1. Who we are
Everykept is operated by TiqyTech Inc. (“Everykept”, “we”, “us”), based in Ontario, Canada. We are the organization accountable for your personal information under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial law. Questions and requests go to privacy@everykept.com.
2. What we collect
Information you give us
- Account details: name, email address, and a password (stored only as a salted argon2id hash; we cannot read it). If you enable two-factor authentication we store the encrypted authenticator secret and hashed backup codes.
- Sign in with Google: if you choose it, Google sends us your name, email address and a Google account identifier. We never receive your Google password.
- Receipts and notes: images and PDFs you upload, and any notes or category changes you make on a transaction.
- Preferences: display currency, colour scheme, budgets you create.
Information from your financial institutions, via Plaid
When you connect a bank account you do so through Plaid Inc. (“Plaid”). Plaid retrieves data from your institution and passes it to us. We receive and store: the institution name, account names, types and last four digits of account numbers, balances, and transactions (date, amount, description, merchant name, Plaid’s category, and pending status). We never receive or store your online banking username or password. Plaid’s own handling of your data is governed by the Plaid End User Privacy Policy, which you accept when you link an account. You can review and revoke Plaid connections at any time at my.plaid.com.
Information collected automatically
- Security and audit logs: sign-ins, sign-outs, password changes, bank connections and disconnections, with timestamp, IP address and browser user agent.
- Server logs: request path, status, timing and a request identifier. We redact tokens and credentials from logs by design and test that redaction.
- Receipt metadata: when you upload a photo we remove all embedded EXIF metadata, including GPS location, before storing it. We keep only the file type, size and upload time.
We do not use advertising trackers, analytics pixels, or third-party cookies.
3. Why we use it
- To provide the service: show your transactions, balances, budgets and receipts.
- To keep your account secure: verify your email, detect suspicious sign-ins, enforce rate limits.
- To communicate with you: verification, password reset, and notices about a bank connection that needs attention.
- To understand aggregate usage (counts of users, connections, uploads) so we can run and improve the product. This is done on totals, never by reading individual transactions.
- To meet legal obligations and to respond to lawful requests.
We do not sell personal information. We do not use your financial data to build profiles for advertising, and we do not share it with data brokers.
4. Legal basis
We process your information with your consent, given when you create an account and again each time you link a financial institution, and because it is necessary to provide the service you asked for. Where the law of your region requires a different basis (for example the GDPR for residents of the EU or UK), we rely on performance of a contract for the core service and on legitimate interests for security logging.
5. Who else processes your data
We use a small number of service providers (“sub-processors”), each bound by contract to protect your data and use it only on our instructions:
- Plaid Inc. (United States): bank connectivity.
- Neon Inc. (United States, us-east-1): managed PostgreSQL database holding account, transaction and receipt records.
- Cloudflare Inc. (global network, private buckets): object storage for receipt files and thumbnails.
- Fly.io (United States): application hosting.
- Vercel Inc. (global CDN): hosting of the web application’s static files. Vercel does not receive your financial data.
- Resend Inc. (United States): transactional email (verification, password reset, connection alerts). Receives your email address and name only.
- Google LLC (United States): identity provider, only if you sign in with Google.
The current list is also published on our Data Processing Addendum page. We will update it at least 30 days before adding a sub-processor that handles financial data.
6. Where your data is stored
Everykept is a Canadian service, but our database and file storage providers operate primarily in the United States. Your information may therefore be stored and processed outside Canada and be subject to the laws of that jurisdiction, including lawful access requests by its authorities. All data is encrypted in transit (TLS 1.2+) and at rest.
7. How long we keep it
- Transactions, accounts, receipts: for as long as your account exists. Receipts are business records; Canadian tax rules generally require keeping them for six years, so we never delete a receipt automatically.
- Audit and server logs: 13 months, then deleted.
- After account deletion: we delete your data from live systems within 30 days and from backups within 90 days. We revoke every Plaid connection at the same time.
8. Your rights and choices
- Access and export: request a copy of your data in a machine-readable format.
- Correction: change your name, email and preferences in Settings; ask us to fix anything else.
- Withdraw consent: disconnect any bank at any time in Settings, or revoke access through Plaid directly. Disconnecting stops new data; existing transactions stay until you delete them or your account.
- Deletion: delete your account in Settings or by emailing us. Deletion is permanent.
- Complaints: you may contact the Office of the Privacy Commissioner of Canada or your provincial regulator. EU/UK residents may contact their local supervisory authority.
We respond to requests within 30 days. We may need to verify your identity first.
9. Cookies and local storage
We set one strictly necessary cookie: your session token, marked HttpOnly and Secure, sent only to our API. We store your colour-scheme preference in your browser’s local storage. Nothing else. There is no cookie banner because there is nothing to opt out of.
10. Security
A summary of our safeguards is on the Security page. No system is perfectly secure; if we learn of a breach affecting your personal information that creates a real risk of significant harm, we will notify you and the Privacy Commissioner as required by law.
11. Children
Everykept is not directed at anyone under 18 and we do not knowingly collect their information. If you believe a minor has created an account, contact us and we will delete it.
12. Changes
When this policy changes in a way that matters, we will email you and show a notice in the app before the change takes effect. The effective date at the top always tells you which version you are reading.
13. Contact
TiqyTech Inc., Ontario, Canada. Privacy officer: privacy@everykept.com. Write to this address for any request under this policy; we will provide a mailing address on request if you need to send something by post.