Privacy Policy
This policy explains what AccountHouse collects, how it is used, and how access is protected while the product is in beta. It is written for households using the web dashboard and the Android companion.
Document & software versions
Version numbers match the product About screens. When we change how we collect or use personal data in a material way, we update this page and the date above. Product security controls are also described on the Features · Security page.
1. Overview
AccountHouse helps households track shared expenses, income, budgets, payables, Split groups, documents, and related tools. During beta, access is by invitation or approved interest registration. We aim to collect only what is needed to operate the service, send account and security notices, and improve reliability.
We do not sell your personal data. Household financial entries you create belong to your household context and are not used for advertising profiles.
2. Data we collect
- Account data — name, email, username, household membership, and role (admin, member, or viewer).
- Financial and product data you enter — expenses, income, budgets, payables, categories, Split payments and settlements, goals, asset registry entries, card labels, shopping lists, calendar reminders, and similar records you choose to store.
- Documents (DocuVault) — files you upload. Client-side encryption is used so document contents are not stored as plain readable files for routine server browsing; unlock is gated by your PIN (and on mobile, biometrics where enabled).
- Technical and security data — session metadata, IP address at sign-in, approximate location hints derived for session display, device or browser type, push notification tokens on Android, and security event logs (for example sign-in, 2FA, session revoke, password reset).
- Beta interest form — name, email, household details, and any message you submit when requesting access.
3. How we use data
- Provide dashboards, analytics, alerts, Split, DocuVault, calendar reminders, and household collaboration.
- Authenticate you, enforce roles and permissions, and maintain sessions across web and mobile.
- Send transactional email and Android push for budgets, payables, login notices, 2FA codes, calendar reminders, and security recovery when required.
- Detect and respond to suspicious sign-in activity (see Security below).
- Operate and improve the beta service, including diagnosing outages and abuse.
4. Security practices
Security is layered. The following describes controls available in the current suite release (6.26.1) across web 5.1.11 and Android 4.2.1. Availability of optional features depends on your Settings and device capabilities.
4.1 Account authentication
- Passwords are stored hashed; they are not kept in clear text.
- Email verification supports account activation; password reset uses email recovery flows.
- Optional email two-factor authentication (2FA): after password check, a one-time code is sent to your registered email and must be verified on web and mobile before the session is established.
- Successful sign-ins can trigger login notification email and push.
4.2 Sessions and audit
- Active sessions are listed in Settings (web and mobile) with device and location context where available. You can revoke other sessions remotely; that ends access on those devices, including sessions that were opened from the Android app.
- A security activity log records events such as sign-in, 2FA-related actions, session revoke, and password reset so you can review recent access.
4.3 PIN, app lock, and biometrics
- An optional account PIN can hide sensitive views (for example income and related totals), gate app lock, and unlock DocuVault and card amount reveals where those options are enabled.
- Optional app lock on web (PIN) and Android (PIN, with biometric unlock on supported devices) adds a local gate when the device stays unlocked but the app should not.
- Biometric data (fingerprint or face) is processed by the device platform. AccountHouse does not receive or store your biometric templates on our servers.
4.4 Suspicious activity and account security lock
- Automated monitoring looks for patterns such as failed-login bursts, repeated 2FA failures, credential spray across addresses, and sign-ins from unfamiliar locations.
- When activity appears abusive, an account may be placed under a security lock, which blocks normal access until recovery completes through the email recovery path.
- Elevated alerts may also be reviewed by system administrators so incidents are not ignored during beta operations.
4.5 Household isolation
Data is scoped to your household. Roles and permissions limit what each member can see or change on web and mobile. Other households cannot access your ledger through the normal product APIs.
5. Sharing
We do not sell personal data. We may use infrastructure providers (for example hosting, email delivery, and push notification services) solely to operate AccountHouse. Those providers process data under our instructions. We may disclose information if required by law or to protect the service against abuse or fraud.
6. Retention
We retain account and household data for as long as your household remains active in the beta, and for a limited period afterward as needed for security, backup integrity, and legal obligations. Security logs are kept long enough to investigate access issues. Interest-form data is retained to process access requests.
7. Your choices
- Enable or disable email 2FA and app lock in Settings (where available).
- Revoke other sessions from Settings on web or mobile.
- Use PIN and biometric options to limit what appears on shared devices.
- Request access correction or deletion during beta via your household administrator or the contact path below.
8. Children
AccountHouse is intended for adult household administrators and members they invite. It is not directed at children under 16. If you believe a child has provided personal data without appropriate consent, contact us so we can remove it.
9. Changes to this policy
We may update this policy as the beta evolves. Material changes will be reflected here with a new “Policy last updated” date and, where appropriate, matching suite / web / Android version references. Continued use after an update constitutes acceptance of the revised policy for beta participation. Related product terms are in our Terms of Service.
10. Contact
For privacy requests during beta — including access, correction, or deletion — contact your AccountHouse household administrator or the email address on your welcome / approval message. Security incidents involving your account should be reported through the same channel as soon as practicable.
AccountHouse · Privacy Policy · 17 July 2026 · Suite 6.26.1 · Web 5.1.11 · Android 4.2.1