UPDATEDAugust 9, 2026

Privacy Policy

Introduction

Cash Captain is a manual personal finance tracker for people who prefer to stay in control. You record transactions yourself, organize spending, and share a household with people you trust.

Being trusted with your financial information is a responsibility we take seriously. This policy explains what we collect, why we use it, who helps us run the product, and what choices you have. It applies to cashcaptain.app and related app surfaces we operate.

We recommend reading the full policy, but if you only have a minute, start with Quick answers below.

Quick answers

Does Cash Captain connect to my bank?
No. Cash Captain is manual entry — you type or import transactions yourself. We do not offer bank linking, and we cannot see or move money in your accounts.
Do you have my banking credentials?
No. We never ask for bank logins, passwords, or credentials, and we have no access to your accounts at a financial institution.
Do you sell my information?
Never. We do not sell, rent, or trade your personal data. Our business is the product, not your data.
Is my ledger used for ads or AI training?
No. We do not monetize your financial records, and we do not license or feed your transaction data to third-party machine learning or advertising systems.
What goes to analytics?
Product usage signals (which features are used, where flows break) — never transaction amounts or category names. Where we use session replay to improve the product, we apply the same privacy bar: amounts, merchants, account names, categories, and other financial or personal details are automatically redacted in the recording.
Is my information secure?
We use industry-standard protections: HTTPS in transit, encrypted storage through PlanetScale, and sign-in through Clerk (we do not store your password). See Security for more detail.

What personal data we collect

We collect only what we need to run the product, support you, and understand how the product is used. Cash Captain does not connect to your bank — financial data is what you enter (or import) yourself.

CategoryExamplesHow we get it
AccountEmail, name or display name, authentication identifiersWhen you sign up or sign in
Financial dataAccounts, balances, transactions, categories, budgets, goals, and notesWhat you enter or import
HouseholdWorkspace membership, roles, invitations, and shared-space settingsWhen you create or join a workspace
Product analyticsPage views, feature usage events, device and browser signals, approximate region (no raw IP stored)Automatically when you use the app
Session replay (masked)Privacy-first session replay — any sensitive or remotely sensitive data (amounts, merchants, account names, categories, display names, and the like) is automatically redactedAutomatically when you use the app
Support emailWhatever you include when you write to usWhen you contact us

Transaction amounts and category names are not sent to analytics events. Where we use session replay, we apply maximum reduction: anything that could reveal your finances or identity — amounts, balances, merchants, account names, categories, display names, and similar — is masked before a recording is stored.

How we use your data

We use personal data to:

  • Create and secure your account, and keep you signed in
  • Store and display your financial entries, summaries, and household collaboration
  • Respond to support requests
  • Improve Cash Captain with product analytics (what features people use, where flows break, and how the product performs)
  • Detect abuse, debug outages, and keep the Service reliable
  • Meet legal obligations when they apply

We never sell, rent, or trade your personal data — and we do not monetize your financial records. Your transaction ledger is not used to train third-party AI models, and we do not license, share, or feed your financial data to outside machine learning systems. We process your data to run Cash Captain for you, not to build someone else's data product.

Cookies and tracking

Clerk sets authentication cookies so you can stay signed in. Those are required for the Service to work.

We use PostHog for product analytics and masked session replay. We configure PostHog to discard client IP addresses after geo enrichment, so we keep approximate region signals without storing raw IPs. Automatic click and form capture (autocapture) is limited to public marketing pages such as the homepage, blog, and changelog; it is not enabled inside the signed-in app. See PostHog's privacy policy for how PostHog processes data as a processor.

Again: transaction amounts and category names are not included in PostHog analytics events. Session replay is configured for privacy first — we keep enough context to fix broken flows (navigation, buttons, layout), and redact financial and personal content by default.

Third-party services

We rely on a small set of vendors to run Cash Captain. They process data on our instructions — only what is needed for their role — under their terms and our agreements with them. This is who they are and what they do for us (not a repeat of every field listed above):

ServiceWhat they do for usCategories they touch
ClerkSign-in and account identityAccount
PlanetScaleDatabase hostingAccount, financial data, household
RailwayAPI and backend hostingApplication traffic and server logs
VercelWeb app hostingRequest logs and asset delivery
PostHogProduct analytics and masked session replayProduct analytics, session replay

Data retention

  • Account and financial data. Kept while your account is active and as needed to provide the Service, resolve disputes, or meet legal requirements.
  • PostHog analytics events. Retained for about 12 months, then deleted or aggregated according to our PostHog project settings.
  • Session replays. Retained for about 30 days.
  • Support email. Kept as long as needed to resolve your request and for ordinary business records.

Households and shared access

When you create or join a household (workspace), other members can see information shared in that space according to the roles and permissions the product supports. That can include shared accounts, transactions, budgets, and related notes.

Invite only people you trust. You control invitations and membership within the limits of the app. Hidden or personal accounts stay private to the extent the product's privacy rules allow; shared data is visible to members with access.

Security

Protecting your information matters to us. Here is how we approach it:

  • No bank connections. We do not link to financial institutions. We never ask for bank logins or credentials, and we cannot access or move money in your accounts.
  • Encryption in transit. Traffic between your device and our servers uses HTTPS.
  • Encrypted storage. Your data is stored with PlanetScale, which encrypts data at rest.
  • Authentication through Clerk. Sign-in is handled by Clerk; we do not store your password.
  • Limited production access. Access controls limit who on our team can reach production systems and customer data.

No online service is perfectly secure. Help protect your account with a strong password and sign out on shared devices. If you suspect unauthorized access, email hello@cashcaptain.app right away.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing.

To exercise these rights, email hello@cashcaptain.app. We will respond within a reasonable time and may need to verify your identity.

Account deletion is handled manually for now: contact us at hello@cashcaptain.app and we will delete your account data from our systems. Analytics deletion tied to automated account closure is on our roadmap; until then, include a deletion request in your email if you want PostHog person data removed as well.

Changes to this policy

We may update this policy as the product or our vendors change. When we do, we will revise the "UPDATED" date at the top of this page. Continued use of Cash Captain after a change means you accept the revised policy. For material changes we may also notify you in the product or by email.

Contact

Privacy questions or requests? Email hello@cashcaptain.app.