Legal

Privacy Policy

Last updated: 27 July 2026

This Privacy Policy explains what information Salli collects, why we collect it, and how it's used and protected. Salli handles financial data, so we've tried to write this plainly rather than burying it in boilerplate.

1. Information we collect

We collect information in four ways:

  • Account information: your name, email address, and authentication details when you sign up (directly, or via Google/Apple sign-in).
  • Financial data you provide: ledger entries, account balances, income and expense records, goals, and any bank statements or documents you upload for parsing.
  • Usage data: how you interact with the product (pages visited, features used, AI messages sent), collected to operate and improve the service.
  • Bug reports and diagnostics you choose to send us: when you report a problem, we receive your description of it along with a technical snapshot — the page you were on, your browser, device and locale details, recent failed requests and any error message behind them, and any screenshot you attach. This snapshot deliberately excludes your balances, amounts, account names and entry descriptions, and you can review exactly what it contains before you send it.

2. How we use your information

We use your information to:

  • Provide the ledger, tax computation, FIRE scoring, and AI assistant features;
  • Authenticate you and keep your account secure;
  • Process payments for paid subscription plans;
  • Send service-related communications (billing, security alerts, product updates);
  • Diagnose issues and improve the reliability and quality of the product.

We do not sell your personal or financial data, and we do not use your financial data to train third-party AI models.

3. How the AI assistant handles your data

When you ask Scrooge a question, relevant parts of your ledger data are sent to our AI provider to generate a response. This is used only to answer your query within your session; it is not used to train the underlying model. All monetary figures shown to you are computed by Salli's own deterministic engine beforehand; the AI explains and contextualises numbers, it does not calculate them.

4. Where your data is stored

Your data is stored in a managed Postgres database with row-level access controls, hosted in the Asia-Pacific region for lower latency from Sri Lanka. Uploaded documents (such as bank statements) are stored in a private object storage bucket that only your authenticated account can access. Data in transit is encrypted with TLS; our infrastructure providers encrypt data at rest.

5. Sub-processors

We rely on a small number of vetted infrastructure and service providers to run Salli:

  • Database, authentication & storage: for the ledger database, login, and document storage.
  • Application hosting: for running the API and web application.
  • AI provider: to power the Scrooge assistant.
  • Payment processor: to handle paid subscriptions as merchant of record.
  • Issue tracking: to record and resolve bugs you report to us.

Each of these providers processes data only as needed to deliver their part of the service, under their own security and privacy commitments.

6. Data retention

We keep your data for as long as your account is active. If you close your account, we delete your personal and financial data within a reasonable period, except where we're legally required to retain certain records (for example, billing records for tax purposes).

Bug reports are treated differently, and we want to be explicit about it. When you report a problem, we create a corresponding ticket in our issue tracker so the bug can actually get fixed. That ticket is a record about the product rather than about you: it carries a pseudonymous account identifier, never your name or email address. Because other people are usually affected by the same bug, these tickets and their diagnostics are kept for engineering purposes even after an account is closed — while the copy of the report held inside Salli, including your email address if you asked us to follow up, is deleted with the rest of your data.

7. Your rights

You can, at any time:

  • Access and export the data you've stored in Salli;
  • Correct inaccurate information in your account;
  • Request deletion of your account and associated data;
  • Withdraw consent for optional communications.

To exercise any of these, email hello@salli.lk.

8. Cookies

Salli uses a small number of cookies and local-storage entries needed to keep you signed in and remember preferences (like light/dark mode). See our Cookie Policy for details.

9. Children's privacy

Salli is intended for adults managing their own finances and is not directed at children under 18. We don't knowingly collect data from children.

10. International transfers

Some of our sub-processors operate infrastructure outside Sri Lanka. Where data crosses borders, we rely on providers that maintain appropriate safeguards for that transfer.

11. Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated by email or an in-app notice before they take effect.

12. Contact

Questions about this policy or your data? Email hello@salli.lk.