Privacy
Privacy policy
Last updated 10 September 2026.
Contha is operated by OWSH Unlimited LLC, a New York limited liability company (“Contha”, “we”). This policy says what we collect when you use contha.com and app.contha.com, why, who else touches it, how long we keep it, and what you can do about it. It is written to be read. If a sentence here and a sentence in a law disagree, the law wins.
The short version
- We read your financial accounts through a read-only connection so we can do arithmetic on them. We cannot move, hold, freeze or close money, ever.
- We do not sell your data, share it with advertisers, or use it to train anything.
- You can export everything as one file at any time, and delete the account with everything in it.
- The people who can see your books are you, anyone you invite to your household, anyone you hand a read-only link to, and the small number of services below that store or carry the data for us.
What we collect
Account. Your email address and a password hash. If you sign in from a link we emailed, the code in that link.
Financial data you connect. When you link a bank, card, brokerage or loan account through Plaid, we receive the account name and masked number, balances, transactions (date, amount, merchant, description, pending status), and for investment accounts, holdings. We store these in our database. We store the token that lets us re-read the account, encrypted at the application layer with a key that is not the database’s key. We never see or store your bank login.
Financial data you type or upload. CSV files you import, transactions, categories, rules, budgets, goals, mileage trips, entities and their tax treatment, wages and distributions you record, receipts you attach (image or PDF files), tax settings such as your state and filing status, and the name of the account you keep tax money in.
Billing. If you subscribe, Stripe collects your card. We never see the card number. We store your Stripe customer and subscription ids, your plan, the price you pay, and when it was locked.
Household and sharing. The email address of anyone you invite, the role you gave them, and when they joined. For a read-only accountant link: the label you typed, when it expires, and when it was last opened.
Technical. Server logs with IP address, browser type, the pages requested and the time, kept briefly for security and debugging. Error reports, with personal details removed before they leave our servers. Page-view counts on the marketing site with no cookies and no identifier that follows you.
We do not use advertising cookies or trackers. The only cookies are the ones that keep you signed in to the app.
Why we collect it
- To run the product: show your accounts and transactions in one place, categorize them, split business from personal, compute the tax estimate, the quarterly schedule, the reserve, mileage, the year-end package and the other figures the product exists for.
- To keep it working: sync your connections daily, tell you when a feed is behind or dead, and send the monthly digest if you have it on.
- To bill you, and to honour the price your subscription carries.
- To keep it safe: detect abuse, investigate incidents, enforce the terms.
- To meet legal obligations, including the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, which apply to us as a company that handles consumer financial information.
We do not use your data to build profiles for advertising, to sell leads, or to decide anything about your creditworthiness. Where the product recommends a card or a deposit account, the ranking is computed from your own spending on our servers and nothing about you is sent to an issuer or a bank.
Who else touches it
These companies process data on our behalf. Each has its own privacy policy and a contract with us that limits what it may do with the data.
- Supabase (database, authentication, file storage), hosted on Amazon Web Services in the United States.
- Vercel (application hosting, edge network, server logs).
- Plaid (bank connections). Plaid collects and processes your financial data under its own End User Privacy Policy at plaid.com/legal, which you agree to when you connect an account through Plaid Link.
- Stripe (payments and subscription billing).
- Resend (transactional email: sign-in and recovery links, the dead-feed notice, the monthly digest).
- An error-reporting service, once we add one, receiving stack traces with personal details scrubbed.
Beyond those: anyone you invite to your household (they see the books, at the role you gave them), anyone you hand a read-only link to (they see the year-end package until the link expires or you turn it off), and the authorities when a valid legal demand requires it, in which case we tell you unless the law forbids it. If Contha is ever sold, the data goes with it under this policy and you are told first.
We do not sell personal information and have not done so in the preceding twelve months. We do not share it for cross-context behavioural advertising.
How long we keep it
- Account and financial data: for as long as your account exists. Delete the account and it is deleted, receipts included, within thirty days, with backups rolling off within a further thirty.
- Disconnected accounts: the encrypted token is removed at once; the transactions already read stay in your books until you delete them or the account.
- Billing records: seven years, because tax law requires it of us.
- Server logs: thirty days.
- Read-only links: they expire on the date you chose (30, 45 or 90 days) or when you turn them off, and nothing about the link is kept after that except that it existed.
Security
Every row in the database is scoped to its owner in Postgres itself, not only by the screen you look at. The token that reads your bank is encrypted with AES-256-GCM using a key held separately from the database, so a leaked database is not a leaked connection. Everything is encrypted in transit and at rest. Sessions expire after an hour of no activity on the server side and are refreshed while you use the app. Passwords must be at least ten characters and are checked against known leaks. We do not claim certifications we do not hold; there is no SOC 2 yet.
No system is perfectly secure. If we learn of a breach affecting your data we will tell you by email without unreasonable delay and in any case within the time the law requires.
Your rights and choices
- Export: every row you can see, as one document, from Settings, at any time.
- Correct: everything in the app is editable.
- Delete: the whole account, from Settings, behind a typed confirmation. It is not a support ticket.
- Disconnect: any bank connection, from Accounts, at once.
- Email: the monthly digest is off under Settings. Sign-in, recovery and the dead-feed notice are part of the service and cannot be turned off while the account exists.
- Access and portability: the export is the access request. If you want it in another form, write to us.
If you live in California, Virginia, Colorado, Connecticut, Utah, or another state with a consumer privacy law, those rights are yours under it as well: to know, to delete, to correct, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising them. Write to the address below and we will act within the time the law gives, usually 45 days. You may use an authorised agent; we will verify the request through the account. If you live in the European Economic Area or the United Kingdom, the product is not offered there; if you use it anyway, your data is processed in the United States and the rights above are yours under the GDPR or UK GDPR, with OWSH Unlimited LLC as the controller.
Children
Contha is for adults. We do not knowingly collect data from anyone under 18, and an account we learn belongs to a minor is deleted.
Changes
When this policy changes we update the date at the top and, for anything that matters, email every account before it takes effect. The previous version is available on request.
Contact
OWSH Unlimited LLC, Buffalo, New York.
privacy@contha.com for anything on this page, including a request under a state privacy law.