YourCardSentry

Legal

Privacy Policy

Effective September 20, 2026. Last updated September 20, 2026.

The short version

  • We connect to your bank through Plaid with read-only access. Nothing in this product can move, send or spend your money.
  • We do not sell your data, and we do not share it for advertising.
  • This website has no analytics, no tracking pixels, no advertising cookies and no third-party scripts of any kind.
  • We collect what the product needs to answer one question — how much you can still spend. A few things go beyond that question, and every one of them is optional: your address, your household context, and a block of demographic questions you have to switch on yourself.
  • An account can be shared by a household. Everyone on it shares one limit, so everyone’s spending counts toward the same number — but one person’s address and demographic answers are never visible to the rest of the account.
  • The person who set the account up can delete the whole household themselves, from the app. It is immediate, it cannot be undone, and it deletes every member’s data rather than only theirs — so take your own copy first.

Who we are

YourCardSentry is a spending-control app. You connect the bank accounts and credit cards you want to watch, set one spending limit for a period that matches your paycheck, and we tell you how much of it is left — and warn you before you run out.

An account is a household rather than a single person. Whoever signs up can invite the rest of the family to join the same account and the same limit.

This policy covers the marketing website at yourcardsentry.com and the app at app.yourcardsentry.com. We are the controller of the data described here. We are not a bank, and we do not hold or move money.

What we collect, and why

Every category below exists because a feature you use needs it, or because you chose to give it to us after being told what it is for. Nothing here is required reading before you can use the product: the first four categories are what the app runs on, and the two optional ones say so.

Your account and sign-in

Your email address, your name, your phone number if you give us one, and whether your email address has been verified. Sign-in is handled by Google Firebase Authentication, which also gives us an identifier for your sign-in.

Why: to create your account, to let you sign back in, and to know which data is yours. We need this to provide the service you asked us for.

The people on your household account

The person who signs up is the account’s primary. Only they can invite somebody else to join it, by email address, as either a spouse or a family member on the restricted child role. We store the invited address, the role they were invited as, when the invitation was sent, and whether it was accepted, cancelled or left to expire. An invitation is single-use and expires 30 days after it is sent.

Why: so a household can watch one budget together. Everyone on the account shares the same limit, so everyone’s spending counts toward the same number, and the adults on the account can see how it splits between people. That is the point of a shared account, and it is worth knowing before you accept an invitation.

The invitation link is a credential. It is stored hashed, it is never readable through the app’s data layer by anybody, and cancelling an invitation kills the link immediately.

Your bank and card data, through Plaid

When you link an institution, we receive and store: which institution you linked; the accounts you chose, with their name, type and the last few digits of the number; and the transactions on those accounts — amount, merchant name, date, whether the charge is still pending, and our own classification of it (a purchase, a refund, a card payment, a transfer, income, a cash withdrawal, or a fee).

Why: the classification is the product. A purchase counts against your limit, a refund gives budget back, and paying your card off does not reduce what you have spent — we cannot work that out without the transactions themselves.

We never receive your banking username or password. See the Plaid section below.

Your budget

The limit you set, the period you chose and when it resets, and the figures we calculate from your transactions: how much has been spent, how much is left, what percentage of the limit is used, and how that splits across each card and each person on the account.

Why: this is the number the app exists to show you.

Your alerts

The thresholds you want to be warned at, whether you have turned email alerts on, whether you want a daily reminder while you are over budget, and a record of each alert we sent — which alert, when, to which address, and whether it was delivered.

Why: to warn you, and to make sure the same warning is not sent to you twice. The record of what was sent is what stops the duplicate.

Your address and household context — optional

If you open your profile and fill it in, we store your postal address, and whatever household context you choose to give: whether you share the budget with a partner, how many people the budget covers, and how many of them are children or dependants. Every field is optional and can be left blank, and the form says what each one is for before it asks.

Why: so that budget guidance can reflect what things cost where you live and how far a limit has to stretch in your household. Nothing in the product reads these today to change your budget, your alerts or anything you see.

These are yours, not the household’s. Nobody else on your account can see them — not a spouse, and not the primary who invited you. You can delete them from your profile at any time, on their own, without touching your budget, your history or your place on the account.

Demographic answers — optional, and off until you turn them on

Separately from everything above, and only after you consent to it, we store an age range, an employment status, an income band, a preferred language, and an ethnicity. Every question offers “Prefer not to say”, and you can answer some and skip the rest.

Nothing is stored until you tick the consent box. Until then there is no record of you here at all — not an empty one. We also keep the exact wording of the consent you agreed to, so what you agreed to can be shown back to you rather than reconstructed later.

Why: to find out which households our budgeting tools serve badly, and fix that. That is the whole purpose. Nothing in the product reads these answers today.

These are the limits we hold ourselves to, and they are the reason we ask at all:

  • They never feed a decision. Not your budget, not your alerts, not which features you can use, not what anything costs. There is no code path in this product that reads a demographic answer to decide anything about you.
  • Nobody else on your account can see them, including the primary.
  • We never ask them of a member on the child role. See Children and family accounts.
  • You can withdraw and delete the whole block at any time, from your profile, on its own.

Email addresses that cannot receive mail

If an email to you permanently bounces, or you mark one of our emails as spam, we record the address and the reason and stop mailing it.

Why: continuing to send to a dead or complaining address is how a sender gets blocked, which would mean nobody gets their budget warnings.

Operational logs

Our servers write application logs so we can find and fix errors. These describe what the software did — which operation ran, whether it failed and why — and can reference the account it ran for.

Why: to keep the service working and to investigate problems. They are not used to build a profile of you, and access tokens for your bank connections are deliberately excluded from them.

What we do not collect

This section is as much a part of the policy as the one above, and it is worth being specific rather than silent.

  • No date of birth, and no exact age. We never ask how old anybody is, of any member of any account. The optional age range described above is a broad band you choose to give us, not a birthday, and it is the only thing of its kind we hold.
  • No religion, nationality, health or biometric information.
  • No social security number, no government ID, no credit report. We do not lend money and we do not run credit checks.
  • No analytics and no trackers. There is no Google Analytics, no advertising pixel, no session recorder and no third-party script on this website. We do not keep web access logs, so we have no record of which pages you read or what IP address you read them from.
  • No location data. We do not ask your browser or your phone where you are, and we do not infer it. The postal address in your profile is there because you typed it in, and only if you did.
  • No contacts, photos, or files.

If we ever need one of these, we will ask for it at the moment we need it and tell you what it is for. For how well we have kept this page in step with the product so far, see Changes to this policy.

Plaid, and why we cannot move your money

We use Plaid to connect to your bank. You sign in on your own bank’s page, inside Plaid. Your banking credentials go from your device to your bank; they are never transmitted to, seen by, or stored by YourCardSentry.

Plaid’s access is read-only. There is no code path in this product that can move, send or spend your money, because we never request the permission that would allow it. We ask Plaid only for account details and transaction history.

Plaid holds its own relationship with you and handles your data under its own privacy policy, linked above.

Who else sees your data

We do not sell your personal information, and we never have. We do not share it with advertisers, data brokers or analytics companies, and we do not use it to train machine-learning models.

The other people on your account see your spending, not your profile. A shared account means a shared limit, so the adults on it can see which cards and which people the spending came from. It does not mean they can see your address, your household answers or your demographic answers — those are readable only by you, and the primary is no exception.

We use a small number of service providers to run the product. They process data on our instructions and for no purpose of their own:

  • Plaid — connecting your bank accounts and retrieving transactions.
  • Google Firebase — authentication and sign-in.
  • Amazon Web Services — hosting, the database, and backups. Your data is stored in the AWS us-west-2 region, in the United States.
  • Amazon Simple Email Service — sending your budget alerts and your household invitations. Postmark is configured as an alternative provider for the same emails; whichever is in use receives the destination address and the content of the message.

We may also disclose data where the law requires it — a valid subpoena, court order or lawful government request — or where it is necessary to investigate fraud or protect someone’s safety. If YourCardSentry is ever acquired or merged, your data would transfer with the business, and this policy would continue to apply until you were told otherwise.

Cookies and browser storage

This marketing website sets no cookies at all. There is nothing to consent to and no banner to dismiss.

The app at app.yourcardsentry.com does not use cookies either, but it does store two things in your own browser so you stay signed in between visits: a session token, and a refresh token kept by Firebase. Both are first-party, both are used only for sign-in, and signing out removes them. Clearing your browser’s site data for that address has the same effect.

How long we keep it

We keep your account, your linked accounts, your transactions and your budget history for as long as your account is open. Past budget periods are kept on purpose — seeing what you spent last period is part of the product.

If the primary removes you from the household, your record stays. You lose access immediately, but the cards you connected stay connected and the spending you already did still counts in the periods it happened in, so the household’s history and the alerts it was sent still match each other. You can be added back later by a fresh invitation. If you want your personal data deleted rather than retained, email privacy@yourcardsentry.com — being removed from an account is not the same as asking us to delete you, and we would rather you told us which one you meant.

Deleting the household deletes all of it, for everybody on it. The account’s primary can do this themselves, from Settings in the app. It runs in this order, and the order is deliberate:

  1. Every connected bank is revoked at Plaid first, before a single local record is touched. The access token is destroyed at the provider rather than merely forgotten by us, so nothing anywhere can read that bank again.
  2. Then every record of the household is deleted — each member’s login, profile, address, household context and demographic answers, together with the household’s transactions, budgets, past periods, alert history and invitations.
  3. Then the sign-in identities are deleted at Firebase.

It is immediate, and it cannot be undone. There is no grace period, no recovery window and no restore — not by you and not by us. Once it has run there is nothing left for anybody at YourCardSentry to put back, so support cannot reverse it either. The app asks you to type your household’s name out before it will begin.

It deletes other people’s data along with yours. A spouse and a teenager on the account are not asked and cannot stop it: only the primary can delete, and what they delete is everybody. That is inherent in sharing one account, and it is worth knowing before you accept an invitation rather than on the day it happens.

Take your copy first, and take it yourself. An export covers one person, so the primary downloading theirs does not produce a copy for anyone else. Anybody who wants their own has to download it from their own profile while the account still exists — afterwards there is nothing left to export.

A deletion can get stuck, and we would rather say so than imply it always works. If an institution will not accept the revocation, the deletion stops there and nothing local is removed. We will not delete our record of a bank connection while a working credential to that bank still exists somewhere, because “we deleted your account” would then be false about the one part that can still reach your money. The app tells you which institution refused; email privacy@yourcardsentry.com and we will finish it with you.

Three things outlast a deletion, and we would rather say so than leave it implied:

  • Encrypted database backups roll on a 7-day window, so deleted data can persist in a backup for up to seven days before it ages out.
  • A record that an address hard-bounced or complained survives, because its only purpose is to stop us mailing that address ever again. What survives is not the address: it is a one-way fingerprint of it, and the provider’s bounce message goes with the address, because providers quote the recipient back inside it. We are not going to call that anonymous. Email addresses are short and guessable, so a fingerprint of one is no defence against somebody determined to sit and test guesses against it. What it does mean is exact and worth having: the address is not present, cannot be read, cannot be exported, and will not be in the next copy of our database — and we still never mail it.
  • If deleting a sign-in identity at Firebase fails, the rest of the deletion has already completed, and the failure is recorded so that it can be cleared by hand. Until it is, a login that opens nothing still holds an email address and a name.

Your choices and your rights

You can, at any time:

  • Choose which accounts are watched. An account you stop monitoring stops counting toward your budget.
  • Disconnect an institution entirely. Do it yourself, from Cards in the app. We revoke our access at Plaid — so we cannot read that bank again, and reconnecting it later means signing in to it afresh — and we delete the transactions it sent us. Budget periods that have already closed keep the totals they finished with, so your spending history and the alerts you were sent still match each other.
  • Turn alert emails off in your notification settings, or change the thresholds you are warned at.
  • Download a copy of your data. Do it yourself, from your profile in the app. It returns one document containing your account record, your address and household context, your demographic answers together with the exact consent wording you agreed to, and your notification settings. It covers you as a person; the household’s shared budget, cards and transactions are account data rather than yours alone, and the document says so.
  • Delete your address, household context or demographic answers on their own, from your profile, leaving your budget, your history and your membership of the account untouched.
  • Ask us to correct anything that is wrong.
  • Delete the whole household. If you are the account’s primary, do it yourself, from Settings in the app. It is immediate, it cannot be undone, and it deletes every member’s data rather than only yours — How long we keep it sets out exactly what happens, in what order, and what survives it.

Everything above except correcting a mistake is in the app and does not need us. For a correction — or if you would rather ask a person, or you are not the primary, or a deletion has stopped on an institution that will not release its connection — email privacy@yourcardsentry.com from the address on your account. We will respond within 30 days, and we will not charge you or treat you differently for asking.

Depending on where you live, you may have additional rights — for example under the California Consumer Privacy Act or the GDPR — including the right to object to or restrict certain processing, and the right to complain to your local data-protection authority. The same address reaches us for all of them. Where the GDPR applies, our legal basis is the performance of our contract with you for everything in What we collect, except your demographic answers, which rest on your consent alone and which you can withdraw at any time, and operational logs and suppression records, which rest on our legitimate interest in keeping the service working and our email deliverable.

How we protect it

Traffic to this website and to the app is encrypted in transit with TLS. The database is encrypted at rest, and network access to it is restricted to our own servers and a short allow-list of administrative addresses. Credentials and secrets are held in encrypted parameter storage rather than in our source code.

Your bank access tokens are excluded from logs and from every API response by design, and there are tests that fail if that ever stops being true. Invitation links are treated the same way.

Every query in the app is scoped to your account, so one account can never read another’s data. Two things are scoped more tightly still, to the person rather than the account: a member on the child role can only read their own transactions, and a profile and its demographic answers can only be read by the person they belong to. Both are enforced on our servers, not by leaving a link out of the app.

No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your personal data, we will tell you and the relevant regulators as the law requires.

Children and family accounts

YourCardSentry is a household product, and it is not directed at children. We do not advertise it to them, and a child cannot sign up for it on their own.

An adult is the one who adds a family member. Only an account’s primary can invite somebody, and only they can change a member’s role, remove them from the account, or hand the account over to someone else. An invited person signs up for themselves with their own email address and joins the existing account; they never create a second one.

The child role is the restricted one. Somebody on it can see the household’s limit and their own spending against it, and nothing else: not another member’s transactions, not another member’s contact details. They cannot connect a card, change the budget, or change anybody’s alert settings. That restriction is enforced on our servers — a member on the child role querying our data layer directly gets their own rows back and no more.

We never ask a member on the child role a demographic question of any kind — not an age range, not an employment status, not an income band, not an ethnicity. The request is refused on our server, and the demographics data is not present in their version of the app at all. Like anyone else on the account they can choose to fill in a postal address and household context, and like anyone else nobody on the account can see it, including the primary who invited them.

The product never asks anybody’s age, so we cannot tell how old a member is. The child role is a permission level chosen by the adult who sent the invitation; it is not an age, and it is not a statement that the person is a minor. The adult who adds a family member is the one who decides who joins their household and manages them afterwards.

We do not want personal information from a child under 13, and we have no way to verify anyone’s age. If you believe a child under 13 has been added to an account, email privacy@yourcardsentry.com and we will delete their information and remove them. You do not have to be the person who added them.

Changes to this policy

When the product changes what it collects, this page changes with it — as part of shipping the feature, not afterwards. We will update the effective date at the top, and for a change that materially affects you we will email you before it takes effect.

That is the standard, and this update did not meet it. Household invitations, profiles and the optional demographics block all went live before this page described them. Until the version dated September 20, 2026, it said that inviting other people into an account was not built yet, that we collected no demographic information and no home address, and that we would update this policy before either of those became available. We did not, and we are recording that here rather than quietly deleting the sentences. Everything on this page now describes what the product does today.

Contact us

Questions about this policy, or about your data, go to privacy@yourcardsentry.com. A real person reads it.