Legal · Beta
Privacy Policy
Last updated 18 July 2026
Money Leak Detector is currently in Beta. This policy explains exactly what happens to your data today, written in plain language rather than legal boilerplate. If anything here changes as the product grows, we'll update this page and the date above.
The short version
- • Your bank statement is read and analyzed entirely inside your own browser. It is never uploaded, transmitted, or sent to any server we operate.
- • If you create an account, we store your email address and use Supabase Auth to manage sign-in. We never see or store your password — Supabase handles authentication and only we can access rows tied to your account, enforced by row-level security at the database level.
- • Your analysis is always saved instantly in your browser's local storage. If you're signed in, it is also saved to your private account so you can reach it from any device.
- • We do not use analytics, tracking cookies, or advertising pixels on this site.
1. What data you give us
When you upload a bank statement (PDF or CSV), the file is read directly in your browser using client-side code. We do not operate a server endpoint that receives, stores, or has access to the contents of your statement — the analysis (categorizing transactions, detecting duplicates and recurring charges, calculating your savings plan) all happens on your device.
2. Where your analysis is stored
To save you from re-uploading your statement every time you refresh the page, we always keep your most recent analysis result in your browser's localStorage — a standard browser storage mechanism that lives on your device and is cleared when you clear your browser data. If you're signed in, the full analysis is also written to a Postgres database we operate, protected by row-level security so that only your own account can ever read, list, or delete your reports — not other users, and not us through the application itself.
3. Accounts and authentication
Money Leak Detector offers real email/password accounts, handled by Supabase Auth. Creating an account is optional — you can analyze a statement without one — but signing in lets your reports follow you across devices. Passwords are never stored or visible to us in plain text; Supabase manages credential storage and session security on our behalf.
4. Cookies and tracking
This site does not use analytics services, tracking cookies, third-party advertising pixels, or session-recording tools. We are not currently measuring your usage of this site at all.
5. Downloaded reports
The PDF report you can generate and download is built entirely in your browser and saved directly to your device through your browser's normal download mechanism. We never see or receive a copy of it.
6. Beta status and future changes
As Money Leak Detector moves beyond Beta, we may introduce further features such as direct bank integrations. Any such change that involves your financial data leaving your device in a new way will be explained clearly, will require your explicit action to enable, and this policy will be updated in advance to reflect it — we will not change this behavior silently.
7. Who runs this
Money Leak Detector is built by DONRITHIK LABS. As a Beta product we don't yet have a dedicated support channel set up — a proper contact method will be added here before general availability.