Last Updated: June 1, 2026 · Effective: June 1, 2026
Our core commitment: Consent is at the heart of every exchange. Our servers relay encrypted messages but retain no interaction logs and no raw personal data. Your Data actively monitors vendor compliance with data retention obligations on your behalf.
Your Data operates the Your Data mobile application ("the App"). References to "we", "us", or "our" in this policy mean Your Data and its operators. This policy applies to all users of the App regardless of location and covers our obligations under:
Consent is the foundation of every exchange. The App is built on the principle that your personal data belongs to you. We never collect, access, or share any data without your active, informed, per-transaction consent. You set the terms; we facilitate the exchange.
Our server infrastructure (hosted on Google Cloud Platform) acts as a relay and orchestrator only:
All personal data you collect from linked accounts, device sensors, and surveys is stored encrypted on your device in a local SQLite database. We cannot read it. Third parties cannot read it. Only you hold the decryption key.
When a vendor creates a notification, they specify a condition based on a semantic attribute (e.g., "income band is in a certain range"). That condition is evaluated entirely on your device against your local vault data — neither the vendor nor our servers ever see your actual attribute value. The notification is only delivered if your on-device data satisfies the condition. The vendor learns only that their notification reached you; they do not learn the value that triggered the match.
Surveys are the one context in which raw response data may be transmitted directly to a vendor's endpoint. This only occurs under strict conditions:
| Category | Examples | Where stored |
|---|---|---|
| Financial / Banking | Transaction history, account balances, merchant categories | On-device only |
| Streaming & subscriptions | Listening history, subscription tier, usage patterns | On-device only |
| Device sensor data | Location, battery, motion, Camera/Microphone inputs | On-device only |
| Survey responses | Answers to in-app surveys | On-device by default; transmitted to a vendor endpoint only when you complete a vendor survey and explicitly accept its data-use terms (see §2) |
| User preferences & needs | Travel plans, budget preferences, lifestyle statements | On-device only |
| Data element | Purpose | Identifiable? |
|---|---|---|
| Anonymised public key | Uniquely identifies your vault session without revealing identity | No — pseudonymous |
| Account registration timestamp | Account management, CDR consent tracking | No |
| Portfolio metadata | Records which data categories you have connected (not the data itself) | No |
| Vendor notification interaction flags | Tracks whether a notification has been seen / accepted / declined (not content) | No |
We process personal data only for the following purposes, each requiring your explicit consent:
The App does facilitate consent-based, on-device advertising targeting — vendors specify conditions and your device evaluates them locally so relevant offers can be delivered to you. This is the core service. What we do not do is covert or server-side profiling, sale of your data to data brokers, or any processing beyond the purposes you have explicitly consented to.
For users in the European Economic Area (EEA) and United Kingdom, we rely on the following legal bases under Article 6 GDPR:
| Processing activity | Legal basis |
|---|---|
| Collecting and storing data you connect to the App on your device | Consent (Art. 6(1)(a)) — you grant this each time you connect a source |
| Sharing aggregated attributes with vendors | Consent (Art. 6(1)(a)) — you grant this per-transaction via the notification response flow |
| Submitting raw survey responses to a vendor endpoint | Consent (Art. 6(1)(a)) — you grant this by explicitly accepting each survey's data-use disclosure before submission |
| Operating the pseudonymous server account | Performance of contract (Art. 6(1)(b)) — necessary to provide the App |
| Responding to legal requests | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you have the right to withdraw it at any time without penalty (see Section 9).
Under the Consumer Data Right, we hold the following classes of CDR data with your explicit consent:
With your consent, we:
We do not use de-identified CDR data for general research. If we propose to do so in future, this policy will be updated describing the research and any associated benefit to you.
We notify you via in-app notification when:
We only disclose data with your explicit, per-transaction consent. The nature of what is shared depends on the type of interaction:
When a vendor creates a notification, they specify targeting conditions based on semantic attributes (e.g., income band, location, spending category). These conditions are evaluated entirely on your device — your vault data never leaves your phone for matching purposes. Neither the vendor nor our servers learn what your actual attribute values are. The vendor only learns that their notification was delivered to a pseudonymous user whose device satisfied the condition. No attribute values, no aggregated data, and no raw personal data are shared in this flow.
When you complete a vendor survey, the vendor may have configured a completion action — either a direct API submission (your device posts raw responses to the vendor's endpoint) or a website redirect (you are taken to a vendor-controlled web page, which may collect further information under that vendor's own privacy policy). Some surveys have no completion action at all. Where an API submission is configured, your response data travels directly from your device to the vendor's endpoint — it never transits our servers. This is the one context where raw data is disclosed to a third party, and it occurs only when:
Your Data requires vendors who receive survey data to comply with all applicable data protection laws, including restrictions on how long they may retain your responses and prohibitions on selling or sharing the data onward without your consent. We actively engage with vendors on your behalf to verify that these obligations are upheld.
With your explicit consent, CDR data may be disclosed to a trusted adviser (e.g., a financial adviser) under a TA disclosure consent.
With your consent, CDR insights may be shared with specified persons under an insight disclosure consent.
Our infrastructure providers (see Section 16) may be located in the United States or European Union. These providers process operational metadata only; no personal data or CDR data is retained by them.
We may disclose pseudonymous account data where required by law, court order, or regulatory authority. We will notify you of such disclosure where permitted by law.
Your Data is a consent-based data marketplace: vendors pay to reach users, and users are compensated for participating. This is intentional and is the core value proposition of the App — you are in control of and benefit from the exchange.
What we do not do is sell or share your data without your knowledge or consent. We do not take your data and monetise it behind your back, share it with data brokers, or use it for any purpose you have not explicitly agreed to. Every exchange is initiated by you, disclosed to you in advance, and compensated.
Under CCPA, users retain the right to opt out of any specific sharing transaction at any time — see Section 8.
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:
You have the right to request disclosure of: (a) the categories of personal information we have collected about you; (b) the categories of sources from which it was collected; (c) the business or commercial purpose for collecting it; and (d) the categories of third parties with whom we share it. See Section 3 above for a full breakdown.
You have the right to request a copy of the specific pieces of personal information we hold about you. Because almost all personal data is stored on your device, the most complete copy is already in your vault. For server-side data (pseudonymous account records), contact us at privacy@your-data.app.
You have the right to request deletion of personal information we hold about you. On-device vault data can be deleted directly within the App. To request deletion of your server-side pseudonymous account record, contact privacy@your-data.app.
You have the right to request correction of inaccurate personal information. Use the App's correction feature or contact us.
Your Data is a consent-based marketplace: vendors compensate you for participation in targeted offers and surveys. Each exchange requires your explicit, per-transaction consent, so the right to opt out is built into every interaction — you simply decline or do not respond. You may also withdraw a previously granted consent at any time within the App. We do not share your data with third parties for purposes beyond those you have individually consented to, and we do not sell or share data covertly or without your knowledge.
To the extent we process sensitive personal information (e.g., financial data, location, biometric-derived inferences), we do so only with your explicit consent for the stated purpose. You may withdraw that consent at any time.
We will not discriminate against you for exercising any CCPA rights — you will not receive a different level of service, be denied goods, or be charged different prices as a result.
Email privacy@your-data.app with the subject "CCPA Request" and describe your request. We will verify your identity (by matching your pseudonymous public key) and respond within 45 days, with one 45-day extension where reasonably necessary.
You may designate an authorised agent to submit a request on your behalf. We will require written proof of authorisation and may verify directly with you.
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the GDPR / UK GDPR:
You may request confirmation of whether we hold personal data about you and, if so, a copy of that data and information on how it is processed.
You may request that inaccurate personal data be corrected or incomplete data completed.
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, you withdraw consent, or there is no overriding legitimate interest to continue processing.
You may request that we restrict processing of your data in certain circumstances (e.g., while a correction request is pending).
Where processing is based on consent and carried out by automated means, you may request your personal data in a structured, machine-readable format. Since almost all data resides on your device in your encrypted vault, you already have direct access to it. To request a copy of any server-side records we hold, contact privacy@your-data.app.
You may object to processing based on our legitimate interests. We rely on legitimate interests only for operating the pseudonymous server account; you may object at any time and we will stop processing unless we can demonstrate compelling grounds.
We do not make decisions with significant legal or similarly significant effects on you solely by automated means.
Where we rely on consent, you may withdraw it at any time through the App or by contacting us. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
You have the right to lodge a complaint with your local supervisory authority. In the EU, find your authority at edpb.europa.eu. In the UK, contact the Information Commissioner's Office (ICO) at ico.org.uk.
Email privacy@your-data.app with the subject "GDPR Request" and describe your request. We will respond within 30 days (extendable by a further two months for complex requests — we will notify you if an extension is needed).
Given the privacy-by-design architecture of the App — where no identifiable personal data is held server-side — we are not required to appoint a formal DPO. Privacy matters are handled by our Privacy Lead at privacy@your-data.app.
CDR data and raw personal data are not stored outside Australia — they remain on your device. Server-side pseudonymous account data is hosted on Google Cloud Platform infrastructure in the Asia-Pacific region.
Where our cloud infrastructure providers operate in the United States or European Union, we ensure appropriate safeguards are in place (Standard Contractual Clauses for EEA transfers; equivalent protections for other jurisdictions). No identifiable personal data is transferred.
If we propose to transfer CDR data outside Australia in future, we will update this policy and specify the destination countries.
| Data type | Retention period | Deletion trigger |
|---|---|---|
| On-device personal data (vault) | Until you delete it | User action in-App or account deletion |
| Pseudonymous server account record | Until you request deletion | Account deletion request (in-App) |
| Server interaction logs | Not retained | N/A — not written to disk |
| Vendor notification interaction flags | 90 days after interaction | Automatic expiry |
| Aggregated portfolio metadata | Active account lifetime | Account deletion request |
When your account is deleted, all server-side pseudonymous records are permanently removed within 30 days.
We implement the following technical and organisational measures to protect your data:
In the event of a data breach affecting your rights or interests, we will notify you and the relevant regulatory authority within the timeframes required by applicable law (72 hours under GDPR; as soon as practicable under the Notifiable Data Breach Scheme).
The App may request access to the following device features. All permissions are optional unless noted, and you can revoke them at any time in your device settings:
Revoking a permission may limit certain app features but does not affect your existing data vault.
We notify you via in-app alert when:
We do not currently have CDR representatives. If we engage representatives, we will list them here.
All OSPs are contractually bound to our data handling requirements, including deletion and de-identification policies.
We have no sponsorship arrangements with other accredited persons. If this changes, we will update this policy.
We will post any material changes to this policy on this page and update the "Last Updated" date at the top. For significant changes (e.g., new categories of data collected or new third-party sharing), we will notify you via in-app notification at least 14 days before the change takes effect. Continued use of the App after that date constitutes acceptance of the revised policy.
For privacy inquiries, data requests, or to exercise your rights under any applicable law: