Privacy Policy
Last updated: June 29, 2026
Glass Jar ("Glass Jar", "we", "us") helps people and groups see and understand their spending. We built Glass Jar around a simple idea: your financial information is yours. This policy explains what we collect, why, how it's protected, and the choices you have. By using the Glass Jar app you agree to this policy.
1. Information we collect
We collect only what's needed to run the service:
- Account information — your name, email address, and a securely hashed password. If you sign in with Apple, we receive the identifier Apple provides.
- Spending data you create — the transactions, amounts, merchants, categories, notes, tags, splits, settlements, and workspaces you enter or import. This is the core content of the app.
- Imported data — when you import a CSV or JSON file, we process its rows to create transactions. The original file is not stored after import.
- Group membership — who is in a workspace with you and the role each person has, so shared spending can be attributed.
- Technical data — basic, security-related request and error logs (such as timestamps and error messages) needed to operate and protect the service.
We do not sell your data, and we do not use your financial data for advertising.
2. Optional bank connections (Plaid)
Glass Jar works fully with manual entry and file imports. If you choose to connect a bank or card account, we use Plaid Inc. ("Plaid") to link it securely — a feature that is optional and only active when you connect it. When you connect an account, you authorize Plaid to access information from the financial institution(s) you select; Plaid then provides that information to Glass Jar together with a secure access token.
- What we receive via Plaid: your transaction history for the accounts you connect (such as date, amount, and merchant/description) and basic account identifiers. We use the Plaid Transactions product only.
- How we use it: solely to import and display your transactions within your Glass Jar workspace. We do not sell it and do not use it for advertising.
- Credentials: we never see or store your online-banking username or password — those are entered directly with Plaid and your institution.
- Storage & control: the Plaid access token is stored encrypted. You can disconnect a bank at any time, which revokes our access and removes the transactions synced from it.
Plaid's collection and use of your information is governed by Plaid's End User Privacy Policy. By connecting an account, you also agree to Plaid's policy.
3. How we use information
- To provide the core service: showing your spending, balances, settlements, and insights.
- To share spending within a workspace among its members, according to that workspace's visibility settings.
- To secure the service, prevent abuse, and fix problems.
- To communicate with you about your account or important changes to the service.
4. How information is shared
- With your workspace members — spending you add to a shared workspace is visible to other members, subject to the workspace's visibility controls. You choose which workspaces you join and what you add to them.
- With service providers — we use trusted providers to run Glass Jar: Google Cloud (hosting, secrets) and Neon (database) for infrastructure, Plaid for optional bank connections, and Apple for push notifications and Sign in with Apple. They process data only on our behalf and under contract.
- For legal reasons — if required by law or to protect rights, safety, and the integrity of the service.
We do not sell or rent personal information to anyone.
5. Security
Connections to Glass Jar use encryption in transit (HTTPS/TLS). Passwords are stored using a strong one-way hash, never in plain text. Data is stored with reputable cloud providers and access is restricted. No system is perfectly secure, but we take reasonable, industry-standard measures to protect your information.
6. Data retention & deletion
We keep your information for as long as your account is active. You can delete individual transactions and workspaces at any time in the app. You can also delete your entire account from Settings — doing so removes your personal data and, if you are the owner of a workspace, that workspace and its data are deleted as well. Some minimal records may be retained briefly where required for security or legal compliance.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. You can exercise most of these directly in the app, or contact us and we'll help. We won't discriminate against you for exercising your privacy rights.
8. Children
Glass Jar is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their information. If you believe a child has provided us data, contact us and we'll remove it.
9. International users
Glass Jar may process and store information in countries other than your own, including the United States. Where we transfer data, we take steps to protect it consistent with this policy.
10. Changes to this policy
We may update this policy as the app evolves. We'll revise the "Last updated" date above and, for material changes, provide a more prominent notice. Continued use after changes means you accept the updated policy.
11. Contact
Questions about privacy? Email us at privacy@glassjar.dev.