Privacy Policy
Last updated 26 August 2026
The short version
Eskel stores what you put into it, so it can show it back to you. We do not sell your data, we do not run ad trackers, and we do not build a profile of you for anyone else. You can export everything or delete all of it from inside the app at any time.
What we collect
- Your account. The email address you sign in with. We use it to authenticate you and to contact you about the service.
- What you record. Habits, tasks, transactions, loans, subscriptions, books, projects, meals, wishlist items, and — if you turn the module on — practice, fasting, giving, study, and reflection entries.
- Your preferences. Display name, currency, region, time format, which modules you use, and your chosen tradition if you set one.
- Gmail data, only if you connect it. See the section below.
Sensitive categories
If you enable the Faith module, your chosen tradition and your practice records are stored. In several jurisdictions that is a special category of personal data. It is optional, it is never required to use Eskel, it is never used for advertising or profiling, it is never shared, and turning the module off or deleting your account removes it. The other modules never reference it.
Gmail, if you connect it
Connecting Gmail is entirely optional and off by default. If you connect it, Eskel requests read-only access and searches for bank transaction alerts in order to import amounts, dates, and descriptions into your ledger.
- We do not store the contents of your emails.
- We store only the parsed transaction and the message id, so the same alert is not imported twice.
- Your access and refresh tokens are encrypted at rest with AES-256-GCM.
- We never read, send, or delete mail on your behalf.
- Disconnecting from Settings deletes the stored tokens immediately.
Eskel's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI features
If you ask Eskel to analyse your spending, a summary — totals, category names, and your five largest expenses for the period — is sent to Anthropic's API to generate the insights. Your name, email, and account identifiers are not included. The feature runs only when you trigger it.
Who else touches your data
- Supabase — database, authentication, and file storage.
- Vercel — hosting and delivery.
- Anthropic — only for the AI insights described above.
- Google — only if you connect Gmail.
We do not sell or rent your personal data to anyone, for any purpose.
How it is protected
Every table enforces row-level security in the database, so a record is readable only by the account that owns it — that boundary holds even if the application layer is wrong. Traffic is encrypted in transit. OAuth tokens are encrypted at rest.
Your rights
- Access and portability. Settings → Account → Export exports everything as a single JSON file.
- Deletion. Settings → Account → Delete account permanently removes your account and every record in it.
- Correction. Every record is editable in the app.
- Withdraw consent. Disconnect Gmail or switch off any module at any time.
Depending on where you live, the GDPR, UK GDPR, CCPA/CPRA, or India's DPDP Act may give you further rights. Contact us and we will honour them.
Retention
Your data is kept while your account exists. Deleting your account removes it from the live database immediately; encrypted backups are purged on a rolling 30-day cycle.
Children
Eskel is not intended for children under 13, and we do not knowingly collect their data.
Changes
If this policy changes materially, we will update the date above and notify you in the app before the change takes effect.
Contact
Questions, or want to exercise a right? Email privacy@nyx.app.