Privacy Policy

Last updated: May 2025

1. Introduction

XRAY Money ("we", "our", or "us") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, and safeguard the data you provide when using our financial tracking application.

2. Information We Collect

  • Account information: your name, email address, and password (stored as a secure hash).
  • Financial data: transactions, budgets, goals, and reports that you manually enter or import.
  • Billing information: subscription tier and payment status. Payment card details are handled exclusively by Stripe and are never stored on our servers.
  • Usage data: pages visited, features used, and general interaction patterns to help us improve the product.

3. How We Use Your Information

  • To provide and maintain the XRAY Money service.
  • To process subscription payments via Stripe.
  • To send transactional emails (account confirmation, password reset, billing receipts).
  • To respond to support requests.
  • To detect and prevent fraud or abuse.
  • To improve the product based on aggregated, anonymised usage data.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Data Storage and Security

Your data is stored on secure servers. We use industry-standard encryption in transit (TLS) and at rest. Access to production data is restricted to authorised personnel only. While we take reasonable precautions, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

5. Third-Party Services

We use the following third-party services:

  • Stripe — payment processing. Subject to Stripe's own Privacy Policy.
  • Resend / email provider — transactional email delivery.

Each third-party service has its own privacy policy governing how they handle data shared with them.

6. Cookies

XRAY Money uses a small number of strictly necessary cookies for authentication (a secure session token). We do not use advertising or tracking cookies.

7. Data Retention

We retain your account and financial data for as long as your account is active. If you delete your account, your personal data will be permanently removed within 30 days, except where retention is required by applicable law.

8. Your Rights

Depending on your location, you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data.
  • Object to or restrict certain processing activities.
  • Data portability (receive your data in a machine-readable format).

To exercise any of these rights, please contact us at support@xraymoney.app.

9. Children's Privacy

XRAY Money is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notice. Continued use of XRAY Money after the effective date constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy, please email us at support@xraymoney.app.