Features Pricing About Contact Get the app
Legal

Privacy Policy

Last updated: 23 September 2026

Martian Wealth (“we”, “us”, “the app”) is operated by Martian Labs LLC. This policy explains what data we collect, how we use it, who we share it with, and the choices you have. It covers the Martian Wealth mobile app and our website, martianwealth.com. If you have questions, email support@martianwealth.com.

The short version: we collect what’s needed to run a personal-finance app and nothing else. We don’t sell your data, we don’t show ads, we don’t use your data to train AI models, and your raw transactions are never sent to an LLM. The one feature that uses an AI service asks your permission first and sends only the words you type — section 4 spells that out.

1. Information we collect

1.1 Account information

When you create an account we collect your name, email address, phone number (optional), and password (stored only as a bcrypt hash — we never see or store your plaintext password). If you sign in with Google or Apple instead, we receive the provider’s user ID, your name, and your email; we do not receive or store provider passwords. If you sign in with Apple and choose Hide My Email, Apple gives us a private relay address (ending in @privaterelay.appleid.com) instead of your real email address. We store that relay address as your account email and send all account emails to it; Apple forwards them to you, and you can turn the relay off in your Apple ID settings.

We also keep records tied to your account: whether your email is verified, whether you’ve completed onboarding, and a record of each consent you give — your acceptance of the Terms of Service and this Privacy Policy, your attestation that you are 18 or older, and your permission for the AI dashboard feature (section 4). For each consent event we record which version of the document you accepted, the time, your IP address, and the device or app identifier your device sent with the request (its user agent), so that we can show what you agreed to and when. These records are kept as an audit trail and are not used for anything else.

1.2 Financial information from linked institutions

When you connect a bank, credit card, or brokerage through Plaid, you give your institution credentials to Plaid directly — we never see your bank login credentials. Plaid then returns to us:

  • Your accounts at that institution (name, type and subtype, last 4 digits of the account number, balances, currency). We never receive full account or routing numbers.
  • Transactions (date, merchant, amount, category, payment channel, pending status, merchant enrichment such as logo and website, merchant location where your institution provides it, and counterparty details) — as much history as your institution makes available through Plaid, and ongoing thereafter.
  • Recurring transaction patterns (e.g. subscriptions and paychecks) that Plaid detects.
  • For brokerage accounts: investment holdings (security, ticker, quantity, cost basis, value) and investment transactions (buys, sells, dividends, fees) covering up to the last 24 months and ongoing thereafter.
  • An access token for the connection, which we encrypt with AES‑256‑GCM before it is written to our database.

To power Plaid’s faster re-linking experience for returning users, we share your phone number with Plaid when you open the “add institution” flow. You can read Plaid’s End User Privacy Policy at plaid.com/legal. Plaid’s mailing address is Plaid Inc., 1098 Harrison Street, San Francisco, CA 94103.

1.3 Apple Card (FinanceKit)

If you grant access on an eligible iPhone (iOS 17.4+), we read your Apple Card accounts and transaction history through Apple’s FinanceKit API. Access is controlled by an on-device permission prompt you can revoke at any time in iOS Settings. Synced Apple Card data is stored on our servers under the same security controls as Plaid data.

1.4 Manual accounts and transactions

Accounts and transactions you enter by hand are stored like any other account data and included in your dashboards and totals.

1.5 Dashboard prompts

When you ask for a dashboard, we send your natural-language prompt to Google Gemini, which returns only a dashboard structure (widget types and query criteria). We never send your transactions, balances, or account details to the LLM. Your data is fetched from our own database, server-side, after the structure comes back. We store your prompt alongside the resulting dashboard so you can re-run or refine it later. We ask for your permission in the app before any prompt is sent, and you can withdraw it at any time — see section 4.

1.6 Preferences and goals

We store product preferences tied to your account: saved and pinned dashboards, per-category monthly spending goals, and any investment holdings you’ve chosen to hide from your totals.

1.7 Subscriptions and purchases

If you buy Martian Premium, the purchase itself is processed by Apple (App Store) or Google (Google Play) under their own terms and privacy policies. We and our subscription-management provider, RevenueCat, Inc., receive your app user ID (the internal UUID of your Martian Wealth account), the product you purchased, the purchase and expiry dates, and the store’s receipt or transaction identifiers, so we can unlock the features you paid for and keep them unlocked as your subscription renews or lapses. We never receive your card number, billing address, or any other payment details — those stay with Apple or Google.

1.8 Biometric unlock

If you enable Face ID / Touch ID app lock, biometric matching happens entirely on your device, run by iOS or Android. We never receive, store, or have access to your biometric data — the app only learns whether the device reported that unlock succeeded.

1.9 Technical information

We collect server-side logs (request URLs, timestamps, status codes, error stack traces, your IP address, your account ID, and — for the AI dashboard feature — a preview of up to the first 500 characters of the prompt you typed, to diagnose failed or refused requests) for debugging, rate limiting, and abuse prevention. We do not bundle third-party analytics, advertising, or tracking SDKs in the app, and our marketing website sets no tracking cookies. Like most websites, our site loads its fonts from Google Fonts, so Google receives standard request data (such as your IP address) when a page loads.

1.10 Market data (not personal data)

To price your investments we fetch security quotes from Twelve Data. Those requests contain ticker symbols only — never your identity, holdings quantities, or account details.

2. How we use your information

We use your information to:

  • Provide the core features of the app — account linking, transaction sync, dashboards, investment tracking, spending goals.
  • Send transactional emails (verification, password reset, account deletion confirmation, security alerts). We use email for service messages, not marketing.
  • Secure the service — detect and prevent abuse, fraud, token theft, and other security incidents.
  • Comply with legal obligations.

We do not:

  • Sell your data or share it with data brokers.
  • Use your data for advertising, ours or anyone else’s.
  • Use your data to train machine-learning or AI models.
  • Track you across other companies’ apps or websites.

3. Who we share information with

We share data only with the service providers needed to run the app:

ProviderPurposeData shared
PlaidBank, card, and brokerage linking; transaction and investment sync. By connecting an account you also agree to Plaid’s End User Services Agreement; Plaid’s handling of your data is described in its End User Privacy PolicyYour institution credentials (given by you directly to Plaid — we never see them), your phone number (for faster re-linking), and our queries for your account data
AppleSign in with Apple; Apple Card sync via FinanceKit (only if you use them)Your Apple user ID; FinanceKit data is read with your on-device permission
GoogleGoogle sign-in (only if you use it); Gemini dashboard generationYour Google user ID and the email/name Google returns; your dashboard prompt text (plus, when you edit a dashboard, its widget layout and earlier prompts) — no transaction records, and only after you opt in (section 4)
RevenueCatSubscription entitlement management and receipt validation for Martian Premium (only if you subscribe)Your app user ID (our internal account UUID), purchase and receipt data from the App Store or Google Play, and basic device/platform information sent by the RevenueCat SDK — no financial account data
Twelve DataLive and historical security pricesTicker symbols only — no personal data
Amazon Web ServicesHosting, database, and email delivery (SES)All app data, encrypted in transit and at rest
Google FontsWeb fonts on our marketing website only (not the app)Standard request data such as your IP address and browser user agent when a page on martianwealth.com loads

These providers process data on our behalf and are not permitted to use it for their own advertising. We may also disclose information if required by law, subpoena, or to protect the rights, property, or safety of our users or the public.

4. Artificial intelligence (Google Gemini)

One feature of Martian Wealth uses a third-party AI service: the dashboard chat, where you describe a dashboard in your own words and the app builds it. This section sets out exactly what that involves.

4.1 Who receives the data

The AI provider is Google LLC, through its Google Gemini API. Google is the only AI provider we use, and the dashboard chat is the only feature that uses one.

4.2 What we send

  • The prompt text you type — for example, “show my dining spend last month”.
  • When you edit an existing dashboard, the structure of that dashboard — its widget types and filter criteria, such as “pie chart, dining, last month” — and the earlier prompts you wrote for it, so the AI can interpret your edit in context.

4.3 What we never send

  • Your transactions, balances, investment holdings, or account numbers.
  • Your name, email address, phone number, or any identifier that ties the prompt to you or your account.
  • Your bank credentials or the access tokens we hold for your linked institutions.

Gemini returns only a dashboard structure — which charts to draw and what to filter on. Martian Wealth then runs those queries against your data on our own servers. Your financial data never reaches the AI service, and because no account identifier accompanies the prompt, the prompt is not linked to your identity on Google’s side.

4.4 Your permission

We ask for your permission in the app, on a screen that names Google Gemini and lists what is and isn’t sent, before any prompt is shared — and we don’t treat this policy or our Terms of Service as a substitute for that. Until you agree, the feature does not run: our servers refuse the request outright rather than relying on the app to enforce it.

You can withdraw permission at any time under Settings → Privacy control → AI dashboards in the app. Withdrawing stops all further sharing with Google immediately. Dashboards you already saved keep working, because they are rebuilt from your own data with no AI involved. Everything else in the app — account linking, transaction sync, investments, spending goals — works whether or not you turn this on.

4.5 How Google may use it

Google processes prompts as our service provider, under the Google APIs Terms of Service and Google’s applicable data protection terms, which oblige it to protect the data to a standard equivalent to the one described in this policy and to process it only to provide the service to us. We do not permit Google to use your prompts for advertising, and we do not use your data — prompts included — to train AI or machine-learning models, ours or anyone else’s.

4.6 What we keep

We store your prompt alongside the dashboard it produced, so you can re-run or refine it later. Deleting a dashboard deletes its prompt, and deleting your account deletes all of them — see section 6.

4.7 What not to type into a prompt

Prompts are sent to Google when you submit them, so please never include passwords, one-time codes, full account or card numbers, Social Security numbers, or any other secret in a prompt — we do not need them to build a dashboard, and we cannot recall a prompt once it has been sent.

4.8 No automated decisions or profiling

The AI feature only decides how to lay out the information you asked to see. We do not use AI or any other automated processing to make decisions about you with legal or similarly significant effects (such as credit, insurance, housing, employment, or pricing decisions), and we do not build profiles of you for those purposes, so no opt-out from automated decision-making or profiling is needed under state privacy laws.

5. How we protect your information

  • Institution access tokens are encrypted with AES‑256‑GCM before being written to the database. Encryption keys live in AWS Secrets Manager — never in the database or codebase.
  • Passwords are hashed with bcrypt (cost factor 12), and we enforce a minimum password strength on all new passwords.
  • All traffic between the app and our servers uses HTTPS/TLS; our database is encrypted at rest and reachable only from inside our private network.
  • Sign-in sessions use short-lived access tokens plus rotating refresh tokens that are stored hashed; reusing an old refresh token triggers revocation of all sessions for that account.
  • Account deletion requires a one-time confirmation code sent to your email. We store only a keyed hash of that code, it expires after 15 minutes, and it is invalidated after too many wrong attempts — so a stolen phone session alone can’t delete your account.
  • Access to production infrastructure is restricted to authorized personnel and protected by multi-factor authentication.
  • We maintain a written information security program and an incident response plan. If a security breach affects your personal information, we will notify you and the relevant regulators as required by law, including under the New York SHIELD Act.

No system is perfectly secure. If you believe your account has been compromised, email support@martianwealth.com and we’ll help you lock it down.

6. How long we keep your information

  • Account and financial data: until you delete your account, after which we delete or anonymize it within 30 days.
  • Connected-institution data: deleted immediately when you disconnect an institution — its accounts and transactions are removed from our database right away.
  • Server logs (including prompt previews): up to 90 days.
  • Refresh tokens: rotated on every use; expired and revoked tokens remain in our database (hashed, unusable) for security forensics until you delete your account.
  • Deletion confirmation codes: expire after 15 minutes; only a keyed hash is ever stored.

7. Your rights and choices

You can:

  • Access or export your data — email support@martianwealth.com and we’ll send you a machine-readable export within 30 days.
  • Correct your information — email support@martianwealth.com and we’ll fix your name, email, or phone number.
  • Delete your account from the in-app settings panel (Settings → Delete account). We’ll email you a one-time confirmation code; entering it permanently deletes your account, bank connections, accounts, transactions, dashboards, goals, and sessions, and we send a final confirmation email once it’s done. You can also request deletion by emailing us.
  • Disconnect an institution at any time from the Accounts screen, which revokes the Plaid access token and immediately deletes that institution’s accounts and transactions from our database.
  • Revoke Apple Card access at any time from your iPhone’s privacy settings or by disconnecting Apple Card in the app.
  • Object to processing or request restriction — email us and we’ll comply where legally required.

To the extent the GDPR applies, our legal bases for processing are performance of our contract with you (providing the app), our legitimate interests in securing and operating the service, your consent where required, and compliance with legal obligations.

If you’re in the EU/UK (GDPR), California (CCPA/CPRA), or a similar jurisdiction, you additionally have the right to know the categories of personal information we collect (listed in section 1), the right to data portability, the right to non-discrimination for exercising your rights, and the right to lodge a complaint with your local supervisory authority. We honor these requests for all users regardless of location. We do not “sell” or “share” personal information as those terms are defined in the CCPA/CPRA.

Browser and device signals (Do Not Track, Global Privacy Control)

We set no tracking cookies, bundle no analytics or advertising SDKs, and do not sell or share personal information or track you across third-party websites or apps, so there is nothing for an opt-out signal to switch off. We nevertheless treat a Global Privacy Control (GPC) signal, and any other opt-out preference signal recognized by law, as a valid request to opt out of the sale or sharing of personal information for the browser or device that sends it. Our website does not otherwise respond to “Do Not Track” signals, because there is no tracking to disable; if a Do Not Track standard we can act on emerges, we will update this policy.

California residents

If you live in California, the CCPA/CPRA gives you specific rights. Our California Privacy Notice is our notice at collection: it lists, category by category, the personal information we collect, where it comes from, why we use it, who receives it, how long we keep it, and how to exercise your rights to know, access, correct, delete, and port your information. In short: we do not sell or share personal information, we have not done so in the preceding 12 months, we do not use it for cross-context behavioral advertising, we use your financial account data (sensitive personal information) only to provide the service and for the security and legal purposes the CCPA permits, and we do not knowingly sell or share the personal information of anyone under 16. To exercise your rights, email support@martianwealth.com from the address on your account or use the in-app deletion flow; we will verify the request against your account email and respond within 45 days, you may use an authorized agent (we will ask for proof of authorization), and we will never discriminate against you for exercising a right.

Residents of other U.S. states

If you live in a state with a comprehensive privacy law — currently Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and any state that adopts a similar law — you have the right to confirm whether we process your personal data and to access it, to correct inaccuracies, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell personal data, do not engage in targeted advertising, and do not profile you or make automated decisions with legal or similarly significant effects, so the three opt-outs do not apply, but you may still ask. We honor universal opt-out preference signals such as Global Privacy Control. We extend these rights to every user regardless of where they live.

How to exercise and appeal. Email support@martianwealth.com from the address on your account (or use the in-app deletion flow). We will verify the request against your account email and respond within 45 days; we may extend once by a further 45 days for complex requests and will tell you if we do. If we decline all or part of a request, you may appeal within 60 days by replying to our decision with the subject line “Privacy request appeal.” We will answer the appeal in writing within 45 days (60 days where the law allows) with the reasons for our decision. If we deny the appeal, you may contact your state attorney general or privacy regulator; we will include the way to do so in our response.

Nevada residents

Nevada law lets residents direct a website operator not to sell certain covered information. We do not sell covered information and never have. You may nevertheless submit a request by emailing support@martianwealth.com with the subject line “Nevada Do Not Sell,” and we will confirm within 60 days.

Shine the Light and financial incentives

California Civil Code section 1798.83 lets California residents ask which personal information a business shared with third parties for those third parties’ direct-marketing purposes. We do not share personal information with any third party for its own direct marketing. We also do not offer any financial incentive, discount, or other benefit in exchange for the collection, retention, sale, or sharing of personal information, and we do not run referral or rewards programs; if that ever changes we will publish a notice of financial incentive first.

8. International users

At launch, Martian Wealth is offered only in the United States and is intended for U.S. residents. We operate from the United States and store data on AWS infrastructure in the United States. If you nevertheless use the app from elsewhere, the U.S. terms in this policy apply, and your information is transferred to and processed in the U.S. under the safeguards described here. To the extent the GDPR or UK GDPR applies to you, our legal bases for processing are those set out in section 7, and you may lodge a complaint with your local supervisory authority.

9. Children

Martian Wealth is for adults. The Services are offered only to people who are 18 or older, and we do not knowingly collect personal information from anyone under 18 — and never from children under 13. If we learn that we have collected personal information from someone under 18, we will delete it and close the account. If you believe a minor has provided us information, email support@martianwealth.com and we will take care of it.

10. Changes to this policy

We may update this policy as the app evolves. Material changes will be announced in-app or by email at least 14 days before they take effect, and you will be asked to re-accept the updated policy in the app before continuing to use it. The “Last updated” date at the top of this page always reflects the latest version. Prior versions are published at martianwealth.com/legal and are also available on request — email support@martianwealth.com.

11. Contact

Martian Labs LLC
418 Broadway STE N
Albany, NY 12207
United States
Email: support@martianwealth.com
Security reports: the same address, subject line "Security"


See also our Terms of Service.