Introduction
Cash Captain is a manual personal finance tracker for people who prefer to stay in control. You record transactions yourself, organize spending, and share a household with people you trust.
Being trusted with your financial information is a responsibility we take seriously. This policy explains what we collect, why we use it, who helps us run the product, and what choices you have. It applies to cashcaptain.app and related app surfaces we operate.
We recommend reading the full policy, but if you only have a minute, start with Quick answers below.
Quick answers
- Does Cash Captain connect to my bank?
- No. Cash Captain is manual entry — you type or import transactions yourself. We do not offer bank linking, and we cannot see or move money in your accounts.
- Do you have my banking credentials?
- No. We never ask for bank logins, passwords, or credentials, and we have no access to your accounts at a financial institution.
- Do you sell my information?
- Never. We do not sell, rent, or trade your personal data. Our business is the product, not your data.
- Is my ledger used for ads or AI training?
- No. We do not monetize your financial records, and we do not license or feed your transaction data to third-party machine learning or advertising systems.
- What goes to analytics?
- Product usage signals (which features are used, where flows break) — never transaction amounts or category names. Where we use session replay to improve the product, we apply the same privacy bar: amounts, merchants, account names, categories, and other financial or personal details are automatically redacted in the recording.
- Is my information secure?
- We use industry-standard protections: HTTPS in transit, encrypted storage through PlanetScale, and sign-in through Clerk (we do not store your password). See Security for more detail.
What personal data we collect
We collect only what we need to run the product, support you, and understand how the product is used. Cash Captain does not connect to your bank — financial data is what you enter (or import) yourself.
| Category | Examples | How we get it |
|---|---|---|
| Account | Email, name or display name, authentication identifiers | When you sign up or sign in |
| Financial data | Accounts, balances, transactions, categories, budgets, goals, and notes | What you enter or import |
| Household | Workspace membership, roles, invitations, and shared-space settings | When you create or join a workspace |
| Product analytics | Page views, feature usage events, device and browser signals, approximate region (no raw IP stored) | Automatically when you use the app |
| Session replay (masked) | Privacy-first session replay — any sensitive or remotely sensitive data (amounts, merchants, account names, categories, display names, and the like) is automatically redacted | Automatically when you use the app |
| Support email | Whatever you include when you write to us | When you contact us |
Transaction amounts and category names are not sent to analytics events. Where we use session replay, we apply maximum reduction: anything that could reveal your finances or identity — amounts, balances, merchants, account names, categories, display names, and similar — is masked before a recording is stored.
How we use your data
We use personal data to:
- Create and secure your account, and keep you signed in
- Store and display your financial entries, summaries, and household collaboration
- Respond to support requests
- Improve Cash Captain with product analytics (what features people use, where flows break, and how the product performs)
- Detect abuse, debug outages, and keep the Service reliable
- Meet legal obligations when they apply
We never sell, rent, or trade your personal data — and we do not monetize your financial records. Your transaction ledger is not used to train third-party AI models, and we do not license, share, or feed your financial data to outside machine learning systems. We process your data to run Cash Captain for you, not to build someone else's data product.
Legal bases
Some privacy laws (especially in the EU and UK) require us to name why we are allowed to use your data. In plain terms:
- To provide the service you signed up for. When you create an account and use Cash Captain, we need to process your sign-in details, financial entries, and household data to deliver the product — for example storing transactions, showing balances, and syncing shared workspaces.
- To run, secure, and improve the product. We also process data to keep the app reliable, prevent abuse, fix bugs, understand which features are used (via analytics), and reply to support email — in ways that respect your rights.
- When you agree. For some optional uses (such as certain cookies or marketing email), we will ask first where the law requires it. An EU cookie / analytics consent banner is deferred until we have meaningful EU traffic; we will add one before relying on opt-in for those users.
Cookies and tracking
Clerk sets authentication cookies so you can stay signed in. Those are required for the Service to work.
We use PostHog for product analytics and masked session replay. We configure PostHog to discard client IP addresses after geo enrichment, so we keep approximate region signals without storing raw IPs. Automatic click and form capture (autocapture) is limited to public marketing pages such as the homepage, blog, and changelog; it is not enabled inside the signed-in app. See PostHog's privacy policy for how PostHog processes data as a processor.
Again: transaction amounts and category names are not included in PostHog analytics events. Session replay is configured for privacy first — we keep enough context to fix broken flows (navigation, buttons, layout), and redact financial and personal content by default.
Third-party services
We rely on a small set of vendors to run Cash Captain. They process data on our instructions — only what is needed for their role — under their terms and our agreements with them. This is who they are and what they do for us (not a repeat of every field listed above):
| Service | What they do for us | Categories they touch |
|---|---|---|
| Clerk | Sign-in and account identity | Account |
| PlanetScale | Database hosting | Account, financial data, household |
| Railway | API and backend hosting | Application traffic and server logs |
| Vercel | Web app hosting | Request logs and asset delivery |
| PostHog | Product analytics and masked session replay | Product analytics, session replay |
Data retention
- Account and financial data. Kept while your account is active and as needed to provide the Service, resolve disputes, or meet legal requirements.
- PostHog analytics events. Retained for about 12 months, then deleted or aggregated according to our PostHog project settings.
- Session replays. Retained for about 30 days.
- Support email. Kept as long as needed to resolve your request and for ordinary business records.
Security
Protecting your information matters to us. Here is how we approach it:
- No bank connections. We do not link to financial institutions. We never ask for bank logins or credentials, and we cannot access or move money in your accounts.
- Encryption in transit. Traffic between your device and our servers uses HTTPS.
- Encrypted storage. Your data is stored with PlanetScale, which encrypts data at rest.
- Authentication through Clerk. Sign-in is handled by Clerk; we do not store your password.
- Limited production access. Access controls limit who on our team can reach production systems and customer data.
No online service is perfectly secure. Help protect your account with a strong password and sign out on shared devices. If you suspect unauthorized access, email hello@cashcaptain.app right away.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing.
To exercise these rights, email hello@cashcaptain.app. We will respond within a reasonable time and may need to verify your identity.
Account deletion is handled manually for now: contact us at hello@cashcaptain.app and we will delete your account data from our systems. Analytics deletion tied to automated account closure is on our roadmap; until then, include a deletion request in your email if you want PostHog person data removed as well.
Changes to this policy
We may update this policy as the product or our vendors change. When we do, we will revise the "UPDATED" date at the top of this page. Continued use of Cash Captain after a change means you accept the revised policy. For material changes we may also notify you in the product or by email.
Contact
Privacy questions or requests? Email hello@cashcaptain.app.