Privacy Policy
Effective September 10, 2026
What Daymark is
Daymark is a personal budgeting application used by a single account holder to budget against their own bank accounts. It is not a service offered to the public and it has no other users.
What data is collected
Daymark stores only what budgeting requires:
- An email address and a hashed password, used to sign in.
- Account names, types, and balances, and transaction dates, amounts, merchant names, and categories, retrieved from the account holder’s financial institutions through Plaid.
- Budget data the account holder creates: categories, monthly assignments, goals, rules, and notes.
Daymark does not collect analytics, does not use advertising or tracking cookies, and does not build a profile of the account holder for any purpose other than showing them their own budget.
Bank credentials
Daymark never sees, receives, or stores online banking usernames or passwords. Bank sign-in happens inside Plaid Link, which is operated by Plaid Inc. Daymark receives only an access token that lets it read account and transaction data, and that token is stored server-side in a table no client can read.
Plaid’s handling of the data it collects is governed by Plaid’s End User Privacy Policy.
How the data is used
Financial data is used for one purpose: to show the account holder their own accounts, transactions, budget, and reports inside Daymark. It is not sold, rented, shared, or disclosed to anyone. There is no third party with access to it other than the infrastructure providers named below, who process it only to run the application.
Who processes the data
- Plaid Inc. retrieves account and transaction data from financial institutions.
- Supabase hosts the database and handles authentication.
- Vercel hosts and serves the application.
How the data is protected
- Data in transit is encrypted with TLS 1.2 or better.
- Data at rest is encrypted with AES-256, including automated backups.
- Row level security is enabled on every database table, so a row can only be read by the account it belongs to. Plaid access tokens sit in a table with no client-readable policy at all.
- Sessions are held in httpOnly cookies and re-verified on the server on every request.
- Registration is closed, so no additional account can be created.
How long the data is kept
Account, transaction, and budget data is kept until the account holder deletes it, because multi-year comparison is a core function of a budget. Plaid webhook diagnostics are kept for 90 days. Automated database backups are kept for 7 days.
Deleting the data
Under Settings, then Connections, disconnecting a bank revokes Plaid’s access at that institution and deletes the stored access token.
Under Settings, then Data, “Delete everything” revokes Plaid’s access at every connected institution and then deletes all accounts, transactions, categories, budgets, goals, rules, and history. Deletion is immediate. The only residue is in encrypted backups, which age out within 7 days.
All data can be exported to CSV from the same screen before deleting.
Consent
The account holder consents to the collection, processing, and storage described here by creating an account and by connecting each financial institution through Plaid Link, which presents its own consent screen naming the data to be shared. Consent is withdrawn by disconnecting the institution or deleting all data, both described above.
Changes
If this policy changes materially, the effective date above changes with it. Because there is a single account holder, who is also the operator, no separate notice is issued.
Contact
Questions about this policy go to the account holder, who operates the application. Questions about how Plaid handles data should go to Plaid using the link above.