Privacy Policy
Effective May 3, 2026
This Privacy Policy explains how JLM Brands LLC ("JLM Brands," "we," "us," or "our") collects, uses, and protects information when you use the Earned Together website at earnedtogether.com and the Earned Together application (together, the "Service"). We built Earned Together for couples, and we built it with the assumption that you would rather we collect as little as possible.
1. Our principles
- No third-party trackers. The marketing site has zero analytics, zero advertising pixels, and zero third-party scripts.
- No bank linking. The app does not connect to your bank. You enter the numbers manually.
- No selling data. We do not sell, rent, or trade your personal information to anyone, ever.
- No advertising profiles. Your transactions are not used to build ad-targeting profiles.
2. Information we collect
Information you give us directly
- Account information: your email address, password (hashed by our auth provider — we never see it in plain text), and the display name you choose.
- Household information: the household name, your invite code, and the slot you occupy.
- Financial entries you create: joint and private transactions, goal names and amounts, recurring bills, budgets, monthly contributions, and any notes you attach. All of this is entered manually by you.
- Profile photo: if you upload one, it is stored in our object storage with an unguessable identifier.
- Communications: messages you send us at brands@jmorg.org or via in-app feedback.
Information collected automatically
- Server logs: when you use the app, our servers receive standard web request data — IP address, user agent, request path, response status, and timestamp — which we use to operate and secure the Service.
- Authentication cookies: our auth provider sets a session cookie so you stay signed in.
Information we do NOT collect
- We do not collect bank credentials or transaction feeds from financial institutions.
- We do not embed third-party analytics, advertising, or social-media tracking pixels on the marketing site.
- We do not collect biometric, health, or precise location data.
3. How we use information
We use the information described above to:
- provide, maintain, and improve the Service;
- create and protect your account;
- show you and your partner the joint information you have chosen to share;
- send transactional emails (account verification, password resets, invite codes, and important Service notices);
- investigate and prevent fraud, abuse, or violations of our Terms of Service;
- comply with legal obligations.
4. Couples and shared data
Earned Together is a two-person app. By design:
- Joint data is shared. Anything you log as joint — transactions, goals, budgets, recurring bills — is visible to your partner in the same household.
- Private data stays private. Items in your "My Money" side-ledger (your private income, bills, debts, savings, and other entries) are scoped to your account. The server never returns them to your partner.
- You control what becomes joint. You can move an item between joint and private at any time.
5. Service providers we use
We share information with a small set of vendors who help us operate the Service. They are bound by contract to protect your data and use it only for the purposes we specify.
- Clerk — user authentication, session management, and email delivery for verification codes. Clerk receives your email address, hashed password, and session metadata.
- Replit — hosting of the application, database, and object storage. Replit's infrastructure stores all data you enter into the app.
- Email delivery providers — transactional email infrastructure used by Clerk for verification and notification messages.
- Plaid (future, opt-in only) — if and when you choose to enable bank-account linking in the future, Plaid will act as our financial-data aggregator to securely retrieve account balances and transaction history from your financial institution. You will be asked to authenticate with your bank inside Plaid's secure flow; we never see your bank credentials. Bank linking is opt-in per partner and is not required to use the Service.
We do not use third-party advertising networks, behavioral analytics platforms, or data brokers.
6. Legal disclosures
We may disclose information if we believe in good faith that disclosure is required by law, court order, subpoena, or other legal process, or is necessary to protect the rights, property, or safety of JLM Brands, our users, or the public. We will push back on overbroad requests and, where legally permitted, notify the affected user.
7. How long we keep information
We keep your account information and household data for as long as your account is active. If you delete your account, we delete your personal information from our active systems within 30 days, except where we are required to retain it to comply with a legal obligation, resolve a dispute, or enforce our agreements. Backups are rotated on a normal schedule and purged within 90 days.
8. Security
We protect the Service with HTTPS for all traffic, modern password hashing (handled by our auth provider), encrypted database backups, the principle of least privilege for internal access, and a strict Content Security Policy on our marketing site that disallows third-party scripts. No system is perfectly secure; if you discover a vulnerability, please email brands@jmorg.org so we can fix it.
9. Your rights
You may, at any time:
- Access your data — most of it is visible inside the app, and you can request a full export by emailing brands@jmorg.org;
- Correct your account or household information from Settings;
- Delete your account and household data from Settings, or by emailing us;
- Leave a household — your private data leaves with you and the shared data remains with the household.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act ("CCPA"), the Texas Data Privacy and Security Act, or, if applicable, the EU/UK General Data Protection Regulation ("GDPR"). To exercise those rights, contact us at brands@jmorg.org; we do not discriminate against users who exercise their privacy rights.
10. Children
The Service is not directed to children under 18 and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will delete it.
11. International users
Earned Together is operated from the United States. If you access the Service from outside the U.S., your information will be processed in the United States. By using the Service you consent to that transfer.
12. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service before the changes take effect. The "Effective" date at the top of this page tells you when this version was published.
13. Contact
JLM Brands LLC5900 Balcones Drive, Suite 100
Austin, TX 78731
United States
brands@jmorg.org · (214) 420-6450