Your data, explained
Privacy Policy
Effective date: September 1, 2026 · Provider: Apercall LLC
Disclaimer
WealthTrackr is for informational and educational purposes only. It is not a financial advisor and does not provide personalized financial, investment, tax, or legal advice. All projections, ratios, and scores are estimates based on data you enter. Consult a licensed financial advisor before making financial decisions.
Our Privacy Promise
- If you sign in, your data is stored in your cloud account for sync and cross-device access.
- Web guest data stays in that browser session. The Chrome extension keeps its optional local expense ledger in Chrome storage so it remains available offline without an account.
- No ads. We do not sell your data.
- No behavioral analytics provider is enabled. No analytics consent cookie is set.
Information We Do NOT Collect
- Bank account numbers, credit card numbers, or Social Security numbers
- Investment account login credentials or bank transaction imports
- Government-issued ID numbers, physical address, date of birth, photos, or contact lists
- Camera, microphone, GPS location, browsing history, or advertising identifiers
Information We Collect
Account Information
- Email address (your login identifier)
- Password hash (Argon2id; never stored in plaintext)
App Data You Provide
When signed in, the app syncs: categories, financial items (assets and liabilities), net worth snapshots, monthly check-ins, goals, and app settings. This data is stored in PostgreSQL for cross-device sync.
Basic Technical Data
Our servers receive IP address and request metadata for security, troubleshooting, and service reliability.
How Your Data Is Stored
- Cloud data: PostgreSQL on our hosting provider (Railway), transmitted over HTTPS.
- Web auth: HttpOnly cookie; no tokens in browser storage.
- Mobile: tokens, PIN hashes, and app-lock settings use Expo SecureStore.
- Chrome extension: expenses stay in Chrome extension storage on this device; an account access token is stored there only while signed in and is removed when you sign out.
API Access
Personal API keys (Settings → API Keys) provide read-only access to your own data via the REST API. Keys cannot modify or delete data. Keep keys secret; revoke them anytime. See our Terms of Use.
Biometric Authentication
Face ID, Touch ID, and fingerprint unlock use your device's built-in authentication. Biometric data never reaches the app. A PIN fallback is always available.
Error Reporting
The Chrome extension uses the existing WealthTrackr Sentry project for crash diagnostics. Extension reports remove account identity, request details, breadcrumbs, free-text exception messages, and source context before sending. Expense descriptions, amounts, categories, notes, and account tokens are not included in extension reports.
Your Rights and Controls
- View: all your data is visible in the app.
- Edit: modify or delete any financial information.
- Export: download your data as JSON (Settings → Backup).
- Delete: delete your cloud account and associated data.
Security Measures
- Passwords hashed with Argon2id (with transparent bcrypt migration for legacy accounts).
- Authentication tokens in platform secure storage.
- API access authenticated and rate-limited.
- App content hidden when backgrounded.
Children's Privacy
WealthTrackr is designed for users 13 years of age and older. We do not knowingly collect personal information from children under 13.
Changes
We may update this policy occasionally. Continued use after changes means you accept the updated policy.
Contact
GitHub: apercallc/wealthtrackr · Email: security@apercallc.com