Privacy Policy
The safest record is the one nobody is holding.
In short
We hold what you typed in, so we can show it back to you. Nobody else reads it, we do not sell it, and there is no advertising anywhere near it. You can take a complete copy out at any moment, and deleting your household really removes it.
01
What we collect
- Your account
- Name, email address, password (stored only as a hash), and your display preferences — date format, number format, timezone. If you turn on two-factor, the secret for it, encrypted.
- What you type
- Accounts and balances, transactions with their dates, amounts, payees, categories and notes, budgets and targets, loans and their schedules, wishlist items, and the ratings you give past purchases. This is the substance of it, and all of it was typed by you or by somebody in your household.
- Your household
- Who is in it, what role they hold, who invited them and when. Invitations record the email address they were sent to.
- Billing
- Which plan you are on, what was invoiced, and whether it was paid. Card details are handled by the payment provider and never reach us — see below.
- Operational records
- Sign-in times, IP address and browser for active sessions so you can see and revoke them, and an audit log of changes made inside a shared household so a member can see who did what.
02
What we deliberately do not collect
This is the more useful list, because a record that was never collected is the only kind that cannot leak.
- Bank credentials
- None, ever. There is no aggregator, no net-banking login, no read-access authorisation. Transactions are typed in. That is slower, and it is the reason an attacker who got everything we hold still could not move a rupee.
- Card numbers
- Payments go to a payment gateway. Card details are entered on their surface, not ours, and nothing sensitive lands here.
- Your SMS or notifications
- Many Indian budgeting apps read bank SMS to populate themselves. We do not, and there is no app permission to grant, because there is no mobile app doing it.
- Advertising and behavioural trackers
- No ad network, no pixels, no third-party scripts profiling you across the web. You are the customer, so there is nothing to sell.
- Your contacts, location or device identifiers
- None of these are collected, because none of them are needed.
03
Why we hold it
To run the service you are paying for, and for nothing else. Concretely: to show you your own figures, to do the arithmetic on them, to let the other people in your household see the same books, to bill you, to email you about your subscription and your account, and to keep the whole thing secure.
We do not use your financial data to build a profile of you, we do not use it to train anything, and we do not pool it into a dataset about households in general.
04
Who else sees it
Nobody outside your household reads your books. Not us in the ordinary course of running the service — support does not browse your transactions, and the operator console that exists for support deliberately cannot reach a household’s financial records at all. If diagnosing something ever needs a look at your data, we will ask you first.
A small number of companies process data on our behalf to make the service work. They are bound to use it only for that:
- Hosting
- DigitalOcean, in its Bangalore (BLR1) data centre in India — the servers and the database.
- Email delivery
- Zoho ZeptoMail, on its India data centre — carries password resets, billing notices and invitations. The message body includes your name and what the notice is about.
- Payments
- Razorpay Software Private Limited, Bengaluru — receives your card details directly and your billing contact. They never receive your financial records.
We will also disclose data if the law genuinely requires it. If that ever happens, we will tell you unless we are forbidden from doing so.
05
Where it is kept, and for how long
Your data stays in India. Everything you enter — accounts, transactions, budgets, loans — is stored on servers in Bangalore, and it is not stored or processed anywhere else. The companies above that handle data for us do so in India too. The one way it crosses a border is the way you would expect: if you open Ahead while travelling abroad, your own device receives your data wherever you are.
It is encrypted in transit, on every connection. The database sits on encrypted storage, and backups are encrypted before they are copied off the server, and are kept in India as well.
We keep your household’s data for as long as the household exists. Delete it and the records go — not marked deleted, actually removed, along with the accounts, transactions, budgets, loans, memberships and invitations attached to it.
Two things survive that, and only these two: invoices, because tax law requires a business to keep its records of what it charged, and anonymised operational logs, which carry no household data. Backups roll off on their own schedule — thirty days — after which the deletion is complete everywhere.
06
Your rights
Under the Digital Personal Data Protection Act, 2023 you can ask us for a copy of your personal data, ask us to correct it, ask us to erase it, and complain if you think we have handled it badly. You can also nominate someone to exercise those rights if you cannot.
Two of those you do not need to ask for — export and deletion are buttons in the app, and they work immediately. For anything else, write to [email protected] and we will answer within three working days.
We will not charge you for exercising a right, and we will not make the product worse for you because you did.
07
Getting it out, and getting rid of it
Export lives in Settings → Security and hands you a complete archive of your household’s data in open formats. It is never refused — including while an account is locked for non-payment, and including on the day you are leaving.
Delete this household is on the same screen, and it is a real delete rather than a deactivation. It asks you to confirm because it cannot be undone. Take the export first.
09
How it is protected
- Tenancy in the database
- Every record carries the household it belongs to, and that scope is applied at the data layer rather than remembered by each screen — so a query written next year is scoped whether or not the person writing it thought about it.
- Encryption
- Every connection is encrypted. The database is on encrypted storage and backups are encrypted before they leave the server. Your records are not encrypted field by field inside the database — the app has to add up your budget, and no budgeting service that does that on its servers can — which is why who can reach the database matters as much as how it is stored.
- Two-factor authentication
- Available on any account, with recovery codes. Mandatory for our own operators.
- Passwords
- Stored only as a modern hash. We cannot read yours, and neither can anyone who takes the database.
- Sessions you can see
- Every active sign-in is listed with its device and last use, and any of them can be revoked.
- An audit trail
- Changes inside a shared household are recorded with who made them, so a member can check rather than trust.
No system is perfectly secure. If we ever discover a breach affecting your data, we will tell you and the Data Protection Board as the law requires, with what we know and what we are doing about it — promptly, and without waiting until the story is comfortable.
10
Children
Ahead is for adults. Accounts are not knowingly created for anyone under 18, and we do not knowingly collect a child’s personal data. If you believe a child has an account, write to us and we will remove it.
A children’s financial-literacy mode is planned and does not exist yet. If and when it ships, it will be a parent-controlled area inside an adult’s household, and this policy will be updated before it does — not afterwards.
11
Changes, and how to complain
We will update this page when what we do changes, and email you first when the change is material. This version is dated 22 September 2026.
Our grievance officer under the DPDP Act is [email protected], at [ registered address ]. If you are not satisfied with our answer you may complain to the Data Protection Board of India. The contact page has every route in one place.