Privacy
Last updated 2026-09-13
What Whatif reads
Whatif connects to YNAB with read-only access. It cannot change a budget, a transaction, a category or a target — not by design choice, but because the access it is granted does not permit it.
With your permission it reads four things from your budget and keeps them: your account balances, your category names and their budgeted, spent and available amounts, a per-category monthly total for the last twelve months, and your scheduled transactions.
There is a fifth it reads and does not keep unless you ask it to, which is the next section.
Your individual transactions
They are not stored unless you ask for them, and asking is off by default. A forecast needs balances, categories and the calendar of what is scheduled; payee-level detail is not an input to any of that arithmetic, so nothing in the forecast keeps it.
One screen does need them — Where it went, which adds up how a month actually went. You turn that on per budget, from the screen itself. While it is on, Whatif keeps the last twelve months of your transactions: the date, the amount, the payee, the category and the account. Turning it off deletes every one of them, and so does disconnecting the budget or deleting your account. Older ones drop off on their own as the twelve months move.
Worth being exact about, because the difference matters: YNAB sends your transactions either way. They arrive on the same response as your balances and categories, every time Whatif reads your budget, and when this is off they are discarded rather than never received. Saying we do not receive them would not be true, so we do not say it.
Your connection to YNAB
The credential that lets Whatif read your budget is encrypted before it is written to the database, with a key held separately from it. Disconnecting your budget destroys the credential immediately and deletes every row read from it.
Deleting everything
Deleting your account deletes your budget data, your scenarios and your credentials. It is immediate and it is not recoverable. Backups are retained for a limited period and are overwritten on their own schedule.
Who else sees it
Your data is not sold, not shared with advertisers, and not used to train anything. Infrastructure providers — hosting, email, payment processing — see only what they need to perform their function.
One more, added deliberately and worth stating exactly: a product analytics provider, on servers in the European Union, which receives a fixed list of events about which screens were used — that setup was finished, that a sync failed, that a password reset was asked for. It does not receive any figure from your budget, any account, category or payee name, the contents of any page, or a recording of anything. It sets no cookies.
That list is a file rather than a policy: every event the product can send is declared in one place in the source, and nothing else is collected. Page recording and automatic click-tracking are both switched off, which is what makes the paragraph above checkable rather than a promise about intentions.