Privacy notice

Privacy Policy

Your financial plan is among the most personal information you will ever put online. This Policy sets out, in plain terms, what MoneyWhatIf collects, why it is needed, who may ever see it, and the rights you hold over it.

Current versionSeptember 10, 2026

01Your data stays private. Always.

Your financial plan is yours alone. You decide whether to share it and who gets access.

02Never sold, never advertised

We do not sell personal information, share it for advertising, or build marketing profiles from it.

03Collected only to serve you

We collect what the Service needs to run and nothing more.

04Your credentials stay with you

Passwords go to Firebase, bank credentials to Plaid, and card numbers to Stripe. None of them ever reach us.

05No trackers

The Service contains no advertising or product-analytics software.

06Delete it yourself, at any time

One control on your profile page removes your account and every plan on it.

This Privacy Policy (the “Policy”) describes how MoneyWhatIf (“MoneyWhatIf,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information in connection with the MoneyWhatIf website, application programming interface, support channels, and related services (collectively, the “Service”). Each section below opens with a short summary, marked “In brief,” to help you read it. The summaries are provided for convenience only; the full text of each section governs. The Policy forms part of our Terms of Use.

01

Scope and operator

This Policy applies wherever MoneyWhatIf determines why and how personal information is processed through the Service. It does not govern a third-party website or service, or a recipient’s independent use of information after you have shared a plan with that recipient.

02

Our privacy commitments

Your financial plan is held in confidence.

We built MoneyWhatIf to answer your own questions about your own money. Keeping that information private is not a feature of the Service; it is the condition on which the Service operates.

In handling your personal information, we undertake that:

  • Data minimization. We collect only the information reasonably necessary to provide, secure, and support the Service, and we ask for nothing the forecast does not need.
  • Your data stays private. Always. Every plan is restricted to its owner when it is created and remains so until the owner grants access to another person.
  • No sale and no advertising. We do not sell, rent, or trade personal information, share it for targeted advertising, or use it to build marketing profiles.
  • No training on your plan. We do not use your financial plan to train artificial-intelligence or machine-learning models.
  • No trackers. The Service includes no advertising network, advertising cookie, or product-analytics software.
  • Limited internal access. Our personnel access plan data only where necessary to operate the Service, to respond to a request you have made, or to investigate a security incident, and under an obligation of confidentiality.
  • Your control. You may delete any plan, or your whole account, yourself at any time, and you may exercise the further rights described in this Policy without charge.
  • Transparency. We will tell you before any material change in how your personal information is used, and obtain your consent where the law requires it.

03

Information we collect

The categories below describe the personal information we may collect, its sources, the purposes for which it is used, and the categories of recipients to which it may be disclosed for an operational purpose. We collect only information reasonably necessary for those purposes.

Sign-in credentials

Firebase Authentication handles email-and-password and Google sign-in, and, where you enable it, a second factor through an authenticator app. MoneyWhatIf does not receive or store your password, and the secret behind an authenticator app is generated by Firebase and shown once to you; it is never stored by the Service.

Information we ask you not to provide

Please do not place Social Security numbers, government identifiers, passwords, authentication codes, or full financial account numbers in plan labels, community posts, or support messages. The Service does not need them, and a forecast is just as accurate without them.

Connected financial accounts

Connecting a financial account is optional. Where the Service offers it, the connection is made through Plaid Inc. You authenticate with your financial institution inside Plaid’s own interface, and your banking credentials go to Plaid and your institution rather than to MoneyWhatIf. We never receive, store, or have any way to see your banking username, password, or multi-factor code. What we receive is the account information you authorize, which is the institution and account names, balances, and, where you request it, transaction history, together with a token that lets us refresh those figures until you disconnect. Plaid handles that information under its own privacy policy as well as ours, and we encourage you to read it before connecting an account.

04

How we use information

We process personal information only as reasonably necessary to:

  • provide, authenticate, save, synchronize, and support the Service;
  • perform the calculations and apply the plan settings you request;
  • retrieve and refresh the account information you authorize when you connect a financial account, and stop doing so when you disconnect it;
  • carry out and secure your plan-sharing instructions;
  • administer your subscription, apply the access it provides, and keep the records that tax and accounting law require;
  • operate the feature-request board and plan improvements to the Service;
  • detect, investigate, and prevent fraud, abuse, and security incidents;
  • diagnose failures and maintain the reliability of the Service;
  • respond to support, legal, security, and privacy requests; and
  • comply with law and establish, exercise, or defend legal claims.

Where the law of the European Economic Area, the United Kingdom, or Switzerland applies, our legal bases are the performance of our contract with you, compliance with our legal obligations, and our legitimate interests in operating and securing the Service. We rely on consent only where we specifically request it, and consent may be withdrawn prospectively at any time.

A forecast is generated entirely from the assumptions you select. We do not use your information to make a solely automated decision about you that produces a legal or similarly significant effect, and we do not use it for any purpose incompatible with those listed above.

05

When we disclose information

We do not disclose personal information except in the limited circumstances described in this section. A “service provider” is a processor or contractor that handles information on our behalf, under contractual and legal restrictions that confine its use to the services it performs for us.

We may also disclose information at your separate direction or with your consent. If MoneyWhatIf is ever involved in a merger, acquisition, or transfer of assets, personal information would be transferred only subject to this Policy, and you would be notified before any different policy applied to it. Our service providers are not authorized to sell your personal information or to use your financial plan for their own purposes, including advertising.

06

No sale, advertising, or profiling

Our business model is not based on your personal information.

We are paid by subscription, not by advertisers. In the preceding 12 months we have not sold personal information or shared it for cross-context behavioral advertising, and we have not knowingly sold or shared the personal information of anyone under 16 for those purposes.

Because we do not engage in those activities, the Service does not present a “Do Not Sell or Share My Personal Information” link. Should our practices ever change, we will update this Policy and provide the legally required choices before applying any change to information we already hold.

07

Retention and deletion

We retain account and plan information while your account is active so that your plans can be reopened and synchronized. Sharing data is retained until access is removed or the related plan is deleted. A plan or questionnaire begun before signing in is retained until you claim it by signing in or it is deleted. Support and security records are retained only for as long as reasonably needed to answer the request, protect the Service, meet a legal obligation, or establish and defend a claim.

If you connect a financial account, the access token and the imported account information are retained until you disconnect that account or delete your account. Disconnecting revokes the token so that no further information can be retrieved, and removes the imported account data from active application data. Figures you have already saved into a plan remain part of that plan, and you can edit or remove them as you would any other figure. Plaid’s own retention of the information it collected is governed by its policy and by the rights it makes available to you directly.

Billing records are retained for the period that tax and accounting law requires. After account deletion, we retain hashes of the email address and sign-in identifier used to redeem a referral reward to prevent repeated claims. Referral credits already earned by another member remain on their account. Contributions to the feature-request board remain on the board after an account is deleted, attributed to a former member rather than to a name, unless you ask us to remove them.

Deleting a plan removes it from active application data. You can delete your account, and every plan on it, yourself from the Delete account section of your profile page; doing so also cancels any subscription immediately. Plans that other people have shared with you belong to them and are unaffected. You may also request deletion using the methods in this Policy. Residual copies may remain for a limited period in backups and security records until their ordinary rotation or deletion, unless longer retention is required by law or is reasonably necessary to document and protect the integrity of a completed request.

08

Your privacy rights

Depending on where you live, and subject to applicable exceptions, you may have the right to request access to, confirmation of, correction of, deletion of, or a portable copy of your personal information, and to restrict or object to its processing. You may also have the right to withdraw consent, to appeal a decision we make on a request, and to lodge a complaint with a privacy regulator. We will never discriminate against you for exercising a privacy right.

European Economic Area, United Kingdom, and Switzerland

If you are located in one of these jurisdictions, you hold the rights described above under the General Data Protection Regulation or its local equivalent, and you may complain to the supervisory authority of your place of residence or work.

California

If the California Consumer Privacy Act applies, you may request to know, access, correct, or delete covered personal information, and receive a portable copy of it. An authorized agent may submit a request on your behalf where the law permits. We do not sell or share personal information as those terms are defined for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for any purpose other than providing the Service you request.

How to submit a request

Email team@moneywhatif.com from the address associated with your account, or use our privacy request form. Describe the right you wish to exercise and the account involved. We may verify your identity or authority in a manner proportionate to the request, and we will respond within the period required by applicable law. Information collected for verification is used only for that purpose.

09

Browser storage and privacy signals

MoneyWhatIf does not use advertising cookies. Firebase Authentication uses browser storage to maintain a secure sign-in session. The Service stores your light, dark, or system theme preference locally. It records the signed-in account’s choice to show future values in today’s money, and whether the setup and projection guides have been completed, so that those choices follow you across browsers and devices; guide status may also be cached locally. A plan begun before signing in is identified by a value held in your browser. A development-only preview may use session storage and is disabled in ordinary production builds.

If you open a member referral invitation, we save its code in a first-party cookie for up to two days (48 hours), or until it is attached to your new account or you sign out. The cookie lets us attribute a signup during that period to the member who invited you. An eligible new account receives signup credit toward its next subscription invoice. We retain the saved attribution to award the inviting member's credit after your first successful subscription payment, even if that payment occurs after the cookie expires. Email verification is not required for signup credit. A free trial alone does not earn the inviting member's reward.

Because we do not sell personal information or use it for targeted advertising, Global Privacy Control and “Do Not Track” signals do not alter practices we do not engage in. We will honor legally required signals should our practices ever make that necessary.

10

Security

We use administrative, technical, and access-control measures designed for the nature of the information the Service handles. Plans start restricted to their owner. API requests carry Firebase ID tokens and are subject to server-side authorization checks. HTTPS protects traffic in transit. In production, plan request and response bodies also use an application-layer encrypted envelope based on ephemeral ECDH, HKDF-SHA-256, and AES-256-GCM.

We describe our encryption accurately.

This is strong encryption in transit, but it is not zero-knowledge end-to-end encryption. The MoneyWhatIf API decrypts plan data in order to validate, store, and return it. No online service can guarantee absolute security, and we will not claim otherwise.

Where you connect a financial account, the token that authorizes the connection is treated as one of the most sensitive values the Service holds: it is encrypted at rest, is never returned to your browser or written to a log, and is revoked at Plaid when you disconnect. Your banking credentials are never part of this, because they never reach us.

You are responsible for protecting your credentials, your email account, your devices, and any links you share. We encourage you to enable a second sign-in factor from your profile page. Please notify us promptly if you reasonably suspect unauthorized access to your account or to a plan.

11

International processing

The Service and its providers may process personal information in the United States and in other countries where they operate. Those countries may provide privacy protections that differ from those of your own. Where applicable law requires a transfer mechanism, we rely on an approved mechanism, such as standard contractual clauses, and on supplementary safeguards appropriate to the transfer.

12

Children

The Service is intended for adults and is not directed to anyone under 18 years of age. We do not knowingly collect personal information from a child. If you believe a child has provided personal information to us, please contact us so that we can investigate and delete it where appropriate.

13

Changes to this Policy

We may update this Policy to reflect changes in the Service, in our practices, or in applicable law. The effective date at the top of the page identifies the current version. If a change materially expands how personal information we already hold is used or disclosed, we will provide additional notice, and obtain consent where the law requires it, before that change applies.

14

Contact and privacy requests

Questions about this Policy and requests to exercise a privacy right may be sent to MoneyWhatIf at team@moneywhatif.com or through the contact page. Requests are handled without charge, subject to the limits the law permits for manifestly unfounded or excessive requests.