WealthWizard

Privacy Policy

Version 1.5. Effective September 2, 2026.

Who we are

WealthWizard is a personal budgeting app that forecasts your account balance so you can see where your money is heading. This policy explains what data the app and website touch, what we deliberately never keep, and the choices you always have. It applies to the WealthWizard mobile application, this website, and the services behind them.

What we collect

We collect the minimum needed to show you your own forecast:

What we refuse to store

This is the part most privacy policies do not have, and it is the core of how WealthWizard is built:

Not retained in application storage

WealthWizard does not write transaction payloads, account balances, or forecast outputs to application storage. They are processed for the current request only. This is a persistence boundary: financial data still passes transiently through service memory during a sync.

For each transaction, the service receives the Plaid record, removes merchant names, descriptions, locations, and counterparties, and relays only six fields to your phone: a transaction identifier, an account identifier, a date, an amount, a spending category, and a pending flag. This filtering limits the data sent to your device; neither the raw nor the minimized transaction record is written to WealthWizard application storage.

The transaction history and forecasts used by WealthWizard are stored in an encrypted database on your device, locked by a key that never leaves your device's keychain.

Persistent application records for an app user are limited to your email address, an encrypted bank-connection token, and the names and types of your linked accounts. Transient sync processing, Cognito identity records, website waitlist records, and routine delivery and security data are described separately in this policy.

How your data is used

Your financial data is used to produce your balance timeline and forecast, for you. A beta invite email is used to maintain the waitlist and contact you about access. We do not sell your data, share it with advertisers, or train shared models on your personal transactions.

Where your data lives and how it is protected

This architecture is not a roadmap item. It shipped, and this version of the policy describes the running system.

Who we share with

We use the following service providers only for the stated product and website operations:

We do not disclose this data to data brokers, analytics resellers, or advertising networks.

Your rights and deletion

Deletion means deletion

When you request account deletion, deletion is complete only after your persistent application account records have been removed and Plaid access has been revoked. We do not keep an application-level soft delete or tombstone after completion. Transaction payloads, balances, and forecasts are not persistent server records, so there is no server-side copy of them to delete.

You can also delete the encryption key on your device at any time, which makes the encrypted local database unreadable. You can disconnect your bank whenever you want. You can request removal of a beta waitlist email at any time.

Data retention

We keep your account identity, encrypted bank-connection token, and linked-account names only while your account is active and your bank is connected. We do not retain transaction payloads, balances, or forecast outputs in WealthWizard application storage. A beta invite email is kept until access is offered, the waitlist is retired, or you ask us to delete it. Operational logs are kept only as needed to run and protect the service and exclude financial payloads by policy. When you delete your data, retention ends as described above.

Children

WealthWizard is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

When this policy changes, the version and effective date at the top change with it, and meaningful changes will be announced in the app. Prior versions remain available on request.