Cash/MONEY Privacy Policy
Cash/MONEY is currently in a private beta. Access is by invitation or waitlist approval, but real people now sign up, contact us, and use the app with real financial data -- so this page describes what we actually collect and do, not a placeholder for later.
What we collect
- Account & sign-in. When you sign in with Google, we receive your name, email address and profile picture from Google OAuth. We don't see or store your Google password.
- Beta waitlist & contact form. If you request access or use the contact form, we store the email, name and message you provide.
- Financial data you enter. Accounts, transactions, budgets, and anything else you or your household add to the ledger. This is the core of the product -- it's stored so the app can work, not shared or sold.
- Usage analytics. On the production site and the public demo (not local development) we use Google Analytics to understand usage, gated behind the cookie consent banner -- it only runs if you accept.
Who we share it with
We don't sell your data. A small set of service providers process it on our behalf, strictly to run the product:
- Google -- sign-in (OAuth) and, if you accept cookies, analytics.
- Resend -- delivers transactional email (waitlist confirmation, approval, household invites, contact replies).
- Vercel -- hosts the application and, via Vercel Blob, stores encrypted database backups.
- Upstash -- backs request rate-limiting and short-lived caching.
- Sentry -- error tracking, so we can find and fix bugs. Configured to strip authorization headers and cookies before an error ever leaves the server.
- Our database host -- stores the data above. Backups are encrypted.
Cookies
We set an authentication cookie (required to keep you signed in) and a cookie-consent preference. Google Analytics cookies are only set after you accept the consent banner; declining keeps analytics off.
Your data, your choices
- Export. Signed-in users can download a copy of their account, family membership, accounts, ledger entries and budget data from Settings → Profile.
- Deactivate. You can deactivate your account at any time from Settings → Profile -- this immediately signs you out and blocks sign-in until reactivated.
- Delete. Because ledger data can be shared with other household members, full account deletion is currently handled by hand rather than instantly: reach us via the contact form and we'll delete or anonymize your data.
Changes to this policy
This is a beta product and this policy will evolve with it. We'll update this page as data handling changes; check back periodically.
Questions about this policy or how your data is handled? Use the contact form -- see also our Terms of Service.