Where your data lives

Your FamSpend data is hosted on Supabase Cloud (managed PostgreSQL) in the EU. No bank balances, no current accounts — only the expenses you chose to plan. Here's what's there and where.

Updated on Apr 25, 20264 min readPrivacy & security

Your FamSpend data is your data: it belongs to you, it's exportable, and we host it in the simplest, most standard way possible. No cloud magic, no esoteric architectures — a PostgreSQL database on a managed EU provider.

What's in your data

DataExampleSensitive?
Account emailyou@example.comMedium
Signup nameFirst and last nameLow
Password (hashed)bcrypt hash, not recoverableHigh, but protected
WorkspaceWorkspace nameLow
Cost CentersNames, icons, colorsLow
Planned expensesTitle, amount, due date, CenterMedium
Paid expenses+ payment date, final amountMedium
Associated peopleNames (and email if member)Low/medium
App usage historyWhen you logged in, from what IPMedium

What's NOT there (deliberately)

Where they are hosted physically

All providers are GDPR-compliant and have signed standard DPAs with FamSpend.

Data transmission: HTTPS always

All traffic between your browser/app and our servers goes only over HTTPS (TLS 1.3). No HTTP fallback. No clear-text data on public networks.

If you're on an open public Wi-Fi, viewing FamSpend is safe.

Who can see what

WhoSees what
YouAll your data, always
Members of your workspaceAll shared workspace data, per their role (see Roles)
Other FamSpend users (in other workspaces)Nothing. Zero access to your data.
FamSpend teamOnly metadata strictly necessary for support and debugging — and only after your explicit support request
Subprocessors (Supabase, Vercel, Resend)Data strictly necessary for their service. None of them resells your data

Backup and disaster recovery

Backups are encrypted, not accessible to third parties.

Data export (portability)

To request a full workspace export (expenses, income, Centers, people, payment history) write to privacy@famspend.io. We'll respond within 72 hours with the file. A self-service "Export data" function in settings is on the roadmap.

Account deletion

From Settings → Delete account:

From that moment your data on FamSpend no longer exists.

GDPR compliance

FamSpend respects GDPR rights:

Technical security

On the roadmap: optional 2FA, active session management, annual external pen-test.

Known limits / things we DON'T do

Privacy contacts

For any GDPR request, doubt, or concern: privacy@famspend.io. A person answers, not a bot, within 72 business hours.

Related articles

Useful actions