Privacy

Last updated 2026-08-18.

Margin is a personal ledger. This tells you what leaves your phone, where it goes, and how to get rid of it. It is written to be read, not to be survived.

What Margin stores

Your ledger. The lines you write, exactly as you wrote them, and everything the app reads out of them: amounts and currencies, merchants and names you mention, categories, labels, dates, the places your money sits, your subscriptions, your monthly budget if you set one, and the vocabulary Margin learns from your corrections. An account is required, so this is stored in our database (Supabase, hosted in the United States) and kept per-account by row-level security: nobody else's account can read your rows, and neither can we without a deliberate administrative action. It is also cached on your device so the app works with no signal. Each line carries your device's language and time zone settings, because "yesterday" means something different in Jakarta than in London.

Your email address. Used to sign you in and to reach you about your account. Nothing else. If you sign in with Apple or Google, we receive the email address they share; Apple's private relay addresses work fine.

Your purchases. Handled by Apple and by RevenueCat. RevenueCat keeps your purchase history under your Margin account id so your subscription follows your account. Margin never sees your card.

What goes to an AI provider

When Margin needs a model to read something, the text goes to OpenAI through our server. Your name, your email address, and your account id never go with it. Here is each case, in full:

Lines that need interpreting. When the on-device parser cannot settle a line by itself, the text of that line is sent to be read. So the model reads your line the way you meant it, the request also carries your own vocabulary: your category names, the names you gave the places your money sits, your subscription names, words and aliases Margin has learned from you, a handful of your recent lines, and your language, time zone, and currency settings.

Labels and filing. When the model tidies a line into a short label and a category, it is sent the line's text and its amount, along with the same vocabulary above.

Questions you ask. If you ask your ledger a question, the question is sent along with a summary of your ledger: your monthly totals by month and by category, your budget figure if you set one, and up to 250 recent entries with their text, amount, date, and category. The model can only answer from what you wrote; it gives no advice and sees no one else's numbers.

Receipt photos. When you scan a receipt, a compressed copy of the photo is sent to be read, and the app says so before you send it. Margin keeps the ledger entries you save from it; it does not keep the photo, on the phone or on our server.

We do not permit the provider to train on your content, and we send these requests with storage turned off, so they are not retained on the provider's side.

Analytics, if you say yes

Off unless you turn it on, and off again the moment you turn it off.

When on, Margin records how the app is used - which screens, which actions, whether something failed and why - and sends it to PostHog in the United States. The payloads deliberately carry no source lines, no labels, no amounts, no email addresses, and no stable identifiers: the id changes every time you open the app, so days cannot be joined together. Raw events are kept 90 days; after that only aggregates remain.

Who processes your data

Only these, and each only for the job named:

  • Supabase stores your ledger and runs sign-in (United States).
  • OpenAI reads lines, receipts, and questions, as described above (United States).
  • Apple handles Sign in with Apple and App Store billing. If you use voice capture and your language has no on-device model, Apple's servers also do the transcription - Margin only ever receives the words.
  • Google handles Google Sign-In, if you use it.
  • RevenueCat manages subscriptions.
  • PostHog receives analytics, only if you opted in.

Like any service on the internet, our servers and these providers see your IP address when your phone talks to them. Margin does not store IP addresses in your ledger data.

We do not sell your data, and nothing here is advertising or tracking.

Deleting things, and what delete means

Deleting an entry removes it from every screen, every total, and every device, and keeps it restorable in case you change your mind. The removed row stays on our server, invisible, until your account is deleted.

Deleting your account is the real erasure: your rows - including anything you had deleted before - are removed from our database, and there is no copy kept on our side. Backups roll off within 30 days. If you signed in with Apple, we also tell Apple to disconnect Margin from your Apple ID.

Export everything first if you want it - Manage → Export, and it costs nothing.

Your choices

  • Export everything, any time, in a plain format.
  • Delete your account and its data from Manage → Account.
  • Turn analytics off, or never turn it on.
  • Write to us at support@marginmoney.app about any of this.

Deleting your Margin account does not cancel an App Store subscription - only Apple can do that. The app links you straight to it.

Children

Margin is not directed at children under 13 and we do not knowingly collect their data.

Changes

If this changes in a way that matters, the app will say so before the change takes effect rather than quietly moving the date at the top.