Privacy Policy

Version 1.10.0 — effective 4 August 2026

1. About this policy

This Privacy Policy explains how Stead collects, uses, discloses, and otherwise handles your personal information. It applies whenever you access or use the Stead application — including signing in, recording transactions, setting budgets, and receiving emails from us.

This policy is governed by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It was last updated on 4 August 2026 and applies from that date.

Please read this policy carefully. By using the Service, you acknowledge that you have read and understood it.

2. Who we are

Stead is operated by Daniel Gamble (sole trader), ABN 15 639 096 880. We are the entity responsible for the personal information we collect and hold about you.

For privacy enquiries, contact us at: support@steadapp.com.au

3. What information we collect and why

We collect personal information that is necessary to provide the Service. We collect it directly from you when you use the application.

Account and identity

  • Email address — account identification and communication
  • Display name — personalisation and partner-facing features
  • Avatar selection — in-app personalisation (pixel-art character choice)
  • Password (stored as a bcrypt hash, cost 12 — the plaintext is never retained)
  • Password reset tokens (SHA-256 hashed, single-use, expire after 1 hour)
  • Email verification tokens (SHA-256 hashed, expire after 1 hour)

Financial data

  • Transactions — amount (stored as integer cents in AUD), date, category, description, type (income / expense / transfer), ownership (personal / partner / shared), privacy flag
  • Budget allocations by category and month
  • Savings goals — target amount, target date, contributions and progress
  • Quick-saves — micro-saving entries and streak history
  • Recurring financial rules — amount, frequency, category, start date
  • Account balances — account name, type (savings, offset, investment, property, loan) and balance; you enter these manually — we do not connect to your bank
  • Partner linking — if you link to a partner account, we record the bidirectional user ID association

Usage and technical data

  • Session tokens — JSON Web Tokens stored in httpOnly cookies, valid for 24 hours
  • Authentication logs — login timestamps and outcomes
  • Rate-limit counters — a SHA-256 hash of your IP address (not the raw IP) used solely for rate limiting on authentication endpoints; not stored in our database
  • Error and crash data — error messages, stack traces, request metadata, and browser/device info collected by Sentry when the application encounters an error
  • Product-analytics data — which pages you visit and which features you use (for example completing onboarding, creating a goal, or making a quick-save), collected by PostHog so we can understand how the app is used and improve it. Events are tied to a dedicated, random analytics identifier that is separate from your account id and contain no personal information — no name, email, transaction details, or amounts. Page addresses are stripped of any identifiers before they are recorded. This is used only to improve the product; it is never sold or used for advertising, and you can turn it off at any time (see “Your rights” below).
  • Your analytics choice — when you switch product analytics on or off, we record the fact and the time of that change against the same random analytics identifier. This is a record of your choice, not of anything you did in the app, and it is kept even when you have analytics switched off: it is how we can show that we honoured your decision, and it stops a deliberate opt-out from looking like an account that simply went quiet. It contains nothing but the direction of the change — on or off.
  • Visits to our public pages — if, and only if, you agree when we ask. Our home page and the pages describing Stead are readable by anyone, without an account. We would like to know which of them help and which do not, so we ask before recording anything at all. Until you answer, and if you answer no, nothing is loaded, requested or stored, and no visit is recorded. If you say yes, we record the same limited things as above — which pages, no personal information — and nothing more.
  • Linking a public visit to an account — only if you agreed above. If you accepted analytics on our public pages and later create an account, the visit that brought you here can be joined to that account’s random analytics identifier. This is how we can tell how many people who read about Stead went on to sign up — a question we cannot otherwise answer. It never happens for someone who declined or was never asked, and what is joined is still only the pages viewed, never anything personal.
  • A plain count of public-page visits — kept whatever you answer, because there is nothing in it about you. For each of our public pages we keep a daily total of how many times it was opened, and one word for roughly how people arrived: from a search engine, from social media, from another of our own pages, directly, or from somewhere else. So the whole record is a date, the page, one of those five words, and a number. No identifier, no IP address, no device information, nothing stored on your device, and no way to work back to a person from it.
  • Which site you came from is not recorded. The five-way sorting happens inside your own browser and only the resulting word is sent, so the address of the page you arrived from never reaches us at all. That distinction matters: a referring address can itself identify someone — a private forum thread, an employer’s internal site — whereas a word shared by everyone who arrived the same way cannot. We keep this because it tells us how many people a page reached, rather than only how many of those who agreed to analytics reached it; the second number on its own would badly understate the first. It is the one thing we collect on the public site that asking permission for would be meaningless, since there is no personal information in it to permit or refuse.

Launch waitlist

  • Email address — if you join our launch waitlist before self-service sign-up opens, we collect your email address. We use it for three things and nothing else: to send you a single notification when your group can join; to recognise that address when you come to create your account, because your place is held against your email address rather than an invitation code; and to keep a record that the account was opened from a waitlist place. We also record the country your request came from and which page you joined from, together with the date you joined and the version of this policy you were shown — so that we can apply the right email rules to you, see which pages bring people in, and show what you agreed to. We store the email address encrypted, exactly as we store account email addresses. The lawful basis is your express consent, given when you submit the form; you can withdraw it and have the entry erased at any time (see “How long we keep your information” and “Your rights” below). We do not require you to create an account to be on the waitlist.

We do not collect: government-issued ID numbers, health data, biometric data, criminal history, or payment card details. We do not connect to your bank or financial institution.

4. How we use your information

We use your personal information only for the purposes for which it was collected:

  • Service delivery — creating and maintaining your account, authenticating you securely, storing and displaying your transactions, budgets, goals, and accounts, enabling partner-linked features (shared transactions, settlements).
  • Engagement and gamification — awarding badges, tracking savings streaks, enabling quick-save challenges, and delivering the weekly digest email to encourage consistent savings behaviour.
  • Email communications — we group email into four kinds, and you control three of them at any time under Settings → Notifications, or via the unsubscribe link in any email:
    • Account and security — password resets, email verification, account deletion notices, and changes to partner linking. These are necessary to operate your account and cannot be turned off.
    • Your weekly review — a summary of your own activity, sent on Sundays. We only send it once you have activated your account and logged something, and we pause it automatically if you go quiet.
    • Nudges and milestones — occasional prompts and celebrations tied to your goals, streaks and badges.
    • Product news and offers — updates about Stead itself. These are off unless you switch them on.
    We record when you change these settings, and the basis on which each email was sent, so we can honour your choices and show that we did. We never sell your information or share it with advertisers.
  • Error monitoring and reliability — detecting and diagnosing application errors and crashes so we can fix them promptly.
  • Security and fraud prevention — enforcing rate limits, detecting unusual access patterns, and protecting accounts from unauthorised access.
  • Legal compliance — meeting our own legal obligations (such as tax and corporate record-keeping over our business records) and responding to lawful requests from authorities.

We do not sell your personal information to third parties. We do not use your financial data for advertising or profiling.

5. Sharing your information with third-party processors

We use the following third-party service providers to operate the Service. Each acts as a data processor on our behalf, handling your information only as instructed and for the purpose stated.

Neon — Database hosting

Hosts the PostgreSQL database that stores all your account, transaction, budget, goal, and settings data. Region: Australia (Sydney).

neon.tech/privacy

Vercel — Application hosting and deployment

Hosts and serves the Next.js application, including server-side rendering, serverless API functions, and Edge Runtime middleware. Processes all requests you make to the app. Region: United States (and edge locations globally).

vercel.com/legal/privacy-policy

Sentry — Error monitoring and performance tracing

Captures error reports, stack traces, and performance traces when the application encounters an issue. May include request metadata and browser/device information. Sensitive fields (passwords, tokens) are scrubbed before transmission. Region: European Union. Data retained for 90 days, then automatically purged.

sentry.io/privacy

PostHog — Product analytics

Records anonymised, privacy-first usage analytics (pages visited, features used) so we can understand how the app is used and improve it. Events are keyed to a dedicated random analytics identifier — never your name, email, transactions, or amounts — and page addresses are stripped of identifiers before recording. Not used for advertising and never sold. On our public pages nothing runs until you agree; inside the app you can opt out at any time in Settings → Privacy. “Do Not Track” and Global Privacy Control are honoured automatically everywhere. Region: European Union.

Analytics requests are sent to our own subdomain (e.steadapp.com.au) rather than directly to PostHog, so that privacy/ad-blocking tools do not silently drop them. This is a transport arrangement only — it collects nothing extra, and your opt-out and “Do Not Track” choices still stop analytics entirely before anything is sent. In transit these requests pass through Cloudflare (PostHog’s content-delivery network) before reaching PostHog in the European Union — see the Cloudflare entry below.

On our public pages the same is true before you decide: PostHog is not loaded until you accept, so reading those pages puts nothing on your device and sends nothing to PostHog. This page is not measured at all — our policy pages are outside the public pages we count. You do not need an account to make or change that choice; the answer is remembered on your device for six months, after which we ask again.

When analytics is switched off, we do not load PostHog in your browser at all — nothing is requested from it and nothing is stored by it. Two things are still recorded, and neither is about you: the record of the switch itself (described under “What we collect” above — if you turn analytics off, we note that you did, and when), and, on our public pages only, the anonymous page tally described there, which adds one to a daily count and a five-way sorting of how people arrived. Neither carries any information about anything you did in the app, and the tally holds nothing that could be traced to a person.

posthog.com/privacy

Resend — Email delivery

Delivers every email we send you — account and security messages, your weekly review, and any nudges or product news you have switched on. Processes your email address and the content of outbound messages. Region: United States.

resend.com/privacy

Upstash — Distributed rate limiting (Redis)

Stores rate-limit counters used to protect authentication and mutation endpoints from abuse. Counters are keyed by a SHA-256 hash of the requester's IP address — the raw IP is never stored. Counters expire automatically (short TTL, typically seconds to minutes). Region: Asia-Pacific (ap-southeast).

upstash.com/privacy

Cloudflare — Encrypted database backups + analytics transit

Backups (R2): stores encrypted nightly snapshots of the database for disaster-recovery purposes. Backups are encrypted at rest. Retained for 30 days on a rolling basis, then automatically deleted. Region: Oceania (as configured).

Analytics transit: our analytics subdomain (e.steadapp.com.au) is served over Cloudflare’s global edge network, which forwards analytics requests on to PostHog in the European Union. Cloudflare is a transit provider here only — it carries the requests, does not store the analytics data, and the events contain no personal information (see PostHog above).

cloudflare.com/privacypolicy

Google — OAuth sign-in (optional)

If you choose to sign in with Google, your authentication is handled by Google OAuth. Google will share your email address and profile name with us to create or identify your account. We do not receive your Google password. Region: global. This is optional — you may sign in with email and password instead.

policies.google.com/privacy

We do not share your personal information with any other third parties except as required by law or with your explicit consent.

6. Cross-border data transfers

Your primary data is stored in Australia: the database (Neon, Sydney), the nightly database backups (Cloudflare R2, Oceania region), and rate-limiting data (Upstash, Asia-Pacific) are all hosted in-region. Some ancillary services are processed overseas: application compute (Vercel) may run in global edge locations, error monitoring (Sentry) and product analytics (PostHog) are in the European Union, and email delivery (Resend) is in the United States. Analytics requests reach PostHog via Cloudflare’s global edge network (transit only; no analytics data is stored there). As a result, some of your personal information — minimised where possible — is transferred to and processed in countries outside Australia.

These countries may not have privacy laws that provide the same level of protection as Australian law. We take reasonable steps to ensure that our overseas processors handle your information in a manner consistent with the Australian Privacy Principles by:

  • Selecting processors that maintain robust privacy and security programmes
  • Reviewing processor privacy policies before engagement
  • Limiting the scope of data shared to what is strictly necessary for the service

By using Stead, you consent to the transfer of your personal information to these countries for the purposes described in this policy.

7. How long we keep your information

We retain your information for as long as necessary to provide the Service and meet our legal obligations:

  • Financial records (transactions, budgets, goals) — retained while your account is open. Records you delete in the app are purged once they are more than 7 years old (your account’s data-retention window). When you delete your account, your financial records are permanently deleted together with it after the 30-day restore window — we do not retain them afterwards, in line with APP 11’s requirement to destroy personal information we no longer need. If you need records for tax purposes, export your data before deleting your account — the ATO expects you to keep your own records (generally for at least 5 years).
  • Account PII (email, display name, password hash) — retained while your account is active. Upon account deletion, PII is removed within 30 days by an automated deletion job. You have a 30-day restore window before deletion is permanent.
  • Launch waitlist entries (email address) — if you never create an account, we delete your entry automatically 12 months after the later of the day you joined and the day we invited you. We restart that clock at invitation because your place is held against your email address: deleting the entry sooner would quietly withdraw an invitation we had already sent you. If you do create an account, we keep the entry as the record that your account was opened from a waitlist place, and it is deleted together with your account (above). You can withdraw your consent and have the entry erased at any time — by contacting us, or using the unsubscribe link once we have emailed you (see “Your rights” below). Deleting the entry is the erasure.
  • Session tokens — 24 hours from issuance, then invalidated automatically.
  • Password reset tokens — 1 hour from issuance, or immediately upon use (whichever is sooner). Single-use only.
  • Email verification tokens — 1 hour from issuance.
  • Audit logs — 2 years, then deleted.
  • Error monitoring data (Sentry) — 90 days, then automatically purged by Sentry.
  • Product-analytics data (PostHog) — retained for up to 12 months, then deleted. It is anonymised (keyed to a dedicated analytics identifier, never your account details) and you can opt out at any time.
  • Database backup files (Cloudflare R2) — 30 days rolling. Each backup is automatically deleted when replaced by one older than 30 days.

8. Your rights

Under the Australian Privacy Principles (APP 12 and APP 13), you have the following rights:

  • Access (APP 12) — request a copy of the personal information we hold about you. You can download a full export of your data at Settings → Data → Export (available in JSON and CSV formats). You may also contact us directly.
  • Correction (APP 13) — request that we correct personal information that is inaccurate, out of date, incomplete, or misleading. You can update your display name and other profile details at Settings → Profile. For corrections we cannot automate, contact us.
  • Deletion — request deletion of your account and all associated data. You can initiate this at Settings → Account → Delete Account. There is a 30-day restore window during which you can cancel the deletion. After 30 days, your PII is permanently deleted by an automated job.
  • Withdrawal of consent — you may withdraw consent to optional processing at any time via Settings. This includes turning off product analytics at Settings → Privacy (we also honour your browser's “Do Not Track” signal). If you are on our launch waitlist and do not yet have an account, you can withdraw at any time — without logging in — by contacting us, or using the unsubscribe link once we have emailed you; doing so erases your waitlist entry. If we have already offered you a place, this also gives that place up: your email address is what lets you create an account, so once the entry is erased you will not be able to sign up with it. You are welcome to join the waitlist again. Withdrawal does not affect processing carried out before you withdrew consent.
  • Complaint — if you believe we have mishandled your personal information, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

To exercise any of the above rights, contact us at support@steadapp.com.au. We will respond within 30 days. We will not charge a fee for reasonable access requests.

9. Security

We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure:

  • Passwords — hashed with bcrypt at cost 12. Plaintext passwords are never stored or logged.
  • Encryption in transit — all data is transmitted over HTTPS (TLS 1.2 or higher) between your browser and our servers.
  • Field-level encryption — your email address and display name are encrypted with AES-256-GCM at the application layer before they are written to the database. The encryption keys are held separately from the database, so a leaked database snapshot does not by itself reveal them. Note that the running application holds the keys, so this is not zero-knowledge encryption — we can access your data to operate the service.
  • Encryption at rest — the database (Neon, Sydney) and the nightly backups (Cloudflare R2) are encrypted at rest at the storage layer.
  • Session management — authentication cookies are httpOnly, SameSite=Lax, and expire after 24 hours. They are inaccessible to JavaScript running in the browser.
  • Access control — our API routes are designed to validate your session before returning data and to scope data to your user ID, and we test for this. What a linked partner can see is under your control: accounts are shared only if you opt in, and transactions and goals can be marked private. The one exception is Quick Save entries, which have no private setting — a linked partner can always see them.
  • Rate limiting — authentication and mutation endpoints are rate-limited using Upstash Redis to prevent brute-force attacks.
  • Tokens — password reset and email verification tokens are SHA-256 hashed before storage and are single-use with short expiry windows.
  • Content Security Policy — a strict CSP is enforced on all pages to mitigate cross-site scripting and injection attacks.

Despite these measures, no system is entirely secure. Section 10 explains what happens if a breach does occur, and how to report a compromised account or a security vulnerability to us.

10. Data breaches

Despite the measures described above, no system is entirely secure. If a data breach occurs — meaning your personal information is accessed or disclosed without authorisation, or is lost — we have a plan for it, and this section tells you what to expect from us.

When we will notify you

We will notify you if a breach affects your personal information and is likely to result in serious harm to you. We will also notify the Office of the Australian Information Commissioner (OAIC) in those circumstances, in line with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).

Because Stead holds financial information, we start from the presumption that the following are serious. We will notify you if any of them occurs, unless we can positively establish that we stopped the harm before it could reach you:

  • Your financial data is exposed — transactions, amounts, balances, income, or savings goals. Your spending history says a great deal about you, and we treat its exposure as serious by default.
  • Your private transactions become visible to your partner — anything you marked as private was seen by the person you share a budget with. We treat this as seriously as an external breach, because for many people it matters more.
  • Your identifying details are exposed in readable form — your email address or display name, in circumstances where our encryption did not protect them (for example, if our application or its hosting environment were compromised, or the encryption keys were exposed).
  • Your login credentials are exposed — your password hash, an active session, or a password-reset link.

If we are genuinely unsure whether a breach is serious enough to require notification, we will notify you anyway. We would rather tell you about something that turns out to be minor than leave you uninformed about something that was not.

How quickly we will tell you

We aim to notify you and the OAIC within 72 hours of becoming aware of a breach. Australian law requires notification as soon as practicable, and allows up to 30 days to assess a breach we only suspect. We have committed to a fixed 72 hours — modelled on the deadline European law sets for notifying a regulator — because “as soon as practicable” is a standard rather than a deadline, and the harm from a breach grows while you are unaware of it.

If we cannot establish every detail within 72 hours, we will still tell you what we know by then and update you as we learn more, rather than delaying the notification until the picture is complete.

What we will tell you

We will contact you by email at the address associated with your account. That notification will describe what happened and when we discovered it, exactly which information was involved, what could realistically happen as a result, what we have done and will do about it, and what we recommend you do to protect yourself. If we cannot reach you by email, we will publish a notice on our website and in the app.

If one of our third-party processors (listed in section 5) suffers a breach affecting your information, we treat it as a breach of ours and the same commitments apply, timed from the point at which they tell us.

Reporting something to us

If you believe your account has been compromised, or you have found a security vulnerability, please tell us immediately at support@steadapp.com.au. We read every report we receive. If you report a vulnerability to us in good faith — without accessing, altering, or downloading other people’s data, without degrading the service for others, and without testing our suppliers’ systems — we will not take legal action against you. We cannot waive the rights of our third-party providers, or the operation of the criminal law.

If you are unhappy with how we have handled a breach, you can complain to the OAIC — their full contact details are in section 13.

11. Children

Stead is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we become aware that a person under 18 has created an account, we will delete their account and all associated data within 30 days.

If you believe a minor has provided us with personal information, please contact us at support@steadapp.com.au.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable law. When we make changes, we will update the effective date at the top of this page.

For material changes — those that significantly affect your rights or how we handle your data — we will notify you by email to the address associated with your account prior to the changes taking effect, giving you at least 14 days' notice where reasonably practicable.

Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the updated terms. If you do not agree to the changes, you may request account deletion before they take effect.

13. Contact us and complaints

For any questions about this Privacy Policy, to exercise your privacy rights, or to report a concern, contact us:

Email: support@steadapp.com.au

Entity: Daniel Gamble (sole trader), ABN 15 639 096 880

We aim to respond to all privacy enquiries within 30 days.

If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

Stead Privacy Policy — Version 1.10.0 — effective 4 August 2026

Related: Terms of Service · Cookie Policy