Last updated May 15, 2026
Privacy Policy
This Privacy Policy describes how GuapStaxhandles your information. The short version: we collect as little as possible, we don't sell or share your data, and we don't use tracking or advertising cookies.
App Overview
GuapStax is a manual-first personal finance application built to help individuals and couples manage debt, plan payoff strategies, and visualize their cash flow — without ever linking a bank account or surrendering credentials to a third-party aggregator.
Our intended audience is consumers tracking credit cards, loans, mortgages, recurring bills, and income on their own terms. Every entry is made manually (or via CSV import); the app never reaches out to your bank, your card issuer, or any external financial service on your behalf.
Google User Data
If you choose to sign in with Google, the sections below describe exactly what Google user data GuapStax accesses, why we use it, where we store it, and whether we share it. We comply with the Google API Services User Data Policy, including the Limited Use requirements (see the Limited Use section below).
Access
When you sign in with Google, we request the following OAuth scopes:
openid— required by OpenID Connect to identify your Google account.email— your verified Google email address, used as your GuapStax account identifier.profile— your basic Google profile fields (display name, profile picture URL, locale).
We also pass access_type=offline when initiating the OAuth flow so that Google issues a refresh token. The refresh token is used only to maintain your signed-in state — it is not used to call any Google API.
We never request access to Gmail, Calendar, Drive, Contacts, Photos, Tasks, or any other Google product or API.
Use
We use Google user data exclusively to:
- Create your GuapStax account on first sign-in;
- Identify you on subsequent sign-ins (matched by your verified Google email);
- Personalize the in-app greeting and avatar when you have not set a custom display name.
We do not use Google user data for advertising, profiling, training machine-learning models, or any analytics beyond essential authentication and product-usage events tied to your GuapStax account.
Storage
Google data is stored in our Supabase Auth database under our control:
- Your Google email address and basic profile fields are stored in your GuapStax user record.
- The Google-issued refresh token is stored encrypted by Supabase Auth and used solely to maintain your session.
- Session cookies (signed JWTs) are stored in your browser; they expire automatically and are refreshed only while you remain signed in.
Retention. We retain Google-sourced data for the lifetime of your GuapStax account. When you delete your account (by emailing support@guapstax.com), all Google user data — including the refresh token and any cached profile fields — is permanently removed from our systems within 24 hours.
Limited Use of Google User Data
GuapStax's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described in the Google User Data section above.
- We do not transfer Google user data to others except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets — in which case we will give affected users advance notice.
- We do not use Google user data to serve advertisements, including personalized, retargeted, or interest-based advertising.
- We do not allow humans to read Google user data unless: (a) we have your affirmative agreement for specific data; (b) doing so is necessary for security purposes (such as investigating abuse); (c) doing so is necessary to comply with applicable law; or (d) the data has been aggregated and anonymized for internal operations.
Information We Collect
To operate the service, we collect:
- Account information — your email address (used to sign in and recover your account) and, when you sign in with Google, the basic Google profile fields described in the Google User Data section above.
- Financial data you enter manually — tradeline balances, income, bills, subscriptions, and any other entries you choose to record. This data lives in your own account and is never shared outside it.
We do not collect: your real name (unless you supply it as a display name), mailing address, phone number, date of birth, government ID, bank credentials, or any other PII beyond what is listed above.
Data Security
All data is transmitted over HTTPS. Row-level security policies ensure that your data is accessible only to you when signed in. Session tokens are stored in HTTP-only cookies.
No system is perfectly secure. We will notify you promptly of any breach that may have affected your data.
Your Rights
You can:
- Access your data at any time by signing in;
- Request a copy of your data by emailing support@guapstax.com;
- Request deletion of your account and associated data — including any Google-sourced data — by emailing support@guapstax.com.
We will respond to data access and deletion requests within a reasonable timeframe (no more than 24 hours for Google-sourced data deletion).
Children's Privacy
GuapStax is not directed to children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has provided us information, contact support@guapstax.com and we will delete it.
Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will make a reasonable effort to notify you (e.g. via email or an in-app notice).
Contact
Questions about this Privacy Policy can be sent to support@guapstax.com.