Priv Life

Priv Life Privacy Policy

Effective date: September 3, 2026 Last updated: September 13, 2026. Privstead is now called Priv Life, and the apps have moved to priv-life.com. Section 5A adds Priv Life Resident Tracker, a new app; nothing about what the existing apps collect or share has changed. Operator: DGDean, Ocala, Florida, United States Contact: info@dgdean.com

At Priv Life, you are not our product. Our apps are. This policy explains what each Priv Life app stores, why, who else touches it, and how you get it back or make it go away. It covers every app under priv-life.com: Budget, Vote, Resident Tracker, and any app we add later. Where an app needs its own rules, it has its own section below.

1. Who we are

Priv Life is built and run by DGDean, a one-person company in the United States. There is no sales team, no analytics team, and no advertising business. The only person with access to production systems is the operator, and this policy is written in that light.

2. The short version

3. Sign-in and identity (all apps)

We use Clerk to handle sign-in. When you create a Priv Life account, Clerk stores your email address, your name if you give one, your password hash or the identity provider you chose (for example Google), and session records. Clerk's handling is governed by its own privacy policy at https://clerk.com/legal/privacy.

Each Priv Life app stores your Clerk user id so it can tell your data from everyone else's. Vote also caches your name and email so an organization's roster can be displayed without a lookup on every row. Budget stores your email only if you have chosen to provide it. Each app also records the hour your account was last used (updated at most once an hour), which we read only as a total ("how many accounts were active this week"), never per person; see section 7.

One Priv Life account works across every app. A "welcome seen" flag is kept in your Clerk account metadata so the welcome message appears once, not once per app.

Sessions in Budget end after 30 minutes of inactivity.

4. Priv Life Budget

Budget is a personal budgeting tool for individuals and households. It is not for organizations.

4.1 What Budget stores

Data Where it comes from Why we keep it
Linked bank connections: institution name and id, a Plaid item id, a sync cursor, the last sync time, and an encrypted Plaid access token Plaid, when you link a bank To import your transactions and refresh balances
Accounts: name, official name, last four digits, type and subtype, current and available balance, currency Plaid, or entered by you for accounts you keep by hand To show balances and net worth
Transactions: date, amount, description, merchant name, pending flag, Plaid's category guess, and the Plaid transaction id Plaid, entered by you, or imported from a CSV file you upload To show spending and income and to track budgets
Your own additions: categories, subcategories, two custom dimensions and their values, budgets per month, notes on transactions, transfer pairings You To organize and report on your money the way you want
Manual assets and debts: name, kind, value, notes, the date you last valued it You To include property, vehicles and private loans in net worth
Retirement plan: birth year, target age, starting balance and spending, growth and inflation rates, per-year overrides and notes You To run the retirement projection
Timestamps on every record Automatic To show when a balance was last updated and to keep records consistent

Budget does not store your bank username or password, your full account number, your card number, or your Social Security number. Plaid does not give us those, and we do not ask you for them.

4.2 How Plaid works with Budget

When you link a bank, Plaid Link opens inside the app. You enter your bank credentials into Plaid, not into Priv Life. Plaid returns a short-lived public token; our server exchanges it for a permanent access token and stores that token encrypted with AES-256-GCM. The token never reaches your browser and is never written to logs.

We use Plaid's Transactions product only. When you link a bank we ask Plaid for up to two years of history. After that, Plaid notifies our server when new transactions are available, and we fetch them. You can also trigger a sync yourself.

Plaid's collection and handling of your data is governed by Plaid's End User Privacy Policy at https://plaid.com/legal/#end-user-privacy-policy. By linking a bank through Priv Life you also agree to that policy. You can review and revoke Plaid connections through Plaid Portal at https://my.plaid.com.

4.3 CSV import and export

You can export the transactions you see to a CSV file, and import a CSV from a bank or from an earlier export. Imported files are parsed in your browser. Only the rows you choose to import are sent to our server, and the file itself is never uploaded or stored.

4.4 Shared categories

An administrator can create categories that every Budget user can select. Those are category names only. No one, including the administrator, can see another user's transactions, balances, or budgets through the app.

5. Priv Life Vote

Vote runs elections for organizations such as volunteer ambulance corps, fire companies and clubs.

5.1 What Vote stores

Data Where it comes from Why we keep it
Your Clerk user id, name and email Clerk To show you on an organization's roster and turnout list
Organizations: name, tagline, color, emblem, invite code, allowed email domains, required sign-in provider, roster-only setting The organization's admins To brand and control who may join
Roster entries: email and optional name of expected members, and which account claimed each The organization's admins To let admins pre-load who belongs and see who has not yet joined
Memberships: which organizations you belong to and your role You joining, or an admin To decide what you may see and do
Elections, questions and options The organization's admins To run the vote
A record that you voted in a given election Cast automatically when you vote, or entered by an admin for a returned paper ballot To show turnout and to prevent voting twice
Ballots: the choices made, with no link to who made them Cast automatically when you vote, or entered by an admin from a paper ballot To count the results

5.2 How your ballot stays secret

Every vote writes two records in one database transaction. The first says that you voted in this election. It has no timestamp, and its id is random rather than sequential. The second is the ballot itself: the choices, with no user id, no timestamp, and a random id. Nothing stored can join the two back together.

Results are counted only after an election closes. Organization admins can see who has voted and who has not. They cannot see how anyone voted, and neither can we.

This design defeats every honest path: the app, the API, the admins, and the data itself. It is not a cryptographic voting system. With a very small number of voters, a public tally alone can narrow down how people voted, and no system avoids that. A hostile database operator could in principle try to correlate rows by their physical storage order. We are the only database operator, and we do not do this.

5.3 Organization admins

An organization's admins control its roster, its members, and its elections. They see the names and emails of members and roster entries. Ask your organization who its admins are. Admins are bound by these terms not to use member data for anything other than running the organization's elections.

5A. Priv Life Resident Tracker

Resident Tracker records which US state you were in on each day, so you can count days per state for tax residency. It is a personal app: nobody else can see your records, including any organization you belong to.

5A.1 What Resident Tracker stores

Data Where it comes from Why we keep it
Your Clerk user id, name and email Clerk To keep your records apart from everyone else's
Day records: a date, a state code, and whether you entered it by hand or with a check-in You To count days per state
Check-ins: the time, the date, the state, and how accurate your device said the location was You, when you tap "Check in today" To keep a dated record of where you checked in
Coordinates on a check-in, rounded to about 110 meters You, only if you turn on "Keep coordinates as evidence" So you have supporting evidence if a tax authority asks where you were
Your setting for keeping coordinates You To know whether to store coordinates

5A.2 How location works

Resident Tracker never reads your location in the background and never checks in on its own. A check-in happens only when you tap the button and your browser asks your permission.

Your browser works out which state you are in on your own device, using a map of state boundaries that ships with the app. By default only the state, the time, and the accuracy figure are sent to us. Your coordinates are sent only if you have turned on "Keep coordinates as evidence", and we round them to about 110 meters before storing them. If that setting is off, we discard any coordinates we receive.

You can remove every stored coordinate at any time from Settings, and turn the setting off so no more are kept.

5A.3 Not tax advice

Day counts are a record, not a tax opinion. States count days and decide residency differently. Confirm your situation with a tax professional.

6. What we never do

7. Service providers

The following providers process data on our behalf. Each is used only for the purpose listed.

Provider What it does What it sees
Plaid Inc. Connects to your bank and delivers transactions Your bank credentials (entered directly with Plaid), account and transaction data
Clerk Inc. Sign-in and session management Your email, name, sign-in method, and session records
Google Cloud (Cloud Run, Cloud SQL, Secret Manager, Cloud Logging) Runs our servers and database in the United States Everything the apps store, encrypted at rest by Google
Firebase Hosting (Google) Serves the web pages Your IP address and request logs in the ordinary course of serving pages
GitHub Hosts our source code No user data. Code only
Fontshare (Indian Type Foundry) Serves the Satoshi typeface Your IP address and browser details when the font loads

We have no other processors. We do not use third-party analytics, tracking pixels, session recording, cross-site tracking, behaviour profiles, or advertising scripts.

We do count aggregate usage from our own servers: how many requests each app served and how many failed, by route and day, and how many accounts were active in the last day, week and month. To produce the active-account count, each app records the hour your account was last used. These counts contain no user ids and no per-person history, they are stored in our own database, and they are only ever read as totals by the operator.

8. Where data lives

Our servers and database run in Google Cloud's us-central1 region in the United States. If you use Priv Life from outside the United States, your data is transferred to and stored there.

9. How long we keep data, and how to delete it

Budget, disconnecting a bank. When you remove a bank you choose one of two things. "Disconnect, keep history" destroys the stored Plaid token, tells Plaid to forget the connection, and keeps the imported transactions so your categories and notes on them survive. "Delete everything" does the same and also deletes the bank's accounts and every transaction imported from it.

Budget, manual data. Transactions you entered or imported, manual accounts, assets, categories, budgets and the retirement plan can be deleted individually in the app.

Vote. Organization admins can delete elections, including open and closed ones, and can remove members and roster entries. Ballots belong to the election and go with it.

Resident Tracker. Your day records and check-ins stay until you delete them. You can clear individual days on the calendar, remove every stored coordinate, or delete all of your Resident Tracker data from Settings; deletion is immediate. You can export any year as a CSV file first. Keep your own copy for as long as a tax authority might ask: we do not keep deleted records for you.

Deleting your account. Email info@dgdean.com from the address on your account. We delete your Clerk account and every record tied to your user id in every Priv Life app within 30 days, and confirm when it is done. In Vote, the record that you voted in a past election is deleted with your account; the anonymous ballot stays, because it was never linked to you and removing it would change a closed result.

Backups. Our database is backed up automatically by Google Cloud SQL. Backups are retained for 7 days and then expire, so deleted data leaves backups within that window.

Logs. Server logs record request paths, status codes, timings, and error messages. They do not record transaction contents, balances, or tokens. Logs are retained for 30 days.

10. Security

No system is perfectly secure. If we learn of a breach affecting your data we will tell you by email within 72 hours of confirming it, say what was affected, and say what we are doing about it.

11. Your rights

You can, at any time:

We honor these rights for everyone, wherever you live. If you are in a jurisdiction with specific privacy laws, such as California, the European Union or the United Kingdom, those rights apply too and you can exercise them the same way. We do not discriminate against anyone for exercising them.

12. Children

Priv Life is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.

13. Cookies and local storage

We set only what sign-in and the apps need: Clerk's session cookies, and a small amount of browser storage for preferences such as whether Budget's net worth figures are hidden. There are no advertising or analytics cookies.

14. Changes to this policy

When we change this policy we update the effective date at the top and, for changes that affect what we collect or share, tell you in the app before they take effect.

15. Contact

DGDean 8625 SW 5th Pl Road, Ocala, FL 34481 info@dgdean.com