Last updated: 2026-08-05. This policy explains how MarginDeck and the margindeck.app website handle information. Questions or privacy requests: margindeck@proton.me.
MarginDeck is operated by Jin Junhua under the MarginDeck name ("MarginDeck", "we", "us", or "our"). This policy covers the MarginDeck macOS app, the margindeck.app website, the RevenueCat OAuth callback page, support messages, purchase-related entitlement handling, and optional research or feedback you choose to provide.
This policy does not cover RevenueCat, Stripe, Apple, Vercel, Proton Mail, or any other third-party service when they process information under their own terms. Their policies apply to your direct use of those services.
MarginDeck does not require a MarginDeck account or sign-in. Products, costs, cost allocations, manually entered revenue, synced revenue aggregates, cash balances, workspace settings, notes, imported or reviewed records, and calculated results are stored in the app's local database on your Mac. We do not operate a MarginDeck account server or business-data backend that receives or stores this portfolio dataset.
App preferences may be stored in macOS user defaults or equivalent local app storage. Credentials are stored separately in the macOS Keychain where the app can access them for the connection you enabled. Because the primary dataset is local, we generally cannot view, correct, recover, export, or delete your in-app business records remotely.
You may enter product names, cost names, revenue amounts, currencies, allocation percentages, cash snapshots, billing cadences, start or stop dates, scheduled cost occurrences, allocation history, categories, settings, and notes. This information can include confidential business information if you choose to enter it. It remains on your Mac unless you export it, back it up, share screenshots, include it in a support message, enable a future sync feature, or otherwise send it outside the app.
Please do not enter payment-card data, customer personal information, API secrets, tax identifiers, regulated financial account details, health information, or other sensitive personal data into free-form fields. MarginDeck is designed for product-level operating estimates, not customer records or regulated data storage.
Nothing is connected automatically. If you choose a connection, your Mac communicates with the selected provider to authorize access and perform read-only revenue sync. You can disconnect a provider in the app and can also revoke access in the provider's dashboard.
rk_. The key is stored in your macOS Keychain and used by the app to request selected read-only revenue information such as balance transactions, paid invoice line items, and product names. MarginDeck does not accept unrestricted sk_ secret keys and does not send the restricted key through a MarginDeck server.The app stores provider project or product identifiers, product names, aggregate amounts, currency, mappings, and sync timestamps locally. MarginDeck is designed not to store customer names, customer email addresses, card details, full individual order records, refunds outside the aggregate data needed for calculations, or write-capable provider credentials.
The Pro Lifetime purchase is processed by Apple using StoreKit and your Apple ID. We do not receive your payment-card details, Apple ID password, or full Apple account credentials. The app receives verified StoreKit transaction, product, and revocation information needed to unlock Pro features. Apple may provide developers with sales, proceeds, region, tax, refund, and performance reports under Apple's own terms. Apple's handling of this information is governed by Apple's Privacy Policy.
If you choose Export Backup, MarginDeck writes a versioned JSON file to the location you select. It can contain your local products, scheduled cost rules and occurrences, allocation history, revenue, cash balances, workspace and display settings, and saved notes. OAuth tokens, Stripe keys, and App Store transaction data are excluded. The exported JSON is not encrypted by MarginDeck. You are responsible for where you store it, who can access it, and deleting copies you no longer need.
Restoring a backup replaces the app's current local dataset after confirmation. If you send us a backup, screenshot, screen recording, sample dataset, crash detail, or support attachment, we will process whatever information it contains for support, debugging, product improvement, security, or legal purposes. Please remove secrets and sensitive third-party or customer data before sending files to us.
We do not add advertising trackers or third-party analytics to the website at this time. The current public app does not send your business data to a third-party AI service and does not use your portfolio data for advertising, profiling, or selling lead lists. We do not sell personal information or share it for cross-context behavioral advertising.
If we later add analytics, crash reporting, cloud sync, AI features, marketing pixels, or additional integrations that materially change data collection or sharing, we will update this policy and, where required, request consent before the new processing begins.
We use information described in this policy to provide the app, process purchases and entitlements, operate optional provider connections, run and secure the website, answer support requests, conduct voluntary research, debug and improve MarginDeck, prevent abuse, enforce our terms, comply with law, and protect our rights and users.
We may create aggregated or de-identified information from feedback you submit or aggregated website traffic information. We do not use your local portfolio dataset for model training, advertising, or resale.
We share information only as described here: with service providers that help operate the website, email, App Store distribution, purchases, and optional connections; with third-party services you choose to connect; with Apple for App Store distribution and purchase flows; when you direct us to share it; when required by law or legal process; to protect rights, safety, security, and prevent abuse; or as part of a business transfer involving MarginDeck, provided the recipient must honor materially similar privacy commitments for personal information we control.
Our current providers include Vercel, Proton, and Apple. RevenueCat and Stripe process information only when you choose to connect your own account; see the RevenueCat Privacy Policy and Stripe Privacy Policy.
Where a legal basis is required, we process information as necessary to provide requested features or perform a contract, based on your consent, to comply with legal obligations, and for legitimate interests such as security, support, product improvement, fraud prevention, legal compliance, and communications with users who have asked to hear from us. You can withdraw consent for optional processing, but doing so may prevent the related feature or communication from continuing.
We and our providers may process information in the United States and other countries. Those countries may have privacy laws different from where you live. When required, we rely on appropriate transfer mechanisms, provider terms, contractual safeguards, or your consent for international processing.
You can stop optional processing by not connecting a provider, disconnecting it, withdrawing research consent, or not sending optional files. You may ask us to access, correct, export, or delete personal information we control by emailing us. We may need to verify your request and may retain information where required or permitted by law. Depending on where you live, you may also have rights to object, restrict processing, receive a portable copy, appeal a decision, or complain to a data-protection authority. We will not discriminate against you for exercising privacy rights.
We do not sell personal information and do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share personal information of minors. The categories of personal information we may process are described above and may include identifiers, internet or network activity, commercial information related to App Store purchases, communications, and professional or business information you choose to send us. We use and disclose those categories for the purposes described in this policy.
MarginDeck is a small independent product. Some privacy laws apply only to businesses that meet specific thresholds. Even where a law does not apply, you may still contact us with privacy questions or deletion requests for information we control.
We use local-first storage, macOS Keychain, HTTPS, OAuth PKCE, read-only provider access, limited data collection, and provider security controls to reduce risk. No method of storage or transmission is completely secure. You are responsible for protecting access to your Mac, operating system account, provider accounts, Stripe restricted keys, exported backups, screenshots, and files you share.
MarginDeck is a business tool and is not directed to children under 13 or the minimum age required in their country. We do not knowingly collect personal information from children. If you believe a child provided personal information to us, contact us so we can take appropriate action.
We may update this policy as the product, providers, laws, or App Store requirements change. We will update the date above and, when appropriate, provide additional notice. Changes apply prospectively unless required by law.
Jin Junhua / MarginDeck
margindeck@proton.me