Legal
Privacy Policy
Effective September 20, 2026. Last updated September 20, 2026.
The short version
- We connect to your bank through Plaid with read-only access. Nothing in this product can move, send or spend your money.
- We do not sell your data, and we do not share it for advertising.
- This website has no analytics, no tracking pixels, no advertising cookies and no third-party scripts of any kind.
- We collect what the product needs to answer one question — how much you can still spend — and nothing beyond it.
Who we are
YourCardSentry is a spending-control app. You connect the bank accounts and credit cards you want to watch, set one spending limit for a period that matches your paycheck, and we tell you how much of it is left — and warn you before you run out.
This policy covers the marketing website at yourcardsentry.com and the app at app.yourcardsentry.com. We are the controller of the data described here. We are not a bank, and we do not hold or move money.
What we collect, and why
Every category below exists because a feature you use needs it. We do not collect anything on the basis that it might be useful later.
Your account and sign-in
Your email address, your name, your phone number if you give us one, and whether your email address has been verified. Sign-in is handled by Google Firebase Authentication, which also gives us an identifier for your sign-in.
Why: to create your account, to let you sign back in, and to know which data is yours. We need this to provide the service you asked us for.
Your bank and card data, through Plaid
When you link an institution, we receive and store: which institution you linked; the accounts you chose, with their name, type and the last few digits of the number; and the transactions on those accounts — amount, merchant name, date, whether the charge is still pending, and our own classification of it (a purchase, a refund, a card payment, a transfer, income, a cash withdrawal, or a fee).
Why: the classification is the product. A purchase counts against your limit, a refund gives budget back, and paying your card off does not reduce what you have spent — we cannot work that out without the transactions themselves.
We never receive your banking username or password. See the Plaid section below.
Your budget
The limit you set, the period you chose and when it resets, and the figures we calculate from your transactions: how much has been spent, how much is left, what percentage of the limit is used, and how that splits across each card.
Why: this is the number the app exists to show you.
Your alerts
The thresholds you want to be warned at, whether you have turned email alerts on, whether you want a daily reminder while you are over budget, and a record of each alert we sent — which alert, when, to which address, and whether it was delivered.
Why: to warn you, and to make sure the same warning is not sent to you twice. The record of what was sent is what stops the duplicate.
Email addresses that cannot receive mail
If an email to you permanently bounces, or you mark one of our emails as spam, we record the address and the reason and stop mailing it.
Why: continuing to send to a dead or complaining address is how a sender gets blocked, which would mean nobody gets their budget warnings.
Operational logs
Our servers write application logs so we can find and fix errors. These describe what the software did — which operation ran, whether it failed and why — and can reference the account it ran for.
Why: to keep the service working and to investigate problems. They are not used to build a profile of you, and access tokens for your bank connections are deliberately excluded from them.
What we do not collect
This section is as much a part of the policy as the one above, and it is worth being specific rather than silent.
- No demographic information. We do not ask for and do not store your age, date of birth, employment status, income band, ethnicity, race, religion, nationality, health, or preferred language.
- No home address, marital status, household size or dependants.
- No social security number, no government ID, no credit report. We do not lend money and we do not run credit checks.
- No analytics and no trackers. There is no Google Analytics, no advertising pixel, no session recorder and no third-party script on this website. We do not keep web access logs, so we have no record of which pages you read or what IP address you read them from.
- No location data. We do not ask your browser or your phone where you are.
- No contacts, photos, or files.
If we ever need one of these, we will ask for it at the moment we need it, tell you what it is for, and update this policy first.
Plaid, and why we cannot move your money
We use Plaid to connect to your bank. You sign in on your own bank’s page, inside Plaid. Your banking credentials go from your device to your bank; they are never transmitted to, seen by, or stored by YourCardSentry.
Plaid’s access is read-only. There is no code path in this product that can move, send or spend your money, because we never request the permission that would allow it. We ask Plaid only for account details and transaction history.
Plaid holds its own relationship with you and handles your data under its own privacy policy, linked above.
How long we keep it
We keep your account, your linked accounts, your transactions and your budget history for as long as your account is open. Past budget periods are kept on purpose — seeing what you spent last period is part of the product.
When you ask us to delete your account, we delete your personal data and disconnect your institutions from Plaid. Two things outlast that deletion, and we would rather say so than leave it implied:
- Encrypted database backups roll on a 7-day window, so deleted data can persist in a backup for up to seven days before it ages out.
- A record that an address bounced or complained is kept after deletion, because its only purpose is to stop us mailing that address again.
Your choices and your rights
You can, at any time:
- Choose which accounts are watched. An account you stop monitoring stops counting toward your budget.
- Disconnect an institution entirely. There is no button for this in the app yet — email us and we will unlink it and delete the transactions that came from it.
- Turn alert emails off in your notification settings, or change the thresholds you are warned at.
- Ask for a copy of your data, in a portable format.
- Ask us to correct anything that is wrong.
- Ask us to delete your account and everything in it.
Self-service export and deletion are not built into the app yet. Until they are, email privacy@yourcardsentry.com from the address on your account and we will handle it by hand. We will respond within 30 days, and we will not charge you or treat you differently for asking.
Depending on where you live, you may have additional rights — for example under the California Consumer Privacy Act or the GDPR — including the right to object to or restrict certain processing, and the right to complain to your local data-protection authority. The same address reaches us for all of them. Where the GDPR applies, our legal basis is the performance of our contract with you for everything in What we collect, except operational logs and suppression records, which rest on our legitimate interest in keeping the service working and our email deliverable.
How we protect it
Traffic to this website and to the app is encrypted in transit with TLS. The database is encrypted at rest, and network access to it is restricted to our own servers and a short allow-list of administrative addresses. Credentials and secrets are held in encrypted parameter storage rather than in our source code.
Your bank access tokens are excluded from logs and from every API response by design, and there are tests that fail if that ever stops being true.
Every query in the app is scoped to your account, so one account can never read another’s data.
No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your personal data, we will tell you and the relevant regulators as the law requires.
Children and family accounts
YourCardSentry is not directed at children, and we do not knowingly collect personal information from a child under 13.
Today there is only one way to get an account: an adult signs up for themselves. Inviting other people into an account is not built yet, so every person using the product created their own account and gave us their own information.
The product is designed for households, and we intend to add family members — including a restricted role for a teenager who can see the household limit and their own spending, but not anyone else’s transactions. When that ships, an adult will be the one who adds a family member and manages their data, and we will update this policy before it is available, not after.
If you believe a child has given us personal information, email privacy@yourcardsentry.com and we will delete it.
Changes to this policy
When the product changes what it collects, this page changes with it — as part of shipping the feature, not afterwards. We will update the effective date at the top, and for a change that materially affects you we will email you before it takes effect.
Contact us
Questions about this policy, or about your data, go to privacy@yourcardsentry.com. A real person reads it.