MoneyRoom / Legal reference
Current version — replacement upcomingPRIVACY POLICY
On this page
Effective Date: June 14, 2026
Last Updated: August 12, 2026
MoneyRoom LLC ("MoneyRoom," "we," "us," or "our") respects your privacy. This Privacy Policy explains what personal information we collect, how we use and share it, and the rights you have. It applies to your use of the MoneyRoom mobile application, website, and related services (collectively, the "Service").
By using the Service, you agree to this Privacy Policy.
Important: Because MoneyRoom helps you manage personal financial information, we also provide a separate Financial Privacy Notice under the Gramm-Leach-Bliley Act, available at https://moneyroom.net/financial-privacy-notice?version=2026-08-11, explaining how we collect, share, and protect your financial information. The Financial Privacy Notice and this Privacy Policy are intended to work together.
California Notice at Collection
This section serves as the Notice at Collection required under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). At or before the point of collection, we inform you that:
- Categories of personal information we collect: identifiers; commercial information; financial information you authorize us to collect via Plaid; internet or other electronic network activity information; and inferences drawn from the foregoing. See Section 2 below for details.
- Purposes of collection and use: to provide, operate, secure, and improve the Service; to process payments; to communicate with you; to comply with legal obligations; and to detect and prevent fraud and abuse. See Section 3 below for details.
- Retention: we retain personal information for the periods described in Section 6 below.
- Sale or sharing for cross-context behavioral advertising: We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.
- Sensitive personal information: financial-account information collected via Plaid when you link an account (see Section 2 below). We use it only to provide the Service and do not use it to infer characteristics about you.
1. Who We Are
MoneyRoom LLC, is a personal-finance application based in Prescott, Arizona, USA. The Service is available only in the United States and is restricted to users 18 years or older.
2. Information We Collect
We collect the following categories of personal information:
(a) Information you provide directly
- Name (if provided)
- Email address
- Account credentials, including password and PIN (stored hashed and/or encrypted)
- Communications you send us, such as support requests and feedback
- Payment information processed by our payment processor; we do not store full payment-card numbers
(b) Financial information you authorize us to collect via Plaid
- Linked financial-institution names
- Account names, types, balances, and identifiers
- For credit cards, your credit limit and available credit (part of the balances above), used to show card utilization
- Transaction history, including date, amount, merchant, and category
- Investment holdings, securities, and transaction history (read-only)
We do not receive or store your bank login credentials. Plaid handles all credential exchange. See https://plaid.com/legal/#end-user-privacy-policy.
Limited Agency. By linking a financial account, you grant MoneyRoom a limited power of attorney to access this information on your behalf, solely as described in our Terms and Conditions, Section 6. This authority is read-only — we do not place trades, transfer funds, or initiate any action on your accounts.
(c) Information collected automatically
- Device identifiers, operating system, browser type
- Push-notification device tokens, if you enable notifications on a mobile device, used solely to deliver the notifications you turn on
- IP address (used for security and to infer general region; we do not collect precise geolocation)
- Log data, including timestamps, pages viewed, and errors
- Product signals you trigger, such as the search text you enter when you tell us a card is missing from our catalog, and the bank-posting description of a suggested credit match you dismiss — used only to improve the catalog and the matching, and never sold
- Cookies and similar technologies, where used (see Section 5)
(d) Information from third parties
- Plaid, as described above
- Email delivery providers, including delivery and bounce data
- Payment processors, including transaction confirmations
- Hosting and infrastructure providers, including operational logs
- Analytics and error-tracking providers, where used
(e) Sensitive personal information
When you connect a financial account through Plaid, we collect and store financial-account information — account identifiers, balances, and transaction history — which is "sensitive personal information" under the CCPA/CPRA. We use this information only to provide the core features you request — tracking your card credits, benefits, spending, and investments — and for the security, quality, and legal purposes described in this policy. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not sell it or share it for cross-context behavioral advertising. MoneyRoom never receives or stores your bank login credentials — account connections are handled by Plaid.
We do not collect Social Security numbers, driver's-license numbers, precise geolocation, racial or ethnic origin, religious beliefs, health information, sexual orientation, biometric data, union membership, or the contents of your private communications.
3. How We Use Your Information
We use your information to:
- Create, maintain, and secure your account.
- Provide, operate, and improve the Service, including budgeting tools, credit-card benefit tracking, and read-only investment summaries.
- Process payments and manage subscriptions.
- Send transactional communications (account, security, billing, and service updates).
- Send marketing communications only if you opt in, with the ability to unsubscribe at any time.
- Respond to support requests and feedback.
- Detect, investigate, prevent, and address fraud, abuse, security incidents, and violations of our Terms.
- Comply with legal obligations, court orders, subpoenas, and regulatory requests.
- Enforce our Terms and protect the rights, safety, and property of MoneyRoom, our users, and others.
- Conduct internal research, analytics, and product development.
Automated Decision-Making and Artificial Intelligence
We do not use artificial intelligence or machine-learning systems, automated decision-making, or profiling to evaluate, score, or make decisions about you based on your financial data. Transaction categorization and credit-benefit tracking are performed by deterministic, rule-based logic — not by an AI model — and your financial data is not sent to any third-party artificial-intelligence service.
6. Data Retention
Automatic age-based cleanup is not currently enabled. Account and tracking data is kept for the life of your account unless you delete it through an available deletion control or delete your account. We do not promise an automatic deletion deadline based on a record's age. The categories below explain what account deletion removes and what remains.
- Account and tracking data — your cards, statement-credit records, tracked credit-usage history, learned matching answers, period-attribution choices, credit-matching decision records, preferences, and settings — is kept for the life of your account and deleted when you delete your account. Learned matching answers remember how you classified a posting; period-attribution choices remember which credit period you assigned it to. Credit-matching decision records are account data, not legal-evidence records.
- Linked-account financial data imported through Plaid includes accounts, balances, and transactions. Imported bank transactions are retained while they support your tracking history, corrections, and account features, and are deleted when you delete your account. You can also remove a connection's imported data by disconnecting it as described below. Legacy investment information is retained until you remove the connection or delete your account. Your tracked credit-usage history is separate account data kept for the life of your account.
- When you disconnect a linked account in Settings, we direct Plaid to revoke our access and remove that connection's imported account and transaction data from your workspace. If revocation fails, we may retain an encrypted access credential in a restricted, revocation-only recovery record until the revocation is resolved; it is not used to continue importing activity. Your tracked credit-usage history, learned matching answers, period-attribution choices, and credit-matching decision records remain account data. If a plan change ends live syncing instead, the connection is revoked at Plaid but the activity already imported stays in your workspace under the account-data retention described above.
- Derived records, such as imported-transaction category overrides and pending review items, are deleted with their source transactions. Tracked usage, learned matching answers, period-attribution choices, credit-matching decision records, and catalog-gap feedback have the separate retention treatment described here.
- Anonymous contributions to shared matching rules are retained after account deletion. We delete your private learned matching answers when you delete your account, but retain their anonymous aggregate contributions: scrubbed matching wording and counts, associated with catalog cards and credits and the type of answer, carrying no account or other user identity. These shared contributions are not your private answer records.
- In-app support messages and catalog-gap signals — including the search text and posting descriptions described in Section 2(c) — are kept for the life of your account and removed when you delete it. Correspondence in our support mailbox is separate and is not automatically erased by deleting your app account.
- Security logs, such as sign-in attempts, can remain after account deletion for security and abuse prevention; no automatic age-based deletion is currently enabled. Short-lived rate-limit records are pruned as subsequent requests run the limiter, rather than by a guaranteed deletion timer.
- Consent records, subscription renewal-notice records, and privacy-request records are retained after account deletion as evidence of our handling of legal obligations. Privacy-request free text and direct identity fields in renewal-notice evidence are removed during account deletion. Retained evidence can include internal identifiers, document or statement versions, notice and acceptance dates, request type and disposition, subscription plan, price, cadence, renewal date, and delivery identifiers. No automatic age-based deletion is currently enabled. Notice delivery, receipt and acceptance are separate events; a recorded notice does not mean you agreed.
- Account-deletion audit and recovery records remain after deletion, including internal identifiers, a masked email address, completion status, and provider outcomes. Unresolved revocation or provider-erasure records can retain encrypted credentials or provider identifiers solely to finish the requested operation. A minimal internal deletion-fence record is retained to prevent a deleted account's data from being recreated by delayed work or recovery. No automatic age-based deletion is currently enabled.
- Offboarding feedback — the reason you give if you cancel — remains after account deletion. Automatic age-based unlinking and deletion are not currently enabled, so feedback can retain an account identifier and any identifying information you chose to include in free text. Please avoid including personal details in cancellation feedback.
- Provider-held information and backups are separate from the live application database. Account deletion does not instantly erase provider logs, mailbox copies or backup copies. Providers apply their own retention and recovery processes; payment providers can retain transaction records under their own legal obligations.
When you delete your account, we begin deleting your account and tracking data. Local deletion and provider revocation or erasure are separate steps; provider work may continue after access to the account ends. Completion can require identity verification or technical recovery. The retained categories above are limited to their remaining purposes, including:
- legal, tax, accounting, or regulatory obligations;
- fraud prevention, security, or audit purposes; or
- the establishment, exercise, or defense of legal claims.
Automatic expiry for these retained categories is not currently enabled. You can contact us about retained information and exercise the rights below; applicable legal obligations and exceptions still apply.
Current-practice correction: The earlier retention description is withdrawn and corrected above. This factual correction does not change this document's consent version or represent acceptance of the replacement. The historical source is preserved in our records.
7. Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption of sensitive credentials at rest, transport-layer encryption (HTTPS) in transit, and access controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for safeguarding your password and PIN, and for promptly notifying us of any unauthorized access to your account.
8. Your Privacy Rights
(a) All U.S. Users
You may:
- Access, update, or correct your account information through your account settings.
- Delete your account through the in-app account-deletion feature.
- Opt out of marketing communications via the unsubscribe link or by contacting us.
(b) California Residents — CCPA/CPRA Rights
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and (if applicable) sell or share.
- Access the specific pieces of personal information we hold about you.
- Delete personal information we hold about you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information ("Do Not Sell or Share My Personal Information"). We do not sell personal information or share it for cross-context behavioral advertising, so every user already has the protection this opt-out provides. We nonetheless honor every opt-out request — submitted through the methods below or via a Global Privacy Control signal (see Section 10) — and record it, so that if our practices ever changed, your opt-out would already be in effect.
- Limit the use of sensitive personal information ("Limit the Use of My Sensitive Personal Information"). We use sensitive personal information only to provide the services you request and for purposes permitted by the CCPA regulations. You may nonetheless submit a Limit request at any time — in the app under Settings → Privacy & Your Rights (select the limit-sensitive-personal-information request type) or by email — and we will honor it.
- Non-discrimination: we will not discriminate against you for exercising these rights.
To exercise your rights, submit a request in the app under Settings → Privacy & Your Rights, or contact us at moneyroomtracking@gmail.com. We will verify your request through your signed-in account, or by confirming information that matches what we have on file, such as your account email. You may use an authorized agent; we may require proof of authorization (such as a power of attorney or signed written permission) and may also verify your identity directly. We will respond within 45 days, with a possible 45-day extension if reasonably necessary, and we will inform you of any extension.
(c) Other State Privacy Laws
Residents of other U.S. states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Rhode Island, and others — may have similar rights, including the right to access, correct, delete, and obtain a portable copy of personal information, and to opt out of certain processing. To exercise such rights, contact us at the email above. You may appeal any decision regarding your request by replying to our response within 30 days.
9. Children's Privacy
The Service is intended for users 18 years and older. We do not knowingly collect personal information from anyone under 18. If we learn we have collected personal information from a person under 18, we will delete it. If you believe a minor has provided us information, please contact us at moneyroomtracking@gmail.com.
10. Do Not Track and Global Privacy Control
We do not sell personal information or share it for cross-context behavioral advertising, so a Global Privacy Control ("GPC") signal has nothing to opt you out of — every user already has, at all times, the protection the signal requests. We still recognize the signal: when your browser sends GPC while you are signed in, we record it, so your preference is on file and will be honored if our practices ever change (a change we would also announce by updating this policy, as Section 13 describes). Older "Do Not Track" signals receive the same substantive treatment — nothing is sold or shared with or without them — though they are not separately recorded. No user's data is sold or shared regardless of whether these signals are present.
11. International Users
The Service is intended only for use by U.S. residents. We do not target or solicit users outside the United States. Information is processed and stored in the United States and may be subject to U.S. law, including lawful access requests by U.S. government authorities.
12. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. Review their privacy practices before providing them with information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (if we have your email) or via in-app notice at least 30 days before the changes take effect. Non-material changes will be effective on posting. The "Last Updated" date above reflects the most recent revision.
14. Contact Us
For questions, requests, or to exercise your privacy rights:
MoneyRoom LLC
PO Box 1393, Prescott, AZ 86302, USA
Email: moneyroomtracking@gmail.com
Publication and Change Log
Version displayed: 2026-08-12. Current version — replacement upcoming. The dates in the document above describe the selected text, not the other version.
Replacement publication: revised September 6, 2026; version 2026-10-07; scheduled effective date October 7, 2026.
Public version versus your account. The default public page changes on the scheduled date. For existing accounts, the replacement applies no earlier than that date and 30 days after the in-app notice recorded for that account. Your account notice identifies any later date. Notice is not acceptance. The previous documents remain applicable during that notice period. Reading this public page does not change your account's consent record.
What changed in this document — replacement treated as material: Corrected retention to disclose that automatic age-based cleanup is off, lifetime tracking history, retained deletion exceptions and anonymous shared matching contributions; clarified diagnostics, analytics, support-mailbox copies, provider records and privacy-request handling. Prices, plans and feature access are unchanged.
Earlier text and factual corrections. Previous version identifiers are preserved. The public Privacy retention section and Terms copyright contact carry conspicuously identified current-practice corrections; historical source text remains in our records. Earlier corrections also used these identifiers, so an identifier alone is not a claim that every historical acceptance saw identical text.
Revision dates, effective dates, and consent versions have separate meanings. Updating a revision date alone does not request new consent.