Privacy Policy

Last updated 1 October 2026

The short version

  • We collect what it takes to run your workspace, and no more. We never sell it or use it for ads.
  • No one else can see your records unless you share a specific one with someone you have linked with.
  • Records of how the service is used say where you went, never what you saw — and are deleted after 30 days.
  • AI features send only what a question needs to OpenAI, and only when you use them.
  • No advertising or tracking cookies. Export or delete your data from Settings whenever you like.

A summary to help you read what follows — the full text below is what applies.

Overview

veyra, operated by Amiel Brencis Salipande, is a private money workspace. This policy explains what we collect, why, who helps us run the service, and the control you have.

Your workspace is scoped to you. No other user can browse, search, or open your records. The single exception is deliberate and always started by you: if you link with someone and choose to share an expense with them, specific details of that one expense are sent to them. This is described under Sharing with people you link below.

Information we collect

  • Account details — when you sign in with Google, our authentication provider gives us your name, email address, and profile photo to identify your workspace.
  • Financial information you enter — accounts, balances, transactions, bills, loans, income, budgets, goals, categories, and notes. This is the content of your workspace.
  • Statements you import — when you upload a bank or card statement, we store the rows read from that file so you can review them before anything is recorded, along with a fingerprint of each row used to recognise duplicates on a later import. The uploaded file itself is not retained, and a document password, if you supply one, is used only to open the file and is never stored or logged.
  • Location, only if you allow it — when you record a transaction you may attach where it happened. If you grant your browser’s location permission, we store the coordinate, its accuracy, and the time it was taken, and we send the coordinate to a mapping provider to turn it into a place name. This is entirely optional: deny or ignore the permission and no location is collected, and you can remove a saved location from any transaction.
  • Usage and technical data — to operate, secure, and debug the service we record each request your browser makes: the page or address it went to (for example /transactions), whether it succeeded, how long it took, and the account it came from. We record where you went, never what you saw: no amounts, balances, account names, merchants, notes, search terms, or anything you typed is stored in these records. Messages you send the assistant are not recorded here either — only that a request to it was made.
  • Visits while signed out— when you open Veyra's public pages without being signed in (the home page, the legal pages, the sign-in form), we record each page you open — including moving from one of those pages to another — the approximate country and city our hosting provider estimates from your connection, whether the visit looks automated, and an anonymous code. The code lets us count how many different people visited that day and see the order in which one visitor moved through the public pages that day; it is never linked to an account. It is built from your connection and browser together with a random value that is deleted once the day is over (by 8 a.m. Philippine time the next morning at the latest), so it cannot be traced back to you or linked to another day. Your IP address is never stored, and no cookie is set for this. None of this is recorded for visits made while signed in.
  • Assistant usage — Ask Veyra runs on a paid service that charges by the amount of text processed, so for each question we also record how much text it involved (a token count for the question and the answer), how long it took, and whether it completed. This lets us see what the feature costs and how often it fails. It is a measure of size, not of content: these usage records never contain what you asked or what Veyra replied, and nothing in them can reconstruct it. Your conversations are kept separately, as described next.
  • Your Ask Veyra conversations — so your conversations follow your account from one device to another, we store what you asked, what Veyra replied (which can quote your own figures), and the cards it drafted, with where each got to. Photos you send are still never stored; a conversation only notes that one was sent. Conversations are deleted automatically 90 days after their last message, deleting one from History removes it from our servers, and clearing your workspace removes them all. They are included when you export your data.
  • How long we keep it— successful usage records are deleted after 30 days and error records after 180 days, automatically — except the operator’s own visits to the pages only the operator can open, kept as their permanent access log; Ask Veyra conversations 90 days after their last message. From the assistant records we keep one daily total per account — how many questions and how much text, that day — so we can see costs across a month after the individual records are gone. We chose a daily total deliberately: keeping the individual records for longer would mean keeping a log of exactly when you used Veyra, and a daily total answers the same question without it. Your financial records are kept until you delete them or close your account; those things are separate.

Cookies and browser storage

veyra uses no advertising or analytics cookies, and does not track you across other websites. What it does keep in your browser:

  • Sign-in cookies, set by our authentication provider so you stay signed in. The service cannot work without them.
  • One short-lived cookie remembering the page you were heading to when you were asked to sign in, so you land back on it. It lasts 30 minutes at most and is cleared once used.
  • Your browser’s storage, for small preferences (such as hiding amounts on screen) and a copy of your Ask Veyra conversations, so the assistant opens quickly. That copy is kept per account but stays on the device after you sign out — on a shared computer, use a private window, or clear this site’s data when you are done.

How we use your information

  • to provide the workspace — store your records and compute balances, summaries, and forecasts;
  • to send the notifications you enable (such as bill reminders);
  • to keep the service secure, prevent abuse, and diagnose problems;
  • to comply with legal obligations.

We do not sell your data, and we do not use your financial records for advertising.

Service providers

We rely on a small set of processors to run veyra. They handle data only to provide their service to us:

  • authentication — ClerkClerk, with GoogleGoogle sign-in;
  • database and application hosting — NeonNeon and VercelVercel;
  • transactional email such as reminders — ResendResend;
  • merchant and brand logos — logo.devlogo.dev and BrandfetchBrandfetch;
  • turning a coordinate into a place name, only when you attach a location — LocationIQLocationIQ;
  • map imagery for a saved location, only when you view it — the map area around the saved coordinate is requested from MapboxMapbox, or CARTOCARTO when the primary map fails to load;
  • the route drawn across a day’s map, only when you open that day and only when more than one of its transactions has a saved location — the saved coordinates for that day are sent to Mapbox, in order, to draw a line that follows roads. They are reduced to about 11 metres of precision before they are sent, which is coarser than a typical location fix. Nothing else about the transactions goes with them: no amount, merchant, account, time, or description;
  • rate limiting and abuse protection — UpstashUpstash;
  • the optional AI assistant, only when you enable it (see below).

Exchange rates (from WiseWise) and crypto-asset prices (from CoinGeckoCoinGecko) are fetched by our servers. Nothing that identifies you is sent to either.

Where your data is stored

Our database, our servers, and our rate limiter run in Singapore. Some of the providers listed above process data in other countries, including the United States — for example, our authentication and AI providers. We choose providers that protect the data they handle for us, and they may use it only to provide their service to us.

Sharing with people you link

veyra lets you split an expense with someone and keep track of what is owed. If that person also uses veyra, you can link with each other by exchanging a signature that you generate and send yourself. Linking is mutual and can only be started deliberately — nobody can add you.

Once linked, when you split an expense with them, settle a balance, or forgive one, the details of that record are sent to their workspace so they can accept it into their own books. What crosses is limited to a fixed list:

  • the amount, currency, and date;
  • the label you gave it, and the merchant and its logo if set;
  • the place name and coordinate, if you attached a location;
  • your name as it appears on your account.

Linking also shares your name and profile photo with that person, so you each appear as yourselves rather than as initials. This is the photo on your veyra account, which you control and can change or remove at any time — it is held by our authentication provider, not stored by us, and it is shared only with people you have linked with. Removing it, or unlinking, stops it being shown.

Nothing else is shared. Your private notes, categories, budgets, payment methods, account names, and balances are never sent, and the other person cannot see any record you did not choose to share. Only records involving a person you have linked with are ever eligible; everything else stays entirely in your workspace.

AI features

veyra includes AI features, such as the Ask Veyra assistant and the explanations some screens offer. They run only when you use them: when you ask a question or tap to explain something, the specific data needed to answer is sent to our AI provider, OpenAIOpenAI, to generate a response.

Voice. If you dictate to Ask Veyra, the recording is sent to OpenAI to be transcribed, and the words come back to your message box for you to check. veyra does not store the recording, and the words are kept only if you send them — as part of your conversation, like any other message.

Photos. If you send Ask Veyra a photo — a receipt, usually — it is made smaller in your browser and sent to OpenAI so the assistant can read it and draft the transaction for you to confirm. veyra does not store the photo, on our servers or in your browser: it is used for that turn of the conversation and the next, and a reopened chat only notes that a photo was sent.

Keeping and deleting your data

We keep your workspace data for as long as your account is active. You are always in control: from Settings you can export your workspace, or permanently delete it. Deletion removes your records from the live service; residual copies in encrypted backups age out on our providers’ ordinary schedules. Deleting your workspace leaves your sign-in account in place, so you can start fresh; to close your account entirely, email absalipande@gmail.com and we will delete it.

Who is behind Veyra

veyra is built and operated by one person — Amiel Brencis Salipande, its sole developer. There is no team, no contractors, and no staff with access to your workspace.

This matters for your data rather than as an introduction: it means the only human who can reach the systems holding your records is Amiel Brencis Salipande, and that access is used to run and repair the service, never to browse your finances. Requests you send to the address below are read by the same person.

To keep veyra running there is an internal dashboard showing whether the service is healthy and the usage records described above — which addresses were requested, by which account, and whether they worked; and, for signed-out visits, counts by page and place and the order of pages one anonymous visitor opened in a day. It shows how many accounts exist, never a list of them. It is built so that it cannot display anyone’s financial records: it can show that a workspace posted a transaction and how many ledger lines it created, and it cannot show the amount, the account, or the merchant.

Security

We take reasonable measures to protect your information, including per-user data isolation, encryption in transit, and access controls. No online service can be guaranteed perfectly secure, but protecting your financial data is a core priority.

Your rights

You can access and export your data at any time, correct it by editing your records, and delete your workspace. Depending on where you live, you may have more rights over your personal data. Under the Philippines’ Data Privacy Act of 2012, for example, you have the right to be informed, to access, correct, and delete your data, to object to its processing, to take it with you, and to complain to the National Privacy Commission. To use any of these rights, contact us at absalipande@gmail.com.

Children

veyra is not intended for anyone under the age required to form a binding contract in their jurisdiction, and is not directed at children.

Changes and contact

We may update this policy from time to time; material changes update the date above. Questions or requests can be sent to absalipande@gmail.com.