Reference

Privacy & data

Practical expectations for guest vs signed-in data.

Where data lives
ModeWhere data livesWhat leaves the device
Signed-inYour user row in the TrackIt API / DBAuth token, API calls, Agent prompts/tools
GuestBrowser session mock (sample seed)Nothing of your bank CSVs (you have not uploaded)
Signed-in API storage vs guest browser session mock.
Isolation

Your user

Accounts · transactions · rules

Another user

Separate scope · not visible to you

Signed-in users never see each other's accounts or rules.

Self-host operators: see the GitHub README for environment and deployment. Product docs stay at /docs; Swagger at /api/docs.