Legal

Legal and privacy

Back to sign in

Last updated October 6, 2026.

In short

  • Your money data is kept on the server that runs this copy of Okay, and goes only to the services you turn on. No ads, no tracking, and nothing is sold.
  • Okay reads from your bank and other services. It never moves money, pays bills, or trades.
  • It helps you see your numbers. It is not financial, tax, or legal advice.
  • Team names and colors are only there for decoration. No team or league is involved.
PrivacyTerms of useNot financial adviceTrademarksOpen-source software

Privacy

Okay is a personal finance app. Each copy runs on one server, set up by the person who uses it (the owner), who can invite up to two other people to share the same money. There is no company in the middle that sees your data. “Okay” below means this copy and the person who runs it.

What Okay keeps

  • What you type: spending, income, bills, goals, limits, reminders, notes, and plans.
  • A hosted account: the email and password hash of the person who starts a ledger. Each account is its own ledger. The private copy and the public sample do not offer that signup.
  • About you, if you fill it in: name, birth date, address, filing status, dependents, and your Social Security number. The number is encrypted and only ever shown as its last four digits.
  • Pictures you snap of receipts and bank screens, encrypted on the server. A paystub picture is read and thrown away: only the numbers you confirm are kept.
  • From what you connect: account names, balances, transactions, and holdings.
  • Sign-in records: when, which kind of device, and its network address, so you can see your devices and sign them out. The last 2,000 security events are kept, and only the owner sees them.
  • People the owner invites: their name, email, and sign-in. A password is only ever stored as a one-way hash. Authenticator seeds are encrypted.

Where it goes, and only when you turn that on

  • Plaid. Okay uses Plaid Inc. (“Plaid”) to gather your data from your bank. By connecting a bank, you grant Okay and Plaid the right, power, and authority to act on your behalf to access and send your personal and financial information from your bank. You also agree to that information being transferred, stored, and processed by Plaid under the Plaid End User Privacy Policy. Okay receives your account, balance, and transaction data. Disconnecting in Okay also tells Plaid to stop.
  • Stripe, to read a shop you connect. If you add a Stripe key in Settings, it is read-only. Okay reads balances, payouts, fees, and holdings. Card numbers stay at Stripe.
  • Stripe, to pay for bank sync. On a hosted copy that sells bank sync, Stripe receives the email you sign in with and charges the card. Okay keeps Stripe’s customer and subscription ids, whether the plan is paid, and the date it runs through. The card number stays at Stripe. The private copy and the public sample do not sell bank sync.
  • Crypto prices. If you type crypto you hold, Okay asks Coinbase’s public price service for the price of its symbol, like BTC, and nothing else.
  • Reading pictures and writing short notes. A vision model reads your pictures, and a small text model turns your own numbers into short notes. Both run in Ollama on this machine or the home network. Okay will not send them to an address on the public internet.
  • An assistant, on the owner’s own copy only: Josie’s API can read and change the ledger, and the memory service (Honcho) gets short summaries of what you log. Honcho’s address has to be on this machine or the home network. The public sample has neither.
  • Notifications pass through your phone’s or browser’s push service (Google, Apple, Mozilla, or Microsoft). They are encrypted, so the push service cannot read them.
  • Backups stay on the same server: by default, database copies for 14 days and the last 2 picture archives. Keys inside them stay encrypted.

Sharing the ledger

Everyone on a ledger sees the same money: entries, bills, goals, accounts, the plan, and the tax profile. Each person has their own password, authenticator, and signed-in devices. Keys, bank connections, fingerprint sign-in, invitations, the sign-in log, and the Social Security number stay with the owner. The owner can remove someone at any time, and that signs them out everywhere.

What Okay never does

No advertising, no analytics or tracking, and no selling, renting, or trading your information. Okay sets no third-party cookies. When you open Plaid’s window to connect a bank, that window follows Plaid’s own policy.

Cookies

Three cookies, all needed for the app to work: one keeps you signed in, one remembers which page you were headed to before signing in (for 15 minutes), and one keeps your theme on this device. One item in your browser remembers if you said “not now” to installing the app.

Your choices

  • Download everything as a spreadsheet from More → Download.
  • Delete any entry, bill, or goal. A picture goes with the last entry made from it. Disconnect a bank at More → Connect your bank. Remove keys in Settings → Connections, and your Social Security number in Settings → About you.
  • The owner can remove someone from the ledger at Settings → Someone else, and can remove everything by deleting the database, pictures, and backups on the server.

The public sample

If you are using the public sample, the numbers are made up. Anything typed there can be seen by the next visitor. It is erased the next day, or sooner when someone taps Refill. The sample does not call the assistant’s API or the assistant’s memory, and it does not connect a real bank. Do not put real information in the sample.

Changes and questions

If this page changes, the date at the top changes. Questions about privacy go to the person who runs this copy of Okay.

Terms of use

  • For your own money. Okay is for keeping track of your own finances.
  • As is. Okay is provided as is, without warranty of any kind, express or implied. Its numbers can be wrong: a bank feed can be late, a picture can be misread, and a rule can file something in the wrong place. Check anything important against your bank or the source.
  • It only reads. Okay cannot move money, pay bills, or trade. Connections use read-only access.
  • Your sign-in is yours to keep safe. Keep your password, authenticator, and signed-in devices to yourself, and sign out a device you lose (Settings → Security).
  • Bank sync is a monthly plan, only where this copy sells it. It is $7.99 a month and renews every month until you cancel. The price and how to cancel are shown before you pay, and you have to check a box. You cancel on Settings → Bank sync. Sync keeps running through the month you already paid for, and you are not charged again after that. The private copy includes bank sync. The public sample never connects a real bank.
  • Other services have their own terms. Plaid, Stripe, Coinbase, and your bank each have terms of their own, and those apply when you use them through Okay.
  • Limits. As far as the law allows, the people who make and run Okay are not liable for any loss or damage from using it. That includes fees, overdrafts, tax penalties, and decisions made from what it shows.

Not financial advice

Okay helps you see your own numbers. It is not a bank, a financial adviser, a tax preparer, or a lawyer, and nothing in it is financial, investment, tax, or legal advice.

  • Tax figures are estimates from 2026 federal and state rules and can be wrong for your situation. For taxes, the IRS (irs.gov) and your state have the final word.
  • Tips about bills, credit, debt, saving, and investing are general. They do not know everything about you.
  • Short notes on pages are written by a computer model from your own numbers. They can be wrong.

Before a big decision, talk to a qualified professional.

Trademarks

Team names, league names, and colors appear only so you can choose the app’s colors. Okay is not affiliated with, endorsed by, or sponsored by Major League Baseball, the National Football League, the National Basketball Association, the National Hockey League, Major League Soccer, the Women’s National Basketball Association, or any of their teams. Okay uses no team or league logos.

Team and league names, and the names of products and services Okay works with, such as Plaid, Chime, Stripe, Coinbase, DoorDash, Uber Eats, and Ollama, are trademarks of their owners. They are used only to name what Okay works with.

Open-source software

Okay runs on Node.js and Astro and 259 open-source packages in all. Each keeps its own license. The full license texts are in the third-party notices.

MIT211

@astrojs/compiler-binding, @astrojs/compiler-binding-linux-x64-gnu, @astrojs/compiler-binding-linux-x64-musl, @astrojs/compiler-rs, @astrojs/internal-helpers, @astrojs/markdown-satteri, @astrojs/node, @astrojs/prism, @astrojs/telemetry, @babel/helper-string-parser, @babel/helper-validator-identifier, @babel/parser, @babel/types, @bruits/satteri-linux-x64-gnu, @capsizecss/unpack, @clack/core, @clack/prompts, @esbuild/linux-x64, @img/colour, @ioredis/commands, @jridgewell/sourcemap-codec, @oslojs/encoding, @oxc-project/types, @rolldown/binding-linux-x64-gnu, @rolldown/binding-linux-x64-musl, @rolldown/pluginutils, @shikijs/core, @shikijs/engine-javascript, @shikijs/engine-oniguruma, @shikijs/langs, @shikijs/primitive, @shikijs/themes, @shikijs/types, @shikijs/vscode-textmate, @types/estree, @types/estree-jsx, @types/hast, @types/mdast, @types/nlcst, @types/node, @types/unist, am-i-vibing, ansi-regex, ansi-styles, astro, bail, camelcase, ccount, character-entities-html4, character-entities-legacy, chokidar, ci-info, clsx, color-convert, color-name, comma-separated-tokens, commander, cookie, cookie-es, crossws, css-tree, csso, debug, decamelize, defu, depd, dequal, destr, devalue, devlop, dijkstrajs, dom-serializer, dset, ee-first, emoji-regex, encodeurl, es-module-lexer, esbuild, escape-html, etag, eventemitter3, extend, fast-string-truncated-width, fast-string-width, fast-wrap-ansi, fdir, find-proc, find-up, flattie, fontace, fontkitten, fresh, get-tsconfig, h3, hast-util-to-html, hast-util-whitespace, html-escaper, html-void-elements, http-errors, ioredis, iron-webcrypto, is-docker, is-fullwidth-code-point, is-plain-obj, jsonc-parser, locate-path, magic-string, magicast, mdast-util-to-hast, micromark-util-character, micromark-util-encode, micromark-util-sanitize-uri, micromark-util-symbol, micromark-util-types, mime-db, mime-types, mrmime, ms, nanoid, neotraverse, nlcst-to-string, node-fetch-native, node-mock-http, normalize-path, obug, ofetch, ohash, on-finished, oniguruma-parser, oniguruma-to-es, p-limit, p-locate, p-queue, p-timeout, p-try, package-manager-detector, path-exists, pg, pg-cloudflare, pg-connection-string, pg-pool, pg-protocol, pg-types, pgpass, picomatch, pngjs, postcss, postgres-array, postgres-bytea, postgres-date, postgres-interval, prismjs, process-ancestry, property-information, qrcode, radix3, range-parser, readdirp, redis-errors, redis-parser, regex, regex-recursion, regex-utilities, require-directory, resolve-pkg-maps, retext-smartypants, rolldown, satteri, send, shiki, sisteransi, space-separated-tokens, standard-as-callback, statuses, string-width, stringify-entities, strip-ansi, svgo, tiny-inflate, tinyclip, tinyexec, tinyglobby, toidentifier, trim-lines, trough, tsx, ufo, ultrahtml, uncrypto, undici, undici-types, unified, unifont, unist-util-is, unist-util-position, unist-util-stringify-position, unist-util-visit, unist-util-visit-parents, unstorage, verkit, vfile, vfile-message, vite, vitefu, wrap-ansi, xtend, xxhash-wasm, yargs, yocto-queue, zod, zwitch

ISC20

@ungap/structured-clone, anymatch, boolbase, cliui, get-caller-file, github-slugger, inherits, pg-int8, piccolore, picocolors, require-main-filename, semver, server-destroy, set-blocking, setprototypeof, split2, which-module, y18n, yaml, yargs-parser

Apache-2.08

@img/sharp-linux-x64, @img/sharp-linuxmusl-x64, aria-query, axobject-query, cluster-key-slot, denque, detect-libc, sharp

BSD-2-Clause8

css-select, css-what, domelementtype, domhandler, domutils, entities, http-cache-semantics, nth-check

BlueOak-1.0.03

common-ancestor-path, lru-cache, sax

BSD-3-Clause3

diff, smol-toml, source-map-js

MPL-2.03

lightningcss, lightningcss-linux-x64-gnu, lightningcss-linux-x64-musl

LGPL-3.0-or-later2

@img/sharp-libvips-linux-x64, @img/sharp-libvips-linuxmusl-x64

CC0-1.01

mdn-data

The server image also includes Node.js (MIT), Tesseract OCR (Apache-2.0), and Alpine Linux packages, each under its own license. The models that read pictures and write notes run separately, under their own licenses. The sign-in picture, the app icons, and the icons on every page were made for Okay.

Okay © 2026 its authors. All rights reserved.