Legal Agreements & Information

Legal information and agreements related to the use of Understatement. Last updated 2026-09-25.

Contents

Definitions

Key terms used in these legal agreements and information.

Disputes

Terms of Service

By using Understatement, you agree to these terms. If you do not agree with any of these terms, you are prohibited from using Understatement.

Privacy Policy

Cookies

We use cookies for authentication, session management, and analytics.

Security and data handling policies

These policies cover Understatement and the systems used to run it. The maintainers own them.

Information security

We identify security risks through reports, code and dependency review, and operational checks. We track significant risks in private issues, decide how to reduce them based on likely impact, and follow up on the work. Our controls include application access checks, encrypted statements, and backups. We review the program at least annually and adjust it when we learn about new risks.

Access control

We give people access to application administration, infrastructure, source code, and secrets only when needed for their work, with the least privilege practical. We remove access when it is no longer needed. We review who has access and this policy at least annually and when someone's role changes.

Vulnerabilities and unsupported software

We review reported vulnerabilities and check whether production dependencies and operating systems are still supported at least quarterly. For identified vulnerabilities affecting production, we patch critical or high severity issues within 30 days and other issues within 90 days when a fix is available. If no fix is available or a deadline cannot be met, we document the reason and a mitigation in a private issue, and revisit it until resolved. We replace unsupported software or document how we will limit the resulting risk.

Data retention and deletion

Understatement keeps customer profiles, connected-bank information, and statements while needed to provide the service. We may also retain data to meet legal obligations, resolve disputes, prevent abuse, or enforce agreements; notification and activity logs may be kept indefinitely. We may delete data for profiles without an active subscription at any time. Disconnecting a bank stops new retrieval but does not delete stored data. To request deletion, email support@understatement.app. After verifying a request, we remove the person's data from the live service except what we need for the purposes above. Backups kept for recovery are not edited to remove individual users and currently have no automatic expiry, so copies may remain after live data is deleted. We review this policy at least annually.

Understatement, including all content on this website, is © 2024-2026 Micah R Ledbetter & Hannah Lindsley. All rights reserved.

Contact

support@understatement.app