Skip to content

Privacy notice

Last reviewed 2026-08-16. This describes NetWorthy as it actually operates today, not as a future release might.

What we are

NetWorthy is a personal-finance tracker: net worth, budgeting, debt payoff, bills, and goals, built by Garrett Makes It, LLC. NetWorthy never moves money — no transfers, no bill pay, no order routing — and nothing on the product is or ever will be a recommendation to buy or sell a specific security. This notice covers the NetWorthy product and its API only.

Data we collect

We collect only what the product needs to do what you asked it to do:

  • Account and authentication data — the email and password you sign up with, handled entirely by Supabase Auth. We never see or store your password ourselves. If you sign in with Google, Apple, or Facebook instead, see "Who processes your data" below for what that involves.
  • Financial data you enter directly — accounts, balances, assets, liabilities, budget envelopes, bills, and goals you type in by hand.
  • Bank and brokerage data, when you connect an account — account balances, transaction history, and holdings, pulled through a linked aggregation provider once that integration is live in your region. Aggregation is read-only: we can never initiate a transfer or a trade with it.
  • Health-adjacent spend — if you use NetWorthy alongside MuscleBuddy, certain categories of spend (therapy, medication, lab work) can arrive as expense records through that integration. This is health data: it is consent-gated, hidden from your transaction list by default, never shared to any social feature regardless of that setting, and covered by both account deletion and the data export below. You control this consent from Settings → Privacy at any time.
  • Support and feedback content — anything you submit through the in-app feedback form, which files as a GitHub issue (see "Who processes your data" below).
  • Payment data — if you subscribe to a paid module, billing is handled entirely by Stripe. NetWorthy stores a Stripe customer and subscription reference, never your card number.

Who processes your data

We do not sell your data, and we do not share it with anyone for their own marketing purposes. The following sub-processors handle data strictly to run the product on our behalf:

  • Supabase — authentication, the primary database, and private object storage for uploaded receipt attachments (served only via short-lived signed URLs, never a public link).
  • Resend — outbound transactional email (notifications, digests).
  • web-push / your browser vendor — browser push notifications, delivered through the standard Web Push protocol via whichever push service your browser uses (e.g. Google, Mozilla, Apple).
  • Massive — market-data pricing for securities you hold. This traffic is symbol and price lookups; it does not carry your identity or account data.
  • Stripe — billing and subscription management for paid modules.
  • Sentry — error monitoring, on both the server and in your browser. Sentry receives exception details and stack traces when something goes wrong, which can incidentally include whatever request or app state was present at the moment of failure.
  • Plausible — traffic measurement on our public marketing pages (the landing page, guides, blog, docs, tools and glossary) and nowhere else. It is cookieless and stores no identifier: it records the page URL, the referring site, and a coarse browser and country, all aggregated. No page you see while signed in is ever reported to it, and neither is an advisor share link.
  • Cloudflare Turnstile — a bot check on the sign-in and sign-up form. It sees your IP address and how your browser behaves on that page, which is what distinguishes a person from an automated credential-stuffing attempt. It never receives your email, your password, or anything in your account.
  • Google, Apple, or Facebook — only if you choose to sign in with one of them instead of an email and password. That provider receives the redirect address we send you back to and the scopes we request (your name and email address); we receive back your name, email address, and an identifier for your account with that provider, via Supabase Auth. We never see your password with that provider.
  • GitHub — in-app feedback is filed as an issue in our private tracker. The page URL, route, and user agent attached to a report are redacted of anything identifying before the issue is created.
  • Railway and Vercel — hosting for the API and the web application, respectively.
  • A bank-data aggregator — once a provider is connected for your account, the aggregator that supplies balance and transaction data. No aggregator is live yet; the product's aggregation port has no adapter wired into production today, so nothing is sent to one.

If you use NetWorthy through MuscleBuddy or another Life OS product, that product's own privacy notice covers what it collects from you directly; NetWorthy only receives the specific records (expense, asset, revenue) that product's own consent flow sends us.

Financial privacy notice

This section is our financial privacy notice, in the shape US financial-privacy law (the Gramm-Leach-Bliley Act) expects. It covers nonpublic personal information — the financial information you give us, and the account and transaction information we obtain on your behalf.

What we collect. Account balances and types, transaction history, holdings and share counts, assets and property values, debts and their rates, income and budget figures, bills and due dates, and the goals you set. Some of this you type in; some arrives from an institution you connected. Together with your contact details, this is the nonpublic personal information this section governs.

Why we collect it. To provide the product you asked for and nothing else: computing your net worth, running your budget, projecting a payoff schedule, reminding you about a bill.

Who we share it with, and who we do not. We do not sell your nonpublic personal information. We do not share it with non-affiliated third parties for their own marketing purposes, and we do not share it for joint marketing with other financial institutions. The only parties who handle it are the sub-processors named above, strictly to run the product on our behalf, and any party you yourself direct us to share with — a Life OS partner link you approved, or an advisor share link you created and can revoke.

Your opt-out right. Because we do not share nonpublic personal information with non-affiliated third parties for their own purposes, there is nothing you need to opt out of, and no opt-out election you make could reduce what is shared. If that ever changes, we will tell you before it takes effect and give you a genuine opt-out first. You can still revoke any sharing you initiated — disconnect a partner link or delete an advisor share — from your settings at any time.

How we protect it. Access to your data is scoped to your own account. Credentials for a connected institution are encrypted, and every decryption is written to an audit log by the same code path that performs it, so a read that skipped the log cannot exist. Attachments are stored privately and served only through short-lived signed links.

Your privacy choices (California)

Notice at collection. We collect the categories described above: identifiers (your email), commercial and financial information (accounts, transactions, holdings, debts, budgets, bills, goals), internet activity strictly necessary to run the app, and — only if you turn it on — health-adjacent spend. We collect them for the purposes described above, and we keep them for as long as your account exists.

Sensitive personal information. Your financial account information, and health-adjacent spend if you have enabled it, are sensitive personal information. We use them only to provide the product you asked for and for related operational purposes such as security and support — never to infer characteristics about you. Because we do not use sensitive personal information for any purpose beyond those, the right to limit its use does not reduce anything; enabling or revoking the health-adjacent consent in Settings → Privacy is the control that actually changes what we hold.

We do not sell or share your personal information — not for money, and not for cross-context behavioural advertising, which is what "share" means under California law. We have not done so in the preceding twelve months. There is no advertising network and no data broker in the product, and the one analytics vendor (Plausible, above) is cookieless, confined to our public marketing pages, and collects no identifier that could be used to build a profile of you.

Turning traffic measurement off. Plausible reports a page path and nothing else, only on these public pages, and never on a signed-in screen. Because it stores nothing on your device it is on unless you turn it off, which you can do here or from "Cookie settings" in the footer of any page. Turning it off stops the reporting and keeps the script from loading at all.

Global Privacy Control. Because we do not sell or share personal information, there is no sale or share for a GPC signal to stop. We honour it anyway on the one thing it can reach: a browser sending GPC gets traffic measurement off, and cannot be opted back in from the control above.

Non-discrimination. Exercising any of these rights never changes your price or the features available to you.

How long we keep it

A formal, published retention schedule — how long a closed account's data or a stale audit log is kept before deletion — is in progress. Until it ships, we intentionally do not commit to a specific retention window here rather than publish one we cannot yet back up operationally. Deleting your account (see below) removes your data immediately rather than waiting on that schedule.

Two records outlive a deleted account, and they are the only ones that do. The security audit log records who did what to your account, and a compliance log a member can erase records nothing. Your acceptance of these documents — which version of the Terms of Service and this notice you agreed to, and when — is the record that our agreement was formed, and a record of an agreement that either side can delete proves nothing about it. Neither contains your financial data: no balances, transactions, holdings, or goals survive deletion.

Your rights

You can, at any time:

  • Review and adjust your health-data consent from Settings → Privacy.
  • Manage your sign-in and security settings — password, MFA — from Settings → Security.
  • Manage a connected Life OS partner link from Settings → Connected apps, including revoking it.
  • Export your whole account as JSON, from Settings → Privacy. You confirm it with a verification code first, the same as any other sensitive action.
  • Delete your account and its data, also from Settings → Privacy. Deletion removes your data rather than deactivating it, and it sweeps stored attachments as well as database rows. If you would rather we handled it, email support@networthy.app from your account's email address and we will do it for you.

Questions

Reach us at support@networthy.app for anything in this notice, including a request under GDPR, CCPA, or a similar regional privacy law. We aim to reply within two business days, and to complete a request made under one of those laws within the period that law allows.