← Back to Cervidia

Privacy Policy

Last updated: August 26, 2026

Who we are

Cervidia is a personal finance application for personal and household use. It is not a bank, financial institution, or registered investment adviser.

It is currently a private beta operated by one individual. Your data is held in a managed cloud database that we control — not on your own machine, and not in an instance you administer. Every account belongs to a household, and all data is scoped to that household, so no account can read another's. We do not sell, rent, or trade your data, and the only outside companies that touch it are the four named under Data sharing below.

What data we collect

Cervidia collects the data you provide, plus the minimum needed to run an account securely:

  • Your name and email address (for account creation and sign-in)
  • Financial data you manually enter: account balances, transaction amounts, dates, descriptions, categories
  • Financial data you import: only the fields you explicitly map or confirm (date, description, and amount). All other columns — including account numbers, IFSC codes, customer IDs, branch details, and any other fields in your bank statement — are never read, never stored, and discarded from browser memory after mapping.
  • Import profile settings (column names only, not any financial data)
  • Budget, category, and reporting preferences, including which financial year you follow
  • Security records — sign-ins, password changes, failed sign-in attempts and similar events, each stored as an action name, the email address involved, and a timestamp. They carry no amounts, no transaction details, and no financial data. They exist so that a burst of failed sign-ins is visible rather than silent.
  • Email records — which summary emails were sent to you and when, so the same message is never sent twice

What we do NOT collect

  • Your full bank account numbers
  • Net banking credentials or passwords
  • IFSC codes, branch details, or bank addresses
  • PAN, Aadhaar, or any government-issued identification
  • Credit card numbers or CVVs
  • Any columns in uploaded files that are not explicitly mapped by you
  • Location data
  • Browser history or behaviour outside the app
  • Device identifiers, fingerprints, or advertising IDs
  • IP addresses.Cervidia's own database stores none — even the limit on repeated failed sign-ins counts against the email address rather than the network you connected from. Our hosting provider keeps short-lived request logs of its own; see Data sharing.

There are no analytics, no advertising trackers, and no third-party scripts of any kind on this site.

How statement imports work

When you upload a bank or credit card statement — CSV or PDF — the file is parsed entirely in your browser and never leaves your device in its raw form. For a CSV, only the four fields you select during column mapping (date, description, debit amount, credit amount) are extracted; all remaining columns are discarded from browser memory immediately after the mapping step. For a PDF, the text is extracted locally and the document itself is never uploaded — a password, if the statement needs one, is used in your browser and never transmitted.

In both cases only the rows you choose to add are sent to the server. Rows you untick, and rows the importer flags as duplicates, are never transmitted at all.

You can verify this by inspecting the network requests in your browser's developer tools — only a small JSON array of date/description/amount rows is ever transmitted, not the full statement content.

Import diagnostics (off by default)

You can optionally let Cervidia record how well each statement import was read. This is off unless you turn it on in Settings, and it exists for one reason: how much of a statement can be categorised automatically depends on your bank, not on this app. Some banks print a merchant category code on every line; some print none.

When enabled, each import records:

  • which bank format was used (for example “federal”)
  • how many rows were parsed, categorised automatically, and left for you
  • whether each automatic category came from a rule, a merchant code, or a recurring match
  • any four-digit merchant category codes we did not recognise
  • how many warnings the parser raised

It records nothing else. No transaction descriptions, amounts, dates, payees, account numbers or balances — nothing that could identify you or indicate what you bought. The function that builds this record cannot return text from your statement, and its tests assert that names, phone numbers and UPI handles fed into it never appear in the output.

How your data is stored

Your financial data is stored in a PostgreSQL database on Neon (neon.com), a managed cloud database provider. Data is encrypted at rest and in transit using industry-standard TLS. The database runs on AWS infrastructure in the Asia Pacific (Singapore) region, chosen because it is the closest region available to India.

Your data is therefore stored outside India. Our database provider offers no region inside India. If that matters to you, please weigh it before entering real financial data.

Passwords are hashed using bcrypt with a cost factor of 12 before storage. Plaintext passwords are never stored or logged anywhere in the system.

Sessions are managed via signed JWT tokens stored in httpOnly cookies and are never accessible from JavaScript. Tokens expire after 30 days, and changing your password invalidates every session that already exists.

Backups of the database are taken daily and held on private storage controlled by the operator, kept separately from the database provider.

Data sharing

We do not sell, rent, or share your financial data with any third party for any purpose. Four service providers necessarily process some data in order for the application to run at all:

  • Neon (database hosting, Singapore) — stores all of your account and financial data.
  • Vercel (application hosting) — runs the application and serves every page. Vercel receives the network requests your browser makes, which necessarily includes your IP address, and keeps short-lived operational logs of them. It does not receive a copy of your financial data to store.
  • Resend (email delivery) — receives your email address and the contents of what we send you: account verification, password resets, and — only if you turn them on — periodic summaries of your own figures. Verifying an email address is required to hold an account, so this is not optional. Open and click tracking are switched off.
  • Sentry (error reporting, EU) — receives a report when the application crashes, so a fault can be fixed rather than waiting for somebody to describe it. Reports carry the page that failed and the programming error behind it. They deliberately do not carry your financial data.Request bodies, cookies, headers and query strings are stripped before a report leaves our servers; your email address and IP are removed from it; and there is no session recording and no performance tracing at all. Data is stored in Sentry's European region.

No financial data is sent to any analytics platform, advertising network, or AI service. Your data is not used to train any model.

Your rights

At any time, and without asking us, you can:

  • Export everything. Settings → Your data → Download everything (JSON)returns a complete copy of your household's data. Reports can also be exported as CSV, Excel or PDF.
  • Delete everything. Settings → Your data → Delete permanently erases your account and all data belonging to it. This cannot be undone. We keep no shadow copy; deleted data leaves our backups as those backups age out.
  • Correct anything — every figure in the app is editable by you
  • Ask a question about any of the above, at the contact address below

Beta status

Cervidia is in private beta. Features change often, and while backups run daily and the restore path has been tested, you should not yet treat this as your only record of your finances. Please keep whatever you use today alongside it.

Important disclaimer

Cervidia is a personal financial tracking tool. It is not a licensed financial adviser, investment adviser, bank, or regulated financial service under SEBI, RBI, IRDAI, or any other regulatory authority. Any numbers, projections, or insights shown in the app are for personal informational purposes only and do not constitute financial advice.

Always consult a qualified financial professional before making significant financial decisions.

Contact

Questions, corrections, or complaints about your data go to cervidia.official@gmail.com, which reaches the person who operates Cervidia.

Changes to this policy

This policy may be updated as new features are added. The last-updated date at the top of this page will always reflect the most recent version. Continued use of the application after changes constitutes acceptance of the updated policy.

Questions about this policy? Read our Terms of Service