Lake Financial: Privacy Policy
Effective date: August 31, 2026
Last updated: August 31, 2026
Revision note (August 31, 2026): this revision replaces the July 24, 2026 policy, whose source and SHA-256 hash are archived. It adds disclosures for Vercel Web Analytics, Google Analytics 4, the Meta Pixel on the public funnel pages, the first-touch campaign-attribution cookie, the HubSpot customer-relationship system, the in-product accuracy survey, the free trial, and marketing email, and it corrects the July version's statement that the Service used no analytics or advertising technology, which stopped being accurate when advertising measurement launched in August 2026. Because the prior policy understated actual practice, this revision was published on an accelerated schedule rather than after a 14-day notice window; the notice describing the change is shown in the Service. Review by outside counsel is recommended and pending; publication was directed by the owner.
This Privacy Policy explains how Rieper LLC, an Indiana limited liability company doing business as Lake Financial ("Lake," "we," "us"), collects, uses, protects, shares, and deletes information when you use www.lakefin.net and the Lake application (the "Service").
Lake exists to show you your own money clearly. Handling your financial data carefully is not a side concern of that job: it is the job. This policy is written to be read, not skimmed past.
The short version
- We do not sell your personal information. We never have and we do not intend to.
- We do not share your financial data with advertisers. We use Vercel Web Analytics (cookie-free, aggregated) and Google Analytics (first-party cookies, measurement only, with sensitive URLs minimized) for usage statistics as described below. Our public landing and sign-in/sign-up pages use the Meta (Facebook) advertising pixel to measure our own advertising; it does not run on signed-in application pages, never receives your linked-account or financial data, and does not load at all when your browser sends the Global Privacy Control signal.
- We keep a customer-relationship record. Your email address, plan and trial status, campaign attribution, and survey and feedback responses are kept in HubSpot, our customer-relationship system, so we can run the Service's emails and understand our customers. Your linked-account and financial data never goes there.
- We never see your bank username or password. You enter credentials or authorize access through Plaid Link or your financial institution's OAuth flow, not through Lake.
- Your Plaid access tokens and your optional profile fields are encrypted at rest with AES-256-GCM, separately from ordinary database storage.
- You can delete your Lake account from Settings at any time. Lake attempts to remove each Plaid connection, deletes the active Lake database records linked to your user, deletes your Clerk authentication record, and deletes your HubSpot contact record, subject to the provider-retention, support-record, and backup limits in Sections 5 and 6.
- We use your data to run Lake for you. Not to build a profile to monetize elsewhere.
The rest of this document is the detail behind those statements.
1. Information We Collect
1.1 Information you give us
| What | Detail | Required? |
|---|---|---|
| Account identity | Email address, and any name or profile image you provide, handled through our authentication provider Clerk | Required |
| Optional profile | Birth year you choose to provide, plus any legacy gender value you provided before that field was removed | Optional: birth year is used only for an age-group comparison based on published public benchmarks; stored profile fields are encrypted at rest and separately deletable |
| Your labels and notes | Budget and category names, goal names and targets, account nicknames, colors and icons, transaction notes, custom merchant categorization rules | Optional |
| Attachments | Receipts and documents you attach to transactions (up to 4 MB per file, 5 per transaction) | Optional |
| Support and feedback | Support emails, including the sender address and any message, attachment, and email metadata you choose to send; answers you submit through in-product feedback prompts; in-app thumbs up, thumbs down, and dismissals on Insights, together with the Insight/template/instance context, relevant merchant, category, budget, or goal label, wording variant, and timestamp | Optional |
| Accuracy survey | If you answer the one-time in-product survey about the spending summary ("the reveal"), your multiple-choice answers about accuracy and usefulness and any free-text notes about what surprised you or looked wrong | Optional |
| Plan and trial status | Your plan, billing interval, subscription status, and, if you start the free trial, the trial's start and end dates | Created when you subscribe or start a trial |
1.2 Financial information from your linked accounts
When you link a financial institution, Plaid Inc. facilitates the connection with that institution and provides us with account data on an ongoing basis. Depending on the institution and the accounts you select, this includes:
- Account details: account name, official name, an account mask (typically the last four digits when the institution provides it), account type and subtype, currency
- Balances: current balance, available balance, credit limits
- Transactions: amount, date, authorized date, description as reported by your institution, merchant name, pending status, and the institution's own category assignments
- Investments: securities held, quantities, cost basis, market values, and related security details
- Liabilities: for supported credit-card, student-loan, and mortgage accounts: APRs or interest rates, statement or principal amounts, minimum and last-payment amounts and dates, next due dates, payoff details, overdue status, and similar terms
- Institution identity: the name and identifier of the institution, and the technical status of the connection
We do not receive or store your online banking credentials. You enter them through Plaid Link or authorize access through your financial institution's OAuth flow. Lake receives an access token, which is encrypted before it is stored and is used solely to fetch the data above.
1.3 Information we generate
- Derived information: merchant normalization and repeat-place or repeat-category groupings; visit counts and frequency; the Hodges-Lehmann estimated amount of recent eligible visits used as your usual spend; mapped spending-limit amounts and estimated visits left; detected recurring income streams; and budget pacing, snapshots, rollups, trends, forecasts, volatility measures, anomaly flags, and Insights. Lake calculates these from your linked-account and user-provided data.
- Enriched transaction fields: a cleaned merchant name, a category, and a merchant logo, described in Section 3.
- Alerts: unusual-transaction, low-balance, and goal-off-track notices, with their dismissal state.
- Lifecycle events: timestamps for when your account was created, when you first synced a linked institution, when a trial started or is scheduled to end, and when a subscription started or ended, recorded in our customer-relationship system as described in Sections 1.5 and 3.1.
1.4 Information collected automatically
- Authentication and session data: handled by Clerk, including session cookies strictly necessary to keep you signed in.
- Server and security logs: Vercel processes request information such as IP address, timestamp, user agent, requested path and search parameters, request identifiers, region, response status, and function or routing metadata for hosting, security, abuse prevention, and debugging.
- Route and page-view analytics: Vercel Web Analytics receives route and page-view data across the Service that may include timestamp, hostname, page URL, framework route, filtered query parameters, referrer, approximate location derived from IP address, browser, operating system, device type, and analytics script version. Lake sends no custom analytics events. Before a page view is sent, Lake replaces transaction identifiers and reversible spending-detail keys in the corresponding detail URLs with route placeholders and removes query strings and fragments from those two normalized URLs.
- Google Analytics (site-wide): the Service uses Google Analytics 4 (Google LLC) to understand how the Service is used. Google Analytics sets first-party cookies (including `_ga`) and receives information such as your IP address, browser and device information, approximate location derived from IP address, the pages you visit, and product-funnel events such as sign-up, paywall views, and checkout starts. Lake configures it for measurement only: Google Signals and ad-personalization are disabled, automatic page tracking is replaced with events that pass through the same URL minimization described above for Vercel Web Analytics (transaction identifiers and reversible spending-detail keys are replaced with route placeholders before transmission), and no linked-account or financial data, no merchant, amount, balance, or account detail, is ever included in an event. Google's handling is governed by Google's privacy policy (policies.google.com/privacy); you can opt out with the Google Analytics opt-out browser add-on (tools.google.com/dlpage/gaoptout) or by blocking cookies.
- Advertising measurement (public funnel pages only): the public landing page, the sign-in and sign-up pages, and the brief post-signup welcome page load the Meta Pixel, which sets Meta advertising cookies (including `_fbp`) and sends Meta Platforms, Inc. information such as your IP address, browser and device information, the funnel page visited, referrer, cookie identifiers, and standard events (page views, and a signup-completed event on the welcome page). Lake uses this to measure whether its Facebook ads work and to reach ad audiences. The pixel does not load on signed-in application pages, no linked-account or financial data is ever sent to Meta, and the pixel does not load at all when your browser sends the Global Privacy Control (GPC) signal. Meta's use of this information is governed by Meta's own privacy policy (facebook.com/privacy); you can also limit Meta's ad targeting at facebook.com/adpreferences, and browser tracking protections or blocking third-party cookies likewise limit the pixel.
- Campaign attribution cookie: if you first arrive at Lake from a link carrying campaign parameters (`utm_source`, `utm_medium`, `utm_campaign`, `utm_content`), Lake stores those values in a first-party cookie named `lake_utm` for up to 90 days. It is written once, your first visit's values are never overwritten, and contains only those campaign labels, never an identifier of you. If you later create an account, the stored campaign labels are copied to your customer-relationship record (Section 1.5) so we know which of our campaigns brought you, and the cookie has no other use.
Signed-in application pages do not use advertising cookies, advertising pixels, session recording, or cross-site behavioral trackers; the Meta Pixel described above runs only on the public funnel pages. Vercel states that Web Analytics does not use cookies and stores page-view data in anonymized, aggregated form rather than associating it with an individual or IP address. Vercel also states that its visitor-identification hash is reset every 24 hours; that statement does not mean page-view records are deleted within 24 hours. See Vercel's Web Analytics privacy documentation at vercel.com/docs/analytics/privacy-policy.
1.5 Your customer-relationship record
Lake keeps a customer-relationship record for each account in HubSpot and Lake Financial's internal database, keyed to your email address. It can include: your lifecycle stage with Lake (signed up, activated, trialing, subscribed, or churned, with timestamps); your trial start and end dates; the first-touch campaign labels described in Section 1.4; your answers to in-product feedback prompts and the accuracy survey; and the delivery history of emails we send you. It never includes your linked-account or financial data, no balances, transactions, merchants, holdings, or liabilities, and no derived spending information. Section 3.1 describes HubSpot as a processor; Section 6 describes how this record is deleted with your account.
2. How We Use Your Information
We use your information only for these purposes:
- To provide the Service: automatically track spending from linked accounts; identify and display repeat-place or repeat-category habits, usual spend, visit frequency, recent visits, and matched spending-limit context; display accounts, balances, transactions, and selected liability indicators; receive and maintain supported investment holdings and liability details; and run budgets, goals, snapshots, reports, exports, and Insights.
- To authenticate you and secure your account: verify who you are, detect and prevent fraud and abuse, and protect the integrity of the Service.
- To process payments and administer plans: create and manage subscriptions, one-time purchases, and free trials, and determine which features your plan entitles you to.
- To communicate with you about the Service: service, security, billing, trial-status, and account notices; responses to your support requests. These operational messages are part of the Service and are sent to all accounts.
- To send marketing communications: with the limits in Section 6, we may send you product news, feature announcements, and offers by email. Every marketing email includes a working unsubscribe link, and unsubscribing never affects your account, your data, or the operational messages in purpose 4.
- To measure our advertising and understand usage: the analytics and advertising-measurement processing described in Section 1.4, and campaign attribution as described there.
- To improve and personalize the Service: diagnose errors, fix calculations, rank Insights, select among Insight phrasing variants after enough feedback, honor Insight dismissals, and evaluate whether the spending summaries we show are accurate and useful, using your survey and feedback responses.
- To comply with law: meet legal, tax, and regulatory obligations, and respond to lawful requests.
We do not use your financial data to build advertising profiles, to train models for sale or licensing to third parties, or for any purpose unrelated to operating Lake for you.
Aggregated and de-identified data. We may create aggregated operational statistics that cannot reasonably be linked to an individual and use them to operate and improve the Service. Lake's current age-group comparison uses published Federal Reserve survey benchmarks, not pooled Lake-user financial data. We do not re-identify de-identified data or license it to third parties.
3. Who We Share Information With
We share information only in the circumstances below. We do not sell personal information, and we never share your linked-account or financial data with advertisers. The Meta Pixel measurement on our public funnel pages (Sections 1.4 and 3.1) may constitute "sharing" for cross-context behavioral advertising under some state privacy laws; Section 6 describes how to opt out, and the pixel is suppressed automatically for browsers sending the Global Privacy Control signal. It is the only such sharing Lake engages in.
3.1 Service providers who process data for us
| Provider | Role | What it receives |
|---|---|---|
| Plaid Inc. | Bank account connections | Credentials or authorization entered through Plaid Link or your financial institution's OAuth flow, never through Lake, plus account, balance, transaction, investment, and liability data. Plaid's handling of your data is governed by Plaid's own end user privacy policy at plaid.com. |
| Clerk | Authentication and identity | Email address, login and session data, and any profile details you provide at sign-up |
| Stripe, Inc. | Payment processing | Your payment method and billing details, entered directly with Stripe. Lake never receives your full card number. We store only Stripe's customer and subscription identifiers, your plan, and its status. |
| Neon | Database hosting | All data described in Section 1 that we store, as our hosting infrastructure |
| Vercel Inc. (hosting) | Application hosting, scheduled jobs, and server/security logging | Requests and application data processed in transit, plus the request and log information described in Section 1.4 |
| Vercel Inc. (Web Analytics) | Cookie-free route and page-view analytics | The analytics information described in Section 1.4. Lake sends no custom events and normalizes the two sensitive detail-route values described there before transmission. |
| HubSpot, Inc. | Customer-relationship management and email delivery | Your email address and the customer-relationship record described in Section 1.5: lifecycle stage and timestamps, trial dates, first-touch campaign labels, and your feedback and survey answers. Never your linked-account or financial data. Governed by HubSpot's privacy policy at legal.hubspot.com/privacy-policy. |
| Trove (Headline) | Transaction enrichment | For each transaction we enrich: the description, amount, date, and a pseudonymous Lake user identifier. Not your name, email, bank-account numbers, or balances. |
| Logo.dev | Merchant logos | Requests for merchant logos are made from your browser, so Logo.dev may observe your IP address and the merchant domain requested. It does not receive your identity, amounts, or account data. |
| Apple iCloud Mail | Receiving support email sent to contact@rieper.org | Sender address, recipient address, subject, message body, attachments, and email routing metadata included with the message |
| Google LLC (Google Analytics 4) | Site-wide usage analytics (measurement only; Google Signals and ad-personalization disabled) | First-party analytics cookies (including `_ga`), IP address, browser and device information, and pages visited with sensitive detail URLs normalized to route placeholders before transmission. Never linked-account data, balances, or transactions. Governed by Google's privacy policy at policies.google.com/privacy. |
| Meta Platforms, Inc. | Advertising measurement via the Meta Pixel, on public funnel pages only | Cookie identifiers (including `_fbp`), IP address, browser and device information, referrer, and which of the landing, sign-in, sign-up, or welcome pages was visited, including a signup-completed event. Never your identity as a Lake member, and never linked-account data, balances, or transactions. Suppressed entirely for browsers sending Global Privacy Control. Governed by Meta's own privacy policy at facebook.com/privacy. |
Lake uses these providers for the roles listed above. Their agreements and published terms govern their processing, and some providers may have independent legal obligations or expressly permitted uses, including billing recordkeeping or use of de-identified or aggregated data. They are independent companies with their own security programs; we do not control them.
Support messages. Support email is received and stored in Apple iCloud Mail. No artificial-intelligence drafting service or other provider receives your support messages; replies are written by us. Support correspondence is retained as described in Section 5 and is deleted on request.
3.2 Other disclosures
- When you ask us to: for example, when you export your transactions to CSV, or explicitly direct us to share something.
- Legal requirements: when we reasonably believe disclosure is required by law, subpoena, court order, or lawful government request. Where permitted, we will attempt to notify you first.
- Protecting rights and safety: to investigate fraud, enforce our Terms, or protect the rights, property, or safety of Lake, our users, or the public.
- Business transfer: if Lake is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy, and you will have the opportunity to delete your account first.
Other than the funnel-page Meta Pixel measurement described in Sections 1.4 and 3.1, we do not disclose your information to data brokers, advertising networks, or credit reporting agencies.
4. How We Protect Your Information
- Encryption in transit. All traffic to and from the Service uses TLS.
- Encryption at rest for the most sensitive fields. Plaid access tokens, and your optional profile fields, are encrypted with AES-256-GCM using a key held outside the database, in addition to the encryption our database provider applies to storage.
- We never store bank credentials. There is nothing in our systems to steal in that category.
- Ownership scoping. User-specific records are tied directly to your user identifier or through an owned parent record. Authenticated application queries and routes are designed to enforce that ownership boundary.
- Authenticated webhooks. Incoming notifications from Plaid are cryptographically verified (ES256 signature) and rejected if verification fails.
- Least-privilege secrets. Provider credentials are held as environment secrets, not in source code, and the application refuses to start without the required ones.
No system is perfectly secure. We cannot guarantee that unauthorized access will never occur. Protect your side of it too: use a strong, unique password, enable multi-factor authentication where offered, keep your email account secure, and tell us at contact@rieper.org if something looks wrong.
If we discover a breach affecting your personal information, we will notify you and any required authorities as required by applicable law, without unreasonable delay.
5. How Long We Keep Information
| Data | Retention |
|---|---|
| Account and financial data | For as long as your account is open |
| Data for a disconnected institution | Deleted from Lake's active database when you remove that institution from Settings, subject to the backup and provider rules below |
| Optional profile (birth year and any legacy gender value) | Until you delete it from Settings or delete your account, subject to the backup rule below |
| Active Lake database records linked to your user | Deleted from the active Service when you delete your account, subject to the exceptions below (see Section 6) |
| Neon database backups and point-in-time recovery history | Our database's configured point-in-time recovery window is currently six hours (verified August 31, 2026); deleted rows leave recovery history when that window lapses. If we lengthen the window, it will not exceed 30 days, and this policy will be updated. |
| Customer-relationship record (HubSpot) | Deleted when your account is deleted, alongside your Lake records. HubSpot's own systems may retain residual copies for a limited period under its policies. |
| Trove enrichment request data | Trove receives enrichment requests as described in Section 3.1 and handles them under its own agreements and policies; we have requested written confirmation of its retention period and will update this row when we have it. The requests never contain your name, email, or account numbers. |
| In-app Insight feedback, accuracy-survey answers, and feedback-prompt records | Retained with the active Lake account and deleted from the active database when the account is deleted, subject to the Neon backup rule above; copies written to the customer-relationship record follow the HubSpot row above |
| Support correspondence | Retained in our support mailbox until deleted manually; deleted on request (Section 6). Not deleted automatically when you delete your Lake account. |
| Billing and transaction records held by Stripe | Retained by Stripe as required for financial recordkeeping and tax law, independent of your Lake account |
| Vercel server and security logs | Retained or made available under Lake's then-current Vercel plan and configuration and Vercel's applicable terms; reporting availability is not necessarily the same as deletion |
| Vercel Web Analytics | Retained or made available under Lake's then-current Vercel plan and Vercel's applicable terms. The 24-hour visitor-identification-hash lifecycle described in Section 1.4 is not a page-view deletion period. |
| Campaign attribution cookie (`lake_utm`) | Expires from your browser after at most 90 days; the copied campaign labels on your customer-relationship record follow the HubSpot row above |
| Aggregated, de-identified statistics | May be retained indefinitely, as they no longer identify you |
6. Your Choices and Rights
Several controls for data in the active Service are available directly in the app; other requests and provider or retention exceptions are described below.
In the app, at any time:
- Disconnect an institution: Settings. Lake attempts to instruct Plaid to remove the connection, then deletes that institution's active Lake records, including its accounts, transactions, attachments, holdings, and liability details.
- Delete your optional profile: Settings. Removes your birth year and any legacy gender value without affecting anything else, subject to the Neon backup rule in Section 5.
- Edit or delete your notes, attachments, budgets, goals, and categorization rules: wherever you created them.
- Export your transactions to CSV: available on Premium and Lifetime plans and during an active free trial.
- Delete your account: Settings. Lake attempts to remove every Plaid connection, deletes active Lake database records linked to your user, including linked accounts, transactions, notes, attachments, budgets, goals, snapshots, alerts, subscriptions, survey answers, and in-app feedback, deletes your Clerk authentication record, and deletes your HubSpot customer-relationship record. The deleted data is no longer available through the active Service and cannot be restored by you. Account deletion does not itself cancel a Stripe subscription or erase support correspondence, provider-held records, legally required billing records, limited backup copies, or de-identified statistics; those follow Section 5. Cancel any active subscription before deleting.
Marketing email. We send marketing email only about Lake itself, product news, feature announcements, and offers. Every marketing email contains a working unsubscribe link that takes effect promptly, and you can also write to contact@rieper.org to be unsubscribed. Unsubscribing does not affect service, security, billing, or trial-status messages, which are part of operating your account. We do not send marketing on behalf of third parties.
By contacting us at contact@rieper.org, you may also:
- Access the personal information we hold about you, in a portable form
- Correct inaccurate information
- Delete your information, if you prefer we do it rather than doing it yourself
- Withdraw consent for any optional processing
- Ask questions about anything in this policy
We will respond within 45 days, and will tell you if we need more time. We do not charge for these requests, and we will never penalize you, degrade your service, or change your price for making one.
Verification. To protect you, we will verify a request by confirming control of the email address on your account before acting on it.
State privacy laws. Depending on where you live, including under the Indiana Consumer Data Protection Act, the California Consumer Privacy Act, and comparable laws in other states, you may have statutory rights to access, correct, delete, port, and opt out of certain processing, and to appeal a denied request. Some of these laws may not currently apply to Lake because of our size, and some financial data is exempt from them under the Gramm-Leach-Bliley Act. We extend the rights described in this section to all Lake users regardless of whether a statute compels it. If we deny a request, we will explain why and how to appeal; you may also contact your state Attorney General.
Opting out of ad-measurement sharing. The only cross-context sharing Lake engages in is the funnel-page Meta Pixel described in Sections 1.4 and 3.1. Lake honors the Global Privacy Control (GPC) signal: when your browser sends it, the pixel does not load and nothing is sent to Meta. You can also prevent the pixel with browser tracking protection or by blocking third-party cookies, limit Meta's use of collected data at facebook.com/adpreferences, or write to us and we will explain what Meta received. It never involves your linked-account or financial data.
7. Children's Privacy
Lake is intended for users 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact contact@rieper.org and we will delete the account and its active Lake records, subject to the provider, support-record, backup, and legal-retention exceptions in Section 5.
8. Location of Processing
Lake is operated from the United States and currently serves users in the United States. Your information is stored and processed in the United States and in other locations where our service providers operate infrastructure. If you access the Service from outside the United States, you understand your information will be processed in the United States, where privacy laws may differ from those in your location.
9. Changes to This Policy
We may update this Privacy Policy. A change is material if it expands the categories of personal information we collect, adds a new category of recipient or a new purpose for sharing, reduces your rights or choices, or lengthens retention of identifiable data. For material changes, we will give at least 14 days' advance notice by a prominent notice in the Service, and by email once we operate a service-email channel, before the change takes effect, and the notice will state the effective date. Non-material changes (clarifications, provider renames, corrections that do not expand collection or sharing) take effect when posted with an updated "Last updated" date. Continuing to use the Service after a change's effective date means you accept it; if you do not accept a change, stop using the Service and delete your account before the effective date. We preserve superseded versions, including the July 24, 2026 original and its hash, and will provide any prior version on request. A revision to this Privacy Policy does not change the arbitration opt-out period in the Terms of Service, which runs from your first acceptance of the Terms.
10. Contact Us
Questions, requests, or concerns about privacy:
Rieper LLC (d/b/a Lake Financial)
c/o Registered Agents Inc
5534 Saint Joe Road
Fort Wayne, IN 46835
United States
Email: contact@rieper.org
Web: www.lakefin.net
Rieper LLC is an Indiana limited liability company, Business ID 202607202020836, operating under the assumed business name Lake Financial. This Privacy Policy is incorporated into the Lake Terms of Service.