Unowe.

Privacy & Terms

How Unowe handles your data, and the terms you agree to by using it. In short: your financial figures never leave your device, and this is an educational tool rather than financial advice.

1 · Privacy Policy

Unowe is built to keep your financial information private. Here is exactly what happens to your data.

What stays on your device

Everything you enter — income, expenses, loans, savings, monthly logs and your plan — is stored only in your own browser, encrypted with a key derived from your password using AES-256-GCM. It is never transmitted to or stored on our servers. We cannot read it, and neither can anyone who gains access to the server.

Importing a bank or card statement

You can import a statement (CSV or PDF) to help fill in your loans. The file is read and parsed entirely inside your browser — the PDF reader runs in a same-origin worker with no network access. The raw statement and your individual transactions never leave your device and are discarded once parsing finishes; only the summary figures it detects (recurring EMI-like debits) are kept, and only once you choose to add them, stored with the same on-device encryption as everything else. Nothing about the statement is uploaded anywhere.

What the server holds

Authentication is handled by Supabase Auth. The only things stored server-side are your email address, a one-way hash of your password, an optional display name, and a row recording whether you have paid — the minimum needed to let you log in and unlock the app. No financial data is ever sent there.

Emails we send

If your email is confirmed, the app sends one reminder email per month nudging you to log your progress — nothing else. Every email has an unsubscribe link.

Data you carry yourself

Your exported report PDF, JSON backup and CSV each contain a copy of your plan data so you can move it between devices. Treat those files like a bank statement — anyone who has one can read it. Keep them safe.

Third parties

  • Supabase — authentication and your paid/unpaid status only (email, password hash, optional display name).
  • Razorpay — processes the one-time payment on their own checkout; see Pricing below.
  • Cloudflare Pages — hosts the static site and may keep standard, anonymised edge access logs.
  • mfapi.in — a free public API for mutual-fund NAVs, queried only if you add a fund to the Market tab. The request carries that fund's public scheme code and nothing else — no account, no figures, no identifiers. Add no funds and it is never contacted. The rest of the app works fully without it.

Apart from the optional NAV lookup above, the app makes no outbound request to anyone but its own server and Supabase. It loads no third-party fonts, scripts, analytics, or trackers — typefaces are served from our own domain, and there are no cookies beyond the login session. We do not advertise, profile you, or sell or share your data with anyone. There are no ads. The public calculator pages (EMI, prepay-vs-invest, tax regime, credit-card payoff) need no login and run entirely in your browser — they store and send nothing.

Your control

You can erase your on-device data at any time from Settings → Delete on-device data & sign out, change your password, or issue a fresh recovery key. Because your plan data is local, clearing your browser storage erases it — keep a PDF or JSON backup first (the app prompts you before every logout).

2 · Security

Security is treated as a first-class feature, not an afterthought.

  • Encryption at rest — on-device data is sealed with AES-256-GCM under a key derived from your password with PBKDF2; the server never sees the key or the data.
  • Transport — the site is served only over HTTPS, with HSTS enforced so browsers refuse to connect insecurely.
  • Strict Content-Security-Policy — scripts and styles load only from our own domain ('self'), with no inline-script execution surface and no unsafe-inline or unsafe-eval anywhere. Framing, plugins and cross-origin form posts are blocked, and outbound connections are limited to our own domain and Supabase.
  • Almost no third-party calls — fonts are self-hosted and there is no analytics or tracking SDK, so your visit isn't shared with anyone. The single optional exception is the mutual-fund NAV lookup described above, which sends no personal data.
  • Account passwords — must meet a minimum length and are stored only as a salted one-way hash by Supabase.
  • Least privilege — database access is governed by row-level security so an account can read only its own entitlement row, and never any other user's data.

No system is perfectly secure, and you remain responsible for protecting your own password, recovery key, and exported files. If you believe you've found a vulnerability, please report it privately (see Contact) rather than disclosing it publicly.

3 · What the tool does

So that the terms below are read against what the software actually is, here is the current feature set. Everything listed runs in your browser on figures you enter.

  • Plan — your income, expenses, loans and emergency fund, simulated month by month into a debt-payoff waterfall using an avalanche (highest rate first) or snowball (smallest balance first) strategy, with prepayment lock-ins and penalties respected.
  • Progress — a monthly log of what you actually prepaid and invested, compared against what the plan asked for that month.
  • Invest — your post-debt asset allocation and the return assumptions that drive the projection.
  • Market — benchmark rates (repo, PPF, NSC, FD, CPI) for context, plus an optional live NAV check on funds you choose to track.
  • Prepay vs invest — the after-tax return an investment must beat for investing to win over prepaying, including the Section 24b cap.
  • Tax regime — old versus new regime compared on your salary and deductions.
  • Net worth, Life cover and Goals — assets minus liabilities, an indicative cover requirement, and goal feasibility.
  • Statement import — optional CSV or PDF import that flags recurring EMI-like debits for you to confirm.
  • Exports — a PDF report, JSON backup and CSV. The PDF and JSON also restore your plan on another device.
  • Account — change password, regenerate your recovery key, or erase your on-device data.

Unowe requires a modern browser with JavaScript and local storage enabled. Because your plan is held in that browser's storage, it does not sync between devices or browsers — moving it is done by exporting a file and importing it on the other device. Private/incognito windows discard storage when closed. The public calculators work without an account; the planner requires one.

4 · Terms of Use

Educational tool — not financial advice

Unowe is an educational planning and calculation tool. It is not a registered investment adviser, is not SEBI- or IRDAI-registered, and does not provide personalised financial, investment, tax, insurance, or legal advice. The life-cover, goal, prepayment, tax-regime and net-worth figures are illustrative calculations on the numbers and assumptions you enter. Nothing in the app is a recommendation to buy, sell, prepay, or hold any financial product, insurance policy, or investment.

Accuracy & assumptions

Projections are estimates based on the numbers you enter and general assumptions (on-time EMIs, monthly deployment of surplus, illustrative long-term return rates). Real outcomes vary. Interest rates, prepayment charges, lock-ins and tax rules change — always verify against your loan sanction letter, your bank, and current regulations, and consider consulting a qualified, fee-only professional before large decisions.

No warranty · limitation of liability

The tool is provided "as is," without warranties of any kind. To the maximum extent permitted by law, we are not liable for any loss or damage arising from your use of the tool or reliance on its outputs. You are solely responsible for your financial decisions.

Acceptable use

Use the tool for your own lawful, personal financial planning. Don't attempt to attack, disrupt, or misuse the service or other users' access.

5 · Pricing & Refunds

One-time access fee: ₹199 (INR, inclusive of any applicable taxes). Paying once unlocks Unowe for your account permanently — all current features and future updates. There is no subscription and no recurring charge. Demo mode remains free, and the public calculators are free and need no account.

Payments are processed by Razorpay (UPI, cards, netbanking, wallets) on Razorpay's PCI-DSS-compliant checkout. Unowe never sees or stores your card or bank details — we receive only a payment confirmation reference tied to your account.

Refund policy: if Unowe doesn't work for you, email us within 7 days of payment for a full, no-questions-asked refund to your original payment method (processed via Razorpay, typically 5–7 business days). After a refund, the account returns to unpaid status. To request one, contact the operator email below using the address you registered with.

6 · Contact

Questions about privacy, security, or these terms? Reach the operator of this deployment at the email associated with the project. This tool is operated independently and is not affiliated with Supabase, Cloudflare, Razorpay, or any financial institution mentioned.