Privacy Policy
The privacy of your data — and it is your data, not ours — matters to us. This policy explains what we collect, why, how it’s handled, and your rights. We never sell your data.
Money on Rails is operated by [Legal Name / Entity — TBD before legal review], a solo-developer product based in Nuevo León, Mexico. It is a third-party analytics tool that connects to your YNAB budget via YNAB’s own API. Money on Rails is not affiliated, associated, or in any way officially connected with YNAB or any of its subsidiaries or affiliates.
What we collect and why
| We collect | Why |
|---|---|
| Your YNAB account identifier (an opaque ID YNAB gives us — YNAB never shares your email or name with us) | To recognize you as a returning User and enforce the invite gate |
| A YNAB OAuth access/refresh token pair | To read your Budget data on your behalf, for as long as your Connection stays active |
| Your Budget’s Categories, Category Groups, and monthly budgeted/activity/balance figures | To compute your Adherence Rating, Category Adherence, and Budget Quality Rating |
| Your Budget’s inflow transactions only (date, amount, payee, category) | To group payees into Income Sources and attribute income in the app’s cash-flow view. We do not sync outflow transactions, and no view in the product drills below a category’s monthly total. |
| Category names (never amounts, payees, or account/user identity) | Sent to our AI classification provider once per Budget, to suggest a Needs/Wants/ Savings bucket and a true-expense grouping for each category. You can always correct a suggestion. |
| If you contact us to request an invite before you have an account | To evaluate and respond to your request |
We collect the minimum YNAB permissions necessary to do this and nothing beyond it.
When we access or disclose your information
We use a small number of subprocessors to run the service, and we don’t sell or rent your data to anyone:
- YNAB, Inc. — the source of your Budget data. We only read what your OAuth grant authorizes; we never write to your Budget.
- Anthropic, Claude Haiku model family — our AI classification provider. We send only category names (e.g. “Groceries”) — never amounts, payee names, account identifiers, or anything identifying you — and only when a category name hasn’t already been classified before across all Users. Anthropic’s Commercial Terms state Customer Content submitted via the API is not used to train their models without our express permission, and Anthropic does not retain this data by default beyond what’s technically necessary to serve the request. Anthropic publishes a Data Processing Addendum covering this relationship.
- Google Cloud Platform — hosts our application, database, and encryption keys. Your data is stored on infrastructure located in the United States.
- A payment processor, if and when Money on Rails introduces paid plans (it does not have one today).
No human on our side looks at your budget data except as strictly necessary to fix a bug you’ve reported or investigate abuse, and never your transaction-level detail without cause. We do not respond to government requests for your data unless legally compelled to.
Your rights with respect to your information
You can, at any time:
- Access the data we hold about you, by asking us (see Contact, below) — or simply by using the app, since everything we store about your Budget is what the app itself displays back to you.
- Correct a category or archetype classification directly in the app.
- Delete your account and data, from your account settings or by emailing us. See “What happens when you delete your account,” below.
- Object to a specific use of your data, or ask us to restrict processing, by contacting us.
- Export your data — since it’s a synced copy of your own YNAB Budget, the authoritative copy always remains available to you directly in YNAB.
How we secure your data
- All data in transit is encrypted (TLS).
- Your YNAB OAuth tokens are encrypted at rest using application-level envelope encryption: each token is encrypted with its own key, which is itself protected by a master key held in a managed cloud key-management service. Your token is never stored, logged, or transmitted in plain text.
- We keep a strict allowlist of what’s permitted to reach our logs — identifiers, status values, timestamps, and counts. Transaction amounts, payee names, and category names are never logged, because they can reveal sensitive things about you (a payee on an inflow transaction can reveal your employer, benefits, or alimony) — this is enforced by our logging code, not just a policy we intend to follow.
- Database backups are also encrypted.
What happens when you delete your account
- Deleting your account queues a job that permanently removes your data — your Connection, Budget, Categories, Transactions, and every rating we’ve computed — within 30 days.
- Because we keep rolling backups for disaster recovery, a deleted account’s data may persist in an encrypted backup for up to an additional 7 days after that — up to 37 days total in the worst case — before every backup copy has aged out.
- We delete our own copy of your YNAB access token as part of this. We have no way to revoke the grant at YNAB’s end on your behalf — YNAB does not offer us that capability. If you also want to fully revoke Money on Rails’ access to your YNAB account, do so directly from your YNAB account settings under Authorized Applications.
- One narrow exception: two internal logs we use to track how well our AI classification is performing keep a record of a category name and the classification outcome, indefinitely. These records are never linked to your account, Budget, or identity in our database — they never were — so they survive account deletion the same way an anonymous statistic would. We don’t use them for anything beyond measuring and improving classification quality.
Data retention
| Data | Retention |
|---|---|
| Your account | For as long as your account exists, then purged per “What happens when you delete your account,” above |
| Your session (what keeps you logged in) | 30 days of inactivity, independent of your account |
| Your YNAB access token | For as long as your Connection is active; deleted immediately if YNAB tells us the grant was revoked or expired (it’s kept only while it’s still valid, even if you haven’t reconnected after your YNAB data plan or trial changed status) |
| Your synced Budget, Categories, and transactions | For as long as your account exists, deleted with it |
| Ratings and other computed data | For as long as your account exists, deleted with it |
| Classification quality logs (see above) | Indefinite, but never linked to you |
| If you contact us before having an account | Deleted 30 days after you’re admitted, or after 12 months if we don’t hear back |
Who can use Money on Rails
Money on Rails is currently invitation-only and restricted to users located in the United States. It is not directed at, and we do not knowingly collect data from, anyone under 13.
California residents
If you’re a California resident, this policy is our conspicuously posted privacy notice under the California Online Privacy Protection Act. Because Money on Rails is a small, invite-only product, we don’t believe the California Consumer Privacy Act’s thresholds apply to us today — but the rights described above are available to every user regardless.
Location of site and data
Money on Rails is operated from Mexico, and the servers that store and process your data are located in the United States. If in the future we serve users located outside the United States, we’ll update this section — and this policy — to describe how that data is protected in transit.
Changes to this policy
If we start collecting a new kind of data or using your data for a new purpose, we’ll update this policy and, where YNAB’s rules require it, ask for your renewed consent before doing so. We review this policy at least once every 6–12 months against YNAB’s own API Terms of Service and current law, whether or not anything else has changed.
Contact us
Questions, data requests, or a request to delete your account: privacy@moneyonrails.app