This notice supplements the Martian Wealth Privacy Policy and applies to you if you are a California resident. It is our “notice at collection” under the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”). Words defined in the CCPA, such as “personal information,” “sell,” and “share,” have the same meaning here. If anything in this notice conflicts with the Privacy Policy, this notice controls for California residents.
The short version: we collect only what a personal-finance app needs, we have never sold or shared personal information, we do not advertise, and you can see, correct, export, or delete your information at any time.
1. Who this notice covers
This notice covers personal information we collect from California residents through the Martian Wealth app and the martianwealth.com website, including information you give us, information your financial institutions send us through Plaid, and information collected automatically when you use the service. It does not cover information that is exempt from the CCPA, such as information already governed by the Gramm-Leach-Bliley Act when handled by your bank or brokerage.
2. Personal information we collect
In the 12 months before the date of this notice we collected the categories of personal information listed below. Each row shows examples, whether we collect it, where it comes from, why we use it, who receives it, whether we sold or shared it (we did not), and how long we keep it. Section numbers refer to the Privacy Policy.
| Category | Examples | Collected? | Sources | Purposes | Disclosed to | Sold or shared? | Retention |
|---|---|---|---|---|---|---|---|
| Identifiers | Name, email address, phone number (optional), internal account ID, Google or Apple sign-in ID, IP address | Yes | You; Google or Apple when you sign in with them; your device | Create and secure your account; send account emails; consent records; rate limiting and abuse prevention | AWS (hosting and email); Plaid (phone number, for faster re-linking); RevenueCat (account ID, if you subscribe); Google (sign-in only) | No | Life of the account; server logs up to 90 days |
| Customer records (Cal. Civ. Code § 1798.80) | Name, phone number, financial account information described in the next row | Yes | You; your financial institutions via Plaid or Apple FinanceKit | Provide the service | AWS; Plaid | No | Life of the account |
| Commercial information | Linked accounts (name, type, last four digits), balances, transactions, investment holdings and activity, manual entries, spending goals, subscription and purchase records | Yes | Your financial institutions via Plaid; Apple FinanceKit; you; Apple App Store via RevenueCat | Provide dashboards, investment tracking and goals; manage your subscription | AWS; RevenueCat (purchase records only) | No | Life of the account; deleted immediately when you disconnect an institution |
| Internet or other network activity | Server logs (request URL, timestamp, status, IP address, account ID, error traces, a preview of up to 500 characters of an AI prompt when a request fails or is refused) | Yes | Your device and app automatically | Debugging, security, rate limiting | AWS (CloudWatch) | No | Up to 90 days |
| User content | Dashboard prompts, saved dashboards, support messages | Yes | You | Build and re-run your dashboards; answer support requests | Google (Gemini API — your prompt text and, when you edit a dashboard, its existing widget layout and earlier prompts; never account data; only after you opt in); AWS | No | Life of the account; a prompt is deleted with its dashboard |
| Geolocation data | Approximate location that could be inferred from an IP address | Only as part of server logs; we do not derive or store a location | Your device | Security | AWS | No | Up to 90 days (with the log) |
| Sensitive personal information | Financial account data (balances, transactions, holdings); account log-in credentials for Martian Wealth (stored only as a bcrypt hash) | Yes | Your financial institutions via Plaid or FinanceKit; you | Provide the service; security. See section 7 | AWS; Plaid | No | Life of the account |
| Inferences | Profiles reflecting preferences or characteristics | No — dashboards are computed from your data on request; we build no profiles | — | — | — | No | — |
| Biometric information | Face ID or Touch ID data | No — matching happens on your device; we only learn whether unlock succeeded | — | — | — | No | — |
| Protected classifications; professional or employment information; education information; audio, visual or similar information | — | No | — | — | — | No | — |
We do not collect additional categories of personal information, and we will not use the information we collect for materially different, unrelated, or incompatible purposes without first giving you notice.
3. Where it comes from
- You — when you create an account, enter manual accounts or transactions, set goals, type a dashboard prompt, or contact support.
- Your financial institutions, through Plaid — after you connect an institution. You give your credentials to Plaid directly; we never see them.
- Apple FinanceKit — Apple Card accounts and transactions, only if you grant access on your iPhone.
- Google or Apple — your provider user ID, name, and email when you sign in with them.
- Apple App Store and RevenueCat — purchase and entitlement records if you subscribe to Martian Premium.
- Your device, automatically — server logs when the app or website talks to our servers.
4. Why we collect it
We use personal information for the business purposes in Privacy Policy section 2: providing the features of the app (account linking, transaction sync, dashboards, investment tracking, spending goals, subscriptions); sending transactional email; securing the service and preventing fraud and abuse; keeping the consent records described in Privacy Policy section 1.1; and complying with law. We do not use personal information for advertising, to train AI models, or to make automated decisions with legal or similarly significant effects about you.
5. Who we disclose it to
In the preceding 12 months we disclosed personal information for a business purpose only to the service providers and contractors listed in Privacy Policy section 3, each bound by contract to use it only to provide services to us: Plaid (account linking and sync); Apple (Sign in with Apple; FinanceKit); Google (sign-in; the Gemini API, which receives your prompt text and, when you edit a dashboard, its existing widget layout and earlier prompts — never account data — and only after you opt in); RevenueCat (subscription management); Amazon Web Services (hosting, database, email); and Twelve Data (which receives ticker symbols only, never personal information). We may also disclose information when required by law, subpoena, or court order, or to protect the rights, property, or safety of our users or the public.
6. Sale and sharing
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done either in the preceding 12 months. Because of this, we do not offer a “Do Not Sell or Share My Personal Information” link; you may nevertheless send us a request and we will confirm that no sale or sharing takes place. We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age.
7. Sensitive personal information
The sensitive personal information we hold is your financial account data (balances, transactions, and holdings) and your Martian Wealth log-in credentials, which are stored only as a one-way hash. We use it only to provide the service you asked for, to secure your account, to detect and prevent fraud and abuse, and to comply with law — the purposes permitted by California Code of Regulations title 11, section 7027(m). We do not use or disclose it to infer characteristics about you, so the right to limit its use does not apply and we do not offer a “Limit the Use of My Sensitive Personal Information” link.
8. How long we keep it
The retention column in section 2 and Privacy Policy section 6 set out how long we keep each category. In general: account and financial data until you delete your account (after which it is deleted or anonymized within 30 days); an institution's accounts and transactions immediately when you disconnect it; server logs up to 90 days; consent records for the life of the account; and revoked session tokens, in hashed form, until the account is deleted.
9. Your rights
- Right to know — the categories of personal information we collect, the sources, our purposes, the categories of third parties we disclose it to, and the specific pieces we hold about you.
- Right to delete — subject to exceptions the CCPA allows (for example, completing a transaction you requested, security, or legal obligations).
- Right to correct inaccurate personal information.
- Right to data portability — a copy of your information in a portable, readily usable format.
- Right to opt out of sale or sharing and right to limit use of sensitive personal information — not applicable, because we do neither, but you may still ask.
- Right to non-discrimination — we will not deny you the service, charge you a different price, or provide a different level of quality because you exercised a right.
10. How to exercise your rights
- Delete your account in the app: Settings → Delete Account. We email you a one-time confirmation code; entering it permanently deletes your account, bank connections, accounts, transactions, dashboards, goals, sessions, and consent records.
- Everything else — email support@martianwealth.com from the email address on your account, or write to the address in section 19, and tell us which right you are exercising. You may also ask us to delete your account this way.
We will confirm receipt within 10 business days and respond within 45 days; if we need longer (up to a further 45 days) we will tell you why. Exports are provided as a machine-readable file. You may make a request to know or to port your data free of charge up to twice in any 12-month period; we may decline or charge a reasonable fee for requests that are manifestly unfounded or excessive.
11. How we verify requests
We match a request to the email address on the account it concerns, and for requests about specific pieces of information or for deletion we may also send a one-time code to that address (the in-app deletion flow does this automatically). We will not ask you for more information than we need to verify you. If we cannot verify a request we will tell you, and for a request to know we will then treat it as a request for the categories of information only.
12. Authorized agents
You may designate an authorized agent to make a request on your behalf. The agent must send us your signed written permission (or a power of attorney), and we may also ask you to confirm the agent's authority and your identity directly with us. Requests from agents that we cannot verify will be declined.
13. Appeals and complaints
If we decline all or part of a request, you may appeal within 60 days by replying to our decision with the subject line “Privacy request appeal.” We will respond in writing within 45 days with the reasons for our decision. If you are not satisfied, you may complain to the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General (oag.ca.gov/privacy).
14. Opt-out preference signals
We treat a Global Privacy Control signal, and any other opt-out preference signal recognized by California law, as a valid request to opt out of sale and sharing for the browser or device that sends it. Because we do not sell or share personal information, honoring the signal changes nothing about how we handle your data. Our website does not respond to browser “Do Not Track” signals, because there is no tracking to disable.
15. Shine the Light
California Civil Code section 1798.83 lets California residents ask which personal information a business disclosed to third parties for those third parties' direct-marketing purposes. We do not disclose personal information to any third party for its own direct marketing, so there is nothing to report; you may nevertheless ask by emailing support@martianwealth.com.
16. Financial incentives
We do not offer any financial incentive, price difference, or other benefit in exchange for collecting, retaining, selling, or sharing personal information, and we do not run referral or rewards programs. If that ever changes, we will publish a notice of financial incentive that explains the material terms and how to opt in and withdraw.
17. Minors
Martian Wealth is for adults 18 and over. We do not knowingly collect personal information from anyone under 18, and we have no actual knowledge that we sell or share the personal information of anyone under 16. If you believe a minor has provided us information, email support@martianwealth.com and we will delete it.
18. Changes to this notice
We will update this notice when our practices change and at least once every 12 months. Material changes are announced in-app or by email at least 14 days before they take effect. Prior versions are published at martianwealth.com/legal.
19. Contact
Martian Labs LLC (doing business as Martian Wealth)
418 Broadway STE N, Albany, NY 12207, United States
Email: support@martianwealth.com
See also our Privacy Policy, Terms of Service, and Security overview.