Privacy Policy
Effective July 23, 2026 · Last updated July 30, 2026
This Privacy Policy explains how TableHQ LLC ("Company",
"we", "us", or "our") collects, uses, discloses, and retains
personal information when a family uses Cents FYI at cents.fyi,
including the website, family workspace, child views, exports, support, and
billing features (together, the "Services").
TableHQ LLC is the operator responsible for the personal information described in this policy. Privacy questions and requests may be sent to support@cents.fyi.
The Services are a private, guardian-managed virtual family ledger. They do not connect to a bank account, hold or move money, issue a payment card, sell personal information, show behavioral advertising, or provide a public child profile.
This policy is a notice about our practices, not a waiver of a privacy right. Applicable law may give adults and children additional rights.
1 Scope and family roles
The first authenticated person who creates a workspace and agrees to the current Terms is the family owner. The Terms permit only an authorized adult parent or legal guardian to create a workspace. The owner can add children and guardians, transfer ownership, remove another guardian, export family data, and permanently delete the workspace. Other guardians can see and manage the household and every active child ledger. Every active guardian can manage billing and exports. Only the owner can remove guardian access or delete the whole workspace.
A guardian may create a child profile with only a name or may also enable a separate child login with an email address. A signed-in child can see only that child's name, balance, recurring-deposit information, and ledger history and can choose that child's avatar colors and optional mascot. Children cannot add, spend, correct, schedule, export, or administer family records.
This policy does not govern a provider-controlled identity page, payment page, linked website, or downloaded export once it is outside the Services. The person who downloads or shares an export is responsible for handling it appropriately.
2 Information we collect
2.1 Guardian accounts and family members
We process:
-
Guardian names, email addresses, internal user and organization identifiers, authentication method, family role, owner status, avatar colors, optional avatar mascot choices, account timestamps, and access or revocation status.
-
Child names, internal member identifiers, avatar colors, optional avatar mascot choices, and access status. A child email address and separate login are optional.
-
The time, account, and policy version associated with acceptance of the Services' legal terms and with parental consent.
-
Household name, currency, negative-balance rule, and setup status.
We do not ask a child for a date of birth, school, home address, telephone number, precise location, government identifier, or bank information.
2.2 Virtual ledger content
We process information a guardian adds to the family workspace, including:
-
Virtual credits, debits, amounts, descriptions, optional categories, optional merchant or place details entered by a guardian, dates, current balances, and timestamps.
-
The child ledger associated with an entry and the guardian who entered it.
-
Detail-edit history, corrections, links among an original, reversing entry, and replacement, and related audit history.
-
Recurring-deposit amount, description, interval, start and next-deposit date, time zone, status, and the guardian who created the schedule.
Ledger amounts are records of a family's own agreement. They are not bank balances, stored value, or evidence that money is held by us.
2.3 Authentication, communications, and support
We process email addresses and delivery information to send one-time codes, magic links, welcome messages, child-consent confirmations, billing notices, security messages, and support replies.
If a person contacts us, we process the message, attachments, contact information, and related account or request details needed to respond. Please do not put unnecessary sensitive information in a support message or ledger description.
If a person chooses third-party sign-in, the identity provider supplies the
verified email address needed to locate the account. We request the openid and
email scopes, not contacts, profile photos, files, or a full provider profile.
2.4 Payments
Our payment processor may process customer, payment-card, billing-address, checkout, subscription, invoice, price, payment-status, refund, dispute, and fraud-prevention information.
We store payment-customer and subscription identifiers, selected price, subscription and trial status, billing-period dates, upcoming amount and date, whether a payment method exists, and evidence of recurring authorization (guardian account, email, time, price, expected first-charge date, disclosure, and legal version). The payment processor collects complete card details on pages it controls. We do not store full card numbers or card security codes in the Cents FYI application database.
2.5 Technical information and cookies
When a browser requests the Services, our systems and infrastructure providers may process information needed to deliver and protect them. This can include IP address, browser and device type, operating system, requested URL, referring URL, request time, response status, and security or error information.
We use:
-
en_session, an essential, signed, HTTP-only cookie that maintains authentication, short-lived account-creation acknowledgements, chosen plan, and safe return destination. -
en_themeanden_color_theme, one-year preference cookies that remember the selected display mode and color palette, plus client-hint storage for color-scheme, time zone, and related browser preferences. -
Ordinary browser cache storage for application files.
We do not load browser analytics, advertising cookies, analytics cookies, or session-replay tools on the Services. A provider may use cookies on an identity or payment page it controls after a person chooses to open that page.
Blocking the essential session cookie prevents sign-in. Clearing cookies signs the browser out but does not delete records already stored in the family workspace.
3 Sources of information
We receive information:
-
From family owners and guardians, when they create an account, add family members, record or correct entries, create schedules, choose settings, provide consent, manage billing, export data, or contact us.
-
From children under guardian authorization, when a child uses the optional separate login to view that child's ledger or customize that child's avatar.
-
From identity, email, and payment providers, when a person starts an authentication, delivery, or billing interaction.
-
From browsers, devices, and infrastructure, through ordinary requests, essential cookies, preferences, security controls, and error records.
4 How we use information
We use personal information to:
- Create, authenticate, secure, and support family accounts.
- Apply family-owner, guardian, and child permissions.
- Store and calculate private virtual balances, ledger history, corrections, and recurring deposits.
- Send authentication, consent, access, security, billing, and support communications.
- Create a family JSON export requested by a guardian.
- Administer trials, subscriptions, invoices, cancellations, refunds, and disputes.
- Diagnose failures, maintain reliability, prevent fraud or abuse, enforce our Terms of Service, and protect families and the Services.
- Comply with law and establish, exercise, or defend legal claims.
We do not use child information for advertising, behavioral profiling, or model training. We do not make solely automated decisions about a child that produce legal or similarly significant effects.
5 How we disclose information
We do not sell or rent personal information and do not share it for cross-context behavioral advertising. The Services have no public feed, public child profile, or built-in public posting feature.
5.1 Authorized family members
The family owner and active guardians can see every active family member and child ledger. A child with a separate login sees only that child's record.
When the owner removes a guardian, access and active sessions are revoked. The former guardian's name can remain attached to entries or schedules that person created so the remaining family can understand its audit history.
5.2 Service providers
Providers may process information as needed for their role, including:
-
Amazon Web Services (AWS) for hosting, network, compute, storage, backup, and related infrastructure used to operate and secure the Services.
-
PurelyMail for verification, consent, account, billing, security, and support email delivery.
-
Google when a person chooses Google identity services. For a child login, this can include the child's email address and ordinary authentication metadata.
-
Stripe for guardian payment methods, subscriptions, invoices, fraud prevention, refunds, and disputes. We do not send child ledger content to Stripe.
Providers receive only information reasonably needed for their function. A provider's own policy applies when it acts independently or when a person interacts directly with a provider-controlled page. The Company contact in Section 14 is designated to answer parental questions about all collection through the Services.
5.3 Legal, safety, and business purposes
We may disclose information:
-
To comply with law, regulation, subpoena, court order, or valid legal process.
-
To investigate fraud, abuse, security incidents, or threats to a person, family, the Company, or the Services.
-
To establish, exercise, or defend legal claims.
-
In connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and notice where required.
6 Legal bases
Where a law requires a legal basis, we rely on:
-
Contract, to provide the account, ledger, export, and billing features a guardian requests.
-
Consent, including parental consent for a child's profile and optional login.
-
Legitimate interests, to secure, maintain, troubleshoot, and improve the Services and prevent abuse, balanced against the rights of families and children.
-
Legal obligations and claims, for accounting, tax, consumer, privacy, safety, and dispute requirements.
A guardian may withdraw child consent as described below. Withdrawal does not make prior lawful processing unlawful.
7 Children's privacy
The Services are designed to let an adult parent or legal guardian maintain a private family ledger that may include children, including children under 13. We do not permit a child to create a new family workspace.
6.1 Direct notice and parental consent
Sign-in and account creation use the same verified-email or identity-provider flow. If the identity is not already associated with an account, continuing creates a workspace subject to the Terms, which permit only an authorized adult parent or legal guardian to create one. Signing in or creating a workspace is not parental consent for any child profile.
Before a guardian creates any child profile, we prominently explain:
-
The child information collected: name, optional login email, avatar colors and optional mascot choice, virtual balance, entries, schedules, and technical account data.
-
Why it is collected: to provide and secure the private family ledger, optional child access, authentication, support, and legal compliance.
-
Who can receive it: authorized family members and the limited providers and legal recipients described in Section 5.
-
The guardian's review, export, access-revocation, consent-withdrawal, and deletion controls.
The signed-in guardian must expressly consent. We record the guardian, time, and policy version and send a separate confirmation to the guardian's authenticated email address. A legacy child record or materially changed notice requires a new review before routine ledger activity continues or a child login can enter the product. During review, the guardian can identify the affected profile, review the notice, export existing data, disable access, or delete the child record.
6.2 Child access and data minimization
A child profile needs only a name. A separate child email, login, and mascot are optional. A child login receives only that child's member record, balance, recurring deposit, and entries; it does not receive guardian emails, sibling names, sibling balances, or sibling history. Ledger access is view-only, but the child may change that child's own avatar colors and mascot.
We do not condition a child's participation on providing more information than is reasonably necessary for that child to view the family ledger.
6.3 Guardian controls
An active guardian can review the information in Family and each child ledger, download a family export, disable a child's separate login, and permanently delete one child's profile and complete ledger. The family owner can permanently delete the entire workspace.
To revoke only separate child access, use Disable login in Family; this removes the child's login identity while leaving the guardian-managed ledger. To withdraw parental consent and stop collection for the child, use Delete ledger or email support@cents.fyi. Deleting the child ledger removes the profile, login, balance, schedule, and history from the active service.
We may verify that a requester is the signed-in guardian or otherwise authorized before disclosing or deleting a child's information. We will not require disclosure of more child information than reasonably needed to complete that verification.
If we learn that child information was collected without required parental consent, we will disable access and delete it as required. Contact support@cents.fyi with the child's name and the guardian account email; do not send additional child information unless requested.
7 Retention and deletion
We keep family content while the workspace is active because the guardian uses it as an ongoing ledger. Guardians can delete a child ledger or the owner can delete the workspace at any time; those controls remove the covered content from the active application database.
If a subscription ends, the workspace is retained for 90 days so the family can resubscribe, export, or delete it. After that period, the workspace is eligible and scheduled for permanent deletion, including child profiles, logins, balances, schedules, consent records, and entries. Resubscribing before the deadline clears it.
Removing a guardian revokes access but retains the former guardian identity attached to ledger audit history until the related entry or workspace is deleted. Payment, tax, accounting, fraud, security, deletion, and dispute records may be retained separately for the period reasonably necessary to meet legal obligations, demonstrate compliance, or resolve claims. This includes recurring-authorization evidence retained for the applicable statutory recordkeeping period.
Infrastructure logs and backup copies can persist for a limited provider rotation period after active deletion. They are isolated from ordinary product access and are not restored except for continuity, security, or legal needs. We do not retain child information indefinitely for an unrelated future use.
8 Security
We use administrative, technical, and organizational safeguards designed for the nature of the information, including verified passwordless authentication, signed HTTP-only sessions, role checks, child-specific server-side data scoping, restricted database access, encrypted network transport, and provider-access controls.
No service can guarantee absolute security. Guardians should protect email accounts, one-time codes, provider credentials, sessions, exports, and devices. Contact support@cents.fyi promptly if you suspect unauthorized access.
9 International processing
We and our providers may process information in the United States and other countries where they operate. Those countries may have different data protection laws. Where required, we use an approved transfer mechanism or another lawful safeguard.
10 Privacy rights and choices
Depending on where you live, you may have rights to know, access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to appeal a denied request. You may also have a right to withdraw consent or complain to a privacy authority.
Guardians can exercise many rights directly through Family and the family JSON export. For another request, email support@cents.fyi, preferably from the account address, and describe the request. We may ask for information reasonably needed to verify identity, family authority, and the scope of the request.
We do not sell personal information or share it for cross-context behavioral advertising, so there is no sale or advertising-sharing opt-out to apply. A Global Privacy Control signal does not change those practices. Essential authentication, security, and ledger operations also do not change in response to Do Not Track.
10.1 U.S. state disclosures
For state laws using defined categories, we may collect:
-
Identifiers, such as names, emails, IP addresses, and internal account, organization, family, and payment-customer identifiers.
-
Commercial information, such as selected plan, subscription, invoice, and payment status.
-
Internet or electronic activity, such as requested pages, browser data, preferences, and security or error events.
-
User content, consisting of household settings, virtual ledger entries, descriptions, categories, optional places, schedules, edits, and corrections.
We collect these categories from the sources in Section 3, use them for the purposes in Section 4, and disclose them to the recipients in Section 5. We have not sold these categories or shared them for cross-context behavioral advertising, and we do not knowingly sell or share the personal information of people under 16.
11 Third-party services and links
Identity, payment, and other linked services are controlled by third parties. Opening one may disclose ordinary request information and information a person chooses to provide. Review its policy before continuing. We are not responsible for a third party's independent privacy, security, or content.
12 Changes to this policy
We may update this policy as the Services, providers, or legal requirements change. The date at the top identifies the current version. If a change materially affects child information already collected, we will provide direct notice and obtain new parental consent when required before applying that change.
13 Contact
The operator responsible for this policy is TableHQ LLC.
For privacy questions, parental requests, complaints, or account concerns, email support@cents.fyi.