Overview
We collect only the information needed to operate IOU Jar, keep your jars private to members, and support save and sync across devices.
Last updated: March 5, 2026
This Privacy Policy explains how IOU Jar collects, uses, and protects information when you use our web app and related services.
IOU Jar is built for private, shared IOU tracking for families, friends, and partners. We do not provide banking, lending, or payment processing services.
We collect only the information needed to operate IOU Jar, keep your jars private to members, and support save and sync across devices.
When you use IOU Jar, we process profile and jar data such as display name, emoji, optional email address, jar memberships, drops, optional notes, jar scene snapshots, and jar event and sync history.
If you connect Google sign-in, we receive account identity information through Supabase authentication.
We use the iou_session cookie to maintain your session and keep you signed in on the web app. Session tokens are stored as secure hashes on the server.
On supported devices, we also use local storage for limited product-state keys such as add-to-home-screen completion status.
We use your data to run the core product: create and join jars, show members, track drops and feed activity, save jar scene state, and sync changes across clients.
We also use data for account security, abuse prevention, reliability, and product performance improvements.
We do not sell personal information.
We share data with service providers only to run IOU Jar, including Supabase (authentication), optional Resend email delivery for magic links, and Vercel Analytics/Speed Insights for product performance telemetry.
We keep account and jar records while your account or jars remain active.
If an account or jar is deleted, related data is removed according to our application logic and database constraints, except where temporary operational logs or backups are required for security and reliability.
We apply technical controls designed to protect your information, including hashed session tokens, authenticated access checks, and membership-based authorization for jar data.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
You can update your profile details in the app and can request account-related support through the contact email below.
Depending on your location, you may have additional privacy rights under applicable law.
IOU Jar is not directed to children under 13. If you believe a child has provided personal information, contact us so we can investigate and remove data as appropriate.
Your information may be processed in countries other than where you live, including where our hosting and service providers operate.
We may update this Privacy Policy from time to time. When we do, we will update the Last updated date on this page.
For privacy questions or requests, contact us at support@ioujar.com.