MoneyRoom / Legal reference
Upcoming replacement — not yet effectivePRIVACY POLICY
On this page
Effective Date: October 7, 2026
Version: 2026-10-07
Last Updated: September 6, 2026
MoneyRoom LLC ("MoneyRoom," "we," "us," or "our") respects your privacy. This Privacy Policy explains what personal information we collect, how we use and share it, and the rights you have. It applies to your use of the MoneyRoom mobile application, website, and related services (collectively, the "Service").
This policy explains our practices; it is not blanket consent to processing. Where separate permission is required, we request it separately.
Important: Because MoneyRoom helps you manage personal financial information, we also provide a separate Financial Privacy Notice under the Gramm-Leach-Bliley Act, available at https://moneyroom.net/financial-privacy-notice?version=2026-10-07, explaining how we collect, share, and protect your financial information. The Financial Privacy Notice and this Privacy Policy are intended to work together.
California Notice at Collection
This section serves as the Notice at Collection required under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). At or before the point of collection, we inform you that:
- Categories of personal information we collect: identifiers; commercial information; financial information you authorize us to collect via Plaid; internet or other electronic network activity information; and inferences drawn from the foregoing. See Section 2 below for details.
- Purposes of collection and use: to provide, operate, secure, and improve the Service; to process payments; to communicate with you; to comply with legal obligations; and to detect and prevent fraud and abuse. See Section 3 below for details.
- Retention: we retain personal information for the periods described in Section 6 below.
- Sale or sharing for cross-context behavioral advertising: We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.
- Sensitive personal information: financial-account information collected via Plaid when you link an account (see Section 2 below). We use it to provide the features you request and for the security, quality, and legal purposes described below, not for advertising or unrelated profiling.
1. Who We Are
MoneyRoom LLC is a personal-finance application based in Prescott, Arizona, USA. The Service is available only in the United States and is restricted to users 18 years or older.
2. Information We Collect
We collect the following categories of personal information:
(a) Information you provide directly
- Name (if provided)
- Email address
- Account credentials, including password and PIN (stored hashed and/or encrypted)
- Communications you send us, such as support requests and feedback
- Cards, statement credits, annual fees, usage entries, benefit values, points balances, notes, preferences, and other tracking information you enter
- Payment and subscription information supplied by Stripe and Link; payment-card details are entered with them, not in MoneyRoom's tracking forms
(b) Financial information you authorize us to collect via Plaid
- Linked financial-institution names
- Account names, types, balances, and identifiers
- For credit cards, your credit limit and available credit (part of the balances above), used to show card utilization
- Transaction history, including date, amount, merchant, and category
- Legacy investment holdings, securities, and transaction history from previously connected accounts; new investment connections and the investment feature are not currently available
We do not receive or store your bank login credentials. Plaid handles all credential exchange. See https://plaid.com/legal/#end-user-privacy-policy.
Read-only account access. When you link an account, you authorize the read-only retrieval and processing described here, in Section 6 of our Terms, and in Plaid's disclosures. This does not authorize MoneyRoom to move money, trade, or otherwise transact on your behalf.
(c) Information collected automatically
- Device identifiers, operating system, browser type
- Push-notification device tokens, if you enable notifications on a mobile device, used solely to deliver the notifications you turn on
- IP address (used for security and to infer general region; we do not collect precise geolocation)
- Log data, including timestamps, pages viewed, and errors
- Product signals you trigger, such as the search text you enter when you tell us a card is missing from our catalog, and the bank-posting description of a suggested credit match you dismiss — used only to improve the catalog and the matching, and never sold
- Cookies and browser storage (see Section 5)
(d) Information from third parties
- Plaid, as described above
- Email delivery providers, including delivery and bounce data
- Payment processors, including transaction confirmations
- Hosting and infrastructure providers, including operational logs
- Analytics and error-tracking providers, where used
(e) Sensitive personal information
When you connect a financial account through Plaid, we collect and store financial-account information — account identifiers, balances, and transaction history — which is "sensitive personal information" under the CCPA/CPRA. We use this information only to provide the core features you request — tracking your card credits, benefits, and spending — and for the security, quality, and legal purposes described in this policy. We do not use or disclose sensitive personal information for advertising or unrelated profiling, and we do not sell it or share it for cross-context behavioral advertising. MoneyRoom never receives or stores your bank login credentials — account connections are handled by Plaid.
We do not request Social Security numbers, driver's-license numbers, precise geolocation, health information, or information about your racial or ethnic origin, religious beliefs, sexual orientation, or union membership. Please do not include such information, bank passwords, or full payment-card numbers in support messages, notes, or feedback. We receive the content you choose to submit. Device biometric authentication is handled by your device; MoneyRoom does not receive your biometric measurements.
3. How We Use Your Information
We use your information to:
- Create, maintain, and secure your account.
- Provide, operate, and improve the Service, including manual credit-card benefit and annual-fee tracking, spending summaries, and supported automatic detection from linked cards. Some credits need confirmation or remain manual; catalog classifications do not guarantee what a particular bank feed will supply.
- Process payments and manage subscriptions.
- Send transactional communications (account, security, billing, and service updates).
- Send marketing communications only if you opt in, with the ability to unsubscribe at any time.
- Respond to support requests and feedback.
- Detect, investigate, prevent, and address fraud, abuse, security incidents, and violations of our Terms.
- Comply with legal obligations, court orders, subpoenas, and regulatory requests.
- Enforce our Terms and protect the rights, safety, and property of MoneyRoom, our users, and others.
- Conduct internal research, analytics, and product development.
Automated Decision-Making and Artificial Intelligence
MoneyRoom uses deterministic rules for transaction categorization, credit detection, category-based card rankings, and informational estimates. Approval Odds evaluates the credit score and eligibility information you enter together with your card information; the score you type is processed in your browser and is not saved to your MoneyRoom account. These estimates are not lender decisions, credit reports, or guarantees of approval. We do not use an AI model for these calculations, and MoneyRoom does not send your financial-tracking data to any third-party artificial-intelligence service. If you download an export and provide it to an AI service yourself, that service's terms and privacy practices apply. Stripe and Link separately operate payment security and fraud-prevention systems under their own policies.
6. Data Retention
Automatic age-based cleanup is not currently enabled. Account and tracking data is kept for the life of your account unless you delete it through an available deletion control or delete your account. We do not promise an automatic deletion deadline based on a record's age. The categories below explain what account deletion removes and what remains.
- Account and tracking data — your cards, statement-credit records, tracked credit-usage history, learned matching answers, period-attribution choices, credit-matching decision records, preferences, and settings — is kept for the life of your account and deleted when you delete your account. Learned matching answers remember how you classified a posting; period-attribution choices remember which credit period you assigned it to. Credit-matching decision records are account data, not legal-evidence records.
- Linked-account financial data imported through Plaid includes accounts, balances, and transactions. Imported bank transactions are retained while they support your tracking history, corrections, and account features, and are deleted when you delete your account. You can also remove a connection's imported data by disconnecting it as described below. Legacy investment information is retained until you remove the connection or delete your account. Your tracked credit-usage history is separate account data kept for the life of your account.
- When you disconnect a linked account in Settings, we direct Plaid to revoke our access and remove that connection's imported account and transaction data from your workspace. If revocation fails, we may retain an encrypted access credential in a restricted, revocation-only recovery record until the revocation is resolved; it is not used to continue importing activity. Your tracked credit-usage history, learned matching answers, period-attribution choices, and credit-matching decision records remain account data. If a plan change ends live syncing instead, the connection is revoked at Plaid but the activity already imported stays in your workspace under the account-data retention described above.
- Derived records, such as imported-transaction category overrides and pending review items, are deleted with their source transactions. Tracked usage, learned matching answers, period-attribution choices, credit-matching decision records, and catalog-gap feedback have the separate retention treatment described here.
- Anonymous contributions to shared matching rules are retained after account deletion. We delete your private learned matching answers when you delete your account, but retain their anonymous aggregate contributions: scrubbed matching wording and counts, associated with catalog cards and credits and the type of answer, carrying no account or other user identity. These shared contributions are not your private answer records.
- In-app support messages and catalog-gap signals — including the search text and posting descriptions described in Section 2(c) — are kept for the life of your account and removed when you delete it. Correspondence in our support mailbox is separate and is not automatically erased by deleting your app account.
- Security logs, such as sign-in attempts, can remain after account deletion for security and abuse prevention; no automatic age-based deletion is currently enabled. Short-lived rate-limit records are pruned as subsequent requests run the limiter, rather than by a guaranteed deletion timer.
- Consent records, subscription renewal-notice records, and privacy-request records are retained after account deletion as evidence of our handling of legal obligations. Privacy-request free text and direct identity fields in renewal-notice evidence are removed during account deletion. Retained evidence can include internal identifiers, document or statement versions, notice and acceptance dates, request type and disposition, subscription plan, price, cadence, renewal date, and delivery identifiers. No automatic age-based deletion is currently enabled. Notice delivery, receipt and acceptance are separate events; a recorded notice does not mean you agreed.
- Account-deletion audit and recovery records remain after deletion, including internal identifiers, a masked email address, completion status, and provider outcomes. Unresolved revocation or provider-erasure records can retain encrypted credentials or provider identifiers solely to finish the requested operation. A minimal internal deletion-fence record is retained to prevent a deleted account's data from being recreated by delayed work or recovery. No automatic age-based deletion is currently enabled.
- Offboarding feedback — the reason you give if you cancel — remains after account deletion. Automatic age-based unlinking and deletion are not currently enabled, so feedback can retain an account identifier and any identifying information you chose to include in free text. Please avoid including personal details in cancellation feedback.
- Provider-held information and backups are separate from the live application database. Account deletion does not instantly erase provider logs, mailbox copies or backup copies. Providers apply their own retention and recovery processes; payment providers can retain transaction records under their own legal obligations.
When you delete your account, we begin deleting your account and tracking data. Local deletion and provider revocation or erasure are separate steps; provider work may continue after access to the account ends. Completion can require identity verification or technical recovery. The retained categories above are limited to their remaining purposes, including:
- legal, tax, accounting, or regulatory obligations;
- fraud prevention, security, or audit purposes; or
- the establishment, exercise, or defense of legal claims.
Automatic expiry for these retained categories is not currently enabled. You can contact us about retained information and exercise the rights below; applicable legal obligations and exceptions still apply.
7. Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption of sensitive credentials at rest, transport-layer encryption (HTTPS) in transit, and access controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for safeguarding your password and PIN, and for promptly notifying us of any unauthorized access to your account.
8. Your Privacy Rights
(a) All U.S. Users
You may:
- Access, update, or correct your account information through your account settings.
- Delete your account through the in-app account-deletion feature.
- Opt out of marketing communications via the unsubscribe link or by contacting us.
(b) California Residents — CCPA/CPRA Rights
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and (if applicable) sell or share.
- Access the specific pieces of personal information we hold about you.
- Delete personal information we hold about you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information ("Do Not Sell or Share My Personal Information"). We do not sell personal information or share it for cross-context behavioral advertising, so every user already has the protection this opt-out provides. We nonetheless honor every opt-out request — submitted through the methods below or via a Global Privacy Control signal (see Section 10) — and record it, so that if our practices ever changed, your opt-out would already be in effect.
- Limit the use of sensitive personal information ("Limit the Use of My Sensitive Personal Information"). We use sensitive personal information only to provide the services you request and for purposes permitted by the CCPA regulations. You may nonetheless submit a Limit request at any time — in the app under Settings → Privacy & Your Rights (select the limit-sensitive-personal-information request type) or by email — and we will honor it.
- Non-discrimination: we will not discriminate against you for exercising these rights.
To exercise your rights, submit a request in the app under Settings → Privacy & Your Rights, or contact us at moneyroomtracking@gmail.com. We will verify your request through your signed-in account, or by confirming information that matches what we have on file, such as your account email. You may use an authorized agent; we may require proof of authorization (such as a power of attorney or signed written permission) and may also verify your identity directly. We handle requests within the deadline applicable to the request and your jurisdiction. Access, correction and deletion requests generally have a 45-day response period where applicable; opt-out and limitation requests may require faster action. We explain any permitted extension.
(c) Other State Privacy Laws
Residents of other U.S. states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Rhode Island, and others — may have similar rights, including the right to access, correct, delete, and obtain a portable copy of personal information, and to opt out of certain processing. To exercise such rights, contact us at the email above. If we deny your request, our response will explain how to appeal and any applicable deadline. We will explain the appeal outcome and any available regulator complaint route. We will not shorten rights provided by applicable law.
9. Children's Privacy
The Service is intended for users 18 years and older. We do not knowingly collect personal information from anyone under 18. If we learn we have collected personal information from a person under 18, we will delete it. If you believe a minor has provided us information, please contact us at moneyroomtracking@gmail.com.
10. Do Not Track and Global Privacy Control
We do not sell personal information or share it for cross-context behavioral advertising, so a Global Privacy Control ("GPC") signal has nothing to opt you out of — every user already has, at all times, the protection the signal requests. We still recognize the signal: when your browser sends GPC while you are signed in, we record it, so your preference is on file and will be honored if our practices ever change (a change we would also announce by updating this policy, as Section 13 describes). Older "Do Not Track" signals receive the same substantive treatment — nothing is sold or shared with or without them — though they are not separately recorded. No user's data is sold or shared regardless of whether these signals are present.
11. International Users
The Service is intended only for use by U.S. residents. We do not target or solicit users outside the United States. MoneyRoom is operated from the United States. Our providers may process information in the United States and other countries where they operate, subject to their contractual and legal safeguards. Applicable laws may permit lawful access by government authorities.
12. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. Review their privacy practices before providing them with information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (if we have your email) or via in-app notice at least 30 days before the changes take effect. For an existing account, a material replacement will not become applicable before its stated effective date and the end of your 30-day notice period. Current and archived versions, the change summary, and the materiality classification are available from this page. Non-material corrections may take effect on posting. "Last Updated" records the revision date; a separate version identifies the text for consent purposes. A date-only correction does not itself require renewed acceptance.
14. Contact Us
For questions, requests, or to exercise your privacy rights:
MoneyRoom LLC
PO Box 1393, Prescott, AZ 86302, USA
Email: moneyroomtracking@gmail.com
Publication and Change Log
Version displayed: 2026-10-07. Upcoming replacement — not yet effective. The dates in the document above describe the selected text, not the other version.
Replacement publication: revised September 6, 2026; version 2026-10-07; scheduled effective date October 7, 2026.
Public version versus your account. The default public page changes on the scheduled date. For existing accounts, the replacement applies no earlier than that date and 30 days after the in-app notice recorded for that account. Your account notice identifies any later date. Notice is not acceptance. The previous documents remain applicable during that notice period. Reading this public page does not change your account's consent record.
What changed in this document — replacement treated as material: Corrected retention to disclose that automatic age-based cleanup is off, lifetime tracking history, retained deletion exceptions and anonymous shared matching contributions; clarified diagnostics, analytics, support-mailbox copies, provider records and privacy-request handling. Prices, plans and feature access are unchanged.
Earlier text and factual corrections. Previous version identifiers are preserved. The public Privacy retention section and Terms copyright contact carry conspicuously identified current-practice corrections; historical source text remains in our records. Earlier corrections also used these identifiers, so an identifier alone is not a claim that every historical acceptance saw identical text.
Revision dates, effective dates, and consent versions have separate meanings. Updating a revision date alone does not request new consent.