1. What we use, and what we do not
Smart Money stores things in your browser for three reasons only: keeping you signed in, remembering choices you made in the interface, and — if you allow it — measuring how the product is used so we can fix what is broken.
We run no advertising cookies, no cross-site trackers, no fingerprinting and no data brokers. Nothing here feeds behavioural advertising, and we do not sell or share any of it.
Almost everything below is local storage rather than a cookie, which means it is never attached to a network request — it stays on your device unless the app explicitly reads it and sends something. The two exceptions are the sign-in session and the sidebar layout, both listed as cookies.
The lists in the next two sections are generated from the application's own storage inventory, and an automated check fails our build if the app writes a key that is not declared here. That is deliberate: a cookie policy is only worth reading if it cannot quietly fall out of date.
2. Strictly necessary — always on
These cannot be switched off; without them the service does not work. They do not require consent under Quebec Law 25 s.8.1 or the equivalent ePrivacy exemption.
- Base44 / Google session — Keeps you signed in. Set by the hosting platform and Google's sign-in, not by this application. (Cookie; Session, or until you sign out)
- sm-consent — Records your cookie choices, when you made them and how, so we stop asking and can show what you decided. (Local storage; 12 months, then we ask again)
- sm-last-activity — Timestamp of your last interaction, used to sign you out after 30 minutes idle. Shared across tabs so activity in one keeps them all alive. (Local storage; Session, or until you sign out)
- sm-signed-out-idle — Marks that the last sign-out was automatic, so we can explain why rather than leaving you guessing. (Local storage; Session, or until you sign out)
- plaid_link_token, plaid_link_mode, plaid_link_types — Short-lived handles for a bank connection in progress, plus which kinds of account you chose to bring in, so the flow survives the redirect back from your bank. Not credentials — they cannot read an account on their own and expire quickly. (Local storage; Cleared when the connection finishes)
- plaid_pending_exchange — Holds a bank connection that was interrupted — if your sign-in expires while you are at your bank's website, the half-finished handover is kept here so it can be completed the moment you sign back in. Without it the connection would be left stranded at the bank with no way for us to finish or undo it. Not your bank login, and never sent anywhere but to complete that same connection. (Session storage; Cleared when the connection finishes, and when the tab closes)
- sm_applock_enabled — Whether you turned on the app lock. Kept on the device so the lock screen can appear the instant the app opens, before we can ask the server. It does not hold your PIN — the code itself is never stored on this device. (Local storage; Until you turn the lock off)
- sm_applock_unlocked — Marks that you already unlocked in this session, so a reload does not challenge you again. Session storage on purpose: closing the tab must forget it, or the lock would stop locking. (Session storage; Until the tab closes)
- sm_applock_fails, sm_applock_lockuntil — How many wrong PINs were entered in a row and until when the keypad is frozen. This is what stops a four-digit code being guessed by trying every combination, so it has to survive a reload — otherwise closing the tab would reset the count. (Local storage; Cleared on the next correct PIN)
- Service-worker cache — Stores the application's own files so it loads fast and works with a poor connection. No financial data is cached. (Cache; Until you clear site data)
3. Interface preferences
These remember choices you made yourself. Each one stores only what you set, holds nothing that identifies you, and never leaves your device — so they ride under the same exemption as the necessary set. Clearing site data resets them.
- appLanguage — Remembers Hebrew or English, and the reading direction. (Local storage; Until you clear site data)
- sm-theme — Remembers light, dark or system appearance. (Local storage; Until you clear site data)
- sidebar_state — Whether the desktop sidebar is expanded or collapsed. A cookie rather than local storage because the layout is read before the page paints. (Cookie; 7 days)
- dash_more_collapsed, planner_tools_open_v1 — Whether you left a collapsible section open or closed. (Local storage; Until you clear site data)
- dashboard_tour_v2_done, dashboard_tour_force, planner_guide_done_v1, whatsNewSeenVersion — Which walkthroughs and release notes you have already seen, so they are not shown again. (Local storage; Until you clear site data)
- trial-banner-dismissed, announcement-dismissed:*, yf_alert_dismissed, dash_banner_*_dismissed, dismissedDetectedSubs, sm-bt-dismissed, smartmoney_missing_dismissed_*, sm_setup_checklist_dismissed — Which banners, alerts and suggestions you dismissed, so they stay dismissed. These hold identifiers of the notices you closed — or, for the daily tip, the date you closed it on so it returns the next day — never amounts. (Local storage; Until you clear site data)
- smart-money-agent-mode — Whether you left Agent Mode switched on in the AI adviser, so the screen opens the way you left it. It holds only on or off — never a message, a question you asked, or any figure from your accounts. (Local storage; Until you clear site data)
- smartmoney_recurring_snoozed_* — Which "did this arrive?" prompts you set aside today, so the same question is not repeated for the rest of the day. It holds the identifier of the scheduled item and the date you set it aside — never an amount. (Local storage; Until you clear site data)
- dailyVisitLogged — The date of your last visit, so we count one visit per day instead of one per page load. The count is aggregate; the key itself never leaves your device. (Local storage; Until you clear site data)
4. Optional — off until you say yes
- Product analytics — aggregated page views, feature usage and performance timings, used to find slow or broken screens. IP addresses are truncated and no financial values are ever sent.
- Error and crash reporting — the technical details of a failure and the screen it happened on. Amounts, account numbers and email addresses are stripped before the report leaves your device.
Both stay off until you accept them in the cookie banner, and stop the moment you withdraw consent. Neither writes a storage key of its own — consent is checked at the point of sending — which is why neither appears in the lists above.
If your browser sends a Global Privacy Control signal we treat that as a refusal, never ask, and do not show the banner at all.
5. Changing your mind
Use the "Cookie settings" link in the footer of any page, or Settings › Privacy inside the app. The change applies immediately — we do not wait for a page reload.
You can also clear cookies and site data in your browser. That signs you out and resets every preference above, including your consent choice, so we will ask again.
6. Third parties that can set storage
- Google — sign-in only. Governed by policies.google.com/privacy.
- Plaid / Salt Edge — during a bank connection, inside their own window. Governed by their privacy policies.
- Google Fonts — serves the app typeface. Sets no cookie, but your IP is visible to Google when the font loads.
Questions about anything on this page: eliezereisenbach@gmail.com.