← MarginDeck

Privacy Policy

Last updated: 2026-09-14. This policy explains how MarginDeck and the margindeck.app website handle information. Questions or privacy requests: margindeck@proton.me.

1. Operator and scope

MarginDeck is operated by Jin Junhua, an individual based in China, under the MarginDeck name ("MarginDeck", "we", "us", or "our"). This policy covers the MarginDeck macOS app, the margindeck.app website, the RevenueCat OAuth callback page, support messages, purchase-related entitlement handling, and optional research or feedback you choose to provide. Contact: margindeck@proton.me.

This policy describes information processing for MarginDeck. It does not replace the policies that apply when you use third-party services directly. Where a provider processes information on our behalf, our responsibilities under applicable law remain.

2. Your business data stays on your Mac

MarginDeck does not require a MarginDeck account or sign-in. Products, costs, billing terms, cost activity history such as Pause and Resume dates, cost allocations, manually entered revenue, synced revenue aggregates, cash balances, workspace settings, notes, imported or reviewed records, and calculated results are stored in the app's local database on your Mac. We do not operate a MarginDeck account server or business-data backend that receives or stores this portfolio dataset.

App preferences may be stored in macOS user defaults or equivalent local app storage. Credentials are stored separately in the macOS Keychain where the app can access them for the connection you enabled. Because the primary dataset is local, we generally cannot view, correct, recover, export, or delete your in-app business records remotely.

3. Information you enter in the app

You may enter product names, cost names, revenue amounts, currencies, allocation percentages, cash snapshots, billing cadences, billing terms, reminder preferences, start, stop, Pause, and Resume dates, scheduled cost occurrences, allocation history, categories, settings, and notes. The information you enter may include confidential business information. It remains on your Mac unless you export it, back it up, share screenshots, include it in a support message, or otherwise send it outside the app.

Please do not enter payment-card data, customer personal information, API secrets, tax identifiers, regulated financial account details, health information, or other sensitive personal data into free-form fields. MarginDeck is designed to help you plan around product revenue and costs, not to store customer records or regulated data.

4. Optional revenue connections and reference rates

Revenue accounts are not connected automatically. If you choose a connection, your Mac communicates with the selected provider to authorize access and perform read-only revenue sync. You can disconnect a provider in the app and can also revoke access in the provider's dashboard. ECB reference-rate updates are enabled by default, can be turned off in Settings, and do not require an account.

The app stores monthly provider project or account identifiers, product identifiers, live or test environment where available, UTC reporting month, metric definition, product name, aggregate net amount, currency, local product mapping, sync timestamp, and cached ECB reference-rate observations on your Mac. It does not store customer names, customer email addresses, card details, raw individual transactions, or connection credentials (including read-only credentials) in the business database or backups.

5. App Store purchases

The Pro Lifetime purchase is processed by Apple using StoreKit and your Apple ID. We do not receive your payment-card details, Apple ID password, or full Apple account credentials. The app receives verified StoreKit transaction, product, and revocation information needed to unlock Pro features. Apple may provide developers with sales, proceeds, region, tax, refund, and performance reports under Apple's own terms. Apple's handling of this information is governed by Apple's Privacy Policy.

6. Optional local reminders

If you turn on a reminder for a saved cost, MarginDeck stores that choice locally and then asks macOS for notification permission. Your Mac schedules the notification. MarginDeck does not use a push server, send reminder emails, require a MarginDeck account, or send the schedule to a MarginDeck reminder service.

Reminder content is generated from the cost name, expected amount, expected date, and saved activity status in your local billing schedule. Pausing or resuming a cost can remove or recreate future local reminders, but it does not contact the vendor or change the real service. Reminder content is an estimate based on what you recorded, not a bank or vendor confirmation. System notification permission state and pending notification request identifiers are not exported in MarginDeck backups.

In version 1.5, an optional weekly check-in also uses local macOS notifications. Its weekday and time stay on your Mac; the notification asks you to review your records and does not contain a newly calculated financial report. The menu bar brief reads saved local records. Opening it does not fetch or apply revenue from a provider. Menu bar, weekly reminder and usage analytics preferences are device settings; analytics consent and the analytics identifier are not included in exported backups. You can turn reminders off in MarginDeck or control their display in macOS notification settings.

7. Backups, exports, screenshots, and files

If you choose Export Backup, MarginDeck writes a versioned JSON file to the location you select. Backup format v5 can contain your local products, scheduled cost rules, billing terms, Pause and Resume activity history, planned-cost activity snapshots, reminder preferences, allocation history, manual revenue, monthly synced-revenue identity and mapping fields, aggregate net amounts, cached ECB reference rates, cash balances, workspace and display settings, and saved notes. OAuth tokens, Stripe keys, App Store transaction data, analytics consent, analytics identifiers, system notification permission status, and pending notification request identifiers are excluded. The exported JSON is not encrypted by MarginDeck. You are responsible for where you store it, who can access it, and deleting copies you no longer need.

Restoring a backup replaces the app's current local dataset after confirmation. If you send us a backup, screenshot, screen recording, sample dataset, crash detail, or support attachment, we use the information needed to respond to your request, diagnose and fix the issue, investigate security or abuse, or meet legal obligations. We do not publish these materials or use them in marketing without your separate, explicit permission. Please remove secrets and sensitive third-party or customer data before sending files.

8. Website, support, and research

9. Analytics, tracking, advertising, and AI

Optional app usage analytics is off by default. You can enable it in Settings. If enabled, MarginDeck sends selected feature interactions and sync, purchase, and restore outcomes to TelemetryDeck. Events include the app version and build, an app-scoped hashed random identifier, and a random session identifier. They exclude business records, product names, financial amounts, and credentials. We do not use these events for advertising or link them to identities from other apps or websites. Pending events are held briefly in memory and are not written to disk. Turning analytics off clears pending events, requests cancellation of in-flight requests, and resets the local analytics identifier. It does not delete events TelemetryDeck has already received, and a request already in progress may have reached the service. As with other HTTPS services, the receiving service may receive your IP address. See the retention and privacy-rights sections for information about data already received and requests concerning information we control. See TelemetryDeck’s privacy policy.

We use Vercel Web Analytics on the public website to understand aggregate page views, referrers, countries or regions, device and browser information, and visited routes. It does not use cookies and is not used for cross-context behavioral advertising. The current public app does not send your business data to a third-party AI service and does not use your portfolio data for advertising, profiling, or selling lead lists. We do not sell personal information.

If we later add advertising trackers, marketing pixels, crash reporting, cloud sync, AI features, or additional integrations that materially change data collection or sharing, we will update this policy and, where required, request consent before the new processing begins.

10. How we use information

We use information described in this policy to provide the app, process purchases and entitlements, operate optional provider connections, run and secure the website, answer support requests, conduct voluntary research, debug and improve MarginDeck, prevent abuse, enforce our terms, comply with law, and protect our rights and users.

We may create aggregated or de-identified information from feedback you submit or aggregated website traffic information. We do not use your local portfolio dataset for model training, advertising, or resale.

11. When we share information

We share information only as described here: with service providers that help operate the website, email, App Store distribution, purchases, and optional connections; with third-party services you choose to connect; with Apple for App Store distribution and purchase flows; when you direct us to share it; when required by law or legal process; to protect rights, safety, security, and prevent abuse; or as part of a business transfer involving MarginDeck, provided the recipient must honor materially similar privacy commitments for personal information we control.

Our current providers include Vercel, Proton, and Apple. RevenueCat and Stripe process information only when you choose to connect your own account; see the RevenueCat Privacy Policy and Stripe Privacy Policy. When reference-rate updates are enabled or manually refreshed, the ECB receives the limited request described above; see the ECB data-protection statements.

TelemetryDeck receives the limited app analytics described in section 9 only when you enable usage analytics. It processes those signals under its own privacy policy. We use the resulting analytics to understand feature use and operation outcomes and improve MarginDeck.

12. Legal bases

Where a legal basis is required, we process information as necessary to provide requested features or perform a contract, based on your consent, to comply with legal obligations, and for legitimate interests such as security, support, product improvement, fraud prevention, legal compliance, and communications with users who have asked to hear from us. You can withdraw consent for optional processing, but doing so may prevent the related feature or communication from continuing. Optional app usage analytics is sent only after you choose to enable it. Turning it off does not change Free or Pro access.

13. International processing

Jin Junhua operates MarginDeck from China and handles support correspondence there. Vercel operates internationally, including in the United States. TelemetryDeck documents hosting in Germany and the Netherlands; Proton Mail documents server storage in Switzerland, Germany, or Norway. These locations concern the website, support, and optional analytics described above; your local portfolio remains on your Mac. See the providers' policies for their processing locations and safeguards. Where applicable law requires a transfer mechanism, additional notice, or separate consent, we must meet that requirement before the relevant transfer. Using the app or accepting our terms is not blanket consent.

14. Retention, deletion, and your choices

You can stop optional processing by not connecting a provider, disconnecting it, withdrawing research consent, or not sending optional files. To the extent provided by applicable law, you may request access to, a copy of, correction, export, or deletion of personal information about you that we control by emailing us. We may need to verify your request and may retain information where required or permitted by law. Depending on where you live, you may also have rights to object, restrict processing, receive a portable copy, appeal a decision, or complain to a data-protection authority. We will not discriminate against you for exercising privacy rights.

To withdraw consent for app analytics, turn off usage analytics in Settings. Turning it off stops future sends and discards the app's pending events; it does not erase previously delivered events. We do not hold a copy of your raw local analytics identifier. Contact us about analytics information we control. We will assess requests and work with the provider where needed; locating particular events depends on the identifiers available. We do not promise that every event can be linked to a requester or deleted immediately.

15. California and similar privacy notices

We do not sell personal information and do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share personal information of minors. The categories of personal information we may process are described above and may include identifiers, internet or network activity, commercial information related to App Store purchases, communications, and professional or business information you choose to send us. We use and disclose those categories for the purposes described in this policy.

MarginDeck is a small independent product. Some privacy laws apply only to businesses that meet specific thresholds. Even where a law does not apply, you may still contact us with privacy questions or deletion requests for information we control.

16. Security

We use local-first storage, macOS Keychain, HTTPS, OAuth PKCE, read-only provider access, limited data collection, and provider security controls to reduce risk. No method of storage or transmission is completely secure. You are responsible for protecting access to your Mac, operating system account, provider accounts, Stripe restricted keys, exported backups, screenshots, and files you share.

Local storage and security measures do not guarantee that records will remain accurate or intact. Software defects can cause data errors, loss, or corruption. Keep original business records and separate backups, and verify important results. We cannot remotely restore your local dataset from a MarginDeck account server. These precautions and limitations do not waive your statutory privacy rights or our legal obligations. See our Terms of Use for the applicable liability framework.

17. Children

MarginDeck is a business tool and is not directed to children under 13 or anyone below the applicable minimum age in their country. We do not knowingly collect personal information from children. If you believe a child provided personal information to us, contact us so we can take appropriate action.

18. Changes

We may update this policy as the product, providers, laws, or App Store requirements change. We will update the date above and, when appropriate, provide additional notice. Changes apply prospectively unless required by law.

19. Contact

Jin Junhua / MarginDeck
margindeck@proton.me

Built by Junhua Jin →