Privacy Policy
The short version
- We connect to your bank through Plaid. We never see or store your bank password.
- We use your data for one thing: personalized money lessons and insights for you.
- We never sell your data and never share it with advertisers.
- Disconnect a bank or delete your account any time. Your data goes with it.
- Your bank access tokens are encrypted. Everything travels over TLS.
Contents
1. Who we are
MoneyGator is a personal finance education app made by Artifiqa, Inc., a Delaware corporation ("we", "us"). This policy explains what data the MoneyGator mobile app and the moneygator.app website collect, why, and what you can do about it. It applies wherever you use MoneyGator.
MoneyGator is an education product. We are not a bank, a lender, or a financial advisor, and we cannot move money or make changes to your accounts.
2. What we collect
Information you give us
- Account details: email address and password (stored as a one-way hash) when you create an account. Name, if you choose to add one.
- Answers and progress: your answers to onboarding questions and quizzes, lessons completed, streaks, and actions you mark as done. This is how we personalize what you see.
- Messages: anything you send us through support or feedback.
Information from your bank, through Plaid
When you choose to connect a bank, we receive the following through Plaid (see Section 3):
- Account names, types, and current balances
- Transactions: date, merchant, amount, category, and whether a charge is recurring
- For credit cards and loans: balances, minimum payment, due date, interest rate, and payment history
We do not receive your bank username or password. We do not receive full account numbers, and we do not request identity, income, or investment products unless you explicitly enable a feature that needs them.
Information collected automatically
- Device and app data: device type, OS version, app version, language, and crash reports, so we can fix bugs.
- Usage data: which screens and lessons you open and when, so we can improve the product. We do not use third-party advertising trackers.
- Website: if you join the waitlist on moneygator.app, we store the email you enter. The website does not use tracking cookies.
3. How bank connection works
Bank connections are powered by Plaid Inc. When you tap "Connect your bank", Plaid's secure interface opens inside the app. You log in to your bank directly with Plaid, and Plaid returns to us an access token and the data listed above. Your credentials go to Plaid and your bank, never to MoneyGator.
Plaid's use of your information is governed by the Plaid End User Privacy Policy. You can see and manage every app connected to your bank through Plaid at my.plaid.com.
Connecting a bank is optional. You can use MoneyGator's lessons without it; connecting is what makes the lessons personal.
4. How we use your data
We use your data to run MoneyGator and for nothing else. Specifically, to:
- Show you your spending, subscriptions, and upcoming payments in one place
- Generate personalized insights (for example, a subscription you haven't used in 60 days) and choose which lesson to show you next
- Track your progress, streaks, and achievements
- Send you notifications you have turned on, such as a reminder before a credit card due date
- Respond to your support requests
- Keep the service secure, prevent abuse, and fix bugs
- Understand how the product is used, in aggregate, to improve it
We do not use your financial data to make credit decisions, and we do not build profiles of you for third parties.
5. Who we share it with
We do not sell your personal information and we do not share it with advertisers or data brokers. We share data only with service providers who need it to run MoneyGator, and only under contracts that require them to protect it:
| Provider | Purpose | What they receive |
|---|---|---|
| Plaid Inc. | Bank connection and transaction data | Your bank login (entered by you in Plaid's interface), account and transaction data |
| Cloud hosting provider | Running our servers and database | Encrypted data stored on their infrastructure |
| Apple Inc. | App distribution, push notifications, crash reports | Device identifiers, crash logs. Never your financial data |
| Email provider | Sending account and support emails | Your email address and message content |
We may also disclose data if required by law, to protect the rights and safety of users or the public, or as part of a merger or acquisition (in which case this policy continues to apply and we will notify you).
6. How we protect it
- Encryption in transit: all traffic between the app, our servers, and Plaid uses TLS 1.2 or higher.
- Encryption at rest: Plaid access tokens are encrypted with AES-256-GCM using a key stored separately from the database. Our database runs on storage that is encrypted at rest.
- Access control: access to production systems is limited to the people who operate the service, protected by multi-factor authentication and SSH keys. Nobody at MoneyGator can see your bank password, because we never have it.
- No tokens in logs: access tokens and credentials are never written to logs.
- Written security program: we maintain an information security policy covering access control, encryption, vendor management, incident response, and periodic review.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify you and the relevant authorities as required by law, and we will tell you what happened and what we are doing about it.
7. Retention and deletion
- Disconnect a bank: in the app, go to Settings → Bank connection → Disconnect. We immediately revoke our access at Plaid and permanently delete the access token and all transactions from that bank.
- Delete your account: in the app, Settings → Delete account, or email privacy@moneygator.app. We delete your account and all associated data within 30 days. Backups are overwritten within 30 days after that.
- Inactive accounts: if you have not opened MoneyGator for 12 months, we disconnect your banks and delete your financial data. Your account and learning progress are kept so you can come back.
- Legal holds: we may keep specific records longer if a law requires it. We will keep only what is required.
8. Your rights
Wherever you live, you can:
- Access the data we hold about you and receive a copy
- Correct inaccurate information
- Delete your data (Section 7)
- Withdraw consent for bank data by disconnecting your bank at any time
- Opt out of notifications in the app or in your device settings
California residents (CCPA/CPRA): you have the right to know what personal information we collect, use, and disclose; to delete it; to correct it; and to not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of. To make a request, email privacy@moneygator.app. We will verify your identity by confirming access to the email on your account and respond within 45 days.
Gramm-Leach-Bliley Act: because MoneyGator handles nonpublic personal financial information, we protect it in line with GLBA safeguards and do not share it with nonaffiliated third parties for their own marketing.
9. Children
MoneyGator is for people 18 and older. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, email us and we will delete it.
10. Changes to this policy
If we make a material change, we will notify you in the app or by email at least 14 days before it takes effect, and we will update the date at the top of this page. Continuing to use MoneyGator after that date means you accept the updated policy. Previous versions are available on request.
11. Contact
Artifiqa, Inc.
1390 Market St, Ste 200
San Francisco, CA 94102, USA
Privacy requests: privacy@moneygator.app
Security: security@moneygator.app
Everything else: hello@moneygator.app