The Services are intended for users located in the United States and are not directed to children under the age of thirteen (13). We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will delete it promptly.
1. Information We Collect
1.1 No Account Registration. The Services do not require the creation of an account and do not collect your name, email address, or password. Upon installation, the App generates a random device identifier ("Device ID"), which is stored in your device's secure keychain. The Device ID is transmitted with each request to our server solely to associate your linked financial institutions with your device. The Device ID does not identify you personally.
1.2 Financial Account Linking. Financial institutions are linked to the App through Plaid Inc. ("Plaid"). When you link an account, you provide your banking credentials directly to Plaid through Plaid's interface; we do not receive, transmit, or store your banking username or password at any time. Plaid provides us with an access token (the "Access Token") that permits the App to retrieve your account balances and transaction data. Plaid's collection and use of your information are governed by Plaid's End User Privacy Policy.
1.3 Data Stored on Our Server. For each linked financial institution, our server stores only the following:
- (a) the Device ID associated with your device;
- (b) the Plaid Access Token; and
- (c) the name of the financial institution (e.g., "Chase").
We do not store transactions, balances, account numbers, or any other financial account data on our server. When the App refreshes your data, transaction and balance information is transmitted from Plaid, through our server, to your device without being written to persistent storage, and all such responses are designated as non-cacheable.
1.4 Product Analytics and Error Reporting. The App uses PostHog, Inc. ("PostHog") to measure how the App's features are used and to receive automatic reports when the App encounters an error. This information is transmitted to PostHog's United States cloud infrastructure. PostHog assigns your installation a random analytics identifier that it generates itself; that identifier is separate from the Device ID described in Section 1.1 and is not linked to it. We do not call PostHog's user-identification feature, and no PostHog person profile is created for you.
The information sent to PostHog consists of:
- (a) a fixed set of events recording that an action occurred — beginning, skipping, or completing the introductory walkthrough; starting a bank link; linking or unlinking a financial institution; setting a savings goal; selecting or deselecting a spending habit; setting a payday; and completing a lesson;
- (b) the savings cadence you have chosen (weekly, biweekly, or monthly), and, when you select a spending habit, which of the App's nine predefined categories it falls under;
- (c) screen views within the App, and lifecycle events such as the App being installed, opened, or sent to the background;
- (d) technical characteristics of your device: device model, manufacturer, and type; operating system name and version; App version and build number; screen dimensions; language; time zone; and network connection type;
- (e) your IP address, which PostHog receives with each request and uses to derive an approximate location (such as country, region, and city); and
- (f) where the App encounters an unhandled error, a diagnostic report containing the error's type, its message, and the sequence of code locations at which it arose.
We do not send transaction descriptions, amounts, balances, account numbers, financial institution names, or goal amounts to PostHog, and the App does not record your screen. PostHog's handling of this information is governed by PostHog's Privacy Policy.
2. Transaction Categorization
When you use the App's categorization feature, the App transmits transaction descriptions and amounts (e.g., "Corner Coffee, $4.75") to our server, which submits them to Google LLC's Gemini API for assignment to one of nine predefined categories. The resulting categories are returned to and stored solely on your device. Neither our server nor the App retains any copy of this data, and no information regarding your identity or your financial accounts is included in these requests.
We use Google's paid API tier, pursuant to which Google does not use submitted data to train its models and retains such data only for a limited period for abuse-monitoring purposes, as described in the Gemini API Terms of Service.
3. Hosting Infrastructure
Our server is hosted on Railway Corp. ("Railway"). Requests to our server pass through Railway's infrastructure in the ordinary course. We have configured our server not to log request contents. Railway's practices are described in Railway's Privacy Policy.
4. Data Stored on Your Device
Your transactions, balances, categories, goals, and lesson progress are stored locally on your device. Deleting the App from your device permanently removes this data.
5. What We Do Not Do
We do not: (a) use advertising identifiers or cross-application tracking technologies; (b) display advertisements; (c) record your screen or use session-replay technology; or (d) sell, rent, or share your personal information with third parties for any purpose, including for cross-context behavioral advertising. Our use of analytics is limited to what Section 1.4 describes.
6. Data Retention and Deletion
6.1 Unlinking. You may unlink a financial institution at any time within the App (Accounts → Manage). Unlinking immediately and permanently deletes the associated Access Token from our server. If all institutions are unlinked, our server retains no information associated with your device.
6.2 Automatic Deletion. Any Access Token that remains unused for twelve (12) consecutive months is automatically deleted from our server, together with its associated Device ID.
6.3 Deletion Requests. You may contact us at the address in Section 10 to request deletion of any information our server holds in connection with your device, or to request a description of such information.
7. Security and Incident Response
All data transmitted between your device, our server, Plaid, and Google is encrypted in transit using HTTPS (TLS). The most sensitive information held on our server consists of Plaid Access Tokens. In the event we become aware of a security incident affecting Access Tokens, we will promptly revoke the affected tokens with Plaid and provide notice within the App to affected users, in addition to any notification required by applicable law.
8. Children's Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13, consistent with the Children's Online Privacy Protection Act (COPPA).
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The effective date above will be revised to reflect any update. In the event of a material change, we will provide notice within the App before the change takes effect. Your continued use of the Services following the effective date of any update constitutes your acknowledgment of the revised Privacy Policy.
10. Contact
Questions, requests, or concerns regarding this Privacy Policy may be directed to: miles@mileskuperus.com.