Paycheck to paycheck

Privacy Policy

This policy describes how Paycheck to Paycheck (“we”, “us”) handles information when you use our household budgeting service.

What we collect

  • Account information — name, email address, and password (stored hashed).
  • Optional security information — phone number if you enable SMS two-factor authentication; authenticator app secrets if you enable TOTP.
  • Household financial information you enter — account balances, bills, income schedules, transactions, giving records, and related notes or amounts.
  • Bank data you connect — if you link an account through Plaid, we receive account identifiers, balances, and transaction details Plaid provides for that connection (including merchant and category metadata when available).
  • Billing information — subscription and trial status, plan choice, and Stripe customer or subscription identifiers needed to bill the household. Payment card details are collected and processed by Stripe; we do not store full card numbers on our servers.
  • Technical information — session cookies, IP address, and standard server logs needed to operate and secure the service.

How we use information

  • Provide and maintain the service, including safe-to-use calculations and household sharing.
  • Authenticate you and protect your account, including optional two-factor authentication.
  • Sync linked bank accounts and transactions when you choose to connect Plaid.
  • Process subscriptions, trials, invoices, and payment-method updates through Stripe.
  • Respond to support requests and fix problems.
  • Comply with law and enforce our Terms of Service.

We do not sell your personal information.

SMS two-factor authentication

If you choose SMS two-factor authentication, you provide your mobile phone number so we can send you one-time passcodes to verify your identity when you log in or confirm security settings.

  • We send SMS messages only for authentication and account security—not for marketing or promotional purposes.
  • Message frequency varies based on how often you log in, enable or confirm SMS 2FA, or request a new code. Typically this is a small number of messages per month.
  • Your phone number is shared with our SMS provider, Twilio, solely to deliver these verification messages.
  • We do not sell your phone number to third parties for their marketing.

You can stop receiving SMS verification codes at any time by disabling SMS two-factor authentication in Profile → Two-factor authentication. Disabling SMS 2FA does not delete your account, but you may need another sign-in method if SMS was your only two-factor option.

Message and data rates may apply. Contact your mobile carrier for details about your plan.

Who can see your data

Paycheck to Paycheck is built for shared household use. Other members of your household can see the financial information stored for that household. Do not invite people you do not trust with this information.

Billing is managed at the household level. Members with access to Billing can manage the subscription for the whole household.

We do not make your household data public.

Service providers

We use trusted providers to run parts of the service. They process data only as needed to provide their function:

  • Plaid — bank account linking and transaction sync, if you connect an account.
  • Stripe — subscription billing, trials, invoices, and payment processing.
  • Twilio — SMS one-time passcodes, if you enable SMS two-factor authentication.
  • Google Ads — advertising measurement, including conversion tracking, when you visit from an ad or use the public site. Google may set cookies; see Google’s privacy policy.
  • Hosting and infrastructure — application hosting, database, and related operations (for example Laravel Cloud).

Each provider has its own privacy practices. Connecting a bank account, starting a paid plan or trial, or enabling SMS 2FA means data is also handled under those providers’ terms.

Retention and deletion

We keep your information while your account and household subscription (or trial) are active, and as needed to operate the service, resolve disputes, and meet legal obligations (for example limited billing records retained by Stripe).

Delete your account. You can delete your account from Profile settings. If you are the only member of your household, that permanently disconnects Plaid-linked banks, cancels billing when possible, and deletes household budget data from our database — that cannot be undone. If other household members remain, only your login is removed and household data stays for them.

Cancel subscription or trial. If you cancel, you keep access until the end of the current paid period or trial. When that access ends, we disconnect Plaid-linked banks for the household and permanently delete the household’s budget data from our platform. That deletion cannot be undone. Resume before access ends if you want to keep the data.

You can also disconnect Plaid-linked accounts from the Accounts screen without deleting your account or canceling billing.

Security

We use reasonable technical and organizational measures to protect your information, including encrypted connections, hashed passwords, and optional two-factor authentication. No method of transmission or storage is completely secure.

Children

The service is not intended for children under 13, and we do not knowingly collect their information. You must meet the age requirements in our Terms of Service to create an account.

Changes

We may update this policy from time to time. We will post the revised version on this page and update the effective date shown with these legal pages.

Contact

Privacy questions: ntinius@trybossman.com