Effective date: 2026-07-02 ยท Last reviewed: 2026-07-02 Operator contact: chriscwt@outlook.com
CC-Tracker is a self-hosted personal finance tracker operated by a single individual (the "operator") for their own personal use. It is not a commercial product, has no customers other than the operator, and is not offered to the public. This policy describes how the service handles the operator's own financial data.
financial institutions the operator has explicitly linked: transaction dates, amounts, merchant names, and category metadata.
transactions.
and notes.
The service does not collect analytics, advertising identifiers, location data, or data about anyone other than the operator.
Data is used solely for personal spend tracking, budgeting, and credit-card benefit management by the operator. There is no advertising, no profiling, no sale of data, and no sharing with third parties. No automated decisions with legal or similar effects are made.
Bank connectivity is provided by Plaid. When the operator links a financial institution, credentials are handled by Plaid โ this service never sees or stores bank passwords; it stores only the access tokens Plaid issues. Our use of Plaid is governed by Plaid's End User Privacy Policy, available at https://plaid.com/legal/#end-user-privacy-policy.
All data is stored on operator-controlled hardware with full-disk encryption enabled. The database accepts connections only from the local machine. The application is reachable only over a private, mutually-authenticated network (WireGuard-based) and is not exposed to the public internet. Backups are encrypted with a modern public-key tool (age) before leaving the machine; the decryption key never travels with the backups. Details are documented in the operator's Information Security Policy.
actively used.
deleted automatically), both locally and at the encrypted off-site copy.
backups are deleted, and the backup decryption key is destroyed.
The full procedure is documented in the Data Retention & Deletion Policy. Requests concerning personal data may be sent to the contact address above; as the operator is also the only data subject, requests are honored directly.
Material changes to this policy are recorded in the service's version-control history with the effective date updated above.
chriscwt@outlook.com