MoneyRoom can
- Read balances and transactions you authorize through Plaid.
- Organize cards, benefits, usage, points, and spending in your workspace.
- Use connected activity to support tracking and recommendation features.
Security & Trust / Architecture first
A finance product should show where access begins, where it ends, and which controls remain yours. This is the operating model behind MoneyRoom.
How the connection works
The connection has five distinct stages. The line below is the entire path from institution sign-in to the data products MoneyRoom requests.
Your bank password never touches our servers. MoneyRoom receives a short-lived public token from Plaid, not the credentials entered in Plaid Link.
MoneyRoom exchanges the public token for a Plaid access token. We store the access token encrypted and decrypt it only when making an authorized request to Plaid.
Read-only, by construction. The configured products read balances and transactions; MoneyRoom does not configure payment or transfer products.
Capability boundary
Connected data can make the product useful. It does not give the product authority to act on the underlying account.
MoneyRoom can
MoneyRoom cannot
Move money or initiate a payment through the Plaid products it requests.
MoneyRoom does not receive the bank credentials entered in Plaid Link.
Data map
The system resolves a signed-in identity first, then uses that owner boundary for app-data access and diagnostics.
Account authentication, sign-in sessions, and identity recovery.
Cards, benefits, usage, connected activity, and app preferences.
Reads are scoped to the resolved owner and fail closed when the required owner context is missing.
Request bodies, headers, cookies, query strings, and direct user identity are removed or scrubbed before an error event is sent.
Control surfaces
The same Settings area that manages the workspace also exposes portability, connection, notification, and account controls.
Download a full JSON backup or focused cards, credits, and usage CSV files.
Settings / AdvancedRemove a connected institution and begin Plaid item revocation.
Settings / ConnectionsDelete the account through a confirmed flow that cancels billing, removes the auth identity, and purges owner-scoped app data.
Settings / AdvancedChoose the iOS push notification categories that are useful to you.
Settings / Push notificationsThe reminders we send name card nicknames and credit amounts only - never account numbers, masks, or tokens.
Processors & policies
MoneyRoom's policies name the principal processors involved in delivering the service and explain the categories of data they handle.
Connected-account data you authorize
Policy02SupabaseAccount authentication and sign-in
Policy03TursoApplication database hosting
Policy04SentryScrubbed error diagnostics
Policy05VercelApplication hosting and aggregate usage analytics
PolicyWe do not sell your personal information.
Honest limits
Connected data can be delayed, unavailable, or stale. MoneyRoom cannot make a third-party data source more current than the source itself.
If Plaid cannot confirm removal, the encrypted token is retained in a revoke-only retry record while local cleanup proceeds.
Account deletion purges owner-scoped app data; the Privacy Policy describes narrow legal, tax, fraud-prevention, security, and audit retention exceptions.
The threshold
MoneyRoom is designed to make a private financial workspace useful without giving it authority over the accounts it reads.
Start free