Khushin

Fine print
Updated 21 Aug 2026

The parts I'd want to read first.

What this site collects, how Garden protects data, and who owns it.

Garden
Technical

Garden — how your data is protected.

The server cannot read your money. Garden has no readable server-side ledger, key escrow, operator vault access, ads, tracking, sale, or sharing. Telemetry, sync, bank linking, and mailing lists are opt-in and off by default. Third parties: Cloudflare, Apple, SimpleFIN, Resend, and recipient mail providers.

The vault
Records are encrypted in the browser or on-device with AES-GCM, 256-bit, unless you choose "Use without a passphrase", which stores them unencrypted on the device. Sync sends an encrypted copy to Garden's server and back; the key never leaves the device, so the server holds an opaque blob.
Your passphrase
It derives with PBKDF2-SHA256 at 210,000 iterations. On web and desktop, passphrase and key remain in memory while unlocked; neither is written to disk or sent anywhere. On iOS, Face ID or Touch ID stores the passphrase in the biometric-protected device Keychain; it is not backed up or synced off-device.
Recovery
No reset link or server-side access exists. A long recovery code is generated on your device and shown once; Garden never sees or stores it. Lose the passphrase and the code, and the data is gone.
Bank linking
Optional and additive; manual import works without it. The only path is SimpleFIN, which you buy and manage directly under its terms and privacy policy; Garden does not collect that payment. Bank data and its connection credential pass through Garden's relay in readable form only for the seconds needed to reach your device, then are not stored.
Network calls
The desktop app checks garden.khushin.com at launch for updates. That request carries your IP address, timestamp, and browser user agent, not vault data. Sync stores the opaque encrypted vault blob under a random device-generated token.
Local and manual modes
Manual entry and CSV/PDF import run on your device. Without sync pairing, there is no account or server call. With pairing, saving a manual entry sends an encrypted copy to Garden's relay. In SimpleFIN mode, credentials and returned bank data cross the Worker only to reach you; Garden retains no readable copy.
On iOS
Budget alerts can appear on your lock screen; account answers can appear in Siri. That information never leaves your device for these features.
Separation and review
The email store and vault share no identifier or key; no code path joins them.

khushin.com
Privacy

What this site knows about you.

No analytics
No Google Analytics, Plausible, pixels, ad networks, or third-party scripts. Nothing about your visit is sold or shared. Every script is served from this domain and is in its public source.
No cookies
No cookies: no document.cookie and no cookie-setting header. Cloudflare's hosting settings are the last mile; they have been checked by hand, and any change will be stated here.
Local preferences
The day/night choice is in browser local storage under khushin:theme; reading, accessibility, and minimal-mode choices are in khushin:theme. The /design/ workbench stores theme, and viewport width under khushin:workbench. The service worker caches public pages in Cache Storage khushin-dev. These never leave your browser or go to me; clear site data to remove them.
Hosting
Cloudflare Pages records edge logs — IP address, timestamp, and requested page — for security and abuse prevention. They belong to Cloudflare, not me. I see only a recent dashboard window and have not verified its underlying retention period. This site cannot read, profile, or join those logs; no analytics product uses them.
Email
garden@khushin.com is the published Garden address and forwards to a personal iCloud mailbox. Writing gives me your address and message. The mailbox feeds no list or newsletter; this site has no signup form, and nothing from it is sold or shared.
Beta download emails
A beta request sends your address to Resend, a transactional email provider, only to deliver your personal download link. This is separate from telemetry, which never includes email. Resend handles retention under its own terms.
Your data, back or gone
Write to the address above to learn what is held about you and request deletion. For Garden that is usually nothing readable: the server never receives the vault key.

Garden
What the app records

The complete list of Garden telemetry.

What is recorded
  1. Onboarding beat reached — step name, count, and timestamp.
  2. Onboarding finished or skipped to the demo — which happened.
  3. Named section opened — Overview, Transactions, Plan, Documents, or Learn, and when; the screen name only.
Three events; counts and timestamps only.
What is never recorded
Garden never sends dollar amounts, account names, merchant names, transaction content or descriptions, or balances, in any setting or mode. They remain in the encrypted vault; no code path lifts them out.
The switch
These events are off by default, with a one-tap switch. Leave them off and Garden sends none; you can change the choice anytime.
Everything else is opt-in
Deeper product analytics, feature usage, and session detail are also opt-in and off by default; this page changes before that default changes.
Where it goes
It goes to Garden's first-party endpoint. No third-party analytics vendor receives it — no Google, Amplitude, Mixpanel, Firebase, or other SDK. It is not sold or shared.
mail@khushin.com