Privacy Policy

For the Unspending Spree app and the accounts you create in it

Last updated September 3, 2026

Effective Date: August 28, 2026


Introduction

Third Ralph, LLC, doing business as Unspending Spree ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our personal finance application and related services (collectively, the "Service").

This Policy applies to users located in the United States. The Service is not offered to residents of other countries.

We understand that you are trusting us with sensitive financial information. We take this responsibility seriously and have implemented strong security measures to protect your data.

Please read this Privacy Policy carefully. This Policy describes our practices; it is a notice, not a consent document. Where applicable law requires your separate affirmative consent for a particular use of your information, we will ask for it. If you do not agree with our policies and practices, please do not use the Service.


Table of Contents

  1. Information We Collect
  2. How We Use Your Information
  3. How We Share Your Information
  4. Third-Party Services
  5. Data Security
  6. Data Retention
  7. Your Privacy Rights
  8. State-Specific Privacy Rights
  9. United States Only
  10. Children's Privacy
  11. Changes to This Privacy Policy
  12. Contact Us

1. Information We Collect

1.1 Information You Provide Directly

Account Information:

  • Email address (required for account creation)
  • Display name (optional)
  • Password (stored securely by our authentication provider)

Household Information:

  • Household name
  • Member invitations and roles

Financial Account Information (Manual Entry):

  • Account names and nicknames
  • Account types (credit card, checking, savings, loan)
  • Last four digits of account numbers
  • Current balances, credit limits, interest rates
  • Due dates and payment amounts

Transaction Information (Manual Upload):

  • Transaction dates, descriptions, and amounts
  • Categories and notes you assign
  • Uploaded statement documents (PDFs, CSVs)

Billing Information:

  • Subscription plan, billing interval, and subscription status
  • Trial start and expiration dates and renewal dates
  • Invoices and transaction identifiers
  • Payment method type and last four digits
  • Billing contact information received from Stripe

We use the account email address to determine trial eligibility. Full payment-card numbers are provided directly to Stripe and are not stored by us.

User Preferences:

  • Notification settings
  • Display preferences
  • Calendar integration settings

1.2 Information Collected Automatically

Financial Data via Plaid: When you connect your bank accounts through Plaid, we receive:

  • Account information (account name, type, balances)
  • Transaction history (dates, amounts, merchant names, categories)
  • Account and routing numbers (masked, for identification only)

We do NOT receive or store your bank login credentials. Plaid handles authentication directly with your financial institution.

Technical Information:

  • IP address (for security and rate limiting)
  • Browser type and version
  • Device information
  • Access times and dates
  • Pages viewed within the Service

Authentication Data:

  • Login timestamps
  • Session information
  • Multi-factor authentication status

How You Found Us: When you create an account we record, once, where you came from, and we keep that record with your account:

  • The campaign labels on the link you followed to us (the utm_source, utm_medium, utm_campaign, utm_content, and utm_term values), if the link carried any
  • The website that referred you, and the first page you landed on
  • Whether you arrived with a referral code or an invitation code, or had joined the waitlist on our website (we check the email address you sign up with against the waitlist)
  • The date and time of that first arrival

Our signup pages hold these values in your browser's session storage for the duration of the visit and clear them once your account is created. If you accepted marketing cookies on our website, the website also holds them in a cookie named us_first_touch on the unspendingspree.com domain, and we read that cookie once, when you sign up. The Website Privacy Notice describes that cookie. For accounts created before this record existed, we filled it in from what we already held (the referral or invitation code used at signup, or the waitlist) and otherwise recorded the source as unknown.

AI-Generated Information: We process uploaded statements, transaction data, account information, user-selected settings, and related prompts through AI-assisted tools to extract data, classify transactions, identify recurring charges, and generate observations. The resulting classifications, patterns, and observations may constitute inferences about financial activity.

1.3 Information from Third-Party Services

Google Calendar (if connected):

  • Calendar ID for the calendar you select
  • We create calendar events on your behalf
  • We do NOT read your existing calendar events

Plaid:

  • Financial institution name
  • Account and transaction data (as described above)
  • Connection status and error information

1.4 Information We Do NOT Collect

We do NOT collect:

  • Your bank login credentials (Plaid handles this securely)
  • Social Security numbers
  • Government-issued ID numbers
  • Biometric data
  • Location data (GPS)
  • Contact lists or address books
  • Social media data
  • Health or medical information

2. How We Use Your Information

We use your information for the following purposes:

2.1 Providing the Service

  • Creating and managing your account
  • Displaying your financial accounts and transactions
  • Detecting recurring charges and subscriptions
  • Calculating debt payoff strategies
  • Generating financial analytics and insights, including through AI-assisted tools that extract data from statements, classify transactions, identify recurring charges, and generate observations
  • Sending bill reminders and calendar events (if enabled)

2.2 Improving the Service

  • Understanding how users interact with features
  • Identifying and fixing bugs and errors
  • Developing new features based on usage patterns
  • Improving transaction categorization accuracy
  • Measuring which campaigns, referrals, invitations, and the waitlist bring people to the Service, from the arrival record described in Section 1.2

2.3 Security and Fraud Prevention

  • Protecting against unauthorized access
  • Detecting and preventing fraudulent activity
  • Enforcing our Terms of Service
  • Investigating potential violations

2.4 Communication

  • Sending service-related notifications (password resets, security alerts)
  • Responding to your inquiries and support requests
  • Providing important updates about the Service
  • Complying with applicable laws and regulations
  • Responding to legal requests and legal process
  • Protecting our rights and the rights of others

3. How We Share Your Information

We are committed to keeping your financial data private. We share your information only in the following limited circumstances:

3.1 With Your Household Members

If you are part of a household, all household members can see all household financial data, including account balances, transactions, recurring charges, and debt payoff plans. There is no per-account or per-member visibility restriction within a household.

Consent mechanism. We obtain informed consent for household data sharing at three points:

  1. When an invitation is sent, the inviter is shown a data-sharing warning describing the scope of data the invitee will access.
  2. The invitation email includes a disclosure that accepting grants mutual access to financial data.
  3. Before accepting, the invitee must check a consent box affirming they understand all household members will see shared financial data.

When a member leaves. Financial data placed in a household is visible to all current household members. If you leave or are removed from a household, your access to that household's data is immediately revoked, and if you then delete your account, we delete your credentials and access rights. Shared records may remain where needed to maintain the remaining members' household history, but on a verified request we will delete or deidentify information uniquely attributable to you unless retention is permitted or required by law. Data you contributed (linked accounts, imported statements) is not transferred to you separately.

3.1.1 Accountability Partners

If you designate an accountability partner, we share only goal progress information with them (such as milestone celebrations, monthly progress summaries, and optional setback alerts). We do not share raw financial data (account balances, individual transactions, or account details) with accountability partners.

3.2 With Service Providers

We share information with third-party service providers who perform services on our behalf:

Provider Purpose Data Shared
Amazon Web Services (AWS) Cloud hosting, authentication, encryption All data (encrypted)
AWS Bedrock AI-assisted document extraction and financial-data observations Statement contents, transactions, related prompts, and generated outputs
Stripe Payment processing and subscription administration Billing contact information, subscription details, invoices, payment identifiers; payment-card information is submitted by you directly to Stripe
Plaid Bank account connectivity Your bank credentials go directly to Plaid and never to us; Plaid sends us account and transaction data
Google Calendar integration (optional) Calendar events we create
Loops Transactional and marketing email delivery Email address, name
Cloudflare Turnstile CAPTCHA/bot detection on signup IP address, browser/device signals

All service providers are contractually obligated to protect your information and use it only for the purposes we specify.

We may disclose your information if required by law or if we believe in good faith that such disclosure is necessary to:

  • Comply with legal obligations or legal process
  • Protect and defend our rights or property
  • Prevent fraud or illegal activity
  • Protect the safety of users or the public
  • Respond to government requests

3.4 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or control of your personal information.

We may share your information for other purposes with your explicit consent.

3.6 What We Do NOT Do

We do not sell personal data, use it for cross-context behavioral or targeted advertising, or profile users to make decisions producing legal or similarly significant effects. We process financial information only as reasonably necessary to provide, secure, support, and improve the Service. If these practices change, we will provide any required notice and opt-out or consent mechanism before the change.

We also do NOT:

  • Share your data with advertisers or data brokers
  • Allow third parties to use your data for their own marketing

4. Third-Party Services

4.1 Plaid

We use Plaid to connect your bank accounts. When you connect an account:

  • You are redirected to Plaid's secure interface
  • You enter your bank credentials directly with Plaid
  • Plaid authenticates with your bank and retrieves your data
  • Plaid sends us your account and transaction information
  • We never see or store your bank login credentials

Plaid's use of your information is governed by Plaid's Privacy Policy.

Your Rights with Plaid:

  • You can disconnect your bank at any time in the app
  • You can manage your Plaid connections at my.plaid.com
  • Disconnecting revokes our access to new data from that account

4.2 Amazon Web Services (AWS)

We use multiple AWS services to securely store and process your data:

Data Storage:

Service Purpose Data Stored
Aurora PostgreSQL Primary database Financial accounts, transactions, user profiles
DynamoDB Specialized storage Audit logs (3-year retention), encrypted tokens, invitations
S3 File storage Uploaded statement documents

Authentication & Security:

  • Cognito: User authentication, password management, MFA
  • KMS: Encryption key management for all sensitive data
  • Secrets Manager: Database credentials (internal use only)

Application Infrastructure:

  • Amplify Hosting: Serves the web application
  • Lambda: Serverless compute for processing tasks
  • CloudWatch: Application monitoring and logging (internal)

Email:

  • SES (Simple Email Service): Sends transactional emails (password resets, notifications, invitations)

Data Protection:

  • All data is encrypted at rest (AES-256) and in transit (TLS 1.2+)
  • All data is stored in US regions (us-east-1)
  • AWS does not access your data except as necessary to provide services or as required by law

For details on AWS's security practices, see AWS Data Privacy.

4.3 Google Calendar (Optional)

If you choose to connect Google Calendar:

  • We request permission to create and manage events in a calendar you select
  • We create reminder events for bills, due dates, and tasks
  • We do NOT read your existing calendar events
  • You can disconnect Google Calendar at any time

Google's use of your information is governed by Google's Privacy Policy.

4.4 AI Document Processing (AWS Bedrock)

When you upload financial statements or use AI features, we use Amazon Bedrock (AWS's AI service) with Claude AI models to extract transaction data and generate observations.

Data Handling:

Based on our configured AWS Bedrock service and applicable provider terms, prompts and outputs are not used to train the underlying foundation models and are not provided to model providers for model training. We configure logging and retention consistent with Section 6 and our internal data-retention controls. All data is encrypted in transit and during processing. These practices may change if our provider or configuration changes, in which case we will update this Policy before materially different processing begins.

Processing Flow:

  1. You upload a financial statement (PDF or image), or use an AI feature
  2. The content is sent securely to AWS Bedrock
  3. AI extracts transaction data or generates observations
  4. The results are returned to our application
  5. Original documents are retained per the schedule in Section 6 (Data Retention)

For more information, see AWS Bedrock Data Protection

4.5 Stripe (Payments)

We use Stripe, Inc. to process subscription payments. When you subscribe:

  • You provide your card details directly to Stripe; we never receive or store your full card number
  • From Stripe we receive what we need to operate your subscription: your plan, subscription status, trial and renewal dates, invoices, transaction identifiers, payment method type and last four digits, and billing contact information
  • The billing portal in Settings is operated by Stripe

Stripe's use of your information is governed by Stripe's Privacy Policy.


5. Data Security

We implement robust security measures to protect your financial data:

5.1 Encryption

  • In Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher
  • At Rest: Sensitive data (including Plaid tokens and Google tokens) is encrypted using AES-256-GCM encryption
  • Key Management: Encryption keys are managed using AWS Key Management Service (KMS)

5.2 Authentication

  • Passwords are never stored in plain text
  • Multi-factor authentication (MFA) is available for all accounts
  • Sessions expire after periods of inactivity
  • JWT tokens are used with short expiration times

5.3 Access Control

  • Role-based access control limits what household members can see and do
  • Administrative access to systems requires MFA
  • Access to production systems is strictly limited and logged

5.4 Infrastructure Security

  • Hosted on AWS with enterprise-grade security controls
  • Regular security assessments and vulnerability scanning
  • Automated monitoring for suspicious activity
  • Rate limiting to prevent abuse

5.5 Data Isolation

  • Your data is isolated from other users at the database level
  • Each household's data is completely separate
  • No user can access another user's data through the application

5.6 Incident Response

If a security incident affects personal information, we will investigate, mitigate harm, and provide notices to affected individuals and government authorities within the time and in the manner required by applicable law. Because notification periods differ by jurisdiction and circumstances, this Policy does not promise a universal deadline.


6. Data Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Privacy Policy. The schedule below states our retention commitments to you, subject to the legal-hold, backup, and legally required retention exceptions described below. We maintain an internal Data Retention Policy governing implementation of these commitments.

Data Type Retention Period Reason
Account information While account is active + 30 days Service provision
Arrival record (how you found us) Same as account information; deleted with the account Measuring how people find the Service
Financial transactions and account records While account is active, then deleted under the account-deletion or lapsed-household schedule Service provision and user-directed history
Subscription and billing records Subscription term plus the period reasonably necessary for accounting, tax, chargeback, fraud-prevention, and dispute-resolution purposes Billing, accounting, tax, fraud prevention, disputes
Plaid connection tokens While connected + 30 days Service provision
Uploaded statement files 7 days after processing Extraction verification
Extracted processing files 7 days after processing Extraction verification
Operator review copies Up to 90 days Quality review
Data exports 1 day Delivery window
Audit and security logs 3 years Security and compliance
Application logs 30 days Debugging and security

Records you permanently delete in the app are hidden immediately and purged from active systems within 45 days.

Information you gave our website before signing up (the waitlist, survey, and feature-request forms) is covered by the Website Privacy Notice, which keeps it for two years from when you submitted it.

Account Deletion:

  • You can request deletion of your account at any time
  • After a 30-day grace period (to allow recovery), your data is permanently deleted
  • A verified statutory deletion request is not delayed by the grace period beyond what applicable law allows
  • Some data may be retained longer if required by law

Lapsed Households:

Data for a lapsed household, meaning one with no active paid subscription, is retained for one year after paid access ends and is then permanently deleted. We email the household owner 30 days before deletion and again 7 days before it. Full access can be restored at any time before deletion by resuming a paid subscription.

Backups and Legal Holds:

Deleted information may remain temporarily in encrypted, access-restricted backups until those backups are overwritten through their ordinary rotation. Legal holds and applicable law may require us to retain limited information longer than the periods stated above.


7. Your Privacy Rights

Depending on your location, you may have some or all of the following rights:

7.1 Right to Access

You can request a copy of the personal information we hold about you. We will provide this information in a portable format (JSON) within 30 days.

7.2 Right to Correction

You can request that we correct inaccurate personal information. Most information can be corrected directly in the app.

7.3 Right to Deletion

You can request that we delete your personal information. We will delete your data within 30 days, except where retention is required by law.

7.4 Right to Data Portability

You can request your data in a machine-readable format to transfer to another service.

7.5 Right to Opt-Out

You can opt out of:

  • Non-essential communications (via account settings)
  • Google Calendar integration (by disconnecting)
  • Plaid bank connections (by disconnecting)

7.6 Right to Non-Discrimination

We will not discriminate against you for exercising your privacy rights.

7.7 How to Exercise Your Rights

To exercise any of these rights:

  • In the app: Use the Settings > Privacy section
  • By email: Contact privacy@unspendingspree.com
  • By mail: 5900 Balcones Drive #8371, Austin, TX 78731, US

We will verify requests and respond within the period required by applicable law (and in any case aim for 30 days). Authorized agents may submit requests on your behalf where permitted by law.

Appeals. Where applicable law provides an appeal right, you may appeal a denied request by replying to the decision or emailing privacy@unspendingspree.com with "Privacy Appeal" in the subject line. We will respond to appeals within the period required by applicable law.


8. State-Specific Privacy Rights

8.1 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Categories of Personal Information Collected:

  • Identifiers (email address, IP address)
  • Financial information (account balances, transactions)
  • Internet activity (pages viewed, features used)
  • Inferences (spending patterns, subscription detection)

Your California Rights:

  • Right to know what personal information we collect, use, and disclose
  • Right to delete your personal information
  • Right to correct inaccurate personal information
  • Right to opt-out of the sale or sharing of personal information
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising your rights

We Do Not Sell Your Personal Information. We have not sold personal information in the preceding 12 months and do not intend to sell personal information.

Sensitive Personal Information: We collect financial information, which is considered sensitive under CPRA. We use this information only to provide the Service and do not use it for profiling or advertising.

Shine the Light: California residents may request information about disclosure of personal information to third parties for direct marketing. We do not disclose personal information for third-party direct marketing.

To exercise your California privacy rights, contact us at privacy@unspendingspree.com or use the [Do Not Sell or Share My Personal Information] link (when applicable).

8.2 Virginia Residents (VCDPA)

If you are a Virginia resident, you have rights under the Virginia Consumer Data Protection Act:

  • Right to access your personal data
  • Right to correct inaccuracies
  • Right to delete your personal data
  • Right to data portability
  • Right to opt out of targeted advertising, sale of data, or profiling

We do not engage in targeted advertising, sale of data, or profiling for decisions with legal effects.

8.3 Colorado Residents (CPA)

If you are a Colorado resident, you have rights under the Colorado Privacy Act similar to those described for Virginia residents. You also have the right to opt out of the processing of your personal data for targeted advertising, sale, or profiling.

8.4 Connecticut Residents (CTDPA)

If you are a Connecticut resident, you have rights under the Connecticut Data Privacy Act similar to those described for Virginia residents.

8.5 Utah Residents (UCPA)

If you are a Utah resident, you have rights under the Utah Consumer Privacy Act, including rights to access, delete, and port your data, and to opt out of sale of personal data or targeted advertising.

8.6 Texas Residents (TDPSA)

If you are a Texas resident, you have rights under the Texas Data Privacy and Security Act effective July 1, 2024, including rights to access, correct, delete, and port your data.

8.7 Oregon Residents (OCPA)

If you are an Oregon resident, you have rights under the Oregon Consumer Privacy Act effective July 1, 2024, including rights to access, correct, delete, and port your data.

8.8 Other States

Privacy laws are evolving rapidly. If you reside in a state with consumer privacy laws not listed above, please contact us to learn about your rights.


9. United States Only

The Service is offered to users located in the United States and is not offered to residents of other countries. Your information is stored and processed in the United States. If you access the Service from outside the United States, you do so at your own risk, and your information will be transferred to and processed in the United States, where data protection laws may differ from those of your country.


10. Children's Privacy

The Service is not intended for children under 18 years of age.

We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@unspendingspree.com.

If we learn that we have collected personal information from a child under 18, we will delete that information as quickly as possible.


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes:

  • We will update the "Last Updated" date at the top of this policy
  • For material changes, we will notify you by email and/or prominent notice in the app before the change takes effect
  • Where applicable law requires your consent for a materially different use of your information, we will obtain it before that use begins

We encourage you to review this Privacy Policy periodically.

Previous versions of this Privacy Policy are available upon request.


12. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Email: privacy@unspendingspree.com

Mail: Third Ralph, LLC dba Unspending Spree 5900 Balcones Drive #8371, Austin, TX 78731, US

Response Time: We aim to respond to all privacy inquiries within 30 days.

For California Residents: You may also contact the California Attorney General at oag.ca.gov if you believe your rights have been violated.


Summary of Key Points

Topic Summary
Data Collection We collect account info, financial and billing data (via Plaid, Stripe, or uploads), usage data, and a record of how you found us
Data Use To provide the Service, improve features, ensure security; AI tools process financial data to extract, classify, and observe
Data Sharing Only with service providers (AWS, including Bedrock, Plaid, Stripe, Google, Loops); never sold
Security AES-256 encryption, MFA, role-based access, AWS hosting
Retention Financial data: while account is active, then per the deletion schedules; statement files: 7 days after processing
Your Rights Access, correct, delete, port your data; appeal a denial; opt out of integrations
Children Not for users under 18

This Privacy Policy is effective as of August 28, 2026.


Document Control:

  • Document ID: PP-001
  • Version: 2.2 (reviewed by outside counsel August 28, 2026; Section 6 retention references reviewed September 1, 2026; arrival record added to Sections 1.2, 2.2, and 6 on September 3, 2026)
  • Classification: Public
  • Legal Entity: Third Ralph, LLC dba Unspending Spree
  • Owner: Corey Suzanne Jackson, CEO
  • Review Schedule: Annual or upon material changes