Privacy Policy
Effective date: September 19, 2026
This Privacy Policy describes how Halaga handles information when you use the Halaga personal finance application. This policy is written for the current product and infrastructure and should be reviewed by qualified counsel before a commercial launch.
1. Information we handle
Halaga can handle information you choose to provide, including your email address, profile name, profile bio and profile photo URL, as well as financial information you enter such as income, expenses, categories, budgets, savings goals, investment accounts and holdings, assets, recurring transactions, debts and net-worth snapshots.
Halaga also handles account and security information such as authentication/session state, MFA factors managed by the authentication provider, recovery-code hashes, account-recovery events, security-event metadata, support tickets, subscription and purchase records, and administrative audit records.
When offline support is enabled, the application stores a local copy of applicable account state and queued changes in the browser's IndexedDB storage on that device.
2. How we use information
Information is used to provide authentication, save and display your finance records, synchronize offline changes, provide Premium features, process purchases, provide account recovery, operate support, prevent abuse, maintain security records, and operate the service.
3. Service providers
Halaga currently uses third-party infrastructure and providers including Supabase for authentication/database/Edge Functions, Vercel for hosting/serverless API routes, and Maya for payment processing. Information shared with providers is limited to what is needed for the relevant service and is handled according to their applicable terms and policies.
Halaga does not need your full card or bank credentials in its application database to operate the Maya-hosted payment flow. Halaga stores purchase and payment-reference metadata needed to reconcile transactions and entitlements.
4. Financial data
Halaga is a tracking and planning tool. Financial information is user-entered and may be incomplete or inaccurate. Do not use Halaga as the sole source of truth for bank balances, brokerage balances, tax records, legal records, or regulated financial decisions.
5. Security
Halaga uses authenticated sessions, database Row Level Security, server-side authorization for privileged operations, MFA-aware administration, hashed recovery/security identifiers, payment verification, security headers and input validation. No web application can guarantee absolute security, and users are responsible for protecting their devices and credentials.
6. Retention
Account-linked Halaga records are retained while needed to provide the service or until the account is deleted, subject to any retention obligations that may apply to specific provider or transaction records. Operational provider records may have separate retention periods under their own policies.
7. Account deletion
You can request deletion from inside Halaga through Settings → Danger zone → Delete account. You can also start from the public account deletion page. A successful deletion removes the Halaga account and the account-linked Halaga records described in the deletion workflow. Local browser state is cleared after successful deletion.
8. Children's privacy
Halaga is not designed to knowingly collect information from children in violation of applicable law. Do not use the service where prohibited by age or local law.
9. Changes
We may update this Privacy Policy when the product, providers or legal requirements change. The effective date at the top will be updated when material changes are made.
10. Contact
For privacy questions or account-deletion assistance, use the support channel available inside Halaga. Do not send passwords, MFA seeds, recovery codes or secret API credentials through support.