Legal
Privacy Policy
What we collect, who processes it on our behalf, how long we keep it, and how to get it deleted.
- Effective
- 8 September 2026
- Version
- 2026-09-08
1. Who is responsible for your data
Performant LLC, a limited liability company registered in Texas, with its mailing address at 5900 Balcones Drive, Suite 100, Austin, TX 78731, USA, is the data controller for the personal data described here. You can reach us about anything on this page at development-team@performant.pro.
2. What we collect
- Account data. Your email address and a securely hashed password. We never store your password in a readable form.
- Consent record. The date and document version at which you accepted these terms, so we can show what you agreed to.
- Billing data. Opening a billing page creates a customer record at Stripe holding your email address, even if you never subscribe. If you do subscribe, Stripe collects and stores your payment details. We do not see or store your card number. Your invoices and subscription status stay with Stripe and we read them from Stripe each time you open a billing page; the only billing identifier we keep ourselves is the subscription reference.
- Content you create. Whatever you put into the applications you use. Your Venova financial records are encrypted on your device before they reach us. Section 4 explains what that does and does not cover.
- Support correspondence. Tickets and messages you send us, and our replies. A ticket also records which app version and platform you reported from and, only if you choose to attach it, a trail of the screens you visited and actions you took. Our staff can add private notes to a ticket.
- Game statistics. If you play a game on the site, your scores and streaks for that game.
- Technical data. Timestamps, error reports and request records, kept for security and debugging. Our own logs identify subscriptions and accounts rather than you personally; your IP address and browser user agent are recorded by Cloudflare as part of serving the request.
3. Why we use it, and our legal basis
- To provide the Service by creating your account, authenticating you, storing your content, and running the features you use. Basis: performance of our contract with you.
- To take payment by processing subscriptions and handling cancellations and refunds. Basis: performance of our contract, and our legal obligation to keep financial records.
- To keep the Service secure by detecting abuse, debugging faults, and preventing unauthorised access. Basis: our legitimate interest in a secure service.
- To communicate with you through confirmation emails, password resets, and service notices. Basis: performance of our contract.
We do not sell your personal data, we do not share it with advertisers, and we do not use your content to train machine-learning models.
4. How your Venova data is encrypted
Your Venova financial data is encrypted on your device before it is sent to us, and we hold it only as ciphertext. Your password never reaches our servers in a form they can use to open it. There are two protection levels, and they differ in one respect: whether we also hold a copy of the key.
Recoverable protection is where every household starts. Alongside your own copy of the key we keep a sealed copy that only our servers can open. It exists so we can restore your access if you forget your password, and that is the only thing we use it for. It does mean we are technically capable of decrypting your financial data, and that a valid legal order could compel us to. That is a capability, not a routine: nothing in the Service reads your financial data in normal operation.
Advanced protection is available to every household, free, from Venova's security settings. Turning it on destroys our copy of the key. From then on we cannot read your financial data, cannot disclose it if we are compelled to try, and cannot restore it. Recovery depends entirely on the one-time recovery code you are given when you switch.
Encryption covers the contents of your financial records. It does not cover the information we need in order to run the Service around them: your email address, which household you belong to, when you last saved a change, and how large the encrypted record is. Those stay visible to us at both protection levels.
5. Who processes data on our behalf
We use a small number of sub-processors. Each handles data only on our instructions and under a data processing agreement.
- Supabase provides authentication, database, and transactional email (confirmations, password resets).
- Stripe handles payment processing and subscription billing.
- Cloudflare gives us application hosting, file storage, and network protection.
Connecting a bank or brokerage account to Venova would add Plaid to this list. That feature is not enabled, no data reaches Plaid today, and we will update this policy before it does.
Some of these providers operate outside your country. Where personal data is transferred internationally we rely on the safeguards those providers offer, including standard contractual clauses.
6. Cookies
We set only the cookies needed to run the Service. These hold your login session, are marked HttpOnly so scripts on the page cannot read them, and expire when the session ends or is refreshed. We do not use advertising or third-party tracking cookies, so there is no consent banner to dismiss.
7. How long we keep it
- Account and content data stays until you delete your account, and is then removed as described in section 8.
- Saved versions of your Venova data. Venova keeps a short history of your document so you can roll back a mistake. Everything from the last day is kept, thinning to one version a day for a month, and a small number of the most recent versions is always retained. They carry the same encryption as the document itself.
- Billing records are retained after account deletion for as long as tax and accounting law requires, typically several years. Invoices and receipts also keep the email address they were issued to, because tax records cannot be altered.
- Billing account at Stripe. Opening a billing page creates a customer record at Stripe holding your email address, even if you never subscribe. When you close your account we clear your email address, name and billing address from that record. The record itself remains, carrying an internal reference with no name or address attached, so that the closure stays auditable.
- Support tickets. A ticket closes after two weeks without activity, and its contents are destroyed a month after it closes, leaving a record that a ticket was raised and closed. Anything untouched for six months is closed and cleared the same way. You can clear a ticket yourself at any time.
- Account closure records. When an account is deleted we keep a record of the closure itself, so we can show it completed and finish cancelling anything attached to it. Identifiable detail is stripped after thirty days; the record itself is erased after six months.
- Backups. Disaster-recovery backups are taken daily and kept on a rolling seven-day cycle, then overwritten. Deleted data can persist in a backup until that cycle completes.
8. Deleting your account
You can delete your account yourself from your account settings. Doing so cancels every subscription attached to it before anything is destroyed, so you are not charged again, and then erases your data. Removing a single application's data works the same way for that application's subscription.
Deletion is permanent and we cannot undo it. Some records outlive it. Billing history is kept because tax law requires it. Your customer record at Stripe is emptied of your details but not deleted. A cleared shell of each support ticket remains, holding the reference and the dates but none of the words. The closure record described in section 7 is kept for six months. Deleted data may also remain in a disaster-recovery backup until that backup ages out.
If you delete Venova's data from within Venova rather than closing your whole account, the saved version history described in section 7 is not cleared with it. Closing your account does clear it. If you want everything gone, close the account.
9. Your rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you, and receive a copy of it.
- Correct data that is inaccurate or incomplete.
- Delete your data. You can do most of that yourself from account settings.
- Object to or restrict processing we carry out on the basis of legitimate interest.
- Withdraw consent where we relied on it, without affecting past processing.
- Complain to your local data protection authority.
To exercise any of these, email development-team@performant.pro. We respond within one month.
10. Children
The Service is not intended for children under 16. We do not knowingly collect their personal data, and we delete it if we learn we have.
11. Changes
If we change this policy materially we will notify you by email or in the application before the change takes effect, and the version identifier at the top of this page will change.