MyMoneyConcierge keeps your financial records on your own device, in an encrypted database. Your transactions, balances, account names, categories, budgets, goals, notes and receipts are not stored in an account on our servers, and we cannot read them. We never sell your data, and we use no advertising or cross-app tracking SDKs.
Two things do involve other companies, and both are described in full below: bank connections (optional, on the Connected plan) are handled by a regulated aggregator that never gives us your banking credentials, and subscriptions are processed by Apple or Google. A few further features — cloud AI and crash reporting — are opt-in and off by default.
If you want the engineering detail rather than the legal summary, the security page sets out exactly what we hold, what we can read, and where our protection stops.
MyMoneyConcierge is developed and operated by SmartHarmony AI LLC. For any privacy question or request, contact support@smartharmonyai.com. We are the controller of the limited personal data described in this policy.
If you choose the Connected plan and link an account, the connection is made through Plaid, a regulated data aggregator. What that means concretely:
The everyday intelligence in the app — balances, totals, forecasts, projections, category suggestions — is ordinary code that runs on your device, and sends nothing anywhere.
If you turn on the optional cloud tier, a minimised, structured summary is sent over TLS to our own edge service, which authenticates your subscription and forwards it through Cloudflare AI Gateway to our model provider (Anthropic and/or OpenAI, depending on the task). Specifically:
Purchases are processed by Apple and Google. We use RevenueCat to confirm your subscription status; it receives a randomly generated pseudonymous identifier and your purchase details — not your financial records. We also keep a count of the AI Actions used in your billing period, so your allowance can be metered. That is a count, not the content of the requests.
If you opt in, the app may send diagnostic crash reports to Sentry to help us fix bugs. Reports are scrubbed of personal information, and a report that still carries a marker of sensitive data after scrubbing is discarded rather than sent. Off by default.
Where the app sends you a push notification, the payload contains only an opaque event identifier and a category — never an amount, merchant, account name or balance. The words you read are composed on your device after it is unlocked, so a bystander glancing at your lock screen learns nothing about your finances.
The app fetches a small, read-only configuration over HTTPS to enable or disable features. It contains no personal data and sends none about you.
We share personal data only with the providers below, only for the purpose shown, and only when the related feature is used. Each handles data under its own privacy policy and only on our instructions.
| Provider | What is shared | Purpose |
|---|---|---|
| Plaid | The connection you authorise; we receive transaction and balance data for the accounts you link. Your banking credentials are never shared with us. | Connect your bank accounts (Connected plan) |
| Cloudflare | Request metadata; envelope-encrypted bank-token ciphertext at rest. Transaction data passes through memory in transit and is not stored. | Edge services, model routing, protection against abuse |
| Anthropic and/or OpenAI, via Cloudflare AI Gateway | The minimised, allowlisted content of a cloud AI request you consented to — totals, category names, date ranges. No identifiers, no account details, no raw notes. | Phrase an insight or propose a categorisation; zero retention, no model training |
| Apple, Google (app stores) | Purchase and subscription details | Process purchases and deliver the app |
| RevenueCat | Pseudonymous ID + purchase details (no financial records) | Confirm subscription entitlement |
| Sentry | Scrubbed crash diagnostics (opt-in) | Diagnose and fix crashes |
| Expo (push delivery) | A device push token and an opaque event identifier | Deliver a notification with no financial content in it |
We keep this list current. If we add a processor, we assess it before it touches any data and update this page.
| Purpose | Basis |
|---|---|
| Providing the app and its on-device functionality | Performance of a contract |
| Managing your subscription and entitlement | Performance of a contract |
| Bank connectivity (Connected plan) | Your explicit consent, plus performance of a contract |
| Cloud AI features | Your explicit, per-capability consent |
| Crash reporting | Your consent |
| Security, abuse prevention and keeping the service working | Legitimate interests |
| Meeting legal and contractual obligations | Legal obligation |
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to the processing of your personal data, to withdraw consent at any time, and to complain to your data-protection authority. Because your financial records live on your device, the fastest route for most of these is the in-app export and delete controls above — they are immediate and complete.
For anything we hold, email support@smartharmonyai.com. We respond within the shortest period the applicable law requires, and we will not ask you for more personal information to verify a request than the request itself concerns. Exercising a right never costs you access to the app.
| Data | Retention |
|---|---|
| Your on-device ledger | Until you delete it. We hold no copy. |
| Your exports | Yours entirely — we hold no copy and no recovery key |
| Bank connection tokens (encrypted) | Until you disconnect, or until automatic removal after a defined period of inactivity, whichever comes first |
| Connection details (institution, masked account, health state) | Life of the connection, then 90 days |
| Consent records (what you agreed to, and when) | Life of the connection, then 24 months — we keep the proof of consent longer than the consent itself |
| Transaction data in transit from your bank | Never stored. It exists in memory for the length of the request and is passed to your device |
| Cloud AI requests | Not retained by the provider (zero-retention configuration); not used for training; response caching deliberately disabled |
| AI Action counts | The billing period, plus 90 days for reconciliation |
| Subscription and entitlement state | Life of the subscription, then 24 months. Records held by Apple, Google and RevenueCat follow their own policies |
| Push notification tokens | Until you turn notifications off, or 180 days of inactivity |
| Crash reports (opt-in) | 90 days, then deleted |
| Application logs | Up to 30 days |
| Operational logs | Up to 90 days |
| Security and administrative event logs | 400 days, append-only. None of these logs contain financial values. |
| Usage analytics (bucketed, pseudonymous) | 400 days |
| Backups and snapshots | Rolling window of up to 35 days, then they expire automatically |
| Support correspondence | Up to 24 months after your request is resolved, then deleted |
| Breach records | At least 24 months — we record every incident, whether or not it meets a notification threshold, because the law requires the register |
Most privacy policies go vague here. Ours doesn't, because the honest answer is better than the vague one.
We won't claim instant erasure from every backup, because with immutable snapshots that isn't achievable — and a claim we couldn't stand behind would undermine everything else on this page.
A summary; the full programme is described on the security page.
No method of storage or transmission is completely secure, but the app is designed so that the most sensitive information never leaves your device at all.
MyMoneyConcierge is intended for adults managing their own finances. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
Because your ledger stays on your device, it resides wherever your device is. The limited data we do process is handled on infrastructure located in Canada where we control the region. Our providers may process data in other countries under their own terms and with appropriate safeguards; the optional cloud AI tier is routed to a contractually adequate processing region. Availability of bank connections varies by country and institution.
MyMoneyConcierge is a tool for recording and understanding your own money. It does not provide financial, investment, tax or legal advice, does not perform credit scoring, and does not make automated decisions about you. For advice about your circumstances, consult a qualified professional.
If we change how the app handles data, we update this page and its effective date before or at the same time as the change reaches you — keeping this page accurate is part of our release process, not an afterthought. Material changes are surfaced in the app.
Questions, requests, or help with deletion: support@smartharmonyai.com.