This policy is written in plain language on purpose. It is not a substitute for legal advice, and if you're relying on it for a commercial launch you should have it reviewed by a lawyer familiar with your jurisdiction — this covers the practical basics, not every regulatory nuance.

The short version

What we collect

Local, on-device data

By default, everything you enter into NeverRunShort — accounts, transactions, budgets, settings — is saved in your browser's local storage on your own device. This never leaves your device unless you create an account and sign in.

Account data (only if you sign up)

If you create a NeverRunShort account, we store: your email address and authentication credentials (handled by our authentication provider, Supabase — we never see or store your password in plain text), and your planner data (the same accounts/transactions/budgets described above), synced to a private database row tied to your account. If you sign in with Google, we receive only the basic profile information Google shares for authentication (your email address) — never your Google password.

Transaction logs

If you have an account, a lightweight audit log of transaction create/edit/complete/delete actions is kept for your own history and troubleshooting, visible to you in the Sync tab. It's private to your account, same as your planner data.

Newsletter signups

If you subscribe to product updates, we store the email address you provide and nothing else. That list is used only to send you updates about NeverRunShort, and every email includes an unsubscribe option.

What we don't collect

We don't use third-party analytics or advertising trackers on this site or in the app. We don't sell, rent, or share your data with advertisers or data brokers. We don't ask for your bank login — NeverRunShort has nothing to connect to your bank in the first place.

Where data is stored

The site and app are hosted on Cloudflare. Account and planner data, when you choose to sync, is stored with Supabase, our database and authentication provider, protected by row-level security so only your own signed-in account can read or write your row. The app's static files also load the Supabase client library from the jsDelivr CDN — this is a code library, not a tracker, and does not receive your data unless you're actively syncing.

Your choices

Changes to this policy

If this policy changes in a material way, we'll update the date at the top of this page. Continued use of NeverRunShort after a change means you accept the updated policy.

Contact

Questions about this policy or your data: hello@neverrunshort.com.