Privacy Policy

Last Updated: September 13, 2026

GlimmerMaster LLC ("we," "our," or "us") operates InkWyrm at https://www.inkwyrm.app and in the InkWyrm iOS application on the Apple App Store (bundle identifier app.inkwyrm.mobile) (the "Service"). The iOS application loads the same Service as the website. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

Information We Collect

Account Information

When you create an account — with email and password, Google, or Sign in with Apple — we collect:

  • Full name and email address (if you use Sign in with Apple, Apple may hide your real email behind a relay)
  • Password (stored in hashed form), when you choose email and password
  • Billing information (processed by Stripe on the website; we do not use Apple In-App Purchase)
  • Profile picture and preferences, including Privacy Mode (Hide Amounts), which hides dollar amounts on screen and does not change what we collect or store

User-Generated Content

We store content you create, upload, or submit through the Service, including:

  • User-generated financial and organizational content, including custom budget categories, account balances, transaction logs, custom notes, user profile configurations, and account authentication details.
  • Comments, annotations, and collaborative content
  • File attachments and uploads

Usage Data

We automatically collect:

  • Application Logs: Feature usage, actions performed, errors encountered
  • Device Information: Browser type, operating system, screen resolution, device type
  • Network Information: IP address, approximate location (city/country level)
  • Session Data: Login times, session duration, pages/features accessed
  • Performance Data: Load times, crashes, and diagnostic information

Information from Third Parties

We may receive information from:

  • Authentication Providers: If you sign in via Google, Apple, or other OAuth providers
  • Plaid: If you link a financial account, we receive institution and account details, balances, and transaction history (see "Financial Account Data" below)
  • Stripe: Subscription status, tier, billing period, payment outcomes, refunds and disputes, and invoice receipts (we do not store full card numbers)
  • Analytics Services: Aggregated usage patterns

Financial Account Data (Plaid)

If you choose to connect a bank, credit card, loan, or investment account, we use Plaid Inc. to establish that connection. You provide your credentials directly to Plaid — we never see or store your online banking username or password. Plaid returns to us an access token plus the account and transaction data you authorize.

Data we receive and store for linked accounts includes:

  • Institution name, account name, account type and subtype, and a masked account number
  • Current and available balances, and, for liabilities, balance, APR, minimum payment, and due date where provided
  • Transaction date, description, merchant, amount, pending status, and category

We also receive webhook notifications from Plaid so new and updated transactions can sync automatically. This data is used solely to display, categorize, and report on your finances inside the Service. We do not sell it, use it for advertising, or share it with third parties for their own marketing.

You may disconnect a linked account at any time from Bank Connections in Settings. Disconnecting revokes our access token with Plaid so no further data is retrieved. You may keep or delete the records already imported. Plaid's handling of your data is governed by Plaid's own end user privacy policy.

Shared Realms, Shared Ledgers, and Public Sharing

Shared Realms and Shared Ledgers. If you invite another user into your workspace, or accept an invitation to one, financial data in that shared workspace — accounts, balances, transactions, Ledgers, goals, and debts — becomes visible to the other members of that workspace. The workspace owner can see entries created by invited members and can remove a member's access at any time. Only invite people you intend to share this information with.

Membership badges and sharing. If you choose to share a membership badge, we generate a public page containing your display name or subscriber number and cohort, along with preview metadata used by social networks. This page is public and may be indexed or cached by those networks. It never contains financial data, and sharing is entirely optional.

How We Use Your Information

PurposeLegal Basis (GDPR)
Provide and maintain the ServiceContractual necessity
Process payments and subscriptionsContractual necessity
Send transactional emails (receipts, password resets)Contractual necessity
Improve features and user experienceLegitimate interest
Detect and prevent fraud or abuseLegitimate interest
Send product updates and announcementsLegitimate interest (opt-out available)
Send marketing communicationsConsent
Comply with legal obligationsLegal obligation

Data Storage and Security

Infrastructure

Your data is stored on servers provided by AWS (Amazon Web Services) located in the United States.

Security Measures

We implement industry-standard security measures:

  • All data encrypted in transit (TLS 1.2+)
  • Data encrypted at rest (AES-256)
  • Regular security audits and penetration testing
  • Role-based access controls
  • Multi-factor authentication available
  • Automated backups with encryption

Data Breach Response

In the event of a data breach that affects your personal information, we will:

  • Notify affected users within 72 hours (as required by GDPR)
  • Notify relevant supervisory authorities
  • Provide details on the nature of the breach and remediation steps

Third-Party Services

We use the following third-party services that may process your data:

ServicePurposeData Shared
StripePayments, subscriptions, invoices, billing portalName, email, billing info, subscription and payment history
PlaidLinking financial accounts and importing transactionsInstitution and account details, balances, transactions
SupabaseDatabase, authentication, and file storageAccount data and all Service content
ResendTransactional email delivery (verification, resets, receipts, reminders, gifts)Email address, name, message content
Google (OAuth)Optional sign-inName, email, profile image
Apple (OAuth)Optional sign-inName, email (Apple may hide the real address behind a relay)
PlausibleUsage analyticsAnonymized page views
Hosting / CDN ProviderApplication hosting and content deliveryIP address, request metadata

Each third-party service has its own privacy policy governing the use of your information.

Data Sharing

We do not sell your personal information. We may share data:

  • With your team/organization: If you use a team or enterprise plan, administrators may access usage data and manage accounts
  • With service providers: As listed above, strictly for providing the Service
  • For legal compliance: When required by law, subpoena, or court order
  • During business transfers: In connection with a merger, acquisition, or asset sale (you will be notified)

Data Retention

Data TypeRetention Period
Account dataDuration of account + 30 days after deletion
User-generated contentDuration of account + 30 days after deletion
Linked account and transaction data (Plaid)Until you unlink the account or delete the records, then removed with your account
Usage logs12 months
Payment records7 years (legal requirement)
Email delivery logs12 months
Support tickets3 years

You can delete your account at any time from your account settings. Deletion cancels any active subscription, revokes all Plaid access tokens so no further financial data is retrieved, and removes or anonymizes your data within 30 days, except where retention is required by law (for example, payment and tax records). Entries you contributed to another person's shared Realm may remain with that workspace owner.

Your Rights

All Users

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate information
  • Deletion: Delete your account and associated data
  • Export: Download your data in a machine-readable format
  • Objection: Object to certain processing activities

GDPR Rights (EEA/UK Residents)

  • Right to restrict processing
  • Right to data portability
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

CCPA Rights (California Residents)

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt out of the sale of personal information (we do not sell data)
  • Right to non-discrimination

To exercise any of these rights, contact us at privacy@inkwyrm.app, use Legal & Policies in Settings, or visit Your Privacy Choices.

Cookies

We use cookies for:

  • Authentication: Keeping you logged in
  • Preferences: Remembering your settings
  • Analytics: Understanding how the Service is used
  • Security: Detecting and preventing threats

You can manage cookie preferences in your browser settings.

International Data Transfers

If you access the Service from outside the United States, your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) for EU data transfers
  • Data Processing Agreements with all sub-processors

Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect information from children.

Changes to This Policy

We will notify you of material changes via email or an in-app notification at least 30 days before the changes take effect. Continued use of the Service after changes constitutes acceptance.

Contact

For privacy-related inquiries:

Email: privacy@inkwyrm.app