Privacy policy
Last updated 20 September 2026
Headroom is a budgeting tool for people aged 15 to 30 in Australia. This policy says what we collect, why, where it is kept and what you can do about it. We follow the Australian Privacy Principles as our standard.
There is a shorter version of this page written for younger readers: privacy in plain English.
What we collect
Things you tell us
- Your email address, so you can sign in and we can send you a code.
- Your age range: either 15 to 17, or 18 and over. We never ask for or store your date of birth.
- Your time zone, so a fortnight starts on the right day.
- A display name, if you give one.
- Your budget: income and expense lines, pay cycle, goals and trims.
Your money data
- Transactions you add by hand, or import from a file you export from your own bank. We do not connect to your bank, and we never ask for your banking password.
- The accounts you set up in the app: a name, the institution, the kind of account and, if you enter one, a balance.
- Categories, rules and the column mapping the app learned for each of your files.
Bank files are read in your browser. Only the tidied rows are sent to us: the date, the amount and the description. Before a description is stored we strip out BSBs, account and card numbers, phone numbers and email addresses, because those usually belong to somebody else. The file itself is never uploaded.
How you use the app
We keep a short log of what you did, from a fixed list of actions such as “imported a file” or “saved a goal”, with the date. These entries never hold amounts, merchant names or anything you typed. They are the only usage measurement we have: there are no third-party analytics, no advertising tools and no tracking pixels anywhere in the app.
We also keep a security log of a few account-level events, such as an account being deleted. Your identity in that log is stored as a one-way hash, so the entry cannot be traced back to you.
What we never do
- We never sell or share your data with anyone for money.
- We never show advertising.
- We never load scripts, fonts or trackers from other companies. The app forbids it.
- We do not build a profile of you for anybody else.
Where it is kept
Your data is stored in Australia, in Sydney, with Supabase, who host the database for us. The app itself runs on Vercel. Sign-in emails are sent by our email provider and contain a six-digit code and nothing else.
Access is limited to the person who runs Headroom. Every table in the database is locked so that one account can only ever read its own rows, and that rule is tested automatically before any change ships.
How long we keep it
We keep your data until you delete it. When you delete your account, every row we hold about you goes immediately, and it drops out of our backups within 30 days. The only thing left is the dated security-log line saying an account was deleted, which cannot be linked back to you.
Your choices
- Get a copy. Settings, then Export your data. You get spreadsheet files holding everything: your details, your transactions, your budget, your goals and trims, and your accounts.
- Delete everything. Settings, then Delete your account. It takes effect straight away.
- Fix something. You can edit or remove anything in the app yourself. If something is wrong and you cannot change it, write to us.
- Sign out everywhere. Settings, then Sign out everywhere, if you left yourself signed in on a device you no longer have.
Exporting or deleting asks for a fresh code by email first, so somebody who finds your phone or a shared computer still signed in cannot take your data or close your account.
If you are under 18
You can use Headroom from age 15. Under 18, the app does not offer bank connections at all: files and manual entry only. We treat everyone the same way regardless of age, because we do not advertise to anyone or sell anyone’s data.
If you would rather a parent or carer helped you set this up, that is fine, but the account is yours and only you can sign in to it.
If something goes wrong
If we ever have a data breach that is likely to cause you serious harm, we will tell you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Questions or complaints
Write to us and we will answer within 30 days. If you are not happy with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
If we change this policy we will update the date at the top, and we will tell you in the app before anything that affects you takes effect.