Privacy Policy
Last updated: August 13, 2026
LazyFinance ("LazyFinance", "we", "us") is a personal-finance tracking app operated by Code Éclair (NEQ 2271379655), based in Québec, Canada. This policy explains what we collect, why, and how we look after it. The short version: LazyFinance is manual-first, so we never connect to your bank, and we don't sell your data or run advertising trackers. Our only analytics are privacy-friendly and anonymous (Plausible, which we self-host, no cookies, can't identify you).
What we collect
- Account details: your email address and a securely hashed password.
- Financial information you enter: the accounts, balances, transactions, bills, categories, and preferences you type in. You add these yourself; we do not connect to your bank or import from any third party.
- Basic technical data: standard server logs (such as IP address and timestamps) needed to run and secure the service.
For basic web analytics we use Plausible, an open-source, privacy-friendly analytics tool that we host on our own servers, to see aggregate traffic (such as how many people visit and which pages are popular). Because we self-host it, no analytics data is sent to any third-party provider. It is cookieless, collects no personal data, sets no persistent identifiers, and does no cross-site tracking, so it cannot identify you as an individual. We do not use Google Analytics, ad pixels, or advertising trackers, and we never sell or share your data for advertising. To understand product health we also keep a simple internal dashboard of aggregate counts (e.g. number of users and transactions), not individual tracking.
How we use it
- To provide the app: your dashboard, net worth, bills, and insights.
- To send essential account emails: email verification, password resets, and trial/billing notices.
- To keep the service secure and prevent abuse.
We never sell your data or share it for advertising.
Where your data lives
- Our servers are hosted at OVH, in their Beauharnois (BHS) datacentre in Québec, Canada. So your primary data stays in Québec.
- Traffic is served through Cloudflare's DNS and a Cloudflare Tunnel (Cloudflare is a US company), so the origin server is never exposed directly to the internet. As a proxy, Cloudflare handles requests in transit at its nearest global edge and keeps limited technical logs (such as IP addresses) for security and performance; it may also cache public files like our app's scripts. Your account and financial data are not stored on Cloudflare, they live on our servers at OVH.
- Backups are encrypted on our server before they leave it, then stored with our backup partner BorgBase, in the United States. BorgBase only ever holds encrypted data it cannot read. Backups are kept for up to three months.
- Account emails (verification links, password resets, trial and billing notices) are sent through Resend (resend.com), a US email provider. Resend processes your email address and the message content to deliver it, and keeps limited delivery logs.
- Web analytics are collected by Plausible, which we host ourselves, on the same infrastructure as the rest of our data (OVH, in Québec). No analytics data is sent to any third party: it never leaves our servers. Plausible collects only anonymous, cookieless page events (no account or financial data, nothing that identifies you).
- If you turn on the optional AI assistant (the LazyFinance AI plan), your questions and the financial data needed to answer them are processed by Anthropic (anthropic.com), the company behind the Claude model, in the United States. Our use runs under Anthropic's commercial terms: your data is not used to train AI models, and is kept for at most about thirty days for abuse monitoring. Nothing is sent to Anthropic unless you turn the assistant on, and you control what it can see (hidden categories, private notes). See How we use AI.
Your primary data stays in Québec (OVH BHS). Encrypted backups are held in the US (BorgBase only ever sees ciphertext), traffic is proxied by Cloudflare's global network, account emails are delivered by Resend in the US, and questions you ask the optional AI assistant are processed by Anthropic in the US (only if you turn it on). Our web analytics stay on our own servers (self-hosted Plausible), with no transfer to a third party. These transfers are covered by each provider's privacy policy (linked above).
Payments
Subscriptions are handled by Polar (polar.sh), our Merchant of Record. When you subscribe, your payment goes through Polar, and we never see or store your card details. Polar processes the payment and issues your receipts.
Because Polar is the Merchant of Record, it keeps billing and transaction records under its own policy and for as long as tax and accounting laws require, which is longer than we keep your data. Deleting your LazyFinance account does not erase those records at Polar; their handling is covered by Polar's privacy policy.
Cookies
We use a single essential cookie: a secure, httpOnly session cookie that keeps you signed in. We don't use advertising or tracking cookies.
How we protect it
- Your connection is encrypted in transit with HTTPS.
- Passwords are hashed, never stored in plain text.
- Rate limiting and rotating login sessions guard against abuse.
- Servers are locked down and hosted with a reputable provider (OVH).
- Data is backed up automatically, multiple times a day, encrypted before it leaves our server.
- We never connect to your bank, so your banking logins are never at risk.
Your choices
- Export: download all your data to Excel anytime from the app.
- Access & correct: everything you store is visible and editable in-app.
- Delete: delete your account and its data; residual copies in encrypted backups age out within three months.
Data retention
We keep your data for as long as your account is active. When you delete your account we remove your data from the live service; encrypted backup copies are cycled out within three months.
CSV files you import are sent over an encrypted connection and parsed in memory on our server, never written to disk: the file is discarded as soon as it's processed, and only the transactions you choose to import are saved.
Conversations with the optional AI assistant are kept for at most 90 days, then deleted automatically. Clearing the conversation or turning the assistant off deletes them immediately, and deleting your account removes them too.
To protect accounts and investigate abuse, we keep a security log of account events (for example sign-ins, with the IP address and device). It is stored separately from your financial data, kept for up to 90 days, then deleted. Because its only purpose is to catch an accident or a compromise, this log can briefly outlast the deletion of an account, but no more than 90 days. After that, with backups also cycled out, nothing about a deleted account remains.
Session records (what keeps you signed in between visits, along with the IP address they were opened from) expire after 14 days and are deleted at most 30 days after that.
We also keep a minimal, non-identifying record of deletions (an internal account identifier and the date, no email or financial data) so that, if we ever restore a backup, deleted accounts stay deleted.
Children
LazyFinance isn't directed at children and isn't intended for anyone under 16.
Changes
We may update this policy from time to time. When we do, we'll change the date at the top of this page.
Person in charge of personal information
Code Éclair is responsible for the personal information LazyFinance holds. For any question, or to access, correct, or delete your information, contact our person in charge of personal information (privacy officer), Danny Ferguson, at privacy@lazyfinance.app.
If you're not satisfied with our response, you can file a complaint with Québec's Commission d'accès à l'information.
Contact
Questions about your privacy? Reach us through the Contact page or at privacy@lazyfinance.app.