No policy has been written yet, because nobody has an account and no personal data is being collected. What is already true about how this is built:
A household owns the data, not a person
Every account, transaction, category, budget and goal belongs to a household. Deleting a person nulls their authorship and leaves the household's money intact, because a partner's history is not theirs to erase.
The database itself enforces the boundary
Postgres row-level security is switched on and forced for every table that carries a household, and the application connects as a least-privilege role it applies to. A query that forgets its filter returns nothing rather than another family's money.
Bank access never touches your browser
Bank connections run server-side, through Salt Edge: you sign in at your own bank, and no bank credential is ever handled by this app. The permission is read-only, and disconnecting a bank revokes it at the provider.
Your data leaves as easily as it arrives
Transactions export as CSV today, on every plan, and the export imports straight back. That is a design commitment, not a feature to be gated later.