Sarathy is a beta. It reads what you spend and works out what you can still do. This page is the whole of what it holds about you — there is nothing on a server that isn’t listed here.
Email address, sign-in method, and the name you asked to be called.
Supabase (authentication and the profiles table).
What arrives each month, undated running costs, dated commitments, a goal, and the currency you said your money is in.
Supabase.
Amount, merchant, date, category and how each one reached Sarathy — typed, shared, a Shortcut, an Android payment alert, or an emailed receipt. Never the message or the email itself.
Supabase.
Sentences you asked it to remember, periods you said were not normal, Worth it / Fine / Regret marks, and your answers to its notices.
Supabase.
From an emailed receipt or a payment alert: the amount, the merchant, the date, the kind of transaction, the sender's domain and the short line the amount was read from (at most 60 characters) — kept while it waits for you, and after, as the record of what you decided. Never the message or the email itself.
Supabase (the capture_candidates table).
If you connected an inbox: the address and the tokens Google issued so Sarathy can read receipts. Read-only. Removed the moment you disconnect.
Supabase; the grant itself is held by Google.
A long-lived token for an iPhone Shortcut or the Android listener, if you set one up. Revoked when you sign out.
Supabase.
Gmail — disconnect from Ledger › Sources or from your account screen. The tokens are deleted and the grant is revoked at Google; the charges already captured stay unless you remove them.
A charge — open it on Ledger and remove it. It leaves every figure.
Something you told Sarathy — Remove it on Memory.
Your whole account — during the beta, deletion is carried out by a person, not a button. Ask from your account screen and it is done, with everything above, within seven days.
Sarathy is built in Singapore. This page changes when what is stored changes, and not otherwise.