Privacy Policy
This privacy policy applies to the Money app (hereby referred to as "Application") for iOS and Android that was created by Macaroni Studios, a sole proprietorship (hereby referred to as "Service Provider"). This service is intended for use "AS IS".
Last updated: August 7, 2026
Policy owner: Anthony Stuvecke, Proprietor — support@macaroni-studios.com
Information Collection and Use
Money is a personal finance app that lets you connect to financial institutions so you can keep track of your finances. When you affirmatively connect an institution, the Application may access and display information such as:
- Transaction data from accounts you choose to connect
- Account balances and account names or masks
- Budgets, categories, and other tracking data you create in the Application
This information is used only to help you view and track your own finances within the Application. It is not sold to third parties or used for advertising.
You initiate every bank connection. Linking occurs inside the aggregator's own consent interface (Plaid Link, Stripe Financial Connections, or the Enable Banking / PSD2 consent flow), which discloses the institution, the data categories requested, and the aggregator's role before any credential is entered. No data is collected from an institution you have not affirmatively connected. This privacy policy is presented during onboarding, before the first connection.
The Application may also process limited operational information needed to run the service, such as subscription entitlement status, push notification tokens, and aggregator link metadata (for example, institution name, connection status, and sync cursors). Product analytics events may be collected; these contain event names only and do not include financial data.
The Application does not gather precise information about the location of your mobile device.
Local-First Storage of Financial Data
Money is a local-first application. Consumer financial data — including transactions, balances, categories, and budgets — is stored in an encrypted database on your device. There is no server-side copy of your transaction history. Financial data retrieved through bank aggregators is passed through to your device and persisted locally; it is not retained on Macaroni Studios' servers.
The on-device database is encrypted (SQLCipher / AES-256). The encryption key is a per-device value stored in the iOS Keychain or Android Keystore and is not synced to iCloud or included in device backups.
Money uses a local-first, account-less identity model. You do not create a username or password. Identity is a device-bound key stored in the iOS Keychain / Android Keystore, bound to an anonymous authentication principal. App access may optionally be gated by device biometric authentication (Face ID, Touch ID, or fingerprint) with device-passcode fallback. Because your data is bound to your device and its backups, losing access to the device may mean losing access to locally stored financial data.
Server-Side Data
Server-side storage is limited to what cannot live solely on the device:
- Aggregator access tokens and credentials (encrypted; never transmitted to or stored on the client)
- Link metadata (institution, status, sync cursor)
- Subscription entitlements
- Push notification tokens
Bank data is retrieved by server-side functions that call the aggregator API, normalize the response, and return it to the device, which persists it locally. The client addresses a linked institution by a connection identifier; the server resolves the credential for the authenticated user.
Third-Party Services
The Application uses the following third-party services. Your use of those services is also subject to their own privacy practices:
- Plaid — US bank data aggregation (plaid.com/legal)
- Stripe Financial Connections — US bank data aggregation (stripe.com/privacy)
- Enable Banking — EU/UK (PSD2) bank data aggregation (enablebanking.com/privacy-policy)
- Supabase — authentication, aggregator credential custody, and sync brokering (supabase.com/privacy)
- RevenueCat — subscription entitlement management (revenuecat.com/privacy)
- PostHog — product analytics (event names only; no financial data) (posthog.com/privacy)
- Apple App Store / Google Play — distribution
- Expo / EAS — build and release pipeline
The Service Provider may disclose information:
- as required by law, such as to comply with a subpoena or similar legal process;
- when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
- with trusted service providers who work on their behalf, do not have an independent use of the information disclosed to them beyond providing the service, and have agreed to appropriate confidentiality and security obligations.
Security
The Service Provider takes the confidentiality of your information seriously. Network traffic uses TLS 1.2 or higher. On-device financial data is encrypted at rest. Aggregator access tokens stored server-side receive application-layer encryption in addition to database encryption at rest. Because financial data is stored on your device, you are also responsible for protecting access to your device (for example, with a passcode or biometric lock). No method of electronic storage or transmission is completely secure.
Data Retention and Deletion
Retention depends on the type of data:
- Transactions, balances, budgets, categories — retained on your device until you delete the connection or the Application
- Aggregator access tokens — retained (encrypted) until the connection is removed; deleted at removal
- Link metadata — until the connection is removed
- Subscription entitlements — for the duration of the subscription relationship plus any statutory retention
- Push tokens — until notifications are disabled or the Application is deleted
- Product analytics events — rolling retention per PostHog configuration; contains no financial data
You can stop use of the Application by uninstalling it using the standard uninstall process for your device or app marketplace. Disconnecting an institution revokes the credential at the aggregator, deletes the stored server-side credential, and marks the record deleted. Deleting the Application destroys the encrypted local database and its keychain key.
On request to support@macaroni-studios.com, all server-side records associated with you are deleted within 30 days. You may also exercise access, portability, correction, and deletion rights by contacting that address; requests are acknowledged within 7 days.
Children
The Service Provider does not use the Application to knowingly solicit data from or market to children under the age of 13.
The Service Provider does not knowingly collect personally identifiable information from children. If you have reason to believe that a child has provided personally identifiable information through the Application, please contact the Service Provider at support@macaroni-studios.com so that the necessary actions can be taken. You must also be at least 16 years of age to consent to the processing of your personally identifiable information in your country (in some countries we may allow your parent or guardian to do so on your behalf).
Changes
This Privacy Policy may be updated from time to time for any reason. The Service Provider will notify you of any changes by updating this page with the new Privacy Policy. You are advised to consult this Privacy Policy regularly for any changes, as continued use is deemed approval of all changes.
This privacy policy is effective as of 2026-08-07.
Your Consent
By using the Application, you are consenting to the processing of your information as set forth in this Privacy Policy now and as amended by us.
Contact Us
If you have any questions regarding privacy while using the Application, or have questions about these practices, please contact the Service Provider via email at support@macaroni-studios.com.