Privacy Policy
Cowrie is a personal finance tracker. This policy describes exactly what it stores, why, and what control you have over it.
Last updated 26 July 2026
The short version: everything you enter stays in Cowrie. There is no advertising, no analytics, no tracking, and your financial data is never sold or shared with anyone.
1. Who is responsible for your data
Cowrie is operated by Manidu Maneesha, who acts as the data controller for the information described here. For any question about this policy or your data, write to manidumaneeshaww@gmail.com.
2. What data is collected
Only what the service needs in order to work. There are three categories.
Account details
- Your name, used to address you in the interface and in email.
- Your email address, used to sign in and to send password resets.
- Your password, stored only as a bcrypt hash. It is never stored in a readable form, and cannot be recovered — only replaced.
- Your preferred currency, which controls how amounts are displayed.
Financial information you enter
- Accounts, their type, and their opening balances.
- Transactions: amount, date, category, account and any note you add.
- Categories and budgets you create.
- Debts you record, including the name of the person the debt is with, amounts, due dates and repayments.
- Wishlist items: what you wanted, its price, and what you decided.
This information is entered by you, is visible only to you, and is never analysed for any purpose beyond showing it back to you.
Technical information
- A session recordfor each device you sign in on, holding the sign-in time, your IP address and your browser's user-agent string. This exists so you can see and revoke your active devices in Settings.
- When you request a password reset, a single-use token and the IP address that requested it, kept for one hour.
3. What is not collected
To be explicit, Cowrie does not:
- use analytics, tracking pixels or any third-party measurement tool;
- serve advertising, or share data with advertisers;
- sell, rent or trade your data to anyone, under any circumstances;
- connect to your bank or read your real account balances;
- build a profile of you, or use your data to train any model.
5. How your data is used
Your information is used solely to provide the service:
- to authenticate you and keep you signed in;
- to display your balances, budgets, debts and reports back to you;
- to send a password reset link when you ask for one;
- to protect the service from abuse, through rate limiting.
Where data protection law such as the GDPR applies, the lawful basis for this processing is performance of a contract — you cannot be given a working account without it — and, for the abuse protections, legitimate interests in keeping the service secure.
7. How your data is protected
- Passwords are hashed with bcrypt. Even with full database access, the original passwords cannot be read.
- Session tokens are stored only as SHA-256 digests. A copy of the database cannot be used to impersonate you.
- Password reset links are single-use and expire after one hour. Completing a reset signs out every device.
- Traffic is encrypted in transit using HTTPS.
No system is perfectly secure. You are responsible for choosing a strong, unique password and keeping it private.
8. How long data is kept
- Your account data is kept until you delete your account.
- Sessions expire automatically — after 30 days if you chose to stay signed in, otherwise after one day.
- Password reset tokens expire after one hour, or as soon as they are used.
- Deleting your account permanently removes everything: accounts, transactions, categories, budgets, debts, contacts, wishlist items and sessions. This is immediate and cannot be undone.
9. Your rights
You can, at any time:
- See all your data — it is what the application displays.
- Correct it, by editing any record directly.
- Delete it, permanently, from Settings → Danger zone.
Export your data at any time from Settings → Your data — a complete JSON file, or your transactions as CSV. Take a copy before deleting your account.
Depending on where you live, you may also have the right to object to processing, to restrict it, or to complain to your local data protection authority.
10. Information about other people
The debts feature lets you record the name of a person you lent to or borrowed from. Those names are personal data about someone else. Please record only what you need — a first name is usually enough — and do not store sensitive details about anyone in the notes. You are responsible for the information you enter about other people.
11. Children
Cowrie is not directed at children under 16 and should not be used by them. If you believe a child has created an account, contact us and it will be removed.
12. Changes to this policy
If this policy changes in a way that materially affects you, the change will be announced in the application before it takes effect. The date at the top always reflects the current version.
13. Contact
Questions, requests or complaints: manidumaneeshaww@gmail.com. See also our Terms of Service.