there is no “Do Not Sell or Share My Personal Information” action to take. Residents of other states with comparable laws (including Virginia, Colorado, Connecticut, Utah and Texas) have equivalent rights, which we extend to all US users regardless of state.

Middle East and North Africa

Where the Jordanian Personal Data Protection Law No. 24 of 2023, the Saudi Personal Data Protection Law, or UAE Federal Decree-Law No. 45 of 2021 applies to you, you have rights of access, correction, deletion, and objection substantially as described above, and you may complain to your national regulator. We apply one standard globally rather than a weaker one by region: the protections in this policy are available to every user.

11. Children

Qirsh is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.

12. Changes to this policy

If we change how we handle your data in a way that materially affects you, we will notify you by email and in the app before it takes effect. The date at the top of this page always reflects the current version.

13. Contact

Privacy questions, requests, or complaints: privacy@qirsh.app. See also our Terms of Service.

Privacy Policy • Qirsh