Privacy Policy
1. Who we are
Baray is a personal dashboard that brings your net worth, budget, passive income, training, and meal planning into one place. It is operated by Kiegan Scott, an individual carrying on business in Alberta, Canada as Baray ("Baray," "we," "us").
General contact: hello@baray.ca Privacy contact: privacy@baray.ca
This policy explains what personal information we collect, why, who handles it, where it is stored, how long we keep it, and what you can do about it. We are governed by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA).
2. The short version
- Baray is available only to residents of Canada outside Quebec, aged 18 or older.
- We collect financial and health information because that is what the product does. We treat both as sensitive and ask for your express, opt-in consent before collecting them.
- We never connect to your bank. We never hold banking credentials. Financial data reaches us only because you type it in or upload a file you exported yourself — and that file is read in your browser, not uploaded to us.
- We do not sell your personal information, share it with advertisers, or send it to any AI or machine-learning service.
- If you invite a partner into your household, they see the parts of your account you chose to share — and only those. Section 4.6 explains.
- Your database is in Montréal, Canada, and the application runs in Montréal. A small number of service providers we use for email are in the United States. Section 8 names each one.
- You can access, correct, export, or delete your data yourself, from Settings. Section 11 explains.
- Baray does math on numbers you enter. It does not give financial, health, training, or dietary advice, and nothing it produces is a recommendation.
3. Who can use Baray
Baray is offered only to individuals who are residents of a Canadian province or territory other than Quebec and are 18 years of age or older. You confirm both when you create an account. We do not knowingly collect personal information from anyone under 18; if you believe someone under 18 has an account, contact privacy@baray.ca and we will delete it.
Why not Quebec? Quebec's private-sector privacy law and its French-language requirements impose obligations we are not able to meet as a small operator at this stage. We may extend service to Quebec later.
Your household partner. You can invite one other adult to share parts of your account with their own login (Section 4.6). They create their own account and confirm the same eligibility for themselves.
Meal-planning household members. The meal planning feature lets you enter household members — a name or label, and their portion sizes. That information is entered by you, about your household, under your account. These entries are not users, do not have accounts, and are never contacted. If a household member is a minor, you decide what to enter; a first name or a label like "Kid 1" is all the feature needs.
Other people's information. Some things you connect can contain information about people other than you: calendar event titles often include other people's names or meeting subjects, and shared bank statements may include a partner's transactions. You are responsible for having the right to bring that information into your account.
4. What we collect, and why
4.1 Account and sign-in
| What | Why |
|---|---|
| Email address | Account creation, sign-in, service messages |
| Password — stored only as a hash; we cannot read it | Account security |
| Sign-in and session records held by our authentication provider (Supabase Auth) | Security, keeping you signed in |
| A record of which version of the Terms of Service and this policy you accepted, your eligibility confirmation, and your consent to sensitive-data collection, each with a timestamp | So we can show you have agreed, and ask again when a document changes |
| Your notification preference — whether the monthly entry reminder is on, and which day it is sent — and a record of the months we have sent it for | So the reminder goes out when you asked, and never twice for the same month |
| App preferences — theme, font, layout, which widgets are shown, your units, the time zone used to display dates and times, and internal bookkeeping such as the order of your lines | So the app looks the way you set it |
That is everything signup asks for. We do not collect your name, phone number, or address.
At signup we check where you are. Our hosting provider tells our server which country and province your signup request came from, and we refuse signups from outside Canada or from Quebec. That check happens in the moment; we do not store your IP address or the result of the check.
4.2 Financial information (sensitive — express consent)
| What | Why |
|---|---|
| Account line items you create — chequing/savings, TFSA, RRSP, pension, brokerage, crypto, property, vehicles, receivables — and liabilities — mortgages, credit cards, lines of credit, loans | To build your net worth picture |
| Monthly balance snapshots over time, and for each one how it was entered — typed, carried forward from an earlier month, pasted, or imported | The trends, charts, and projections that are the point of the product; the entry screen shows you which values were carried forward |
| Passive income entries — dividends, rental, interest | The Passive tab |
| Loan terms — balance, rate, term, payment, extra payments | Payoff and renewal calculations |
| Budget categories, rules, targets, and groups you define | The Budget product |
| Retirement inputs you choose to enter in Settings — birth year, province, expected CPP/OAS amounts, contribution figures | Retirement math |
4.3 Transaction history (sensitive — express consent)
If you import a bank statement or a Monarch Money export, or enter transactions by hand, we store each one as a row: date, amount, the merchant description exactly as your bank wrote it, a cleaned-up merchant name, the category, and any notes the file contained or you added. For imports we also store the file name of what you uploaded, so you can undo an import.
This is granular spending data, and we want to be plain about it. We store it so the Budget product can categorize, chart, and total your spending over time.
Two things worth knowing. First, the file itself is never uploaded — it is read in your browser, and only the structured rows are sent to us. Second, we never connect to your financial institution. No bank feed, no aggregator, no stored banking credentials.
4.4 Health and fitness information (sensitive — express consent)
| What | Source | Why |
|---|---|---|
| Workout history — exercises, sets, reps, weights, RPE, workout titles and any notes you wrote in Hevy | Hevy, if you connect it | Strength Lab charts, tonnage, estimated 1RM, personal records |
| Body weight by day, if you log it in Hevy | Hevy | Body-metrics trend |
| Activity data — type, distance, duration, average and maximum heart rate, calories, elevation | Garmin file you upload | Activity log, training charts, and your current training load |
| Training plans, sessions, completion status, skip reasons, notes; race dates, goal times, race location and URL | Entered by you, imported, or generated | Training tab, race calendar |
| Fitness markers you enter for the plan generator — functional threshold power (FTP), lactate-threshold heart rate, critical swim speed, easy run pace, and a recent race result | Entered by you | Setting the intensity zones in a generated plan |
| Training availability preferences — how many minutes you can train on each shift type, which shift types are rest days, which allow two sessions a day, which rotation positions or weekdays you have blocked, whether your first day off after nights is kept easy, which disciplines you can do on which shift types, and a cap on sessions per cycle | Entered by you | Fitting a generated plan to your schedule |
| Plan generation records — a snapshot of the inputs you gave the generator (event, goal, current training load, markers, availability) and a summary of the plan it produced, with the engine version | Created when you generate a plan | So you can see what a plan was built from, regenerate it, and export it |
| Your shift rotation pattern — the day/night/off cycle and its anchor date, if you use the rotation feature | Entered by you | Aligning training, meal planning, and calendar to your schedule |
Where "current training load" comes from. Before generating a plan, Baray looks at your last six weeks of completed training — sessions you marked done on your calendar and activities you imported from Garmin — and works out your recent weekly distance and time in each discipline. That figure is shown to you and used as the plan's starting point. It is computed from data you already gave us; nothing new is collected.
We keep the complete original record returned by Hevy or contained in your Garmin file alongside the fields we chart, so nothing is lost if we add features later.
4.5 Nutrition and meal planning
Foods and macros you enter, recipes (including any instructions you write), meal plans, per-day meal assignments and their computed macros, thumbs-up/down ratings, your calorie and macro targets, dietary preferences, and household member labels and portions.
4.6 Household sharing (only if you invite a partner, or accept an invitation)
Baray lets the person who created an account invite one partner to share parts of it, with their own separate login.
What we store. When you send an invitation: the email address you entered, when it was sent and when it expires, and a hashed random token that makes the invitation link work. When it is accepted: a membership record linking the two accounts and listing the shared areas. Your partner's email address is shown to you in Settings, and yours to them.
What your partner can see. Exactly the areas you chose when inviting — finance (net worth, budget, passive income, loans, retirement inputs) and/or meal planning — including everything that was there before the invitation, and the settings that belong to those areas. For finance that means your retirement and projection inputs, including the birth year and province you entered, and the budget review state; for meal planning, your meal slots, targets, training rules, household members, and solver settings. They can add, change, and export within those areas.
What your partner never sees. Your training, races, shift rotation, calendar, connected services and their credentials, your consent records, your reminder settings, and any other setting that is not part of a shared area. Each of you keeps all of that in your own account.
Whose data it is. Everything in a shared area is stored under the account holder's account, whoever entered it. When a membership ends — the partner leaves, the account holder removes them, or either account is deleted — the partner loses access, and nothing is moved or deleted.
How it is enforced. The database itself checks, on every request, whether the signed-in person is the account holder or an accepted partner for the specific area being read or written. A partner's own account cannot hold data of its own in an area they have been invited into; if it does, the invitation cannot be accepted until that data is removed.
The invitation email goes to the address you entered, through our email provider (Section 8). It shows your email address as the sender, names the areas being shared, and contains the link. It carries no figures.
4.7 Calendar information (only if you connect a calendar)
If you connect a calendar by pasting a secret iCalendar (ICS) feed URL, we fetch that feed and keep a cached copy of your upcoming events on our servers so the Today page can show them. Precisely:
- We keep event title, start time, end time, and all-day flag — nothing else. No location, description, attendees, or organizer.
- Up to 100 events, from one day ago to seven days ahead, with titles truncated at 300 characters.
- The raw calendar file is never stored — it is parsed in memory and discarded.
- Your feed URL is encrypted before it is stored (see Section 12), because we need it to refresh.
- The cache is overwritten each time it refreshes (no more often than every 30 minutes, when you visit) and deleted the moment you disconnect the calendar.
Anyone who holds your secret feed URL can read your calendar. Treat it like a password. If you think it has been exposed, reset it with your calendar provider.
4.8 Credentials and tokens
| What | Handling |
|---|---|
| Hevy API key | Encrypted at the application level before storage; used only to sync your workouts; erased when you disconnect |
| Calendar feed URL | Encrypted at the application level before storage; used only to fetch your events; erased when you disconnect |
| Household invitation token | We store only a hash of it; the token itself exists only in the invitation link; erased when the invitation is accepted or cancelled |
| Random tokens for features you turn on — Hevy webhook, your personal training-calendar feed, a shared training-plan link | Random identifiers, not encrypted (they are the credential); each can be regenerated or revoked from Settings |
4.9 Technical information
- Server logs record what happened (an error name, a table name, an HTTP status), never the contents — no balances, transactions, email addresses, keys, or calendar text. Retained by our hosting provider for a limited period.
- Marketing-page analytics. Our public marketing pages use Vercel Web Analytics, which is cookieless and collects page views and coarse visit metadata. It is not loaded on any signed-in screen.
- Nothing on signed-in screens sends analytics or telemetry anywhere. There is no error-monitoring service and no third-party tracker.
4.10 Support correspondence
If you email hello@baray.ca, support@baray.ca, or privacy@baray.ca, we keep the correspondence so we can help you.
5. How we use your information
- To provide the service — store your data, run calculations, draw charts, build plans.
- To authenticate you and keep your account secure.
- To send you the emails the service needs: sign-up confirmation, password reset, email change, and a household invitation when you send one.
- To send you a monthly reminder to enter your numbers, on the day you chose, if you leave that on. It is on by default, contains no figures from your account, and you can turn it off in Settings › Notifications.
- To respond to support requests.
- To diagnose errors and keep the app working.
- To meet legal obligations, including record-keeping and breach reporting.
We do not make automated decisions about you that have legal or similarly significant effects. Baray's outputs — projections, payoff dates, generated training plans, meal plans, adherence figures — are deterministic arithmetic applied to numbers you supplied. They are calculator outputs, not decisions about you, and not advice.
6. Consent
We collect financial and health information only with your express, opt-in consent, given when you create your account. Where a feature is optional — Hevy, Garmin, calendar, transaction import, the plan generator's markers and availability — you consent again by choosing to connect, import, or enter it.
Household sharing is consent in both directions. Inviting a partner is your consent to show them the areas you share. Accepting an invitation is your partner's consent to work in your account's shared areas under your control, and to have their email address visible to you. Either of you can end it from Settings at any time.
You can withdraw consent at any time. Disconnecting an integration or deleting a data set withdraws consent for that data and removes it. Deleting your account withdraws all consent. Withdrawing consent for a category means we can no longer provide the feature that depends on it.
We will not use your information for a purpose materially different from those in Section 5 without asking you first.
7. What we do not do
- We do not sell, rent, or trade your personal information.
- We do not share it with advertisers or data brokers, and there is no advertising in Baray.
- We do not send your data to any artificial-intelligence, large-language-model, or machine-learning service, and we do not use it to train models. This is a statement about Baray's own code; if that ever changes, this policy will change first. The training-plan generator is deterministic code running on our own servers, not an AI service.
- We do not access any account you hold at a financial institution.
- We do not give financial, investment, tax, medical, training, or dietary advice. See our Terms of Service.
8. Service providers, and where your information is
| Provider | Role | What it handles | Location |
|---|---|---|---|
| Supabase | Database and authentication | All account data | Montréal, Canada (ca-central-1) |
| Vercel | Application hosting; marketing-page analytics | Data in transit while serving your requests; marketing-page visit metadata | Application runs in Montréal, Canada (yul1); Vercel's global network may route around a regional outage, and analytics data is processed in the United States |
| Resend | Delivery of the emails Baray sends — confirmation, password reset, email change, household invitations, and monthly entry reminders | Your email address, a partner's invitation address if you invite one, and the contents of those messages. Reminders and invitations contain no figures from your account. | United States |
| Google Workspace | Our support mailbox — anything you send to hello@, support@, or privacy@ | Your email address and what you wrote to us | United States |
Each provider may use your information only to provide its service to us and is bound by its own contractual and privacy commitments.
Hevy, Garmin, Google Calendar, Microsoft Outlook, and Monarch Money are not our service providers. They are your services. When you connect or import, you move your own data from them into Baray, under their terms and yours. What they log or retain about that transfer — for example, that our server fetched your calendar feed — is governed by their policies.
8.1 Notice about service providers outside Canada
(Alberta Personal Information Protection Act, s.13.1 and s.34.1)
Baray uses service providers outside Canada, in the United States, for email delivery (Resend), support correspondence (Google Workspace), and marketing-page analytics (Vercel). Personal information held in the United States is subject to United States law and may be accessible to U.S. courts, law enforcement, and national security authorities under that law.
Your account data — financial, health, nutrition, calendar, credentials, household records — is stored in Canada and is not held by these providers. What crosses the border is your email address, the contents of emails between us, and marketing-page visit metadata.
For questions about our use of service providers outside Canada, or to obtain our written policies and practices about them, contact:
Privacy Officer — Kiegan Scott, Baray privacy@baray.ca
8.2 Other disclosures
We may disclose personal information without consent where the law requires or permits: in response to a valid legal order, to investigate a suspected breach of an agreement or law, to protect someone's safety, or in connection with a sale or reorganization of the business — including transfer to a corporation formed to carry on Baray — in which case the recipient is bound by this policy and you will be notified.
9. Things you choose to share
Baray lets you turn on three things that expose data to other people, all off by default and all yours to revoke from Settings:
- A household partner (Section 4.6), who sees the areas you chose to share.
- A personal calendar feed of your planned training sessions, for your own calendar app, protected by a long random token.
- A shared training-plan link — plan structure only; no dates, no completion status, nothing that identifies you — protected by a long random token.
If you share a link or an invitation, you decide who receives it.
10. How long we keep your information
Your data stays until you remove it. Baray does not silently expire or purge your history — the whole point is the multi-year picture. Specifically:
| Category | Retention |
|---|---|
| Account, financial, health, nutrition, training, and imported transaction data | Until you delete it, or delete your account |
| Fitness markers and training availability preferences | Until you change or clear them, or delete your account |
| Plan generation records | Until you delete the plan they produced, or delete your account |
| Household invitation | Expires 7 days after it is sent; deleted when accepted or cancelled. An expired invitation is removed when the next one is sent or cancelled. |
| Household membership | Until the partner leaves, the account holder removes them, or either account is deleted |
| Consent records | For the life of your account |
| Record of monthly reminders sent | For the life of your account (a month and a timestamp — nothing else) |
| Calendar cache | Overwritten on each refresh; deleted immediately when you disconnect |
| Hevy API key and calendar URL | Deleted immediately when you disconnect |
| Synced Hevy workout data | Kept on plain disconnect (you may still want the history); erased with "Disconnect & delete data" |
| Server logs | Per our hosting provider's retention (structure only — no personal content) |
| Support correspondence | 24 months |
| Records of privacy breaches | 24 months, as PIPEDA requires |
Removing data yourself. From Settings you can delete individual records, undo an entire import batch, delete all transactions, delete all Hevy data, disconnect any integration, end a household membership, or delete your whole account. One exception to say plainly: deleting an account line item on the net worth screen moves it to trash, where it is hidden from your dashboards; trashed line items are removed for good when you delete your account.
When you delete your account: everything is removed from the live database immediately — including your login record itself. Before that happens, we first disconnect any external integration (for example, we deregister your Hevy webhook) so nothing keeps pointing at an account that no longer exists; if that step fails, the deletion stops and tells you, rather than half-completing. If you are the account holder of a household, the household, its membership, and any open invitation are removed with your account, and your partner keeps their own account with none of the shared data. If you are the partner, only your membership is removed; the account holder's data is untouched. There is no soft delete and no grace period.
Copies may persist in encrypted database backups for up to 7 days, after which they are overwritten.
11. Your rights
You can, at any time:
- Access the personal information we hold about you and learn how it has been used and disclosed.
- Correct anything inaccurate.
- Export your data as CSV files and a JSON settings file, from Settings — everything as a ZIP, or one area at a time. A household partner can export the shared areas.
- Delete any data set or your entire account, from Settings.
- Withdraw consent as described in Section 6.
- Complain, and escalate if you are not satisfied (Section 14).
Export and deletion require your current password each time, so nobody with a stray open browser tab can take your data.
For anything not self-serve, email privacy@baray.ca. We respond within 30 days. If we need longer we will say why. There is no charge for reasonable requests; we may verify your identity first. If we refuse a request, we will explain why in writing and how to challenge it.
12. How we protect your information
Stated precisely, because vague security claims are worse than none:
- Row-Level Security is enabled on every table. The database itself enforces that a signed-in user can read only their own rows — and, for household sharing, only the shared areas they have been accepted into — not just the application code.
- The application never bypasses that boundary. No part of Baray's code uses an administrative database key.
- We built no internal tooling to read your rows. That is the honest ceiling: as the operator we retain database access for maintenance, and Supabase and Vercel personnel access is governed by their terms — so we do not claim that no one can read your data, only that nothing in the product is designed to.
- All traffic is encrypted in transit (TLS).
- Your Hevy key and calendar URL are encrypted at the application level (AES-256-GCM) before they are written to the database, with the key held outside the database. If the key is unavailable, the save fails rather than storing plaintext.
- All other data is stored as ordinary database rows, protected by Row-Level Security and by our database provider's disk-level encryption at rest. We say this explicitly so it is not mistaken for end-to-end encryption, which Baray does not offer.
- Passwords are hashed and cannot be read by us. Minimum length 10 characters.
- Signup confirmation and password reset use one-time links; changing your email requires confirming from both the old and new address, so an unattended session cannot be redirected to someone else's inbox. A household invitation can be accepted only by an account signed in with the invited address.
- The operator's own Supabase, Vercel, GitHub, and mailbox accounts are protected by multi-factor authentication.
- Import files are parsed in your browser and never uploaded. Calendar feeds are parsed in memory and never written to disk. Server logs never contain personal content.
Baray does not currently offer user-facing two-factor authentication.
13. If there is a breach
If a security incident involving your personal information creates a real risk of significant harm to you, we will report it to the Privacy Commissioner of Canada and, where required, the Information and Privacy Commissioner of Alberta as soon as feasible; notify you directly with what happened, what was involved, what we are doing, and what you can do; and notify anyone else who can reduce the harm. We record every incident, reportable or not, in a breach log kept for 24 months.
14. Complaints
Start with privacy@baray.ca. We will acknowledge, investigate, and reply in writing.
If you are not satisfied:
- Office of the Privacy Commissioner of Canada — priv.gc.ca — 1-800-282-1376
- Office of the Information and Privacy Commissioner of Alberta — oipc.ab.ca — 1-888-878-4044
15. Cookies and local storage
The only cookies Baray sets are the sign-in session cookies from our authentication provider. There are no advertising, tracking, or third-party cookies. Vercel Web Analytics on the marketing pages is cookieless.
Baray uses your browser's temporary session storage — which is cleared when you close the tab and never sent to us — for the logged-out demo's state, a couple of refresh guards, and the name you type into a printed export.
16. Accountability
Privacy Officer — Kiegan Scott — privacy@baray.ca — is responsible for Baray's compliance with this policy and with PIPEDA and Alberta PIPA.
17. Changes to this policy
Changes are posted here with a new effective date and version. If a change is material — a new category of information, a new purpose, a new provider — we will email you before it takes effect and, where the law requires, ask for consent before applying it to information we already hold. Prior versions are available on request.
What changed in version 1.1
- Section 1 names the operator: Kiegan Scott, carrying on business as Baray, who is also the Privacy Officer (Section 16).
- New Section 4.6 describes household sharing — what is stored when you invite a partner, what they can and cannot see, and whose data it is. Sections 2, 3, 6, 9, 10, 11, and 12 refer to it.
- Section 4.4 adds the fitness markers, training availability preferences, and plan generation records collected by the training-plan generator, and explains where "current training load" comes from.
- Sections 4.1 and 5 add the monthly entry reminder email — on by default, off in Settings — and the record we keep of months sent. Section 4.1 also lists your app preferences.
- Section 4.2 notes that each monthly value records how it was entered. Section 4.3 now covers transactions you enter by hand as well as imports.
- Section 8 updates what Resend delivers; there is no payment provider yet, so none is listed.
- Section 10 adds retention rows for invitations, memberships, markers, plan records, consent records, and reminder records, states the backup window (7 days), and says plainly that trashed net-worth line items are removed when the account is.
- Section 11: export now covers every area, including meal planning; the earlier caveat is gone.