Privacy Policy
Effective July 14, 2026 · Previous version: May 6, 2026 · privacy@keepingup.com
1. Who We Are
Keeping Up Inc, a Delaware corporation ("Keeping Up," "we," "us," "our"), operates the Keeping Up personal finance benchmarking service. This Privacy Policy explains how we collect, use, and protect your information when you use our website and mobile application.
This policy applies to information we collect through our website at keepingup.com, our iOS application, and any associated services. It does not apply to third-party services we link to (e.g. your bank's website), even when accessed from within our Service.
2. Information We Collect
Information you provide directly
- Account information — name, email address, password (managed by Clerk; we never see your password)
- Profile information — date of birth (used to derive an age range and to assess retirement-account eligibility), city, industry, job title, college (optional), relationship status (optional), number of dependents (optional). All profile fields except age range are optional and are used solely to match you to a peer cohort and to surface relevant product recommendations.
- Income range — you may enter this manually, or we may derive an approximate range from your Plaid transaction history (recurring direct deposits identified as paychecks). Derived income ranges are flagged internally as Plaid-derived and used only for cohort matching; you can override or clear them at any time in Settings.
- Subscription and payment information — billing details are processed and stored by Stripe. We never store full card numbers; we receive only a tokenised reference, the last four digits, the card brand, and the expiration month/year for display.
- Custom assets, debts, goals, bills — anything you manually add (real-estate values, vehicles, manual debts, savings goals, recurring bills) is stored linked to your account.
- Support correspondence — messages you send through the in-app contact form, plus any attachments and the metadata of the conversation.
Financial data via Plaid
When you connect accounts, we receive through Plaid:
- Account balances and types (checking, savings, investment, retirement, credit, loan)
- Transaction history (payee name, amount, date, merchant-provided category)
- Investment holdings (security name, quantity, value, cost basis where available)
- Institution name and account identifiers (Plaid-issued IDs; we do not receive full account numbers or routing numbers)
We request read-only access. We cannot initiate transactions, transfer funds, change account settings, or make any modification to your bank accounts. Plaid's own data practices are governed by Plaid's End User Privacy Policy, which is presented to you immediately before you authorize an institution connection.
Automatically collected information
When you use the Service, we automatically collect:
- Usage data — pages viewed, features used, session duration, action sequences (e.g. "tapped Spending tab → expanded Dining → tapped a transaction"). Used to understand which features users find valuable.
- Device and browser information — operating system, browser version, device model, screen size, locale, time zone.
- IP address — used for approximate geolocation (city/region only), fraud prevention, and rate limiting. Stored in security and access logs for up to 90 days, after which it is rotated out of hot storage.
- Diagnostic and crash data — when an error occurs, a stack trace and limited request context are sent to Sentry to help us reproduce and fix the bug. Sentry session replays are sampled at 10% under normal conditions and 100% when a session contains an error; replays automatically mask financial values, account numbers, and form inputs containing sensitive data.
- Product analytics events — non-identifying events (e.g. "upgrade_completed", "goal_created") are sent to PostHog so we can measure feature adoption and conversion. We do not transmit individual financial values to PostHog. Where required by law (EEA/UK users, California users who have opted out of analytics), product analytics are disabled.
- Aggregate web analytics — page views and referrer information are collected by Plausible Analytics, which does not use cookies and does not collect personally-identifiable information.
Mobile app — location data (optional)
If you enable Location Alerts in the iOS app, we collect background location data (latitude, longitude, motion-activity hints) via Transistor Soft's TSLocationManager SDK and use Google Places to look up nearby venue names. Location is used solely to detect arrival at spending venues you've selected (e.g. coffee shops, restaurants) and to surface the corresponding spending-context notification. We do not store individual location points on our servers — they live on your device and are queried in real time only when an alert is triggered. You can disable this feature at any time in iOS Settings → Keeping Up → Location, or inside the app under Settings → Location Alerts. Disabling immediately stops all location collection.
Mobile app — push notification tokens
If you grant the iOS app permission to send notifications, we receive a per-install push token from Apple Push Notification service via Expo's push relay. This token is used solely to deliver weekly digest reminders, location-triggered spending alerts (if enabled), and account-related notifications. Tokens are stored linked to your user account and rotated when you reinstall the app. Revoking notification permission in iOS Settings invalidates the token and stops all push delivery.
Information from other users (household plans)
If another user invites you to a household and you accept, we associate your account with theirs in our systems. Members of the same household see each other's account-level totals (combined and individual net worth, savings rate, monthly spending and income), but never raw transaction data. See Section 4 for details on what household members can and cannot see about each other.
3. How We Use Your Information
We use your information to:
- Provide the Service — compute your net worth, savings rate, spending totals, and compare them to anonymised peer benchmarks.
- Generate aggregate benchmarks — your anonymised financial metrics contribute to peer cohort statistics. Your identity is never associated with benchmark data visible to others; aggregates are computed from a minimum of 5 users to prevent re-identification.
- Surface AI-generated insights and recommendations — relevant context from your data is sent to Anthropic's API to generate personalised summaries. Anthropic does not use API content to train its models per its privacy policy; we delete prompt history after 30 days unless you ask us to retain it.
- Send digest emails — weekly, monthly, or quarterly summaries of your financial position. You can opt out at any time via the unsubscribe link in any digest email or from Settings.
- Surface product recommendations — based on your stats we may recommend financial products (high-yield savings accounts, brokerages, refinance offers, credit cards). Some of these recommendations may be commercial relationships; any such recommendation is labelled as "Sponsored" or "Partner" in the product card. We do not share your individual financial data with these partners; recommendations are computed on our side and the partner only sees a click-through if you choose to follow the link.
- Process payments — manage your Pro subscription via Stripe.
- Improve the Service — analyse usage patterns and crash reports to improve features, fix bugs, and prevent abuse.
- Communicate with you — respond to support requests, send service announcements, and (with your permission) marketing communications you can unsubscribe from.
- Comply with legal obligations — respond to lawful requests, prevent fraud, enforce our Terms of Service.
We do not use your data to train external AI models, sell to data brokers, target you with third-party advertisements, or share with employers, financial institutions, or anyone outside the listed service providers.
4. Household Plans & Shared Data
Household plans let you and one or more household members (typically a partner) see your combined finances. The data flow is:
- Visible to all household members: combined household net worth, combined savings rate, combined monthly spending and income, each individual member's name, individual member-level totals (their net worth, savings rate, monthly spend, monthly income), and connection status (whether each member has Plaid connected).
- Not visible to household members: individual transactions, individual account balances at specific institutions, individual goals, individual custom assets/debts not summed into the totals above, AI advisor conversations, settings, and email/profile details beyond the displayed first name.
By creating or accepting a household, each member acknowledges that their account-level totals will be visible to other members. The Service surfaces an in-app acknowledgment at the moment of household creation and acceptance.
Leaving or dissolving a household: any member can leave at any time from the Household screen. The household owner can dissolve the household, which removes all member associations and deletes the household record from our systems within 24 hours. Aggregate household metrics are computed in real time from current member data; once a household is dissolved, no historical aggregate is retained.
5. Categories of Personal Information (CCPA Disclosure)
For California residents, the following categories of personal information have been collected from you in the preceding 12 months. None of these categories are sold or shared for cross-context behavioural advertising:
- Identifiers — name, email, account ID, device IDs, IP address.
- Customer records (Cal. Civ. Code § 1798.80(e)) — name, address (city/state only), date of birth, financial information (via Plaid).
- Protected classifications under California or federal law — age range. (You may decline to provide this; it impacts only cohort matching.)
- Commercial information — Pro subscription history, transaction patterns from your connected accounts.
- Internet/network activity — usage data, session events, error reports.
- Geolocation — approximate city-level location (from IP); precise location only if you enable Location Alerts on the iOS app.
- Inferences — derived income range, peer cohort placement, product-recommendation relevance scores.
- Sensitive personal information (CPRA) — financial account information (via Plaid), precise geolocation (only if Location Alerts enabled), and contents of email correspondence with us. We use sensitive personal information only for the purposes described in Section 3 and do not use or disclose it for inferring characteristics about you. Under CPRA you have the right to limit our use of sensitive personal information; see Section 9.
6. Third-Party Service Providers
We share data with the following service providers solely to operate the Service. Each is a contractual "service provider" under CCPA / "processor" under GDPR — they may use your data only on our documented instructions and only to provide the service we've contracted them for.
- Plaid Technologies, Inc. — financial account connectivity. Plaid Legal
- Clerk, Inc. — authentication and user management. Clerk Privacy
- Stripe, Inc. — payment processing and subscription billing. Stripe Privacy
- Anthropic, PBC — AI-generated insights. Your financial context is sent to Anthropic's API to generate personalised summaries. Anthropic does not retain or train on prompt content per its API terms. Anthropic Privacy
- Vercel, Inc. — hosting and infrastructure. Vercel Privacy
- Neon, Inc. — managed PostgreSQL database hosting. Neon Privacy
- Resend, Inc. — transactional email delivery. Resend Privacy
- Sentry / Functional Software, Inc. — error monitoring and session replay. Replays mask all financial values, account numbers, and sensitive form inputs. Sentry Privacy
- PostHog, Inc. — product analytics (non-identifying events). PostHog Privacy
- Plausible Insights OÜ — cookie-free, privacy-focused web analytics for the marketing site. Plausible Privacy
- Google LLC (Google Places) — venue lookup for Location Alerts. Used only when Location Alerts are enabled. Google Privacy
- Apple Push Notification service / Expo (Exponent, Inc.) — push token delivery for the iOS app.
- Transistor Software, Inc. — background-location SDK in the iOS app (only active if Location Alerts enabled).
We do not sell your personal data to any third party. We do not share personal data for cross-context behavioural advertising.
For users in the European Union, European Economic Area, or United Kingdom, we have Data Processing Agreements (DPAs) in place with each sub-processor listed above, as required by GDPR Article 28 / UK GDPR. These DPAs ensure your data is processed only on our documented instructions and with appropriate security measures. DPAs and our list of sub-processors are available upon request at legal@keepingup.com.
7. Data Retention
We retain your information only as long as needed for the purposes described in this Policy:
- Account, profile, and connection data — retained until you delete your account.
- Transaction history — up to 24 months. We chose 24 months because (a) two full annual cycles is the minimum needed for year-over-year trend analysis, and (b) it covers the prior tax year for users referencing their own records. You may request earlier deletion at any time.
- Aggregate, anonymised benchmark data — may be retained indefinitely. Once aggregated and stripped of identifiers, this data is not associated with any individual user.
- Crash reports and session replays — 90 days, then deleted.
- Product analytics events — 12 months in raw form, then aggregated.
- Email logs (delivery, bounce, unsubscribe events) — 18 months for compliance and deliverability monitoring.
- Backup copies — encrypted backups may persist for up to 30 days after live deletion. Backups are not accessed except for disaster recovery.
- Legal-hold or fraud-investigation data — retained as long as required by applicable law or by an active investigation, and deleted when the hold is released.
Dormant Pro account — Plaid connection pause. If you maintain an active Pro subscription but do not access the Service for 120 consecutive days, we may pause your Plaid bank connections to reduce operating costs. Your account, subscription, profile, transaction history, and aggregate benchmark contributions all remain intact. The next time you sign in, the Service will prompt you to reconnect any paused institutions; once reconnected, syncing resumes and historical data continues to display. We will send a reminder email to the address on file before pausing.
8. Security
We implement industry-standard security measures including:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest in our managed database
- No storage of bank account numbers, routing numbers, or login credentials — Plaid manages all credential storage and uses bank-grade encryption
- Role-based access controls; production data access is limited to a small number of authorised personnel and is logged
- Mandatory two-factor authentication for all employees with production access
- Optional multi-factor authentication (MFA) for users. You can enable an authenticator app (TOTP) and recovery backup codes from Settings → Security. We strongly recommend enabling MFA on any account that has a Plaid connection. MFA enrollment, verification, and recovery codes are managed by our authentication provider, Clerk; we do not see, store, or transmit the underlying secrets.
- Regular security review and penetration testing
- Subprocessor security review prior to onboarding
Regulatory framework. We treat consumer financial information as "nonpublic personal information" under the federal Gramm-Leach-Bliley Act (GLBA). Our information security program is designed to satisfy the FTC's GLBA Safeguards Rule (16 C.F.R. Part 314), including written policies, designated security personnel, ongoing risk assessment, encryption of customer information, MFA for personnel with access to customer information, and secure disposal of data. We retain and produce records demonstrating compliance on request from regulators.
Breach notification. No system is completely secure. In the event of a security incident affecting your personal information, we will notify you without unreasonable delay and in accordance with applicable law. For California residents, this notification will be provided in the most expedient time possible and without unreasonable delay, and in any event no later than 30 days after determining that a breach has occurred, consistent with Cal. Civ. Code § 1798.82(a)(1) as amended by SB-446 (effective 2026). We aim to notify affected users within 72 hours of confirmed compromise where feasible — well within the statutory deadline. Notification will describe the nature of the incident, the categories of information affected, the steps we are taking, and recommended steps for you to take.
Please notify us immediately at privacy@keepingup.com if you suspect a security incident on your account.
9. Your Rights
California residents (CCPA / CPRA)
You have the right to:
- Know — request disclosure of the categories and specific pieces of personal information we have collected, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share information.
- Delete — request deletion of your personal information (subject to limited exceptions, e.g. transactions we're required to retain for tax/legal reasons).
- Correct — request correction of inaccurate personal information.
- Opt out of sale or sharing — we do not sell personal information and do not share for cross-context behavioural advertising, so this right is not applicable; we surface a "Do Not Sell or Share" control regardless to confirm our position.
- Limit use of sensitive personal information — direct us to use sensitive PI only for permitted business purposes (operating the Service). To exercise, contact privacy@keepingup.com.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights, refuse service, change pricing, or provide a different level of quality.
- Authorised agent — you may use an authorised agent to submit a request on your behalf with verified written authorisation.
Other US state privacy laws
Residents of states with comprehensive consumer privacy laws — currently including Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana, Iowa, Tennessee, Delaware, New Hampshire, Maryland, New Jersey, Minnesota, Indiana, Kentucky, Rhode Island, Nebraska, and any state that adopts a comparable law during the term of these Terms — have rights substantially similar to those described above for California residents, including the right to:
- Confirm whether we process your personal information and access that information
- Correct inaccurate personal information
- Delete personal information you provided to us or that we obtained about you
- Obtain a portable copy of personal information you provided
- Opt out of the sale of personal information, targeted advertising, and certain forms of profiling that produce legal or similarly significant effects
- Appeal a denial of a privacy rights request through the contact below
We do not sell personal information for monetary consideration, do not engage in targeted advertising across third-party platforms, and do not use your information for automated decision-making that produces legal or similarly significant effects. To exercise any of the above rights, contact privacy@keepingup.com. We respond within the timeframe required by your state's law (typically 45 days, with one possible 45-day extension if reasonably necessary). Where your state recognises an authorised agent, you may use one with verified written authorisation.
Some states (Virginia, Colorado, Connecticut, Oregon, Texas, Montana, and others) provide a right to appeal a denial of a privacy rights request. To appeal, reply to our written denial within 60 days; we will respond in writing within 60 days of receiving the appeal. If your appeal is denied, you may submit a complaint to your state attorney general.
EEA, UK, and Swiss residents (GDPR / UK GDPR)
You have the right to:
- Access, rectify, erase, restrict, or port your personal data
- Object to processing based on legitimate interests
- Withdraw consent (where processing is based on consent)
- Lodge a complaint with your supervisory authority
Our legal bases for processing are: (i) performance of the contract you entered when creating your account; (ii) our legitimate interests in operating, securing, and improving the Service; (iii) compliance with legal obligations; and (iv) your consent for optional features (marketing emails, location alerts).
How to exercise your rights
You can exercise most rights directly in-app:
- Access / portability — Settings → Account → Download my data
- Deletion — Settings → Account → Delete account. Account deletion is processed within 7 days under normal operating conditions, and in any case within 45 days as required by California Civil Code § 1798.130. If a system failure or backup-restore process delays processing, we will notify you and confirm completion. Encrypted backups are purged within 30 days of live deletion.
- Correction — Settings → Profile
- Marketing email opt-out — unsubscribe link in any digest email, or Settings → Notifications
For other requests, email privacy@keepingup.com. We will verify your identity by confirming control of the email on file before processing requests. We respond within 7 days for deletion requests under normal conditions and within 30 days for all other rights requests, with one possible 45-day extension if reasonably necessary.
10. Children's Privacy
The Service is not directed at children, and we do not knowingly collect personal information from individuals under 18. The Service is intended for users 18 years of age or older; sign-up requires an explicit attestation of age.
If you believe a child under 18 has provided us with personal information, contact us at privacy@keepingup.com and we will delete the information promptly.
11. International Data Transfers
Keeping Up Inc is based in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to this transfer.
Where required by law, we rely on Standard Contractual Clauses or other valid transfer mechanisms. EEA / UK users may request a copy of the relevant transfer mechanism documentation at legal@keepingup.com.
12. Changes to This Policy
We may update this Privacy Policy. Material changes — for example, new categories of data collection, new third-party recipients, expanded data sharing, or changes to your rights — will be communicated by email and by an in-app notice at least 14 days before they take effect, and will require your explicit acknowledgment before you can continue using the Service. Non-material changes (typo corrections, clarifications, vendor link updates) are noted by updating the Effective date.
This policy is reviewed at least annually and updated as needed to reflect changes in our data practices, applicable laws, or regulatory requirements.
13. Contact
Privacy questions, requests, or complaints: privacy@keepingup.com
Postal address available on request.