Money on Rails

Privacy Policy

Last updated: [date of first publication]

The privacy of your data — and it is your data, not ours — matters to us. This policy explains what we collect, why, how it’s handled, and your rights. We never sell your data.

Money on Rails is operated by [Legal Name / Entity — TBD before legal review], a solo-developer product based in Nuevo León, Mexico. It is a third-party analytics tool that connects to your YNAB budget via YNAB’s own API. Money on Rails is not affiliated, associated, or in any way officially connected with YNAB or any of its subsidiaries or affiliates.

What we collect and why

We collectWhy
Your YNAB account identifier (an opaque ID YNAB gives us — YNAB never shares your email or name with us) To recognize you as a returning User and enforce the invite gate
A YNAB OAuth access/refresh token pair To read your Budget data on your behalf, for as long as your Connection stays active
Your Budget’s Categories, Category Groups, and monthly budgeted/activity/balance figures To compute your Adherence Rating, Category Adherence, and Budget Quality Rating
Your Budget’s inflow transactions only (date, amount, payee, category) To group payees into Income Sources and attribute income in the app’s cash-flow view. We do not sync outflow transactions, and no view in the product drills below a category’s monthly total.
Category names (never amounts, payees, or account/user identity) Sent to our AI classification provider once per Budget, to suggest a Needs/Wants/ Savings bucket and a true-expense grouping for each category. You can always correct a suggestion.
If you contact us to request an invite before you have an account To evaluate and respond to your request

We collect the minimum YNAB permissions necessary to do this and nothing beyond it.

When we access or disclose your information

We use a small number of subprocessors to run the service, and we don’t sell or rent your data to anyone:

No human on our side looks at your budget data except as strictly necessary to fix a bug you’ve reported or investigate abuse, and never your transaction-level detail without cause. We do not respond to government requests for your data unless legally compelled to.

Your rights with respect to your information

You can, at any time:

How we secure your data

What happens when you delete your account

Data retention

DataRetention
Your accountFor as long as your account exists, then purged per “What happens when you delete your account,” above
Your session (what keeps you logged in)30 days of inactivity, independent of your account
Your YNAB access tokenFor as long as your Connection is active; deleted immediately if YNAB tells us the grant was revoked or expired (it’s kept only while it’s still valid, even if you haven’t reconnected after your YNAB data plan or trial changed status)
Your synced Budget, Categories, and transactionsFor as long as your account exists, deleted with it
Ratings and other computed dataFor as long as your account exists, deleted with it
Classification quality logs (see above)Indefinite, but never linked to you
If you contact us before having an accountDeleted 30 days after you’re admitted, or after 12 months if we don’t hear back

Who can use Money on Rails

Money on Rails is currently invitation-only and restricted to users located in the United States. It is not directed at, and we do not knowingly collect data from, anyone under 13.

California residents

If you’re a California resident, this policy is our conspicuously posted privacy notice under the California Online Privacy Protection Act. Because Money on Rails is a small, invite-only product, we don’t believe the California Consumer Privacy Act’s thresholds apply to us today — but the rights described above are available to every user regardless.

Location of site and data

Money on Rails is operated from Mexico, and the servers that store and process your data are located in the United States. If in the future we serve users located outside the United States, we’ll update this section — and this policy — to describe how that data is protected in transit.

Changes to this policy

If we start collecting a new kind of data or using your data for a new purpose, we’ll update this policy and, where YNAB’s rules require it, ask for your renewed consent before doing so. We review this policy at least once every 6–12 months against YNAB’s own API Terms of Service and current law, whether or not anything else has changed.

Contact us

Questions, data requests, or a request to delete your account: privacy@moneyonrails.app