The short version
- We never see your bank login. Bank connections run through Quiltt; your credentials go to Quiltt and your bank, not to us.
- We don’t sell your data, show ads, or use advertising trackers. There are no analytics scripts on the app or this site today.
- You can delete everything yourself from Settings. Deletion removes your data, your bank connections at Quiltt, your billing record at Stripe, and your login.
- Your partner sees what you share — the transactions you mark as split or theirs, and the running balance between you — never your account numbers or interest rates.
What we collect
Your account
Your name and email address, and a password if you choose one. Passwords are handled by Amazon Cognito, our sign-in provider; we never receive or store them. If you turn on two-factor authentication, Cognito stores the authenticator secret.
If you sign in with Google, Google sends us a signed identity token. From it we keep your name, email address, and Google account id, which we use to create or match your MosyMoney account and to show your name in the app. We don’t currently store or display your Google profile picture. We request only basic profile and email scopes — nothing from Gmail, Drive, Calendar, or Contacts. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your Google name, email, and account id are stored in Amazon Cognito and in our database, are shared only with the processors listed below, and are deleted with your account. You can also revoke MosyMoney’s access at any time from your Google account permissions. When a Google sign-in matches an existing MosyMoney account by verified email, we link the two and email you about it, so a link you didn’t make is visible rather than silent.
Your financial data
To connect a bank we first create a profile for you at Quiltt, our aggregation provider, using your name and email address. Quiltt (which in turn uses providers such as Finicity and MX) then retrieves and sends us: the institution name, each account’s name, type, last four digits, and balance, an interest rate where the bank provides one or you enter it, and your transactions — date, amount, merchant or description, pending status, and the category the bank or aggregator assigned. We refresh this while your connection is active and store balance snapshots so you can see history.
Everything you add on top is also stored: income and savings targets, categories, tags, notes, splits, recurring bills, who paid what, and settlements with your partner.
Shared spaces
Inviting a partner stores their email address and sends them an invite. Once you share a space, your partner can see the transactions you mark as split or theirs — including the institution and account name, category, and any notes on those rows — the recurring bills you share, and the balance between you. Account numbers, last-four masks, and interest rates on your accounts are hidden from them.
Billing
Subscriptions are processed by Stripe. Card numbers go directly to Stripe and never reach our servers. We store your plan, subscription status, and trial dates.
Public forms and support
The contact form stores the name, email, and message you submit; the waitlist form stores your email. Each submission also records your IP address and browser user agent purely for rate limiting; we scrub those after 30 days. Both forms are protected by Cloudflare Turnstile.
Technical data
Our servers keep short-lived request logs for security and debugging. The app keeps your sign-in tokens, Quiltt’s bank-connection session, and a few display preferences (like a collapsed section) in your browser’s local storage. Stripe sets its own fraud-prevention cookies on the checkout page. We set no advertising or analytics cookies.
How we use it
- To run the product: your forecast, shared expenses, recurring bills, and calendar.
- To categorize transactions and name recurring bills. We send Anthropic’s Claude API the merchant or description text as your bank renders it — for transactions our built-in rules can’t categorize, and for newly detected recurring bills together with the category we guessed. We never send amounts, dates, balances, account details, or your identity, though a bank description can occasionally include a payee’s name, as with a Zelle transfer. Anthropic keeps requests briefly under its API data-retention policy and does not train on them.
- To email you about your account: sign-up and password-reset codes, partner invites, a Google sign-in being linked, a waitlist confirmation, and trial or renewal notices. These go through Amazon SES or Amazon Cognito. We don’t send marketing email.
- To keep the service secure, prevent abuse, and answer support requests.
We don’t currently run product analytics. If we add them we’ll say so here first, with a new effective date.
Who processes it for us
We run on a small set of providers, each under its own privacy terms, and share with them only what their job requires:
- Quiltt — bank connections and transaction data; receives your name and email to create your profile.
- Amazon Web Services — sign-in (Cognito) and email (SES), in the United States.
- DigitalOcean — hosts our API and encrypted database, in the United States.
- Cloudflare — serves this site and the app, and runs Turnstile on our public forms.
- Stripe — payments and subscription billing.
- Anthropic — merchant-name categorization, as described above.
- Google — only if you choose Google sign-in.
We don’t sell or rent personal data, and we don’t share it with anyone else except when the law requires it or to protect the service and its users.
How long we keep it
- Account and financial data stay while your account exists. Deleting your account removes them.
- Contact submissions are deleted after 12 months. Waitlist emails are kept until we’ve invited you in or you ask us to remove them. IP and browser details on both are scrubbed after 30 days.
- Webhook event logs from Quiltt and Stripe are deleted after 90 days.
- Database backups are encrypted and roll off on our hosting provider’s short retention schedule.
Deleting your account
Settings → Delete account removes your transactions, accounts, and settings, deletes your bank connections and profile at Quiltt, cancels your subscription and deletes your customer record at Stripe (Stripe keeps the payment records it is legally required to keep; there is no automatic refund), deletes your sign-in at Cognito, and removes any invites, contact messages, or waitlist entries tied to your email. If one of those external steps fails, we finish it by hand.
If you shared a space, your partner keeps their own data and the space continues without you, but the transactions you shared and any settlements you recorded are removed from it.
Security
Data is encrypted in transit and at rest. Sign-in is handled by Amazon Cognito with optional two-factor authentication. Bank credentials never touch our systems. Sensitive server credentials are stored as secrets, never in code.
Your rights
You can view and edit your data in the app and delete it yourself at any time. Depending on where you live you may have further rights — to access, correct, export, or restrict how we use your data. To exercise any of them, or to ask a question, contact us and we’ll respond within 30 days.
Children
MosyMoney is for adults managing household money. It isn’t directed at anyone under 18, and we don’t knowingly collect data from them.
Changes
When this policy changes in substance we’ll post the new version here with a new effective date and, for material changes, email account holders.