Last updated 19 September 2026
Jay is a budgeting app you type into by hand. Everything it knows about your money is something you sat down and entered, and it stays yours. This policy explains what is stored, why, who else can see it, and what you can do about it. It should be read alongside the Terms of Service.
Jay is part of Arachnida Apps, which is the controller responsible for the data described here. For any privacy question or request, write to twc@arachnida-apps.com.
There is no bank connection, no card link, no open-banking provider, and no import of statements or transactions from any financial institution. Jay never holds, moves, or touches money, never sees an account number, a card number, or a balance you have not typed in yourself, and asks for no payment details. It is a private ledger of figures you entered — which is also, deliberately, the entire mechanism of the product.
The data above is used to provide Jay: to sign you in, to store and display what you entered, to compute your budgets from it, to send the reminders you asked for, and to keep the service running and secure. Where the GDPR or a similar law applies, the legal bases are performance of our agreement with you (running the app you asked for), our legitimate interests in operating and securing it (balanced against your rights), your consent (reminders, which you can withdraw at any time), and compliance with law. Your data is not used for profiling or for automated decisions that produce legal or similarly significant effects about you.
Nobody, unless you connect something yourself. Jay has no social features — no sharing, no household accounts, no invitations, no public profile, and no way for another user to see your figures. Budgeting for other people means naming who you spend money on; it does not give them an account, a view, or a notification. We do not sell your personal information, we do not share it for advertising, and we do not use it to train anything.
There are exactly two ways your figures can leave Jay, both off until you switch them on, and both described below: connecting an AI assistant, and subscribing a calendar to your scheduled money. Each sends data to a company Jay has no arrangement with, on that company’s terms rather than these.
Data reaches only the providers that make Jay work:
There is no email provider on that list because Jay sends no email at all — no receipts, no digests, no marketing, no “we miss you”. We may disclose data if required by law, or to protect the rights, safety, or security of Jay and its users.
Jay is free and there is nothing to buy in it. The Further reading page lists the research the app is built on and links the books to two independent booksellers. Some of those links may be affiliate links, which means that if you click one and buy something, the bookseller pays us a small commission through an affiliate network; the price you pay is the same either way. Where a link is an affiliate link it is labelled as one on the page.
What this does and does not involve, precisely:
We do not take money to recommend anything, and no book appears on that page because of a commission. Nothing you record in Jay ever affects what is listed there, because it is the same list for everyone and always will be.
Reminders are off until you switch them on, one recurring item at a time. When they are on you get at most one message a day, and only if something you opted into is coming up — four bills on the 1st is one notification, not four, because the question worth answering is how much needs to be in the account. Each is sent once and recorded as sent, so a retry cannot send it again. You can turn any of them off, or revoke notification permission in your browser, at any time.
Jay speaks the Model Context Protocol, so you can connect an AI assistant to it. This is off until you connect one. Connecting takes you through a Jay screen that names the application and where it sends its approval, and you can disconnect it at any time in Settings — which takes effect on its very next request, not whenever its access would have expired.
A connected assistant can read everything Jay holds about your money: what you have spent and on what, your budgets, your pots, what is scheduled, your categories, and the names of the people you budget for. It can also make changes — record purchases, correct them, set budgets, alter scheduled payments. Anything that changes how your budget works is refused by Jay unless the assistant has first worked out what the change does and put it in front of you. It cannot accept these policies on your behalf, delete your account, or write your reasons for saving.
Whatever it reads is received by whoever runs that assistant — not by Jay. What they keep, how long they keep it, and whether they use it to train anything is governed by their terms and their privacy policy, which you should read before connecting; Jay has no say in it and no visibility of it. Jay’s own promise not to sell, share for advertising, or train on your data covers Jay, and cannot cover them.
Jay can publish what you have scheduled — the names and amounts of recurring income and payments, and the dates they fall on — as a calendar you subscribe to from Google Calendar, Apple Calendar or anything else that reads a calendar address. It is off until you create an address for it, and it is the only part of Jay that can be read without signing in.
That is not a shortcut: a calendar app fetches the address from its own servers, with no browser and no session, so the address itself is the credential. Anyone who has it can read what you have scheduled. Treat it like a password, and if it gets out, generate a new one — the old address stops working immediately and nothing is kept. You can turn the feed off entirely at any time, on the Scheduled or Plan page.
Subscribing means your scheduled names and amounts are fetched by, and stored in, whoever runs that calendar — Google, Apple, or your employer — on their terms rather than these, and Jay has no say in what they do with it. Unlike a connected assistant, the feed carries only what is scheduled: no logged purchases, no budgets, no balances, and nothing that can write back to Jay.
Jay uses a strictly necessary session cookie, set by the Arachnida sign-in service, to keep you signed in, and — if you open the demo — a second strictly necessary cookie holding that throwaway account’s identifier. It stores one small localStorage flag remembering that you dismissed the notification prompt on this device, and registers a service worker so the app can be installed to your home screen, open offline, and receive push messages. Jay sets no advertising or analytics cookies, which is why there is no consent banner. A bookseller or affiliate network can only set a cookie on its own site, after you have chosen to click through to it.
You can try Jay without signing up. Doing so creates a throwaway account filled with invented spending, and sets one cookie holding that account’s identifier so the browser can be returned to it. No email address, name, or password is involved, because none is asked for.
The one thing your browser tells it is your timezone, which decides what “today” means for every figure on the screen. It is stored on the throwaway account and nowhere else.
A demo account and everything in it are permanently deleted after seven days, automatically, including anything you enter. That is a real deletion rather than an archive. Nothing carries over into a real account, and demo data is never merged with anyone else’s.
If you use a Feedback form in Jay, the message you write is sent to Arachnida Apps and reaches one inbox. Alongside it, and only when you send one, your browser and its version, your operating system, your screen size, and the page you were on are attached, because a report about something looking wrong cannot be acted on without them. On the demo’s feedback page this can be switched off with a checkbox before you send, and the message goes on its own. Nothing is collected from you when you are not sending feedback.
Naming someone you spend money on stores their name, and optionally how they are related to you, against your account. That is all: no contact details, no address book access, no account for them, and no way for them to be shown any of it. It is visible only to you. You are still responsible for handling other people’s information lawfully and respectfully, and a person can ask us to remove identifiable information held about them at the contact address above.
Jay is operated from the United States. If you use it from elsewhere, your data is processed in the U.S. and in any other country where the providers above operate, which may have different data-protection laws. Where required, we rely on appropriate safeguards for those transfers.
You can correct or delete anything you entered — transactions, budgets, categories, goals, recurring items, people — directly in the app, at any time, including in past periods. Jay stores no derived totals, so a correction to March corrects March and everything that followed from it.
Deleting your Arachnida Apps account erases your Jay data: the sign-in service sends Jay an authenticated deletion signal and the entire record — transactions, budgets, goals, people, reminders, push subscriptions — is removed. To get a copy of your data, or to have your Jay data deleted without deleting your Arachnida account, write to twc@arachnida-apps.com and we will do it by hand; there is no self-serve export or per-app delete yet, and this page will say so plainly until there is. Depending on where you live you may also have rights to access your data, object to or restrict processing, withdraw consent, and — in the EU or UK — complain to your data-protection supervisory authority. California residents: we do not sell or “share” personal information, and we will not treat you differently for exercising a right.
Your data is kept until you delete it or your Arachnida account is removed — except a demo account, which is deleted after seven days whether you ask or not. Every query is scoped to your own account on the server, the deletion signal from the sign-in service is cryptographically authenticated and bound to the account it names, and we aim to collect the minimum that makes the app work. No system is perfectly secure, and we cannot guarantee absolute security.
Jay is not intended for anyone under 16. Please don’t use it if you are younger.
This policy may be updated. The date at the top changes for any edit, and for a material change you will be asked to accept the revised policy before continuing to use Jay. See also the Terms of Service.