Effective Date: August 28, 2026
Introduction
Third Ralph, LLC, doing business as Unspending Spree ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our personal finance application and related services (collectively, the "Service").
This Policy applies to users located in the United States. The Service is not offered to residents of other countries.
We understand that you are trusting us with sensitive financial information. We take this responsibility seriously and have implemented strong security measures to protect your data.
Please read this Privacy Policy carefully. This Policy describes our practices; it is a notice, not a consent document. Where applicable law requires your separate affirmative consent for a particular use of your information, we will ask for it. If you do not agree with our policies and practices, please do not use the Service.
Table of Contents
- Information We Collect
- How We Use Your Information
- How We Share Your Information
- Third-Party Services
- Data Security
- Data Retention
- Your Privacy Rights
- State-Specific Privacy Rights
- United States Only
- Children's Privacy
- Changes to This Privacy Policy
- Contact Us
1. Information We Collect
1.1 Information You Provide Directly
Account Information:
- Email address (required for account creation)
- Display name (optional)
- Password (stored securely by our authentication provider)
Household Information:
- Household name
- Member invitations and roles
Financial Account Information (Manual Entry):
- Account names and nicknames
- Account types (credit card, checking, savings, loan)
- Last four digits of account numbers
- Current balances, credit limits, interest rates
- Due dates and payment amounts
Transaction Information (Manual Upload):
- Transaction dates, descriptions, and amounts
- Categories and notes you assign
- Uploaded statement documents (PDFs, CSVs)
Billing Information:
- Subscription plan, billing interval, and subscription status
- Trial start and expiration dates and renewal dates
- Invoices and transaction identifiers
- Payment method type and last four digits
- Billing contact information received from Stripe
We use the account email address to determine trial eligibility. Full payment-card numbers are provided directly to Stripe and are not stored by us.
User Preferences:
- Notification settings
- Display preferences
- Calendar integration settings
1.2 Information Collected Automatically
Financial Data via Plaid: When you connect your bank accounts through Plaid, we receive:
- Account information (account name, type, balances)
- Transaction history (dates, amounts, merchant names, categories)
- Account and routing numbers (masked, for identification only)
We do NOT receive or store your bank login credentials. Plaid handles authentication directly with your financial institution.
Technical Information:
- IP address (for security and rate limiting)
- Browser type and version
- Device information
- Access times and dates
- Pages viewed within the Service
Authentication Data:
- Login timestamps
- Session information
- Multi-factor authentication status
How You Found Us: When you create an account we record, once, where you came from, and we keep that record with your account:
- The campaign labels on the link you followed to us (the
utm_source,utm_medium,utm_campaign,utm_content, andutm_termvalues), if the link carried any - The website that referred you, and the first page you landed on
- Whether you arrived with a referral code or an invitation code, or had joined the waitlist on our website (we check the email address you sign up with against the waitlist)
- The date and time of that first arrival
Our signup pages hold these values in your browser's session storage for the duration of the visit and clear them once your account is created. If you accepted marketing cookies on our website, the website also holds them in a cookie named us_first_touch on the unspendingspree.com domain, and we read that cookie once, when you sign up. The Website Privacy Notice describes that cookie. For accounts created before this record existed, we filled it in from what we already held (the referral or invitation code used at signup, or the waitlist) and otherwise recorded the source as unknown.
AI-Generated Information: We process uploaded statements, transaction data, account information, user-selected settings, and related prompts through AI-assisted tools to extract data, classify transactions, identify recurring charges, and generate observations. The resulting classifications, patterns, and observations may constitute inferences about financial activity.
1.3 Information from Third-Party Services
Google Calendar (if connected):
- Calendar ID for the calendar you select
- We create calendar events on your behalf
- We do NOT read your existing calendar events
Plaid:
- Financial institution name
- Account and transaction data (as described above)
- Connection status and error information
1.4 Information We Do NOT Collect
We do NOT collect:
- Your bank login credentials (Plaid handles this securely)
- Social Security numbers
- Government-issued ID numbers
- Biometric data
- Location data (GPS)
- Contact lists or address books
- Social media data
- Health or medical information
2. How We Use Your Information
We use your information for the following purposes:
2.1 Providing the Service
- Creating and managing your account
- Displaying your financial accounts and transactions
- Detecting recurring charges and subscriptions
- Calculating debt payoff strategies
- Generating financial analytics and insights, including through AI-assisted tools that extract data from statements, classify transactions, identify recurring charges, and generate observations
- Sending bill reminders and calendar events (if enabled)
2.2 Improving the Service
- Understanding how users interact with features
- Identifying and fixing bugs and errors
- Developing new features based on usage patterns
- Improving transaction categorization accuracy
- Measuring which campaigns, referrals, invitations, and the waitlist bring people to the Service, from the arrival record described in Section 1.2
2.3 Security and Fraud Prevention
- Protecting against unauthorized access
- Detecting and preventing fraudulent activity
- Enforcing our Terms of Service
- Investigating potential violations
2.4 Communication
- Sending service-related notifications (password resets, security alerts)
- Responding to your inquiries and support requests
- Providing important updates about the Service
2.5 Legal Compliance
- Complying with applicable laws and regulations
- Responding to legal requests and legal process
- Protecting our rights and the rights of others
3. How We Share Your Information
We are committed to keeping your financial data private. We share your information only in the following limited circumstances:
3.1 With Your Household Members
If you are part of a household, all household members can see all household financial data, including account balances, transactions, recurring charges, and debt payoff plans. There is no per-account or per-member visibility restriction within a household.
Consent mechanism. We obtain informed consent for household data sharing at three points:
- When an invitation is sent, the inviter is shown a data-sharing warning describing the scope of data the invitee will access.
- The invitation email includes a disclosure that accepting grants mutual access to financial data.
- Before accepting, the invitee must check a consent box affirming they understand all household members will see shared financial data.
When a member leaves. Financial data placed in a household is visible to all current household members. If you leave or are removed from a household, your access to that household's data is immediately revoked, and if you then delete your account, we delete your credentials and access rights. Shared records may remain where needed to maintain the remaining members' household history, but on a verified request we will delete or deidentify information uniquely attributable to you unless retention is permitted or required by law. Data you contributed (linked accounts, imported statements) is not transferred to you separately.
3.1.1 Accountability Partners
If you designate an accountability partner, we share only goal progress information with them (such as milestone celebrations, monthly progress summaries, and optional setback alerts). We do not share raw financial data (account balances, individual transactions, or account details) with accountability partners.
3.2 With Service Providers
We share information with third-party service providers who perform services on our behalf:
| Provider | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, authentication, encryption | All data (encrypted) |
| AWS Bedrock | AI-assisted document extraction and financial-data observations | Statement contents, transactions, related prompts, and generated outputs |
| Stripe | Payment processing and subscription administration | Billing contact information, subscription details, invoices, payment identifiers; payment-card information is submitted by you directly to Stripe |
| Plaid | Bank account connectivity | Your bank credentials go directly to Plaid and never to us; Plaid sends us account and transaction data |
| Calendar integration (optional) | Calendar events we create | |
| Loops | Transactional and marketing email delivery | Email address, name |
| Cloudflare Turnstile | CAPTCHA/bot detection on signup | IP address, browser/device signals |
All service providers are contractually obligated to protect your information and use it only for the purposes we specify.
3.3 For Legal Reasons
We may disclose your information if required by law or if we believe in good faith that such disclosure is necessary to:
- Comply with legal obligations or legal process
- Protect and defend our rights or property
- Prevent fraud or illegal activity
- Protect the safety of users or the public
- Respond to government requests
3.4 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or control of your personal information.
3.5 With Your Consent
We may share your information for other purposes with your explicit consent.
3.6 What We Do NOT Do
We do not sell personal data, use it for cross-context behavioral or targeted advertising, or profile users to make decisions producing legal or similarly significant effects. We process financial information only as reasonably necessary to provide, secure, support, and improve the Service. If these practices change, we will provide any required notice and opt-out or consent mechanism before the change.
We also do NOT:
- Share your data with advertisers or data brokers
- Allow third parties to use your data for their own marketing
4. Third-Party Services
4.1 Plaid
We use Plaid to connect your bank accounts. When you connect an account:
- You are redirected to Plaid's secure interface
- You enter your bank credentials directly with Plaid
- Plaid authenticates with your bank and retrieves your data
- Plaid sends us your account and transaction information
- We never see or store your bank login credentials
Plaid's use of your information is governed by Plaid's Privacy Policy.
Your Rights with Plaid:
- You can disconnect your bank at any time in the app
- You can manage your Plaid connections at my.plaid.com
- Disconnecting revokes our access to new data from that account
4.2 Amazon Web Services (AWS)
We use multiple AWS services to securely store and process your data:
Data Storage:
| Service | Purpose | Data Stored |
|---|---|---|
| Aurora PostgreSQL | Primary database | Financial accounts, transactions, user profiles |
| DynamoDB | Specialized storage | Audit logs (3-year retention), encrypted tokens, invitations |
| S3 | File storage | Uploaded statement documents |
Authentication & Security:
- Cognito: User authentication, password management, MFA
- KMS: Encryption key management for all sensitive data
- Secrets Manager: Database credentials (internal use only)
Application Infrastructure:
- Amplify Hosting: Serves the web application
- Lambda: Serverless compute for processing tasks
- CloudWatch: Application monitoring and logging (internal)
Email:
- SES (Simple Email Service): Sends transactional emails (password resets, notifications, invitations)
Data Protection:
- All data is encrypted at rest (AES-256) and in transit (TLS 1.2+)
- All data is stored in US regions (us-east-1)
- AWS does not access your data except as necessary to provide services or as required by law
For details on AWS's security practices, see AWS Data Privacy.
4.3 Google Calendar (Optional)
If you choose to connect Google Calendar:
- We request permission to create and manage events in a calendar you select
- We create reminder events for bills, due dates, and tasks
- We do NOT read your existing calendar events
- You can disconnect Google Calendar at any time
Google's use of your information is governed by Google's Privacy Policy.
4.4 AI Document Processing (AWS Bedrock)
When you upload financial statements or use AI features, we use Amazon Bedrock (AWS's AI service) with Claude AI models to extract transaction data and generate observations.
Data Handling:
Based on our configured AWS Bedrock service and applicable provider terms, prompts and outputs are not used to train the underlying foundation models and are not provided to model providers for model training. We configure logging and retention consistent with Section 6 and our internal data-retention controls. All data is encrypted in transit and during processing. These practices may change if our provider or configuration changes, in which case we will update this Policy before materially different processing begins.
Processing Flow:
- You upload a financial statement (PDF or image), or use an AI feature
- The content is sent securely to AWS Bedrock
- AI extracts transaction data or generates observations
- The results are returned to our application
- Original documents are retained per the schedule in Section 6 (Data Retention)
For more information, see AWS Bedrock Data Protection
4.5 Stripe (Payments)
We use Stripe, Inc. to process subscription payments. When you subscribe:
- You provide your card details directly to Stripe; we never receive or store your full card number
- From Stripe we receive what we need to operate your subscription: your plan, subscription status, trial and renewal dates, invoices, transaction identifiers, payment method type and last four digits, and billing contact information
- The billing portal in Settings is operated by Stripe
Stripe's use of your information is governed by Stripe's Privacy Policy.
5. Data Security
We implement robust security measures to protect your financial data:
5.1 Encryption
- In Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher
- At Rest: Sensitive data (including Plaid tokens and Google tokens) is encrypted using AES-256-GCM encryption
- Key Management: Encryption keys are managed using AWS Key Management Service (KMS)
5.2 Authentication
- Passwords are never stored in plain text
- Multi-factor authentication (MFA) is available for all accounts
- Sessions expire after periods of inactivity
- JWT tokens are used with short expiration times
5.3 Access Control
- Role-based access control limits what household members can see and do
- Administrative access to systems requires MFA
- Access to production systems is strictly limited and logged
5.4 Infrastructure Security
- Hosted on AWS with enterprise-grade security controls
- Regular security assessments and vulnerability scanning
- Automated monitoring for suspicious activity
- Rate limiting to prevent abuse
5.5 Data Isolation
- Your data is isolated from other users at the database level
- Each household's data is completely separate
- No user can access another user's data through the application
5.6 Incident Response
If a security incident affects personal information, we will investigate, mitigate harm, and provide notices to affected individuals and government authorities within the time and in the manner required by applicable law. Because notification periods differ by jurisdiction and circumstances, this Policy does not promise a universal deadline.
6. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Privacy Policy. The schedule below states our retention commitments to you, subject to the legal-hold, backup, and legally required retention exceptions described below. We maintain an internal Data Retention Policy governing implementation of these commitments.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information | While account is active + 30 days | Service provision |
| Arrival record (how you found us) | Same as account information; deleted with the account | Measuring how people find the Service |
| Financial transactions and account records | While account is active, then deleted under the account-deletion or lapsed-household schedule | Service provision and user-directed history |
| Subscription and billing records | Subscription term plus the period reasonably necessary for accounting, tax, chargeback, fraud-prevention, and dispute-resolution purposes | Billing, accounting, tax, fraud prevention, disputes |
| Plaid connection tokens | While connected + 30 days | Service provision |
| Uploaded statement files | 7 days after processing | Extraction verification |
| Extracted processing files | 7 days after processing | Extraction verification |
| Operator review copies | Up to 90 days | Quality review |
| Data exports | 1 day | Delivery window |
| Audit and security logs | 3 years | Security and compliance |
| Application logs | 30 days | Debugging and security |
Records you permanently delete in the app are hidden immediately and purged from active systems within 45 days.
Information you gave our website before signing up (the waitlist, survey, and feature-request forms) is covered by the Website Privacy Notice, which keeps it for two years from when you submitted it.
Account Deletion:
- You can request deletion of your account at any time
- After a 30-day grace period (to allow recovery), your data is permanently deleted
- A verified statutory deletion request is not delayed by the grace period beyond what applicable law allows
- Some data may be retained longer if required by law
Lapsed Households:
Data for a lapsed household, meaning one with no active paid subscription, is retained for one year after paid access ends and is then permanently deleted. We email the household owner 30 days before deletion and again 7 days before it. Full access can be restored at any time before deletion by resuming a paid subscription.
Backups and Legal Holds:
Deleted information may remain temporarily in encrypted, access-restricted backups until those backups are overwritten through their ordinary rotation. Legal holds and applicable law may require us to retain limited information longer than the periods stated above.
7. Your Privacy Rights
Depending on your location, you may have some or all of the following rights:
7.1 Right to Access
You can request a copy of the personal information we hold about you. We will provide this information in a portable format (JSON) within 30 days.
7.2 Right to Correction
You can request that we correct inaccurate personal information. Most information can be corrected directly in the app.
7.3 Right to Deletion
You can request that we delete your personal information. We will delete your data within 30 days, except where retention is required by law.
7.4 Right to Data Portability
You can request your data in a machine-readable format to transfer to another service.
7.5 Right to Opt-Out
You can opt out of:
- Non-essential communications (via account settings)
- Google Calendar integration (by disconnecting)
- Plaid bank connections (by disconnecting)
7.6 Right to Non-Discrimination
We will not discriminate against you for exercising your privacy rights.
7.7 How to Exercise Your Rights
To exercise any of these rights:
- In the app: Use the Settings > Privacy section
- By email: Contact privacy@unspendingspree.com
- By mail: 5900 Balcones Drive #8371, Austin, TX 78731, US
We will verify requests and respond within the period required by applicable law (and in any case aim for 30 days). Authorized agents may submit requests on your behalf where permitted by law.
Appeals. Where applicable law provides an appeal right, you may appeal a denied request by replying to the decision or emailing privacy@unspendingspree.com with "Privacy Appeal" in the subject line. We will respond to appeals within the period required by applicable law.
8. State-Specific Privacy Rights
8.1 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Categories of Personal Information Collected:
- Identifiers (email address, IP address)
- Financial information (account balances, transactions)
- Internet activity (pages viewed, features used)
- Inferences (spending patterns, subscription detection)
Your California Rights:
- Right to know what personal information we collect, use, and disclose
- Right to delete your personal information
- Right to correct inaccurate personal information
- Right to opt-out of the sale or sharing of personal information
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your rights
We Do Not Sell Your Personal Information. We have not sold personal information in the preceding 12 months and do not intend to sell personal information.
Sensitive Personal Information: We collect financial information, which is considered sensitive under CPRA. We use this information only to provide the Service and do not use it for profiling or advertising.
Shine the Light: California residents may request information about disclosure of personal information to third parties for direct marketing. We do not disclose personal information for third-party direct marketing.
To exercise your California privacy rights, contact us at privacy@unspendingspree.com or use the [Do Not Sell or Share My Personal Information] link (when applicable).
8.2 Virginia Residents (VCDPA)
If you are a Virginia resident, you have rights under the Virginia Consumer Data Protection Act:
- Right to access your personal data
- Right to correct inaccuracies
- Right to delete your personal data
- Right to data portability
- Right to opt out of targeted advertising, sale of data, or profiling
We do not engage in targeted advertising, sale of data, or profiling for decisions with legal effects.
8.3 Colorado Residents (CPA)
If you are a Colorado resident, you have rights under the Colorado Privacy Act similar to those described for Virginia residents. You also have the right to opt out of the processing of your personal data for targeted advertising, sale, or profiling.
8.4 Connecticut Residents (CTDPA)
If you are a Connecticut resident, you have rights under the Connecticut Data Privacy Act similar to those described for Virginia residents.
8.5 Utah Residents (UCPA)
If you are a Utah resident, you have rights under the Utah Consumer Privacy Act, including rights to access, delete, and port your data, and to opt out of sale of personal data or targeted advertising.
8.6 Texas Residents (TDPSA)
If you are a Texas resident, you have rights under the Texas Data Privacy and Security Act effective July 1, 2024, including rights to access, correct, delete, and port your data.
8.7 Oregon Residents (OCPA)
If you are an Oregon resident, you have rights under the Oregon Consumer Privacy Act effective July 1, 2024, including rights to access, correct, delete, and port your data.
8.8 Other States
Privacy laws are evolving rapidly. If you reside in a state with consumer privacy laws not listed above, please contact us to learn about your rights.
9. United States Only
The Service is offered to users located in the United States and is not offered to residents of other countries. Your information is stored and processed in the United States. If you access the Service from outside the United States, you do so at your own risk, and your information will be transferred to and processed in the United States, where data protection laws may differ from those of your country.
10. Children's Privacy
The Service is not intended for children under 18 years of age.
We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@unspendingspree.com.
If we learn that we have collected personal information from a child under 18, we will delete that information as quickly as possible.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Last Updated" date at the top of this policy
- For material changes, we will notify you by email and/or prominent notice in the app before the change takes effect
- Where applicable law requires your consent for a materially different use of your information, we will obtain it before that use begins
We encourage you to review this Privacy Policy periodically.
Previous versions of this Privacy Policy are available upon request.
12. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Email: privacy@unspendingspree.com
Mail: Third Ralph, LLC dba Unspending Spree 5900 Balcones Drive #8371, Austin, TX 78731, US
Response Time: We aim to respond to all privacy inquiries within 30 days.
For California Residents: You may also contact the California Attorney General at oag.ca.gov if you believe your rights have been violated.
Summary of Key Points
| Topic | Summary |
|---|---|
| Data Collection | We collect account info, financial and billing data (via Plaid, Stripe, or uploads), usage data, and a record of how you found us |
| Data Use | To provide the Service, improve features, ensure security; AI tools process financial data to extract, classify, and observe |
| Data Sharing | Only with service providers (AWS, including Bedrock, Plaid, Stripe, Google, Loops); never sold |
| Security | AES-256 encryption, MFA, role-based access, AWS hosting |
| Retention | Financial data: while account is active, then per the deletion schedules; statement files: 7 days after processing |
| Your Rights | Access, correct, delete, port your data; appeal a denial; opt out of integrations |
| Children | Not for users under 18 |
This Privacy Policy is effective as of August 28, 2026.
Document Control:
- Document ID: PP-001
- Version: 2.2 (reviewed by outside counsel August 28, 2026; Section 6 retention references reviewed September 1, 2026; arrival record added to Sections 1.2, 2.2, and 6 on September 3, 2026)
- Classification: Public
- Legal Entity: Third Ralph, LLC dba Unspending Spree
- Owner: Corey Suzanne Jackson, CEO
- Review Schedule: Annual or upon material changes