Back to home

Privacy Policy

Last updated: 24 August 2026

Introduction

Steady Finance Limited (we, us, our) complies with the New Zealand Privacy Act 2020 when dealing with personal information. Personal information is information about an identifiable individual.

This policy sets out how we collect, use, disclose, and protect your personal information when you use Steady. It does not limit or exclude your rights under the Privacy Act. For more information about the Act, see privacy.org.nz.

Changes to this policy

We may change this policy by posting an updated version at steady.nz/legal/privacy. The change applies from the date the updated policy is posted.

What we collect, and why

We collect personal information from you when you sign up, connect a bank account, use the app, or contact us. We also receive information from Akahu (your bank account data) and from Stripe (subscription billing data).

Specifically, we collect:

  • Account information — name, email, authentication identifier (via Clerk).
  • Bank account data via Akahu — account names, balances, transaction history (merchant, amount, date, description). Read-only. We never see your bank password.
  • Payment information — handled by Stripe on the web, and by Apple or Google when you subscribe inside the app. We never store your card numbers. Stripe gives us a customer reference and subscription status; for in-app purchases RevenueCat tells us the same two things after checking the receipt with the store.
  • App usage data — goals, budgets, settings, AI conversation history (where you have asked Steady questions).
  • Optional analytics — anonymised page views and product interactions, only if you accept the analytics cookie banner.
  • Push notification token — if you turn on notifications in the iOS or Android app, a device token so we can send them. It identifies the device, not you, and you can revoke it in your phone's settings.
  • Error and crash reports via Sentry — only technical context (stack traces, user agent), with a scrub pass that strips probable names and account-number-shaped strings before sending.

We use this information to:

  • provide the Steady service to you;
  • bill you for paid subscriptions and process refunds when applicable;
  • respond to your questions, support requests, and feedback;
  • send transactional emails (e.g. payment failures, weekly summaries you have opted into);
  • improve the Service through anonymised, aggregated usage analysis;
  • detect and prevent fraud, security issues, and abuse of the Service;
  • comply with our legal obligations (e.g. tax records, regulatory enquiries).

Who we share with

We do not sell your personal information. We share it only with the providers we need to run the Service:

  • Akahu (NZ) — open-banking platform that connects to your bank with your consent. Akahu has its own privacy policy at akahu.nz.
  • Clerk (US) — authentication provider. Stores your email + sign-in identifiers.
  • Stripe (US) — payment processor for subscriptions bought on steady.nz. Handles card data; we never see it.
  • RevenueCat (US) — subscription infrastructure for purchases made inside the iOS and Android apps. Apple and Google take those payments, not RevenueCat and not us; RevenueCat checks the receipt with the store and tells Steady whether your subscription is active and when it renews. It receives your Steady account identifier, the plan you bought and the store you bought it from. It never receives your bank data, your transactions, your balances, or your card details.
  • Anthropic (US) — provides the Claude AI used for Ask, weekly summaries, and categorisation. When you use those features we send Anthropic relevant financial context (recent transactions, balances, goals) but never your name, email, or bank account numbers. Anthropic does not train its models on this API data.
  • Google (US) — provides the Gemini API we use to generate the decorative photo on your savings goal cards. When you create or edit a goal, we send Google the goal name you typed (e.g. “Japan 2027”) and nothing else — no balances, transactions, or other financial data, and never your name, email, or bank account numbers. Goal names are free text, so avoid putting information in a goal name you would not want sent to Google. Google's API terms state paid API data is not used to train their models.
  • Supabase (US/EU regions) — managed Postgres database where your Steady data lives.
  • Railway (US) — hosts the Steady application servers.
  • Cloudflare (US) — DNS and edge caching for steady.nz.
  • Sentry (US) — error tracking. Receives stack traces, scrubbed of probable names and account-number-shaped strings.
  • PostHog (US) — product analytics. Only receives data if you accept the analytics cookie banner.
  • Resend (US) — transactional email provider. Receives your email address and email content.
  • Upstash (US) — Redis cache for rate limiting and short-lived state. Stores hashed identifiers only, no raw personal information.

We may also disclose personal information when required by law (e.g. a regulator request or court order), to enforce our Terms, or in the event of a sale or merger of our business — in which case we will require the recipient to treat your data on terms at least as protective as this policy.

Storing data outside New Zealand

Some of our providers (Stripe, Clerk, Anthropic, Google, Supabase, Cloudflare, Sentry, PostHog, Resend, Upstash) store and process data in the United States or other jurisdictions outside New Zealand.

Information Privacy Principle 12 of the Privacy Act 2020 lets us do that only where we reasonably believe the provider is required to protect your information in a way that, overall, provides comparable safeguards to the Privacy Act. That is the basis we rely on for every provider named above — through the binding privacy commitments in their own terms and through the data-processing agreements we hold with them. We do not rely on you simply having agreed to it, because agreement is a weaker basis and you should not have to accept a lower standard to use Steady.

How we protect your information

Steady uses standard industry security practices:

  • HTTPS / TLS for all network traffic.
  • AES-256-GCM encryption at rest for sensitive tokens (e.g. Akahu access tokens).
  • Role-based access controls — production access is limited to the named individuals who need it to run the Service, and is reviewed whenever that list changes.
  • Sentry-side scrubbing rules to strip probable PII from error reports before they leave our servers.
  • Rate limiting and abuse detection on authentication and API endpoints.

If a privacy breach has caused, or is likely to cause, serious harm, the Privacy Act 2020 requires us to notify you and the Office of the Privacy Commissioner as soon as practicable after we become aware of it. The Privacy Commissioner's stated expectation is within 72 hours, and that is the standard we hold ourselves to.

Your rights

You have the right under the Privacy Act 2020 to:

  • Access your personal information that we hold. Settings > Export Data lets you download your data immediately. For a more comprehensive export, email [email protected].
  • Correct your personal information if it is inaccurate. Most fields are editable from inside the app; for anything else, email us.
  • Delete your account and the data we hold for you. Settings > Delete Account cancels any active Stripe subscription, revokes Akahu bank connections, deletes your Clerk authentication account, and removes your Data from our live systems straight away. Backups age out within 90 days. Two small things are kept on purpose — see “How long we keep your information” below.
  • Withdraw consent for analytics or AI features at any time, by changing your preferences in Settings or by clearing the analytics cookie.
  • Complain to the Office of the Privacy Commissioner if you think we have mishandled your information. Contact details at privacy.org.nz.

We may charge a reasonable cost for fulfilling unusually large or repeated information requests, but only as permitted by the Privacy Act.

Cookies & analytics

Steady uses strictly necessary cookies that are required to keep you signed in and to remember your preferences. These are always on.

We also use anonymous product analytics via PostHog (pageviews, button clicks, scroll depth — no financial data or personal information). PostHog runs by default under our legitimate interest in improving the product (NZ Privacy Act 2020 IPP 1, 10). You can click “Opt out” on the cookie banner at any time to stop all analytics; the banner reappears if you clear browser storage for steady.nz. Session recording is OFF by default and only enabled if you explicitly accept it on the banner.

If you're in the EU or UK: under GDPR / UK PECR, we ask for explicit opt-in for any non-essential cookies before they're set. Email [email protected] if you believe an EU/UK visit didn't prompt the banner and we'll investigate.

How long we keep your information

We keep your personal information for as long as you have an account with us, plus the period required by law (e.g. Stripe records of transactions, NZ tax-record retention). When you delete your account, your Data is removed from our live database immediately and ages out of encrypted backups within 90 days. Anonymised and aggregated information may be kept indefinitely.

Two things deliberately outlive account deletion:

  • Records the law makes us keep — principally Stripe payment records, for NZ tax purposes.
  • An unsubscribe record. If you have asked us to stop emailing you, we keep your email address on a suppression list. We do this because the alternative is worse: if deleting your account also erased the record of your unsubscribe, signing up to a waitlist again — or us importing a list you were once on — would start the emails again, and your decision would have been quietly undone. The record holds your email address, the date, and the reason. Nothing else. It is used only to prevent email, never to send it. Ask us and we will remove it too, but then we can no longer guarantee we will not email that address in future.

Using Steady on your phone

This policy covers the Steady iOS and Android apps as well as steady.nz. The apps handle your information the same way the website does — they are the same service in a native shell.

What the app asks your phone for:

  • Notifications — only if you turn them on. We store a device token so we can deliver them. Turning notifications off in your phone's settings stops this.
  • Haptics — the small taps you feel on a button. No data leaves your phone.

What the app never asks for:

  • Your location. We read the country your connection appears to come from, purely to decide which cookie banner to show you, and we do not store it or attach it to your account.
  • Your contacts, photos, camera, microphone, or files.
  • Any advertising identifier. Steady does not advertise.

Apple and Google each publish a summary of what an app collects — the App Store privacy label and the Play Store Data Safety section. Ours are built from this policy, and we update the two together. If you ever spot a difference between them, email us and we will fix it.

Children

Steady is intended for adults (18+). We do not knowingly collect information from children under 18. If you believe a child has signed up for Steady, email us and we will delete the account.

Contact us

For privacy questions, requests for access or correction, or to make a complaint, email [email protected].

This Privacy Policy is adapted from the Kindrik Partners (Simmonds Stewart) free Privacy Policy template (V2.1, 2022) and tailored to Steady's data flows. It is not a substitute for individualised legal advice.