Marked Personal Finance, LLC · Version 1.1 · Effective August 5, 2026
Marked Money is operated by Marked Personal Finance, LLC, a Kentucky limited liability company. You can reach us anytime at mark@markedmoney.app. This policy explains what information the service collects, what it's used for, and what happens to it — in plain English, because the facts here are ones we're glad to state.
Marked Money never connects to your bank, so we never see or hold a bank login. There are no advertising trackers, no third-party analytics profiles of you, and no session recording. We don't sell data — there's nothing here for an advertiser to buy. Your financial records exist because you typed them in or imported a file you chose, they're visible only to your account, and deleting your account erases them from the service immediately and permanently — the exact mechanics, including what happens to our providers' disaster-recovery copies, are spelled out below.
Your account: your name, your email address, and your password. The password is stored only as a salted cryptographic hash — we cannot see it, it travels only inside encrypted connections, and it is never stored in readable form.
Your financial records: the accounts, balances, transactions, budgets, goals, and settings you enter — including any optional book details you choose to add, like a household name or a footer for printed reports — and the rows you import from statement files you choose to upload. All of it comes from you. None of it comes from a bank connection, an aggregator, or any outside source — those don't exist here.
Usage events: the app records a small, fixed set of product events in our own database — things like “account created,” “setup completed,” “a transaction was added,” and steps of the in-app walkthroughs. These events contain no dollar amounts, balances, account names, or payee names — we've checked every place an event is recorded. They exist so we can see whether the product works, in aggregate.
Security housekeeping: your device's IP address is used transiently, in the app's own memory only, to rate-limit sign-in and account flows, and it is passed once to Cloudflare when its bot check verifies a signup. The app does not write IP addresses or browser details into our database. (Our infrastructure providers keep their own standard operational logs — see the provider list below.)
There are no fields for your phone number, date of birth, or government ID — the software has nowhere to put them.
If you share a book with another person, we store the email address you enter, so the invitation can be sent and connected to their account when they accept it. If that address already has an account, they are added straight away and no invitation is stored. A pending invitation expires after 14 days, and you can cancel it in Settings at any time before it is used.
The invitation tells that person who is inviting them: it carries your name and email address and the name of the book you shared, so they can tell whether they were expecting it. Once they accept, you both see the same accounts, transactions and balances, and either of you can add to them.
You can remove someone's access in Settings at any time, and anyone you have shared with can leave a book themselves. Either way the book stays with its owner, and their own account is untouched.
To run the service: showing you your own books, keeping your session signed in, and sending the email described under “Email” below.
To keep the service safe: rate limiting, a bot check on signup, and security headers.
To improve the product: the aggregate usage events above tell us where people get stuck. They are viewed as totals and funnels, not as browsing histories.
We do not sell your data. We do not share it with advertisers, data brokers, or “marketing partners.” We do not use it to advertise to you or to let anyone else advertise to you. We have no advertising business, and the numbers you track here are used for exactly one thing: showing them back to you.
We send no marketing email. If that ever changes, it will be opt-in, with its own separate consent — never a default.
One narrow exception to the section above exists, and it isn't ours to waive: the law can compel us. If we receive a subpoena, court order, or other demand that legally binds us, we will disclose only what the law actually requires and nothing more, we will challenge demands that are overbroad, and unless the law or the order itself forbids it, we will tell you before we comply so you have the chance to object. We may also disclose information when it is genuinely necessary to investigate or stop fraud or abuse of the service, to protect someone's safety, or to establish or defend legal claims. None of this creates a marketing exception, because there isn't one: nothing is ever sold, and nothing is ever shared with advertisers — full stop.
A short list of infrastructure providers processes data on our behalf. This is the complete list of services the software uses to run:
Neon (database hosting) — your account record and your financial records live in a PostgreSQL database operated by Neon on AWS in the us-east-2 (Ohio, USA) region. Connections to it are TLS-encrypted, and Neon states that stored data is encrypted at rest.
Vercel (application hosting) — runs the app's code and, like any host, keeps standard operational logs of requests and errors.
Cloudflare (network and security) — sits in front of the site, so everything you send and receive passes through Cloudflare's network in transit, the way traffic passes through any network provider. Your books are not stored with Cloudflare and are never sent to it as a data recipient. Cloudflare also runs the bot check on our signup page (Turnstile) — which receives the verification token, your IP address, and the browser signals its check collects — and it injects its own small security scripts (email-address obfuscation, bot detection) into pages it serves.
Cloudflare also provides our page analytics (Cloudflare Web Analytics): a cookieless beacon reports page views and page performance to us in aggregate. It sets no cookies, does no cross-site tracking, and builds no individual profiles — it tells us how many people visited and how fast pages loaded, not who anyone is.
Resend (email delivery) — delivers every email the app sends, so Resend processes the recipient's address and the message itself. That covers password resets, the two emails involved in changing your sign-in address, invitations to share a book, and the weekly check-in if you switched it on. When someone signs up, Resend also delivers an internal notification to us containing the new account's email address and name. No email the app sends carries a password, a balance, or any figure from your books.
There is no bank aggregator (no Plaid or anything like it) and no advertising network. Product usage measurement is the first-party event log described above, in our own database; page analytics is Cloudflare's cookieless service described above. The browser-security policy on every page enforces this: the only third-party origin a page may load from is Cloudflare's bot-check service.
One more, outside the app: if you email us, that mail is handled by our business email provider (Google Workspace), like any company mailbox.
The app itself sets exactly two cookies, both functional and both inaccessible to scripts: a session cookie that keeps you signed in for up to 30 days, and a cookie that remembers which of your books you last had open. The app sets no advertising or analytics cookies, and if you just visit the public site and never sign in, the app sets no cookies at all. During signup, Cloudflare's bot check may set its own cookies as part of running its challenge.
Because the app does not track you across other websites, there is nothing here for a Do Not Track or Global Privacy Control browser signal to switch off. We mention this because California law asks sites to say how they respond to those signals: our answer is that every visitor already gets the no-tracking treatment those signals request.
We keep your data for as long as your account exists, so your books are there when you come back. Sessions expire after 30 days; password-reset links expire after 60 minutes and work exactly once.
Deleting your account — from Settings, at any time, no email or approval needed — is immediate and complete. In one atomic operation, every book, account, transaction, budget, goal, imported row, rule, setting, session, and usage event tied to your account is permanently erased, along with the account itself. There is no soft delete, no trash can, and no 30-day window. This behavior is enforced by an automated test that runs as part of every production build — if deletion ever stopped erasing everything, the build could not ship.
Two kinds of records survive, neither of which identifies you. First, one anonymized log row noting that an account created on a given date was deleted on a given date, which versions of the terms it had accepted, and that the deletion was user-initiated — no name, no email, no account identifier, no financial value, and every date in that row is recorded only to the day. Second, anonymous counter events (such as “a signup was started”) that were never linked to any account and carry no identifying information.
Copies of the database made for disaster recovery by our database provider expire on the provider's retention schedule; deleted data is not restored from them in the normal operation of the service.
Export & Backup gives you your records as plain CSV files, one click, whenever you want: your chart of accounts with balances, and your ledger, entry by entry. The ledger file re-imports to reproduce your books' balances — it's a real backup, not a token gesture. Reports also download as spreadsheet files. Exports cover one book at a time; if you keep several books, export each one.
The app emails you only in response to an action, yours or that of someone you share books with. Today that means: a password reset, when you request one; a confirmation link, sent to a new sign-in address when you change yours, together with a notice to the old address so nobody can move your sign-in quietly; a message when someone shares a book with you; and the weekly check-in.
The weekly check-in is off until you switch it on in Settings. It sends at most once a week, it contains no figures from your books, and every one carries a link that unsubscribes you in a single click, without signing in.
None of these are marketing. We send no newsletters and no product announcements, and if that ever changes it will be opt-in, with its own separate consent, never a default.
Marked Money is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, email mark@markedmoney.app and we will delete it.
All traffic is encrypted in transit with TLS. Passwords are stored only as salted scrypt hashes. Session and password-reset tokens are stored only as one-way hashes, so a copy of the database could not be used to impersonate you. Each account's books are isolated at the data layer — every read and write is scoped to your own account's books, verified in code and tests. Every page ships strict browser security headers. No security is perfect, but this one is real, specific, and testable — and we'd rather tell you exactly what it is than call it “bank-level.”
If the company is ever merged, acquired, or its assets sold, your data does not become a bargaining chip. It may move to a successor only if the successor is bound by this policy's commitments — including the promise never to sell your data — and before any transfer takes effect we will give you advance notice and a real window to export your records and delete your account. The promises travel with the data, or the data doesn't travel.
If this policy changes, the new version is posted here with a new date and version. For material changes we will give reasonable advance notice inside the app or by email. We will never change the answer to “do you sell my data” — that one is permanent.
Questions, requests, or concerns: mark@markedmoney.app. A human reads it — the same one who built the product.
See also the Terms of Service and the Beta Terms. Earlier versions of this policy stay readable in the legal archive.