Privacy Policy
Who we are
WealthWizard is a personal budgeting app that forecasts your account balance so you can see where your money is heading. This policy explains what data the app and website touch, what we deliberately never keep, and the choices you always have. It applies to the WealthWizard mobile application, this website, and the services behind them.
What we collect
We collect the minimum needed to show you your own forecast:
- Account identity. Your email address and sign-in credentials, held by AWS Cognito, our identity provider. We never see or store your password.
- Bank connection. When you choose to connect a bank, you do it through Plaid. Your bank username and password are entered only on Plaid's or your bank's own screens. They are never visible to WealthWizard.
- Financial data. During a sync, Plaid sends account balances and transactions to our service. We process them transiently so the app can refresh your timeline and forecast. Transaction payloads and balances are not written to WealthWizard application storage. The transaction history and forecasts used by the app are kept in the encrypted database on your device.
- Beta invite requests. If you join the beta waitlist on this website, we store the email address you submit and the time of the request. We do not store your browser user-agent with the request.
- Routine delivery data. Cloudflare processes connection information such as your IP address and browser headers to deliver and protect the website. WealthWizard does not add third-party analytics or advertising trackers.
What we refuse to store
This is the part most privacy policies do not have, and it is the core of how WealthWizard is built:
Not retained in application storage
WealthWizard does not write transaction payloads, account balances, or forecast outputs to application storage. They are processed for the current request only. This is a persistence boundary: financial data still passes transiently through service memory during a sync.
For each transaction, the service receives the Plaid record, removes merchant names, descriptions, locations, and counterparties, and relays only six fields to your phone: a transaction identifier, an account identifier, a date, an amount, a spending category, and a pending flag. This filtering limits the data sent to your device; neither the raw nor the minimized transaction record is written to WealthWizard application storage.
The transaction history and forecasts used by WealthWizard are stored in an encrypted database on your device, locked by a key that never leaves your device's keychain.
Persistent application records for an app user are limited to your email address, an encrypted bank-connection token, and the names and types of your linked accounts. Transient sync processing, Cognito identity records, website waitlist records, and routine delivery and security data are described separately in this policy.
How your data is used
Your financial data is used to produce your balance timeline and forecast, for you. A beta invite email is used to maintain the waitlist and contact you about access. We do not sell your data, share it with advertisers, or train shared models on your personal transactions.
Where your data lives and how it is protected
- All communication uses TLS 1.2 or better. Our mobile app refuses, in code, to send credentials over anything unencrypted.
- Bank access tokens are encrypted at rest with authenticated symmetric encryption.
- Your transaction history and your forecast are stored on your phone in an encrypted database whose key is generated on your device, kept in your device's secure keychain, never synced anywhere, and protected by your device biometrics where supported.
- Your account balances are read live from your bank each time the app asks and are not written to WealthWizard application storage.
- Consumer identity, including any multi-factor authentication you enable, is handled by AWS Cognito.
This architecture is not a roadmap item. It shipped, and this version of the policy describes the running system.
Who we share with
We use the following service providers only for the stated product and website operations:
- Plaid, which connects to your bank on your instruction and under its own privacy policy.
- Amazon Web Services (Cognito), which stores your account identity.
- Cloudflare, which hosts and protects this website and stores beta invite requests in D1.
- Resend, which receives the submitted email address only when optional owner notifications are enabled for new beta invite requests.
We do not disclose this data to data brokers, analytics resellers, or advertising networks.
Your rights and deletion
Deletion means deletion
When you request account deletion, deletion is complete only after your persistent application account records have been removed and Plaid access has been revoked. We do not keep an application-level soft delete or tombstone after completion. Transaction payloads, balances, and forecasts are not persistent server records, so there is no server-side copy of them to delete.
You can also delete the encryption key on your device at any time, which makes the encrypted local database unreadable. You can disconnect your bank whenever you want. You can request removal of a beta waitlist email at any time.
Data retention
We keep your account identity, encrypted bank-connection token, and linked-account names only while your account is active and your bank is connected. We do not retain transaction payloads, balances, or forecast outputs in WealthWizard application storage. A beta invite email is kept until access is offered, the waitlist is retired, or you ask us to delete it. Operational logs are kept only as needed to run and protect the service and exclude financial payloads by policy. When you delete your data, retention ends as described above.
Children
WealthWizard is not directed at children under 13, and we do not knowingly collect data from them.
Changes to this policy
When this policy changes, the version and effective date at the top change with it, and meaningful changes will be announced in the app. Prior versions remain available on request.