Privacy Policy

Last Updated: June 1, 2026  ·  Effective: June 1, 2026

Our core commitment: Consent is at the heart of every exchange. Our servers relay encrypted messages but retain no interaction logs and no raw personal data. Your Data actively monitors vendor compliance with data retention obligations on your behalf.

1. Who We Are

Your Data operates the Your Data mobile application ("the App"). References to "we", "us", or "our" in this policy mean Your Data and its operators. This policy applies to all users of the App regardless of location and covers our obligations under:

2. Our Privacy Philosophy

Consent is the foundation of every exchange. The App is built on the principle that your personal data belongs to you. We never collect, access, or share any data without your active, informed, per-transaction consent. You set the terms; we facilitate the exchange.

What happens on our servers

Our server infrastructure (hosted on Google Cloud Platform) acts as a relay and orchestrator only:

Where your data lives

All personal data you collect from linked accounts, device sensors, and surveys is stored encrypted on your device in a local SQLite database. We cannot read it. Third parties cannot read it. Only you hold the decryption key.

What vendors receive — standard case

When a vendor creates a notification, they specify a condition based on a semantic attribute (e.g., "income band is in a certain range"). That condition is evaluated entirely on your device against your local vault data — neither the vendor nor our servers ever see your actual attribute value. The notification is only delivered if your on-device data satisfies the condition. The vendor learns only that their notification reached you; they do not learn the value that triggered the match.

What vendors receive — survey exception

Surveys are the one context in which raw response data may be transmitted directly to a vendor's endpoint. This only occurs under strict conditions:

3. Data We Collect All regions

3a. Data you connect to the App (stored on your device only)

CategoryExamplesWhere stored
Financial / BankingTransaction history, account balances, merchant categoriesOn-device only
Streaming & subscriptionsListening history, subscription tier, usage patternsOn-device only
Device sensor dataLocation, battery, motion, Camera/Microphone inputsOn-device only
Survey responsesAnswers to in-app surveysOn-device by default; transmitted to a vendor endpoint only when you complete a vendor survey and explicitly accept its data-use terms (see §2)
User preferences & needsTravel plans, budget preferences, lifestyle statementsOn-device only

3b. Account and operational data (stored server-side)

Data elementPurposeIdentifiable?
Anonymised public keyUniquely identifies your vault session without revealing identityNo — pseudonymous
Account registration timestampAccount management, CDR consent trackingNo
Portfolio metadataRecords which data categories you have connected (not the data itself)No
Vendor notification interaction flagsTracks whether a notification has been seen / accepted / declined (not content)No

3c. Data we do NOT collect

4. Why We Process Your Data

We process personal data only for the following purposes, each requiring your explicit consent:

The App does facilitate consent-based, on-device advertising targeting — vendors specify conditions and your device evaluates them locally so relevant offers can be delivered to you. This is the core service. What we do not do is covert or server-side profiling, sale of your data to data brokers, or any processing beyond the purposes you have explicitly consented to.

6. Managing CDR Data AU / CDR

What CDR Data We Hold

Under the Consumer Data Right, we hold the following classes of CDR data with your explicit consent:

How CDR Data Is Held

Purposes for Collecting, Using, and Disclosing CDR Data

With your consent, we:

General Research

We do not use de-identified CDR data for general research. If we propose to do so in future, this policy will be updated describing the research and any associated benefit to you.

Consequences of Withdrawing Consent

Notifications About CDR Data Events

We notify you via in-app notification when:

7. Who We Share Data With

We only disclose data with your explicit, per-transaction consent. The nature of what is shared depends on the type of interaction:

Vendors — notification responses (on-device matching; no data shared)

When a vendor creates a notification, they specify targeting conditions based on semantic attributes (e.g., income band, location, spending category). These conditions are evaluated entirely on your device — your vault data never leaves your phone for matching purposes. Neither the vendor nor our servers learn what your actual attribute values are. The vendor only learns that their notification was delivered to a pseudonymous user whose device satisfied the condition. No attribute values, no aggregated data, and no raw personal data are shared in this flow.

Vendors — survey submissions (raw survey responses)

When you complete a vendor survey, the vendor may have configured a completion action — either a direct API submission (your device posts raw responses to the vendor's endpoint) or a website redirect (you are taken to a vendor-controlled web page, which may collect further information under that vendor's own privacy policy). Some surveys have no completion action at all. Where an API submission is configured, your response data travels directly from your device to the vendor's endpoint — it never transits our servers. This is the one context where raw data is disclosed to a third party, and it occurs only when:

Your Data requires vendors who receive survey data to comply with all applicable data protection laws, including restrictions on how long they may retain your responses and prohibitions on selling or sharing the data onward without your consent. We actively engage with vendors on your behalf to verify that these obligations are upheld.

Trusted advisers (CDR)

With your explicit consent, CDR data may be disclosed to a trusted adviser (e.g., a financial adviser) under a TA disclosure consent.

CDR insights

With your consent, CDR insights may be shared with specified persons under an insight disclosure consent.

Overseas service providers

Our infrastructure providers (see Section 16) may be located in the United States or European Union. These providers process operational metadata only; no personal data or CDR data is retained by them.

Legal and regulatory disclosure

We may disclose pseudonymous account data where required by law, court order, or regulatory authority. We will notify you of such disclosure where permitted by law.

A note on "selling" data

Your Data is a consent-based data marketplace: vendors pay to reach users, and users are compensated for participating. This is intentional and is the core value proposition of the App — you are in control of and benefit from the exchange.

What we do not do is sell or share your data without your knowledge or consent. We do not take your data and monetise it behind your back, share it with data brokers, or use it for any purpose you have not explicitly agreed to. Every exchange is initiated by you, disclosed to you in advance, and compensated.

Under CCPA, users retain the right to opt out of any specific sharing transaction at any time — see Section 8.

8. California Residents — CCPA / CPRA Rights CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:

Right to Know

You have the right to request disclosure of: (a) the categories of personal information we have collected about you; (b) the categories of sources from which it was collected; (c) the business or commercial purpose for collecting it; and (d) the categories of third parties with whom we share it. See Section 3 above for a full breakdown.

Right to Access

You have the right to request a copy of the specific pieces of personal information we hold about you. Because almost all personal data is stored on your device, the most complete copy is already in your vault. For server-side data (pseudonymous account records), contact us at privacy@your-data.app.

Right to Delete

You have the right to request deletion of personal information we hold about you. On-device vault data can be deleted directly within the App. To request deletion of your server-side pseudonymous account record, contact privacy@your-data.app.

Right to Correct

You have the right to request correction of inaccurate personal information. Use the App's correction feature or contact us.

Right to Opt-Out of Sale or Sharing

Your Data is a consent-based marketplace: vendors compensate you for participation in targeted offers and surveys. Each exchange requires your explicit, per-transaction consent, so the right to opt out is built into every interaction — you simply decline or do not respond. You may also withdraw a previously granted consent at any time within the App. We do not share your data with third parties for purposes beyond those you have individually consented to, and we do not sell or share data covertly or without your knowledge.

Right to Limit Use of Sensitive Personal Information

To the extent we process sensitive personal information (e.g., financial data, location, biometric-derived inferences), we do so only with your explicit consent for the stated purpose. You may withdraw that consent at any time.

Right to Non-Discrimination

We will not discriminate against you for exercising any CCPA rights — you will not receive a different level of service, be denied goods, or be charged different prices as a result.

How to submit a CCPA request

Email privacy@your-data.app with the subject "CCPA Request" and describe your request. We will verify your identity (by matching your pseudonymous public key) and respond within 45 days, with one 45-day extension where reasonably necessary.

Authorised agents

You may designate an authorised agent to submit a request on your behalf. We will require written proof of authorisation and may verify directly with you.

9. EU & UK Residents — GDPR Rights GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the GDPR / UK GDPR:

Right of Access (Art. 15)

You may request confirmation of whether we hold personal data about you and, if so, a copy of that data and information on how it is processed.

Right to Rectification (Art. 16)

You may request that inaccurate personal data be corrected or incomplete data completed.

Right to Erasure — "Right to be Forgotten" (Art. 17)

You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, you withdraw consent, or there is no overriding legitimate interest to continue processing.

Right to Restrict Processing (Art. 18)

You may request that we restrict processing of your data in certain circumstances (e.g., while a correction request is pending).

Right to Data Portability (Art. 20)

Where processing is based on consent and carried out by automated means, you may request your personal data in a structured, machine-readable format. Since almost all data resides on your device in your encrypted vault, you already have direct access to it. To request a copy of any server-side records we hold, contact privacy@your-data.app.

Right to Object (Art. 21)

You may object to processing based on our legitimate interests. We rely on legitimate interests only for operating the pseudonymous server account; you may object at any time and we will stop processing unless we can demonstrate compelling grounds.

Rights related to automated decision-making (Art. 22)

We do not make decisions with significant legal or similarly significant effects on you solely by automated means.

Right to Withdraw Consent

Where we rely on consent, you may withdraw it at any time through the App or by contacting us. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with your local supervisory authority. In the EU, find your authority at edpb.europa.eu. In the UK, contact the Information Commissioner's Office (ICO) at ico.org.uk.

How to exercise GDPR rights

Email privacy@your-data.app with the subject "GDPR Request" and describe your request. We will respond within 30 days (extendable by a further two months for complex requests — we will notify you if an extension is needed).

Data Protection Officer

Given the privacy-by-design architecture of the App — where no identifiable personal data is held server-side — we are not required to appoint a formal DPO. Privacy matters are handled by our Privacy Lead at privacy@your-data.app.

10. Overseas & International Data Transfers

CDR data and raw personal data are not stored outside Australia — they remain on your device. Server-side pseudonymous account data is hosted on Google Cloud Platform infrastructure in the Asia-Pacific region.

Where our cloud infrastructure providers operate in the United States or European Union, we ensure appropriate safeguards are in place (Standard Contractual Clauses for EEA transfers; equivalent protections for other jurisdictions). No identifiable personal data is transferred.

If we propose to transfer CDR data outside Australia in future, we will update this policy and specify the destination countries.

11. Data Retention

Data typeRetention periodDeletion trigger
On-device personal data (vault)Until you delete itUser action in-App or account deletion
Pseudonymous server account recordUntil you request deletionAccount deletion request (in-App)
Server interaction logsNot retainedN/A — not written to disk
Vendor notification interaction flags90 days after interactionAutomatic expiry
Aggregated portfolio metadataActive account lifetimeAccount deletion request

When your account is deleted, all server-side pseudonymous records are permanently removed within 30 days.

12. Deletion & De-identification

Deleting your data

De-identification

13. Security

We implement the following technical and organisational measures to protect your data:

In the event of a data breach affecting your rights or interests, we will notify you and the relevant regulatory authority within the timeframes required by applicable law (72 hours under GDPR; as soon as practicable under the Notifiable Data Breach Scheme).

14. Device Permissions

The App may request access to the following device features. All permissions are optional unless noted, and you can revoke them at any time in your device settings:

Revoking a permission may limit certain app features but does not affect your existing data vault.

15. Notifications About Data Events

We notify you via in-app alert when:

16. Third-Party & Outsourcing Arrangements

CDR representative arrangements

We do not currently have CDR representatives. If we engage representatives, we will list them here.

Outsourced service providers (OSPs)

All OSPs are contractually bound to our data handling requirements, including deletion and de-identification policies.

Sponsorship arrangements

We have no sponsorship arrangements with other accredited persons. If this changes, we will update this policy.

17. Access & Correction

Accessing your data

Correcting your data

18. Complaints

How to lodge a complaint

Our process

External review options

19. Changes to This Policy

We will post any material changes to this policy on this page and update the "Last Updated" date at the top. For significant changes (e.g., new categories of data collected or new third-party sharing), we will notify you via in-app notification at least 14 days before the change takes effect. Continued use of the App after that date constitutes acceptance of the revised policy.

20. Contact Us

For privacy inquiries, data requests, or to exercise your rights under any applicable law: