Privacy Policy
1. Information We Collect
What We DO NOT Store
Zero Transaction Data Storage:
- We do NOT store any transaction data in our database
- We do NOT store transaction amounts, dates, or merchant names
- We do NOT store account balances or account details
- We do NOT store any financial information from your bank accounts
Authentication Data (Stored)
- User Account: Anonymous user identifiers generated by Supabase
- Plaid Access Tokens: Secure tokens to fetch your transactions in real-time
- Optional Apple ID: If you choose Apple Sign In
- Session Tokens: For app functionality and authentication
Usage Data (Non-Financial)
- App Usage Patterns: Feature interactions and navigation (via Sentry)
- Device Information: iOS/Android version, device type
- Crash Reports: Error logs for app improvement (no financial data included)
2. How We Handle Your Transaction Data
Direct Plaid Integration
- Real-Time Fetching: Transactions are fetched directly from Plaid when you open the app
- Client-Side Processing: All transaction data is processed on your device
- No Database Storage: Transaction data never touches our servers or database
- Temporary Memory: Data exists only in your device's memory while the app is open
Maximum Privacy Architecture
- Your transaction data flows: Plaid → Your Device → Display
- No intermediate storage or processing on our servers
- No AI processing or analysis of your transactions
- No third-party analytics services receive financial data
3. Information Sharing and Disclosure
Third-Party Services
- Plaid: Provides secure access to your bank transaction data (see Plaid Privacy Policy)
- Supabase: Stores only authentication data (user accounts and Plaid tokens)
- Sentry: Monitors app performance and errors (no financial data sent)
- Apple/Google: App store services and subscription management only
What We Never Share
- Transaction data (we don't have it to share)
- Account balances or financial details
- Spending patterns or financial profiles
- Any personally identifiable financial information
4. Data Retention and Deletion
What Gets Stored (Minimal)
- Plaid Access Tokens: Stored until you disconnect your accounts or delete your account
- User Authentication: Stored until you delete your account
- App Preferences: Color settings and UI preferences
What Gets Deleted
When you delete your account:
- All Plaid access tokens are immediately revoked and deleted
- User authentication data is permanently removed
- App preferences and settings are deleted
- All data associated with your account is purged from our systems
Transaction Data
- Never stored, so nothing to delete
- Exists only temporarily in your device's memory
- Automatically cleared when you close the app
5. Your Privacy Rights
Data Transparency
- Zero Transaction Storage: Industry-leading privacy with no financial data storage
- Client-Side Processing: Your data never leaves your device
- No Profiling: We don't analyze, profile, or track your spending
- No AI Processing: No machine learning or AI analysis of your finances
Enhanced Privacy Protection
- Data Minimization: Only authentication tokens stored
- Purpose Limitation: Tokens used solely for fetching your data
- No Secondary Use: Data never repurposed for other activities
- Immediate Deletion: Account deletion removes all data instantly
6. California Privacy Rights (CCPA)
Information Categories We Collect
- Authentication Data: User identifiers and access tokens
- Device Information: Technical data for app functionality
- Usage Information: App interaction patterns (non-financial)
Information Categories We DO NOT Collect
- Transaction data or financial information
- Account balances or account numbers
- Spending patterns or financial profiles
- Personal financial details of any kind
Data Processing Purposes
- Authenticating users and maintaining secure sessions
- Fetching transaction data from Plaid for display
- Providing app functionality and user experience
- Customer support when requested
7. Security
Minimal Attack Surface
- No transaction data stored means no transaction data can be compromised
- Only authentication tokens stored, protected with encryption
- Client-side processing eliminates server-side data exposure
- Anonymous user system provides additional protection
Technical Safeguards
- Encryption: All stored data encrypted at rest and in transit
- Access Controls: Multi-factor authentication for system access
- Secure Tokens: Plaid tokens stored securely and never exposed
- Regular Security Audits: Continuous monitoring for vulnerabilities
8. Monitoring and Error Tracking
Sentry Integration
- Used for app performance monitoring and crash reporting
- No Financial Data: Sentry never receives transaction data, amounts, or merchant names
- Only technical error information and app performance metrics
- Helps us identify and fix bugs to improve your experience
Contact Information
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
Email: jabarickemp@ijustwantagoodjob.com
Company: I JUST WANT LLC
Effective Date: October 31, 2025
Last Updated: October 31, 2025