Harbor provisional logoHarbor · Household money, together

Privacy policy

Updated 4 October 2026 · Private household prototype

This notice describes the current private household prototype, Harbor. It helps the household record money, compare actual spending with plans and understand savings, debt and long-term goals.

Who looks after your information

The Scott household owner, Clint Scott, manages this private workspace. For access, correction, export, deletion or privacy questions, contact the owner through your existing private household contact channel. A dedicated contact route and revised notice will be provided before wider invitations.

Information we keep and why

We keep account identifiers used by the app, household membership and roles, names, sign-in identifiers, transactions, budgets, savings and debt plans, asset and pension valuations, goals, notes, uploaded goal images and imported history. These records support the household’s requested budgeting, forecasting and reconciliation. Audit records identify changes and help investigate mistakes or unauthorised access. Forecasts are estimates from your inputs, not bank-confirmed future balances.

Central saving and device storage

Financial records save to the central MariaDB database on the existing Plesk hosting. Approved sessions read the same household records across devices. A save is confirmed only after server acknowledgement. The app holds current records temporarily in memory while open and refreshes idle sessions without replacing an open draft. Persistent browser ledgers and offline write queues are not enabled. Ordinary browser caching of static app files, fonts and images contains no ledger. Older prototype browser records or downloaded exports may remain on a device; they are not authoritative and cookie choices never delete those financial copies.

Sign-in and essential cookies

Google and Microsoft sign-in verify identity; they do not provide access to bank accounts, email or cloud documents. Password access stores a password hash. Essential session and form-security cookies are always active. A separate opt-in at sign-in remembers a trusted device for up to 30 days; sign-out ends it sooner. The harbour_privacy cookie remembers this device’s choice and notice version for 90 days. Optional appearance storage (hbv3-view-mode in localStorage) remembers Simple/Expert only when allowed. Rejecting or withdrawing removes that saved appearance preference; the app still works, and folded sections remain in memory only for the visit. No advertising or analytics trackers are installed. Use Cookie preferences in navigation or the footer to review or change your choice. Choices are device-specific. Acknowledging the privacy notice is separate from consent to optional storage.

Who can receive information

Household records are available to authorised household members according to their permissions, and to the hosting infrastructure and authorised maintenance needed to operate the service. Google or Microsoft processes its own sign-in requests when you choose that method. Public market/news requests are proxied by the app server to the existing Render feed service; the feed request contains the feed type, not your household ledger. Following a news or other external link takes you to that publisher, which has its own privacy practices. We do not sell household records or use them for advertising. No banking connection is currently enabled.

Keeping records and backups

Financial history is retained while the household uses it for reconciliation, year comparisons and planning. The owner reviews requests to remove unnecessary records and access. Recovery backups may retain older versions after a record changes or is removed; those copies must also be considered when handling deletion requests. Current staging recovery archives are created manually. An automated backup retention schedule has not yet been finalised, so this notice does not promise deletion from every backup within a fixed number of days.

Your choices and requests

You can correct permitted records and create a portable JSON export in Settings. Ask the owner to review access, correct identity information, remove records or close your access. Requests involving another household member’s information or retained recovery records need review. If the service expands beyond private household use, its operator, contact details, retention periods, relevant legal basis and applicable data-protection rights will be stated before invitations are opened.

How we protect access

The hosted app uses HTTPS, server-side household access checks, role restrictions, revision checks for conflicting edits and an audit trail for supported changes. Only use remembered sign-in on devices you trust. Exported JSON files contain private financial information and should be kept somewhere you control. Institution illustrations identify records; they do not indicate a bank partnership or live account connection. Supplied bank logos identify institutions; they do not indicate a partnership or live connection. Household checks isolate normal member access. Hosting/database administrators with infrastructure access can technically access stored information; the current app has no encryption with keys held exclusively by each household. Stronger isolation and an explicit operator-access policy are required before inviting other households.

Changes to this notice

This page is reviewed when the service or its data use changes. New uses, additional providers or open-banking connections will be explained before they are enabled. This version describes the current private prototype rather than a public financial service.

Open-source languages and technologies

Project licenses remain with their respective authors.

HTML / CSS
Page structure, glass styling and responsive layouts.
TypeScript / JavaScript
Application language and browser interaction.
React 19
User interface.
Vite
Frontend builds and local development.
Recharts
Charts and visual comparisons.
Lucide React
Interface icons.
PHP 8.3 / Laravel
Hosted API, sign-in, access checks and database writes.
MariaDB / SQL
Central household database.
JumboJett OpenID Connect PHP
Google and Microsoft identity verification.
Node.js
Development tools and the public-feed service source.
Bricolage Grotesque / IBM Plex Sans
Locally served fonts; SIL Open Font License 1.1. License files are included with the app.
Vitest / Playwright / PHPUnit / Laravel Pint
Development testing and formatting; not advertising or visitor analytics.
Python / openpyxl
Local conversion of supplied legacy Excel workbooks; not a live bank feed.

Bricolage font license · IBM Plex font license

External feeds and services

External feeds are not necessarily open-source or freely licensed for redistribution.

Stooq
Public market-price CSV source configured in the feed service. Prices may be delayed or unavailable.
BBC Business
Public business-news RSS headlines configured in the feed service.
MoneySavingExpert
Public personal-finance news RSS headlines configured in the feed service.
Render public-feed service
Existing server-side intermediary for market and news feeds; availability is not guaranteed.
Google / Microsoft / Plesk
Identity providers and hosting tools are third-party services, not described here as open-source feeds.

Return to sign-in · ICO privacy information