Summary
MarginSheet™ is a household financial management service operated by Margin Sheet LLC. To do the work, we hold a detailed picture of your household's money: every transaction, every balance, and the things you tell MyKeeper about your life.
Here is the short version of how we treat it.
We do not sell your personal information, and we never disclose your financial information to an advertiser. Our only revenue is your subscription.
We do advertise, and our marketing website uses Google and Meta advertising and analytics tools, including retargeting. Those tools stop at the login screen. No advertising or analytics tag runs inside the application, nothing about your accounts, transactions, or conversations reaches an advertising platform, and we build no advertising audiences from anything you do after signing in. Section 9 explains this in full and tells you how to opt out.
We collect less than you may expect. No passwords exist anywhere in the service. We store no IP addresses or browser fingerprints with your sessions. We do not record your screen. We never see your bank credentials, and our own application cannot read the tokens that connect to your bank. We cannot move your money.
MyKeeper™, the Money Intelligence™ Analyst that reads your books, composes the messages you receive. Section 6 explains exactly what is sent to our model provider and what is not. Your household's data is not used to train AI models.
Everyone in a household sees the same books. There is no private view for one member. Section 10 explains what that means before you decide to join one.
You can export everything at any time. When you cancel, you choose in the moment whether we keep your file for 12 months or delete it outright.
This summary is not the policy. The sections below are.
Contents
- Scope
- Who we are, and how we treat financial information
- Information we collect
- What we deliberately do not collect
- Where the information comes from
- Artificial intelligence processing
- How we use information
- How we disclose information
- Advertising, and what we do and do not share
- Households, invitations, and shared visibility
- Cookies and tracking technologies
- Security
- Retention, export, and deletion
- Your privacy rights
- How to exercise your rights
- Children and dependents
- Business transfers
- Where your data is stored
- Changes to this policy
- How to contact us
1Scope
This policy explains how MarginSheet treats personal information when you visit our website, sign up, use the web application, or exchange messages with MyKeeper by SMS or email. Together these are the "Services."
"Personal information" means information that identifies, relates to, or could reasonably be linked with you or your household. Some laws call this "personal data" or "personally identifiable information." This policy uses the terms interchangeably.
This policy does not cover your bank, your card issuer, or any other company we do not control. It does not cover Plaid's own handling of your data once you authorize a connection inside Plaid's interface. Plaid publishes its own privacy policy and you should read it.
Your use of the Services is also governed by our Terms of Service, which incorporate this policy.
2Who we are, and how we treat financial information
MarginSheet is operated by Margin Sheet LLC, a Florida limited liability company. References to "MarginSheet," "we," "us," and "our" mean Margin Sheet LLC.
We hold nonpublic personal financial information about households, and we handle it to the standard expected of a financial institution regardless of how any particular statute classifies us. In practice that means three commitments:
We maintain a written information security program with a designated individual responsible for it, covering risk assessment, access controls, encryption, vendor oversight, and incident response.
We do not disclose nonpublic personal information to nonaffiliated third parties except as necessary to provide the service you asked for, to process your payment, to deliver your messages, and as required by law. Every such recipient is listed in Section 8.1.
We have no affiliates and no joint marketing arrangements. There is no information-sharing arrangement for you to opt out of, because we do not have one.
If we are ever required to provide a separate financial privacy notice in a prescribed federal format, we will do so and link it here.
3Information we collect
The table below lists the categories of personal information we collect, why, and to whom we disclose each. The category names follow the framework used by state privacy law so that this table serves as our disclosure under those statutes.
| Category and examples | Why we collect it | Disclosed to |
|---|---|---|
| Identity data. Name of each household member. Which member is the primary. | Addressing you correctly; attributing statements to the member who made them; determining who may invite others. | Service providers. |
| Contact data. Email address and mobile phone number for each member, each verified before use. Home address. | Authentication; delivering statements and assistant messages; deriving your household's timezone so scheduled messages arrive during your local waking hours. | Service providers (email, SMS, and verification vendors). |
| Household composition data. Who belongs to the household, invitations sent and their status, and what each member may see and do. | Operating the shared account; enforcing access rules. | Service providers. Other members of your household. See Section 10. |
| Payment data. Payment card, held by our payment processor. We retain a customer identifier and a card fingerprint. We never store a card number. | Billing; preventing repeated free trials by the same household. | Payment processor. |
| Financial account data. Account name, type and subtype, last four digits, current and available balances, credit limits, institution identity, and daily balance snapshots. | Maintaining your books; computing balances and projections. | Service providers. AI model provider, per Section 6. |
| Transaction data. Up to 24 months of history at connection and continuously thereafter: amount, date, merchant name, the raw descriptor your bank supplies, provider category, payment metadata, counterparties, and pending status. | The core of the service. Every figure we report derives from this. | Service providers. AI model provider, per Section 6. |
| Liability data. For credit cards and loans: statement balance, statement date, minimum payment, due dates, interest rates, promotional rate expiry, and overdue status. | Cash flow projection; surfacing obligations before they arrive. | Service providers. AI model provider, per Section 6. |
| Recurring stream data. Detected recurring charges and deposits: frequency, average amount, predicted next date. | Identifying commitments; projecting the month, the rolling 13 weeks, and the year end. | Service providers. AI model provider, per Section 6. |
| Filings and corrections. The category assigned to each transaction, whether assigned by us or by you, and the rules we learn from your corrections. | Categorization accuracy; making the books reflect your judgment rather than ours. | Service providers. AI model provider, per Section 6. |
| Household context. Facts, goals, plans, worries, preferences, and decisions you state in conversation, recorded with who said it and when. Standing instructions about how and when MyKeeper contacts you. Tags you define. Your decision journal. Your stated Margin and resilience targets, and which goals you have named most important. | Answering your questions with reference to your actual circumstances rather than generic advice. | Service providers. AI model provider, per Section 6. Other members of your household. |
| Communications data. Every message sent and received in both directions on both channels, with content. For each outbound message: the structured data package it was composed from, the model used, and the result of our compliance check. Composed statements and briefings retained as sent. | Continuity of conversation; quality control; proving what we told you and when. | Service providers (SMS and email delivery). |
| Consent records. For each consent: the verbatim language shown to you at the time, the phone number and email address exactly as entered at that moment, a timestamp, and the source. | Demonstrating what you agreed to, in the words you saw, independent of any later change to your contact details. | Retained internally. Disclosed only if legally compelled. |
| Delivery and provider events. Delivery confirmations, bounces, spam complaints, and payment and bank-connection status reported by our providers. | Knowing whether a message reached you; surfacing a failed address so your sign-in and statements keep working. | Retained internally. |
| Marketing site data. When you visit marginsheet.com or move through signup: pages viewed, referring source, campaign parameters, approximate location derived from network address, device and browser type, advertising and analytics cookie identifiers, and conversion events such as starting or completing signup. | Measuring which advertising works; showing ads to people who visited and did not sign up. | Advertising and analytics partners. See Section 8.2. |
| Operational data. A normalized form of your email address and a card fingerprint, used to prevent repeated free trials. Named product events. Scrubbed error reports. | Fraud and abuse prevention; keeping the software working. | Analytics and error monitoring providers, per Sections 4 and 11. |
The boundary that matters in this table. Every category above marked as disclosed to advertising and analytics partners is marketing site data and nothing else. No financial account data, transaction data, liability data, recurring stream data, filing, household context, or communication is ever disclosed to an advertising or analytics partner, in any form, hashed or otherwise.
Sensitive information. Some state privacy laws treat financial account information as sensitive. We collect it because it is the service. We do not use it to infer characteristics about you, and we do not use or disclose it for any purpose beyond providing the Services, securing them, and preventing fraud. We seek no separate permission to use it for anything else because we do nothing else with it.
4What we deliberately do not collect
This section is unusual in a privacy policy. We include it because each item is an engineering decision that reduces what we hold, and because a promise you can verify is worth more than one you cannot.
No passwords exist anywhere in the service. You sign in with a passkey or an emailed link. The database column our authentication library provides for password storage has its read and write privileges withheld from the application, so a password could not be stored even if the software were reconfigured to try.
No IP addresses are stored with your sessions. Suppressed both by configuration and by a database rule that clears the value on every write.
No browser or device fingerprints are stored with your sessions. Suppressed by the same database rule.
No session recording and no screen capture, ever. Our analytics captures only events we have explicitly named in code. Automatic capture of clicks, pageviews, and form contents is disabled.
No advertising or analytics tag runs inside the application. We advertise, and our marketing site carries Google and Meta tags. They stop at the login screen. The authenticated application ships no advertising pixel, no third-party analytics, and no marketing tag of any kind, and this is enforced as a build check rather than left to convention: a tag added to the application fails the build.
No financial data ever reaches an advertising platform. Not your balances, not your transactions, not your categories, not your Margin, not anything you have told MyKeeper. Not in identified form and not in aggregate.
No advertising audiences are built from product usage. Whether you opened the app yesterday, what your Margin is, and whether you corrected a filing are invisible to every advertising platform we use.
We never see your bank credentials. You authenticate directly with your institution inside Plaid's interface. We receive an access token, never a username and never a password.
Our own application cannot read those access tokens. They are encrypted before storage, and the database role our application uses is denied read access to that column entirely. Only the component that synchronizes your bank data can decrypt them.
We cannot move your money. Bank access is read-only. MarginSheet cannot initiate a transfer, a payment, or any movement of funds, and no feature exists that would allow it.
One residual we disclose rather than omit. Our error monitoring provider derives an approximate country from the network connection that reports an error, before discarding the address itself. It is country level only, it describes our hosting provider's egress point rather than your home, it is derived after our own scrubbing has run, and the provider offers no setting to disable it. We state it because "no IP addresses" would otherwise be very slightly too strong a claim.
5Where the information comes from
From you. When you sign up, verify your phone, invite household members, correct a filing, define a tag, set a target, answer a question from MyKeeper, or ask MyKeeper anything.
From your financial institutions, through Plaid. Only after you authorize the connection inside Plaid's interface, and only for the accounts you select. You can disconnect an account at any time.
From other members of your household. Anything a member tells MyKeeper becomes part of the household's shared record. See Section 10.
Generated by us about your household. Filings, learned rules, projections, and the statements we compose.
From our service providers. Delivery confirmations, bounces and complaints from our messaging vendors, payment status from our processor, connection status from Plaid, and error reports from our monitoring.
We do not buy personal information from data brokers. We do not receive information about you from advertising partners, because we have none.
6Artificial intelligence processing
MyKeeper composes its messages using large language models operated by Anthropic. This section describes that processing in detail because it is the part of the service that most deserves a direct explanation.
6.1What is sent to the model provider
For each message, we assemble a fact package: a structured set of figures, dates, and names drawn from your own books, containing only the data required for that class of message. The model receives that package and writes prose from it.
Depending on the message, a package may contain your monthly income and spending totals by category, your Kept figure and Margin percentage, individual transaction details, account balances, upcoming commitments, the names of your income sources (typically employer names), the first names of household members, and facts you have told MyKeeper.
We also use models to classify transactions. An unfamiliar merchant may be classified by a model, and we may look up public information about a merchant name on the web. Content retrieved from the web is treated as untrusted and cannot direct how our system behaves.
6.2Limits we place on model use
The model never computes. All arithmetic happens in our code. The model writes sentences around figures that were already calculated. Any number appearing in a message that does not trace back to a field in the package is a failure our system is built to catch.
The model never sees our internal fields. Confidence scores, rule identifiers, and calibration statistics travel inside the package for routing and are structurally removed before composition.
Anything you delete is excluded structurally. When you delete something you told MyKeeper, the deletion is enforced at the query layer, so the deleted item cannot enter a future package at all. It is not filtered out afterward. It never arrives.
Every outbound message is checked before it is sent. A compliance check runs on each composed message. A message that fails is rewritten or replaced with pre-cleared text. There is no exemption, no override, and the check cannot fail open.
Responses are cached by merchant pattern, so the same question is not asked of the model repeatedly.
6.3Training and retention at the model provider
Your household's data is not used to train AI models. This is not a preference we have expressed. Our agreement with Anthropic prohibits it: their commercial terms state that Anthropic may not train models on customer content from the services.
We retain all rights to what we send and we own what comes back, so nothing we transmit becomes the provider's to use. How long the provider holds what we send is governed by a data processing addendum incorporated into that agreement, under which the provider acts as our processor and may use the information only to provide the service to us.
6.4Learning across households
Our system contains a table designed to hold merchant-to-category facts learned across households, of the form "this merchant is a grocery store." It structurally cannot store amounts, dates, account details, or any household identifier, because those columns do not exist. It requires at least 5 independent households before any fact becomes usable, and it excludes person-name and peer-to-peer merchant patterns.
This feature ships empty and switched off. Nothing is written to it and nothing reads from it. We describe it because it exists in our system, and because turning it on would be a material change to this policy that we would announce before making.
6.5What MyKeeper will not do
MyKeeper does not give investment advice and refuses questions touching securities, allocation, or investment selection. It does not tell you what to cut, buy, or choose. It states what your data shows, what a decision would cost, and what is committed versus chosen. These are constraints enforced in software rather than promises left to the model's judgment. Our Terms of Service describe these limits in full.
7How we use information
To provide the service. Creating and administering your account. Connecting and synchronizing your financial accounts. Categorizing transactions. Maintaining your books, your monthly statement, your rolling 13-week projection, and your year-end projection. Composing and delivering the messages you receive. Answering your questions.
To bill you. Processing your subscription, applying promotional codes, notifying you before a charge, and handling failed payments.
To keep the service secure. Verifying phone numbers and email addresses. Rate limiting one-time passcode requests per phone number, per member, and per source. Requiring re-authentication for sensitive actions. Detecting drift between stored balances and computed flows. Investigating suspected abuse.
To prevent repeated free trials. By comparing a normalized form of your email address and your card fingerprint against prior signups.
To correspond with you. Responding when you contact us. Sending service notices, billing notices, and, if you have not opted out, marketing email from MarginSheet the company. Commercial email always comes from MarginSheet, never from MyKeeper.
To improve the service. Diagnosing errors. Reviewing named product events in aggregate to understand which parts of the product are used.
To meet legal obligations. Complying with applicable law, regulation, subpoena, court order, or other legal process. Establishing, exercising, or defending legal claims. Preventing, detecting, and investigating security incidents and potentially unlawful activity. Protecting the rights, property, or safety of you, of us, or of another person. Enforcing our agreements.
We will not use personal information for materially different, unrelated, or incompatible purposes without telling you first, and where required, obtaining your consent.
8How we disclose information
8.1Service providers
These companies perform functions on our behalf under contract, may use the information only to perform those functions, and may not use it for their own purposes.
| Provider | Role | What it receives |
|---|---|---|
| Plaid | Bank data aggregation | Your authorization; returns account and transaction data. |
| Anthropic | AI model provider | Fact packages for message composition and transaction classification, per Section 6. |
| Stripe | Payment processing | Name, email, payment card. |
| Twilio | SMS delivery and phone verification | Phone numbers and message content. |
| Postmark | Transactional email | Email addresses and message content. |
| Kit | Commercial email | Email address and subscription status, for billing notices and marketing. |
| Cloudflare | Application hosting, edge security, and file storage | Service traffic; stored exports. |
| Neon | Database hosting, United States | Stored data. |
| Sentry | Error monitoring | Scrubbed exception reports, with credentials, connection strings, tokens, authorization headers, network addresses, and geolocation headers removed before transmission. |
| PostHog | Product analytics, United States hosting | Named product events only. |
Our authentication system runs on our own infrastructure with its data in our own database. It is not a third party and receives nothing.
We maintain a current inventory of service providers with access to customer information as part of our information security program. If this list changes, we update it here.
8.2Advertising and analytics partners
These companies receive marketing site data. They are not service providers in the legal sense, because they use the information for their own purposes as well as ours. That is why Section 9 treats what they receive as a disclosure you can opt out of.
| Partner | Role | What it receives |
|---|---|---|
| Google (Analytics and Ads) | Website analytics; advertising measurement and retargeting | Marketing site data as described in Section 3. |
| Meta (Meta Pixel and Conversions API) | Advertising measurement and retargeting | Marketing site data as described in Section 3, which may include a hashed form of an email address entered during signup so that a conversion can be matched to an ad. |
Neither receives anything from inside the application. Neither receives financial information of any kind.
8.3Other members of your household
See Section 10.
8.4Legal and safety disclosures
We may disclose personal information when we believe in good faith that disclosure is required by law or reasonably necessary for the purposes described under "To meet legal obligations" in Section 7.
If we receive a legal demand for your household's information, we will tell you before we comply, unless we are legally prohibited from doing so or unless there is a genuine risk to someone's safety. Where we are prohibited temporarily, we will tell you once the prohibition lifts.
8.5Business transfers
If MarginSheet is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, personal information may be transferred as part of that transaction.
Any acquirer must continue to honor this policy with respect to information collected before the transfer, or must notify you and give you the opportunity to export and delete your information before any materially different practice takes effect.
8.6Aggregated and de-identified information, and the Household Margin Index
We may create aggregated or de-identified information that cannot reasonably be linked to you or your household, and use it internally to operate, secure, and improve the Services. We do not attempt to re-identify it, and we require the same of anyone we provide it to.
We publish one thing derived from aggregate data, and we tell you about it before you sign up. MarginSheet publishes the Household Margin Index™: statistics about household margins in aggregate, figures like the median Margin across households, or the share of households that kept money in a given month. Contributing to the Index is part of joining MarginSheet; your consent to it is part of the signup you complete, stated there in plain language, not inferred from this policy.
What the Index can and cannot contain is a matter of construction, not editorial care:
- It is computed only from aggregate figures across many households. No statistic is published unless it draws on at least 100 households, so no figure can describe yours.
- It contains no identifiers of any kind. No names, no locations, no account details, no transactions, no merchant names, no dates tied to any household. None of these are inputs to the Index at all.
- Nothing about your individual household is ever published, referenced, or derivable. Your Margin contributes to a median the way one voter contributes to a turnout percentage: the number moves, and nothing about you is in it.
- It flows one direction. The Index is computed from the aggregate; nothing is ever looked up, matched back, or re-identified, and we require the same of anyone who receives or republishes it.
Publishing research or statistics beyond the Index, anything of a different kind than described here, would be a material change under Section 19, announced before it takes effect.
9Advertising, and what we do and do not share
We advertise MarginSheet, and we use ordinary advertising tools to do it. This section states exactly what that means, because a household connecting its entire financial life deserves a precise answer rather than a reassuring one.
9.1The line we draw
Our marketing website and signup flow carry advertising and analytics tags from Google and Meta. They record what pages you visited, where you came from, and whether you started or completed signup, and they let us show ads to people who visited and did not sign up.
These tags load when you arrive on the site. We do not gate them behind an acceptance prompt, because United States privacy law gives you a right to opt out rather than requiring us to obtain your agreement first. Section 9.4 tells you how to opt out, and a Global Privacy Control signal stops them running at all.
Those tags stop at the login screen. Once you are inside the application, no advertising or analytics tag runs. This is not a policy we ask employees to remember. It is a build check: a tag added to the application code fails the build before it can ship.
9.2What this means under state privacy law
Advertising cookies used for retargeting are treated by California law as sharing for cross-context behavioral advertising, and by other state laws as targeted advertising. We do not dispute that characterization. Some state laws define "sale" broadly enough to include this exchange even though no money changes hands, and we treat it as though they do.
So: we share marketing site data for advertising, and you can stop us. Section 15 tells you how, and the link is in the footer of every page.
9.3What is never shared, sold, or used for advertising
We do not sell or share your financial information. Not your balances, transactions, categories, Kept figure, Margin, projections, statements, or anything you have told MyKeeper. Not to an advertiser, not to a data broker, not to anyone, in any form.
We build no advertising audiences from product usage. No "people whose Margin fell," no "people who stopped opening the app," no audience of any kind derived from inside the product.
We do not use your information for profiling that produces legal or similarly significant effects. We do not score you, rank you, or make automated decisions about your eligibility for anything.
We do not sell personal information to data brokers, and we do not disclose personal information to third parties for their own direct marketing purposes.
9.4Opting out
You can opt out of advertising sharing at any time:
- Use the "Do Not Sell or Share My Personal Information" link in the site footer.
- Set a Global Privacy Control signal in your browser. We treat it as a valid opt-out, and where it is present the advertising and analytics tags do not run at all.
Opting out costs you nothing. The product is identical either way, and Section 14's anti-discrimination commitment applies.
An opt-out set in one browser applies to that browser. If you use several, set it in each, or contact us and we will apply it to your account.
9.5Text messaging
If you opt in to text messages, MyKeeper™’s messages arrive by SMS. The carrier-required facts, stated plainly:
- Message frequency varies. A typical household receives 2 to 6 messages per month, plus replies to conversations you start.
- Message and data rates may apply, according to your mobile carrier’s plan.
- Text STOP to stop at any time, and HELP for help. Opting out of texts does not affect your subscription; we will find another way to reach you about your account.
- No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party. Your phone number is used to deliver the messages you signed up for and is disclosed only to our SMS delivery provider (Twilio, Section 8.1) for that delivery.
10Households, invitations, and shared visibility
10.1Everyone sees the same books
Every full member of a household sees the same books. Any member can see any transaction, any filing, any statement, and anything any other member has told MyKeeper. There is no private view for one member inside a shared household. We do not offer one and we do not intend to.
We state this in the invitation itself, before you decide whether to join, rather than after.
The practical consequences, stated directly:
- If you join a household, other members will be able to see your spending.
- If you tell MyKeeper something, other members may read it.
- If you invite a member, you are authorizing us to disclose your household's financial information to that person.
If this is not the right arrangement for your circumstances, do not join a shared household.
10.2Who may invite
The primary member of a household may invite others. An invitation requires the invitee's name and mobile phone number, and may include an email address. The invitation link expires after 14 days.
An invitee becomes a full member only after establishing their own identity and verifying their own phone number. Until their phone is verified, no message about the household's money reaches them.
10.3When a member leaves, and when a household separates
This deserves a clear rule rather than a case-by-case decision, because the circumstances are often difficult.
The household file belongs to the household, not to any one member. Removing a member does not delete the household's records, and leaving a household does not entitle you to erase books that the remaining members rely on.
A departing member may export. Any member may export the household's records at any time, including on the way out, and may keep that export.
Removal requires re-authentication and can only be done by the primary member, in the application. It cannot be initiated by SMS, by email, or by asking an assistant.
A departing member's own context is theirs to remove. Facts, goals, and statements a member contributed can be deleted by that member, and the deletion is enforced structurally so the removed items cannot appear in any future message. Transactions and balances are not context and remain part of the books.
We will not adjudicate a dispute between members. If members disagree about who controls a household file, we will maintain the account as it stands and direct you to resolve it between yourselves or through counsel. Contact us and we will explain what we can and cannot do.
11Cookies and tracking technologies
Cookies and similar technologies behave differently on either side of the login screen, so this section is split the same way.
11.1On the marketing website
Three categories of cookie operate here.
| Category | What it does | Your control |
|---|---|---|
| Essential | Keeps the site working, secures forms against abuse, remembers your privacy choices | Always on. The site cannot function without them |
| Analytics | Google Analytics. Tells us which pages work and where visitors come from | Opt out at any time |
| Advertising | Google Ads and Meta Pixel. Measures which ads produce signups and lets us show ads to people who visited | Opt out at any time |
Analytics and advertising cookies are set when you arrive, and you can turn them off. We do not ask you to accept them first. United States privacy law is built around a right to opt out rather than a requirement to opt in, so that is how this works, and we would rather describe it accurately than present a consent banner that implies a choice you were never actually asked to make.
To opt out, use the "Do Not Sell or Share My Personal Information" link in the site footer. Your choice is remembered on that browser.
A Global Privacy Control signal is treated as an opt-out and is honored before any advertising or analytics cookie is set. You do not have to do anything else, and we do not ask you to confirm it. If your browser sends the signal, the tags do not run.
None of this affects the application. See Section 11.2.
11.2Inside the application
No advertising cookies. No third-party analytics. No session replay. No marketing tags.
The only cookies inside the application are the ones that keep you signed in and secure the app against abuse. Our own product analytics is configured deliberately narrowly: automatic capture is disabled, session recording is disabled, automatic pageview capture is disabled, and analytics state is held in memory rather than written to your browser's storage. We capture only events we have explicitly named in code, and those events go to our own analytics provider, never to an advertising platform.
11.3Do Not Track
Browsers vary in how they express tracking preferences and there is no common standard for Do Not Track, so we do not respond to it. We do respond to Global Privacy Control, which is a defined standard, and we treat it as a full opt-out under Section 9.4.
12Security
We protect your information with technical and organizational measures matched to its sensitivity.
Authentication is passwordless. Passkeys, with an emailed sign-in link as the fallback. A member who has not registered a passkey is never treated as a degraded account.
Sign-in links are single use and short lived. Opening the emailed link does not sign you in by itself; an explicit action on the page does. This is deliberate, so that automated systems that follow links in email cannot consume your link before you reach it.
Account recovery requires two independent factors: an emailed link and a one-time passcode to your verified phone. Neither alone is sufficient, and both must belong to the same member. Recovery ends in a newly registered credential rather than leaving you without one.
Sensitive actions require recent re-authentication. Changing your phone number, removing a member, exporting your data, and canceling all require that you authenticated within the last 10 minutes. An older session is refused and you are asked to sign in again.
Your phone number is treated as a security credential. Changing it requires a passkey where you have one registered, and cannot be initiated through any messaging channel. This protects against attacks that take over a phone number in order to take over an account.
Household data isolation is enforced in the database itself, not only in application code. The database role our application uses holds no privilege to bypass it, and a query that fails to specify a household returns nothing rather than everything.
Bank access tokens are encrypted with a key held in a platform secret store, distinct per environment, and readable only by the component that synchronizes bank data.
Sessions are secure and http-only, and expire after 30 days of inactivity.
Stored balances are verified against computed flows on every synchronization. If the two drift beyond tolerance, we stop showing you figures for the affected account until we have investigated, rather than showing you a number we do not trust.
Test and staging environments cannot reach production. They cannot read a real bank connection, send a real message, or charge a real card, and this is verified automatically rather than assumed.
We maintain a written information security program with a designated individual responsible for it, and we carry insurance appropriate to the data we hold.
No method of transmitting or storing data is completely secure, and we cannot guarantee absolute security. You help protect your account by keeping control of your devices, your email account, and your phone number.
If a breach affects your personal information, we will notify you as required by applicable law and without unreasonable delay.
13Retention, export, and deletion
While you subscribe, we retain your information to provide the service. Your financial history is the product: your books are useful precisely because they go back.
Your export is always available. Not only at exit. It contains your transactions with their filings and tags, and every monthly statement we have composed for you.
You can delete individual items at any time. Anything you have told MyKeeper can be corrected or deleted in the application. Deletion is enforced at the query layer, so a deleted item cannot appear in any future message.
When you cancel, you choose. At the moment of cancellation, not buried afterward, you choose whether we keep your file for 12 months in case you come back, or delete everything. Cancellation takes 2 interactions in the application. You never have to call or email us to cancel.
Your bank connections are disconnected immediately on cancellation or expiry, on every path, verified against Plaid. No connection survives your subscription.
Transactions your bank reports as removed are flagged rather than deleted, so your history stays reconcilable.
Some records survive deletion, because we are required to keep them or because deleting them would defeat their purpose:
| Record | Retained for | Why |
|---|---|---|
| Consent records | Duration of the relationship plus 7 years | They exist to prove what you agreed to and when. Deleting them destroys the evidence that protects you as much as us |
| Billing and payment records | 7 years from the transaction | Tax and financial reporting requirements |
| Normalized email and card fingerprint | 24 months from account closure | Prevents repeated free trials. Neither is readable as your address or your card number |
| Records subject to a legal hold | Until the hold lifts | Legal claim, investigation, or process |
| Backups | Up to 35 days | Backups rotate on a fixed schedule. Deleted data disappears from backups as they age out, and is never restored into the live service |
Aggregated and de-identified information is not personal information and is not deleted, because it cannot be linked back to you.
14Your privacy rights
Depending on where you live, you may have rights over your personal information. We extend the rights below to every household regardless of state of residence, because operating two standards would be worse for everyone, including us.
Access. Confirm whether we process information about you, and get a copy.
Portability. Get your information in a machine-readable format. Our export exists for this and is available at any time without asking us.
Correction. Correct information that is inaccurate. Most corrections you can make yourself in the application.
Deletion. Ask us to delete your information, subject to the exceptions in Section 13 and the household rules in Section 10.3. Deleting your MarginSheet account does not by itself remove data already held by an advertising platform; use the opt-out in Section 9.4 and the platform's own controls for that.
List of recipients. Request a list of the specific third parties to which we have disclosed your information. Sections 8.1 and 8.2 list them already.
Opt out of sale, sharing, and targeted advertising. This right is real and it applies to the marketing site data described in Section 3. Section 9.4 tells you how. It does not apply to your financial information, because that is never shared for advertising in the first place.
Opt out of profiling with legal or similarly significant effects. We do no such profiling.
Limit use of sensitive information. Our use of sensitive information is already limited to providing the service, securing it, and preventing fraud.
No discrimination. We will not deny you the service, charge you a different price, or give you a lesser service because you exercised a privacy right.
Appeal. If we decline a request, you may appeal by replying to our decision. We will respond within 45 days. If we deny your appeal, you may contact your state Attorney General.
California residents may also request information about disclosures to third parties for those third parties' own direct marketing purposes. We make no such disclosures. Your right to opt out of sharing for cross-context behavioral advertising is separate, is real, and is exercised under Section 9.4.
Nevada residents may direct us not to sell covered information. Use the same link in Section 9.4.
15How to exercise your rights
Email privacy@marginsheet.com or use the settings in the application.
To opt out of advertising sharing, you do not need to email anyone. Use the "Do Not Sell or Share My Personal Information" link in the site footer, or set a Global Privacy Control signal in your browser. No account and no identity verification is required to exercise that particular right.
Deleting your data and canceling your subscription are different things. Canceling ends your billing and lets you choose what happens to your file. A deletion request removes your information. If you want to stop paying, cancel in the application. If you want your records erased, say so plainly and we will confirm what will be deleted before we do it.
So that we can act on your request, tell us enough to verify that you are the person the information concerns, and describe what you want clearly enough that we can act on it. We verify through your account: a request from your verified email address, confirmed by a link we send to it, is normally sufficient. For deletion requests we may require a second factor.
We respond within the period the applicable law requires, and within 45 days where no shorter period applies. We do not charge a fee unless a request is excessive, repetitive, or manifestly unfounded, and if we conclude a fee applies we will tell you and explain why before doing the work.
Authorized agents. You may authorize an agent to make a request for you. We will ask for written proof of that authority, and we may still verify your identity directly.
If we cannot honor part of a request, we will tell you which part and why.
16Children and dependents
The Services are for adults. We do not knowingly collect personal information from anyone under 18, and nobody under 18 may create an account or be invited as a household member.
A household may mention a dependent to MyKeeper in the ordinary course of describing its circumstances, for example a child's first name and school costs. MyKeeper records only what is needed to answer a question about the household's money. It does not solicit information about children, does not build a profile of a child, and does not collect a child's contact information, date of birth, or government identifiers. Anything a household has told MyKeeper about a dependent can be deleted at any time, like any other context.
If we learn that we have collected personal information from someone under 18, we will delete it. If you believe a minor has provided us information, contact us at privacy@marginsheet.com.
17Business transfers
See Section 8.5.
18Where your data is stored
All personal information is stored in the United States.
The Services are offered to households in the United States only. If you access them from elsewhere, you are responsible for compliance with your local law, and you consent to your information being transferred to and processed in the United States.
19Changes to this policy
We may update this policy. When a change is material, we tell you before it takes effect, by email and by notice in the application, rather than quietly revising the page and updating a date.
The following are material changes by our own definition, and each will be announced: activating cross-household learning, publishing statistics or research beyond the Household Margin Index as described in Section 8.6, placing any advertising or third-party analytics technology inside the authenticated application, building an advertising audience from product usage, disclosing any financial information to an advertising platform, changing our model provider, adding a new category of recipient, or narrowing any right granted in Section 14.
The first three of those would reverse commitments this policy is built on. We do not intend to make them, and if we ever did, we would tell you before it took effect and not after.
If you want a copy of a prior version of this policy, ask us and we will send it to you.
20How to contact us
Margin Sheet LLC 1969 S Alafaya Trail #136 Orlando, FL 32828
General: support@marginsheet.com Privacy requests: privacy@marginsheet.com Web: https://marginsheet.com
If you have a disability and need this policy in an alternative format, contact us and we will provide one.