Priv Life Privacy Policy
Effective date: September 3, 2026 Last updated: September 13, 2026. Privstead is now called Priv Life, and the apps have moved to priv-life.com. Section 5A adds Priv Life Resident Tracker, a new app; nothing about what the existing apps collect or share has changed. Operator: DGDean, Ocala, Florida, United States Contact: info@dgdean.com
At Priv Life, you are not our product. Our apps are. This policy explains what each Priv Life app stores, why, who else touches it, and how you get it back or make it go away. It covers every app under priv-life.com: Budget, Vote, Resident Tracker, and any app we add later. Where an app needs its own rules, it has its own section below.
1. Who we are
Priv Life is built and run by DGDean, a one-person company in the United States. There is no sales team, no analytics team, and no advertising business. The only person with access to production systems is the operator, and this policy is written in that light.
2. The short version
- We store the data you need the apps to work, and nothing collected for its own sake.
- We will not sell or share your data without your permission. The only exception is the vendors we need to run the service, listed in the sub-processors table below, and they may use it only to provide that service to us.
- We never share it with advertisers, never use it to build profiles, and never show it to anyone you did not choose.
- Your bank login never reaches us. Plaid handles that, and we hold only an encrypted token that lets us read transactions.
- You can export your data, delete parts of it, or delete your whole account at any time.
3. Sign-in and identity (all apps)
We use Clerk to handle sign-in. When you create a Priv Life account, Clerk stores your email address, your name if you give one, your password hash or the identity provider you chose (for example Google), and session records. Clerk's handling is governed by its own privacy policy at https://clerk.com/legal/privacy.
Each Priv Life app stores your Clerk user id so it can tell your data from everyone else's. Vote also caches your name and email so an organization's roster can be displayed without a lookup on every row. Budget stores your email only if you have chosen to provide it. Each app also records the hour your account was last used (updated at most once an hour), which we read only as a total ("how many accounts were active this week"), never per person; see section 7.
One Priv Life account works across every app. A "welcome seen" flag is kept in your Clerk account metadata so the welcome message appears once, not once per app.
Sessions in Budget end after 30 minutes of inactivity.
4. Priv Life Budget
Budget is a personal budgeting tool for individuals and households. It is not for organizations.
4.1 What Budget stores
| Data | Where it comes from | Why we keep it |
|---|---|---|
| Linked bank connections: institution name and id, a Plaid item id, a sync cursor, the last sync time, and an encrypted Plaid access token | Plaid, when you link a bank | To import your transactions and refresh balances |
| Accounts: name, official name, last four digits, type and subtype, current and available balance, currency | Plaid, or entered by you for accounts you keep by hand | To show balances and net worth |
| Transactions: date, amount, description, merchant name, pending flag, Plaid's category guess, and the Plaid transaction id | Plaid, entered by you, or imported from a CSV file you upload | To show spending and income and to track budgets |
| Your own additions: categories, subcategories, two custom dimensions and their values, budgets per month, notes on transactions, transfer pairings | You | To organize and report on your money the way you want |
| Manual assets and debts: name, kind, value, notes, the date you last valued it | You | To include property, vehicles and private loans in net worth |
| Retirement plan: birth year, target age, starting balance and spending, growth and inflation rates, per-year overrides and notes | You | To run the retirement projection |
| Timestamps on every record | Automatic | To show when a balance was last updated and to keep records consistent |
Budget does not store your bank username or password, your full account number, your card number, or your Social Security number. Plaid does not give us those, and we do not ask you for them.
4.2 How Plaid works with Budget
When you link a bank, Plaid Link opens inside the app. You enter your bank credentials into Plaid, not into Priv Life. Plaid returns a short-lived public token; our server exchanges it for a permanent access token and stores that token encrypted with AES-256-GCM. The token never reaches your browser and is never written to logs.
We use Plaid's Transactions product only. When you link a bank we ask Plaid for up to two years of history. After that, Plaid notifies our server when new transactions are available, and we fetch them. You can also trigger a sync yourself.
Plaid's collection and handling of your data is governed by Plaid's End User Privacy Policy at https://plaid.com/legal/#end-user-privacy-policy. By linking a bank through Priv Life you also agree to that policy. You can review and revoke Plaid connections through Plaid Portal at https://my.plaid.com.
4.3 CSV import and export
You can export the transactions you see to a CSV file, and import a CSV from a bank or from an earlier export. Imported files are parsed in your browser. Only the rows you choose to import are sent to our server, and the file itself is never uploaded or stored.
4.4 Shared categories
An administrator can create categories that every Budget user can select. Those are category names only. No one, including the administrator, can see another user's transactions, balances, or budgets through the app.
5. Priv Life Vote
Vote runs elections for organizations such as volunteer ambulance corps, fire companies and clubs.
5.1 What Vote stores
| Data | Where it comes from | Why we keep it |
|---|---|---|
| Your Clerk user id, name and email | Clerk | To show you on an organization's roster and turnout list |
| Organizations: name, tagline, color, emblem, invite code, allowed email domains, required sign-in provider, roster-only setting | The organization's admins | To brand and control who may join |
| Roster entries: email and optional name of expected members, and which account claimed each | The organization's admins | To let admins pre-load who belongs and see who has not yet joined |
| Memberships: which organizations you belong to and your role | You joining, or an admin | To decide what you may see and do |
| Elections, questions and options | The organization's admins | To run the vote |
| A record that you voted in a given election | Cast automatically when you vote, or entered by an admin for a returned paper ballot | To show turnout and to prevent voting twice |
| Ballots: the choices made, with no link to who made them | Cast automatically when you vote, or entered by an admin from a paper ballot | To count the results |
5.2 How your ballot stays secret
Every vote writes two records in one database transaction. The first says that you voted in this election. It has no timestamp, and its id is random rather than sequential. The second is the ballot itself: the choices, with no user id, no timestamp, and a random id. Nothing stored can join the two back together.
Results are counted only after an election closes. Organization admins can see who has voted and who has not. They cannot see how anyone voted, and neither can we.
This design defeats every honest path: the app, the API, the admins, and the data itself. It is not a cryptographic voting system. With a very small number of voters, a public tally alone can narrow down how people voted, and no system avoids that. A hostile database operator could in principle try to correlate rows by their physical storage order. We are the only database operator, and we do not do this.
5.3 Organization admins
An organization's admins control its roster, its members, and its elections. They see the names and emails of members and roster entries. Ask your organization who its admins are. Admins are bound by these terms not to use member data for anything other than running the organization's elections.
5A. Priv Life Resident Tracker
Resident Tracker records which US state you were in on each day, so you can count days per state for tax residency. It is a personal app: nobody else can see your records, including any organization you belong to.
5A.1 What Resident Tracker stores
| Data | Where it comes from | Why we keep it |
|---|---|---|
| Your Clerk user id, name and email | Clerk | To keep your records apart from everyone else's |
| Day records: a date, a state code, and whether you entered it by hand or with a check-in | You | To count days per state |
| Check-ins: the time, the date, the state, and how accurate your device said the location was | You, when you tap "Check in today" | To keep a dated record of where you checked in |
| Coordinates on a check-in, rounded to about 110 meters | You, only if you turn on "Keep coordinates as evidence" | So you have supporting evidence if a tax authority asks where you were |
| Your setting for keeping coordinates | You | To know whether to store coordinates |
5A.2 How location works
Resident Tracker never reads your location in the background and never checks in on its own. A check-in happens only when you tap the button and your browser asks your permission.
Your browser works out which state you are in on your own device, using a map of state boundaries that ships with the app. By default only the state, the time, and the accuracy figure are sent to us. Your coordinates are sent only if you have turned on "Keep coordinates as evidence", and we round them to about 110 meters before storing them. If that setting is off, we discard any coordinates we receive.
You can remove every stored coordinate at any time from Settings, and turn the setting off so no more are kept.
5A.3 Not tax advice
Day counts are a record, not a tax opinion. States count days and decide residency differently. Confirm your situation with a tax professional.
6. What we never do
- We do not sell your data, rent it, or trade it.
- We do not use your data for advertising, and we show no ads.
- We do not mine your data to build profiles, train models, or infer things about you.
- We do not share your data with anyone you did not choose, other than the service providers below who are needed to run the apps.
- We do not read your data except to fix a problem you have reported or to keep the service running, and then only as much as the problem requires.
7. Service providers
The following providers process data on our behalf. Each is used only for the purpose listed.
| Provider | What it does | What it sees |
|---|---|---|
| Plaid Inc. | Connects to your bank and delivers transactions | Your bank credentials (entered directly with Plaid), account and transaction data |
| Clerk Inc. | Sign-in and session management | Your email, name, sign-in method, and session records |
| Google Cloud (Cloud Run, Cloud SQL, Secret Manager, Cloud Logging) | Runs our servers and database in the United States | Everything the apps store, encrypted at rest by Google |
| Firebase Hosting (Google) | Serves the web pages | Your IP address and request logs in the ordinary course of serving pages |
| GitHub | Hosts our source code | No user data. Code only |
| Fontshare (Indian Type Foundry) | Serves the Satoshi typeface | Your IP address and browser details when the font loads |
We have no other processors. We do not use third-party analytics, tracking pixels, session recording, cross-site tracking, behaviour profiles, or advertising scripts.
We do count aggregate usage from our own servers: how many requests each app served and how many failed, by route and day, and how many accounts were active in the last day, week and month. To produce the active-account count, each app records the hour your account was last used. These counts contain no user ids and no per-person history, they are stored in our own database, and they are only ever read as totals by the operator.
8. Where data lives
Our servers and database run in Google Cloud's us-central1 region in the United States. If you use Priv Life from outside the United States, your data is transferred to and stored there.
9. How long we keep data, and how to delete it
Budget, disconnecting a bank. When you remove a bank you choose one of two things. "Disconnect, keep history" destroys the stored Plaid token, tells Plaid to forget the connection, and keeps the imported transactions so your categories and notes on them survive. "Delete everything" does the same and also deletes the bank's accounts and every transaction imported from it.
Budget, manual data. Transactions you entered or imported, manual accounts, assets, categories, budgets and the retirement plan can be deleted individually in the app.
Vote. Organization admins can delete elections, including open and closed ones, and can remove members and roster entries. Ballots belong to the election and go with it.
Resident Tracker. Your day records and check-ins stay until you delete them. You can clear individual days on the calendar, remove every stored coordinate, or delete all of your Resident Tracker data from Settings; deletion is immediate. You can export any year as a CSV file first. Keep your own copy for as long as a tax authority might ask: we do not keep deleted records for you.
Deleting your account. Email info@dgdean.com from the address on your account. We delete your Clerk account and every record tied to your user id in every Priv Life app within 30 days, and confirm when it is done. In Vote, the record that you voted in a past election is deleted with your account; the anonymous ballot stays, because it was never linked to you and removing it would change a closed result.
Backups. Our database is backed up automatically by Google Cloud SQL. Backups are retained for 7 days and then expire, so deleted data leaves backups within that window.
Logs. Server logs record request paths, status codes, timings, and error messages. They do not record transaction contents, balances, or tokens. Logs are retained for 30 days.
10. Security
- Bank credentials never reach us. Plaid tokens are encrypted at rest with AES-256-GCM using a key held in Google Secret Manager, separate from the database.
- All traffic uses HTTPS. Our servers are reached only through Firebase Hosting and Cloud Run, both of which enforce TLS.
- Every API request must carry a valid Clerk session, and every database query is scoped to the signed-in user's id. Identity is never taken from the request body.
- Plaid's notifications to our server are verified by signature before they are acted on.
- Secrets live in Google Secret Manager, not in code or in deployment settings. Our source repository is configured to refuse secret files.
- Google encrypts the database and its backups at rest.
- Administrative consoles (Google Cloud, Clerk, Plaid, GitHub, Firebase) are protected with multi-factor authentication.
No system is perfectly secure. If we learn of a breach affecting your data we will tell you by email within 72 hours of confirming it, say what was affected, and say what we are doing about it.
11. Your rights
You can, at any time:
- See everything the apps hold about you, by using the apps, or by asking us for a copy.
- Export your Budget transactions with the Export CSV button, and ask us for an export of anything else.
- Correct anything you entered, in the app.
- Delete individual records in the app, or your whole account by email.
- Revoke a bank connection in the app or through Plaid Portal.
We honor these rights for everyone, wherever you live. If you are in a jurisdiction with specific privacy laws, such as California, the European Union or the United Kingdom, those rights apply too and you can exercise them the same way. We do not discriminate against anyone for exercising them.
12. Children
Priv Life is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.
13. Cookies and local storage
We set only what sign-in and the apps need: Clerk's session cookies, and a small amount of browser storage for preferences such as whether Budget's net worth figures are hidden. There are no advertising or analytics cookies.
14. Changes to this policy
When we change this policy we update the effective date at the top and, for changes that affect what we collect or share, tell you in the app before they take effect.
15. Contact
DGDean 8625 SW 5th Pl Road, Ocala, FL 34481 info@dgdean.com