Cash/MONEY Privacy Policy

Cash/MONEY is currently in a private beta. Access is by invitation or waitlist approval, but real people now sign up, contact us, and use the app with real financial data -- so this page describes what we actually collect and do, not a placeholder for later.

What we collect

  • Account & sign-in. When you sign in with Google, we receive your name, email address and profile picture from Google OAuth. We don't see or store your Google password.
  • Beta waitlist & contact form. If you request access or use the contact form, we store the email, name and message you provide.
  • Financial data you enter. Accounts, transactions, budgets, and anything else you or your household add to the ledger. This is the core of the product -- it's stored so the app can work, not shared or sold.
  • Usage analytics. On the production site and the public demo (not local development) we use Google Analytics to understand usage, gated behind the cookie consent banner -- it only runs if you accept.

Who we share it with

We don't sell your data. A small set of service providers process it on our behalf, strictly to run the product:

  • Google -- sign-in (OAuth) and, if you accept cookies, analytics.
  • Resend -- delivers transactional email (waitlist confirmation, approval, household invites, contact replies).
  • Vercel -- hosts the application and, via Vercel Blob, stores encrypted database backups.
  • Upstash -- backs request rate-limiting and short-lived caching.
  • Sentry -- error tracking, so we can find and fix bugs. Configured to strip authorization headers and cookies before an error ever leaves the server.
  • Our database host -- stores the data above. Backups are encrypted.

Cookies

We set an authentication cookie (required to keep you signed in) and a cookie-consent preference. Google Analytics cookies are only set after you accept the consent banner; declining keeps analytics off.

Your data, your choices

  • Export. Signed-in users can download a copy of their account, family membership, accounts, ledger entries and budget data from Settings → Profile.
  • Deactivate. You can deactivate your account at any time from Settings → Profile -- this immediately signs you out and blocks sign-in until reactivated.
  • Delete. Because ledger data can be shared with other household members, full account deletion is currently handled by hand rather than instantly: reach us via the contact form and we'll delete or anonymize your data.

Changes to this policy

This is a beta product and this policy will evolve with it. We'll update this page as data handling changes; check back periodically.

Questions about this policy or how your data is handled? Use the contact form -- see also our Terms of Service.