Privacy Policy
This app holds your household's money in one place. Here is exactly what that means for your data.
Last updated 30 August 2026
Who runs this
The 2 of Us is operated by Cornfield Media, LLC (“we”, “us”). You can reach us at support@cornfieldmedia.com about anything on this page.
The short version
- We collect what the app needs to work: your sign-in details, and the financial data you add or connect.
- A household is a shared ledger. Every member sees every account and transaction in it — that is what the product is for, and it is why there is nothing to configure here. Join a household with someone you intend to share your finances with completely.
- We do not sell your data, show you ads, or track you across other sites.
- There are no analytics or advertising trackers in this app at all.
- We do not send you marketing email. The app sends exactly one kind of message — a password-reset link, and only when you ask for one.
What we collect
Account details, which you give us when you register:
- Your email address, used to sign in and to identify your account.
- Your display name, if you set one.
- Your password, stored only as an Argon2 hash. We never store it in a form we can read, and we cannot recover it for you.
Financial data, which you enter by hand or connect through your bank:
- Accounts: name, type, institution, currency, and balance.
- Transactions: description, amount, date, category, whether the cost is shared, and who paid.
- Your household’s name, its members, and the categories you create.
- For connected banks: the institution, each account’s name and type, the last four digits of the account number, current balances, and your transaction history as your bank reports it.
Security records, which the app creates on its own:
- A record of recent sign-in and registration attempts, containing the email address used and the network (IP) address it came from. These exist to stop password guessing, and are deleted as the rate-limit window they belong to expires.
- A session cookie that keeps you signed in. It is not used for tracking and carries no advertising identifier.
- The date you agreed to this policy and the Terms, and which published version you agreed to — recorded when you register, so that what you consented to is a matter of record rather than of memory.
Connecting a bank
Bank connections are handled by Plaid Inc., which specializes in them. When you link an account you authenticate with your bank through Plaid — either inside Plaid’s own dialog, or on your bank’s website for institutions that require it.
- Your bank username and password are never seen by this app. They go to Plaid or to your bank directly, and never reach our servers.
- Plaid gives us a long-lived access token for the connection. It is encrypted at rest with AES-256-GCM and is never sent to your browser.
- We request one thing from Plaid: transactions. We do not request account or routing numbers, your identity, your income, or your investments.
- Plaid handles your information under its own End User Privacy Policy. Please read it — it governs what Plaid itself collects and keeps, which is not something we control.
- Unlinking a bank tells Plaid to revoke the connection and deletes our copy of the token. The transactions already imported stay in your ledger, so your history does not develop a hole; ask us if you want them removed too.
Who else can see your data
Nobody buys it and nobody is given it for their own purposes. It passes through these services because the app cannot run otherwise:
- Plaid — bank connections, as described above.
- Stripe — payments. When your household subscribes, your card details are entered on Stripe’s own page and never reach our servers; they hold your card and billing details, and we hold only the identifiers Stripe gives us for your household’s customer and subscription, and whether that subscription is active. We give them the email address of whoever subscribes, so receipts reach a real inbox. Nothing about your accounts, balances or transactions is sent to them. Stripe handles that information under its own privacy policy.
- Vercel — hosting. Your requests reach the app through their infrastructure.
- Neon — the database where all of the above is stored.
- Resend — email delivery, for one message only: the link you get when you ask to reset your password. They see your email address and that link. Nothing about your money passes through them, and the app sends no other mail — no newsletters, no notifications, no receipts.
We may also disclose data if the law requires it, or where it is necessary to investigate abuse or protect someone’s safety.
How it is protected
- Your financial data is encrypted in the database. Every amount, date, description, account name, balance and category is stored as AES-256-GCM ciphertext, not as readable text. Someone holding a copy of the database — a stolen backup, a compromised replica — gets nothing from it without a key held separately by the application.
- Passwords are hashed with Argon2. Plaid access tokens are encrypted at rest too.
- All traffic is served over HTTPS.
- Every request is checked against your household membership, so one household can never read another’s data.
- Sign-in and registration are rate limited to blunt password guessing.
Changing your password signs out every session, on every device, including the one you change it from. If you think someone else has your account, changing your password is enough to lock them out — you do not have to reach the device they are using.
Encryption has limits worth naming rather than glossing over. Your email address, the structural links between records, and timestamps like when a row was created are not encrypted — the app has to look accounts up and join records together. And encryption protects data at rest: it does not protect you from someone who has your password, which is why the password advice above matters more than any of this.
No service can promise perfect security, and we do not. What we can promise is that we will not pretend otherwise.
How long it is kept
Your account and financial data stay until they are deleted — we do not expire them on a schedule, because a finance history is only useful if it goes back. Rate-limit records are discarded as their window expires. When you leave a household, your transactions stay with the household, because removing them would rewrite settled history for the people still in it.
Your choices
You can edit or delete your accounts, transactions and categories in the app at any time, and unlink a bank whenever you like.
To take your data with you, go to Settings → Your data. The spreadsheet holds your full ledger; the JSON also carries your accounts, categories and household members. No request, and no waiting on us.
To delete your account, go to Settings → Delete account. It removes your email, name and password outright. If you are the only person in your household, the household and everything in it goes with you, and any linked bank is disconnected at Plaid first. If others remain, they keep the household, and transactions you entered stay in its ledger without your name on them — we cannot rewrite their records to erase you from them.
Depending on where you live you may also have rights to correct your data, restrict how it is used, or object to that use. Email support@cornfieldmedia.com to exercise them, or for anything the two buttons above do not cover.
Children
This app is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how your data is used, tell you in the app before it takes effect.
The version you agreed to is stored with your account, so the difference between what you accepted and what is published today is something we can see rather than something you have to have noticed.