Privacy Policy

Last updated 5 September 2026

JarHabit helps you run the 6-jar money system. Doing that means holding details of your income and spending, which is about as personal as data gets. This page says plainly what we collect, why, who else can see it, and what you can ask us to do about it.

Who is responsible

JarHabit is an independent product operated by its maker, based in the Philippines. For questions about your data, or to exercise any of the rights below, write to help@jarhabit.com.

What we collect

Your account

Your email address and a password. The password is stored only as a hash by our authentication provider — it is never readable by us. You may also set a display name and a currency.

What you record

The income, expenses, jar balances, allocation percentages, recurring payments and any notes you enter. This is the substance of the product: we hold it so the app can show it back to you.

Technical information

Basic usage analytics — which pages are opened and which features are used — and error reports when something breaks. Analytics records the page path only, never the query string, and error reports are stripped of amounts, notes and email addresses before they are sent. Our hosting provider also keeps standard server logs, including IP addresses, for a short period.

What we do not collect

We do not ask for or store bank credentials, card numbers or government identifiers. JarHabit is not connected to any bank and takes no payments. Every figure in the app is one you typed in yourself.

Why we hold it

To provide the service you signed up for: to keep you signed in, to store and display your jars and transactions, and to send you account email such as password resets and address confirmation. Analytics and error reports are used to keep the product working and to decide what to improve.

We do not sell your data, we do not share it for advertising, and we do not use it to build a profile of you for anyone else.

Who else can see it

We use a small number of service providers to run JarHabit. They process data on our instructions only:

  • Supabase — the database and sign-in system that stores your account and everything you record. Hosted in Singapore.
  • Vercel — hosting and delivery of the site. Application servers run in Singapore.
  • Resend — sends account email (password reset, address confirmation). Receives your email address and the message.
  • PostHog — usage analytics, as described above.
  • Sentry — error reports, with sensitive fields removed before sending.

These providers operate internationally, so your data may be processed outside the Philippines. We will also disclose data where the law requires it.

Backups

Because our database plan includes no automatic backups, a copy of the database is taken on a regular schedule and stored on the operator's own computer in the Philippines, so that data can be recovered if something is deleted or lost. These copies contain the same information as the live database. They are kept private and are not shared.

Cookies and local storage

We use cookies to keep you signed in — without them the app cannot know it is you between pages. Our analytics provider also sets cookies to count visitors. Your theme preference is kept in your browser's local storage and never leaves your device. We do not use advertising or cross-site tracking cookies.

How long we keep it

Your account and the records in it are kept for as long as your account exists. If you ask us to delete your account, the account and everything attached to it — jars, transactions, recurring payments — are permanently removed from the live database. Backup copies taken before that point are overwritten in the ordinary course within a few months.

Your rights

Under the Data Privacy Act of 2012 (Republic Act No. 10173) you have the right to be informed about how your data is used; to access a copy of it; to have it corrected if it is wrong; to object to how it is processed; to have it erased or blocked in the circumstances the law allows; to obtain a copy in a portable format; and to be indemnified for damage caused by false or unlawfully obtained data.

To exercise any of these, email help@jarhabit.com. We will respond as promptly as we can. If you believe your rights have been infringed, you may also complain to the National Privacy Commission at privacy.gov.ph.

How we protect it

Your data is isolated at the database level so that one account cannot read another's. Traffic is encrypted in transit. Passwords are hashed, never stored in readable form. Error reports are scrubbed of amounts, notes and email addresses before they leave the app. No system is perfectly secure, but this product is built so that a mistake does not expose your finances to someone else.

Children

JarHabit is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.

Changes to this policy

If this policy changes in a way that affects you, we will update the date at the top and, for significant changes, tell you in the app or by email.