Your financial plan is yours alone. You decide whether to share it and who gets access.
We do not sell personal information, share it for advertising, or build marketing profiles from it.
We collect what the Service needs to run and nothing more.
Passwords go to Firebase, bank credentials to Plaid, and card numbers to Stripe. None of them ever reach us.
The Service contains no advertising or product-analytics software.
One control on your profile page removes your account and every plan on it.
This Privacy Policy (the “Policy”) describes how MoneyWhatIf (“MoneyWhatIf,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information in connection with the MoneyWhatIf website, application programming interface, support channels, and related services (collectively, the “Service”). Each section below opens with a short summary, marked “In brief,” to help you read it. The summaries are provided for convenience only; the full text of each section governs. The Policy forms part of our Terms of Use.
01
Scope and operator
This Policy covers information handled through MoneyWhatIf. It does not cover other websites, or what a person does with a plan after you choose to share it with them.
This Policy applies wherever MoneyWhatIf determines why and how personal information is processed through the Service. It does not govern a third-party website or service, or a recipient’s independent use of information after you have shared a plan with that recipient.
- Service operator
- MoneyWhatIf
- Privacy contact
- team@moneywhatif.com
- Effective date
- September 10, 2026
02
Our privacy commitments
We keep your data private. We collect the minimum, use it only to run the Service for you, never sell it or use it for advertising, and let you delete it whenever you wish.
We built MoneyWhatIf to answer your own questions about your own money. Keeping that information private is not a feature of the Service; it is the condition on which the Service operates.
In handling your personal information, we undertake that:
- Data minimization. We collect only the information reasonably necessary to provide, secure, and support the Service, and we ask for nothing the forecast does not need.
- Your data stays private. Always. Every plan is restricted to its owner when it is created and remains so until the owner grants access to another person.
- No sale and no advertising. We do not sell, rent, or trade personal information, share it for targeted advertising, or use it to build marketing profiles.
- No training on your plan. We do not use your financial plan to train artificial-intelligence or machine-learning models.
- No trackers. The Service includes no advertising network, advertising cookie, or product-analytics software.
- Limited internal access. Our personnel access plan data only where necessary to operate the Service, to respond to a request you have made, or to investigate a security incident, and under an obligation of confidentiality.
- Your control. You may delete any plan, or your whole account, yourself at any time, and you may exercise the further rights described in this Policy without charge.
- Transparency. We will tell you before any material change in how your personal information is used, and obtain your consent where the law requires it.
03
Information we collect
We collect your account details, the figures you enter into a plan, the sharing choices you make, and the technical data any online service needs to run securely. Bank connections, subscriptions, and the community board add a little more, each only if you use it.
The categories below describe the personal information we may collect, its sources, the purposes for which it is used, and the categories of recipients to which it may be disclosed for an operational purpose. We collect only information reasonably necessary for those purposes.
Account and identity data
- Examples
- Name or display name, email address, Firebase user identifier, account timestamps, interface preferences, and whether a second sign-in factor is enrolled. We never hold your password or the secret behind an authenticator app.
- Source
- You, and Firebase Authentication.
- Purpose
- Create, authenticate, secure, synchronize, and support your account.
- Recipients
- Firebase and the cloud providers that operate the Service.
Financial plan data
- Examples
- Ages, location, income, spending, property, mortgages, cash, investments, retirement assumptions, milestones, goals, labels, figures you record on the current-finances and history pages, and the plan settings you choose.
- Source
- You, including through the changes you save to a plan.
- Purpose
- Calculate, save, synchronize, copy, and display your forecast.
- Recipients
- Cloud infrastructure providers and any person to whom you intentionally grant plan access.
Plans and answers entered before signing in
- Examples
- If you begin the setup questionnaire or a first plan before creating an account, the answers and the plan are stored under an unguessable identifier that only your browser holds.
- Source
- You.
- Purpose
- Let you complete a first projection without an account and keep it when you sign up.
- Recipients
- Cloud infrastructure providers.
Connected financial account data
- Examples
- If you choose to connect a financial account: the institution and account names, account type, balances, and, where you request it, transaction history, together with the access token that authorizes the connection. We never receive your banking username, password, or multi-factor code.
- Source
- Plaid Inc., acting on the connection you authorize with your financial institution. Connecting an account is optional, and the Service works fully without it.
- Purpose
- Populate and refresh the balances and figures in your plan so that you do not have to enter them by hand. While an account remains connected, balances are refreshed on a schedule of no more than once a day.
- Recipients
- Plaid and the cloud infrastructure providers that operate the Service.
Subscription and billing data
- Examples
- A Stripe customer identifier, the plan you subscribe to, the subscription status, the current billing period, trial status, and the event records Stripe sends us. Referral data includes invitation codes, signup attribution, qualifying subscription payment status, and credits earned and applied. Card numbers are entered on Stripe's own pages and never reach us.
- Source
- You, and Stripe.
- Purpose
- Determine which plan applies to your account, apply the corresponding access and referral credits, prevent duplicate referral rewards, and keep the records that tax and accounting law require.
- Recipients
- Stripe and the cloud providers that operate the Service.
Sharing and access data
- Examples
- Recipient email addresses, link-access settings, and the permissions you set on a plan.
- Source
- You, and people who authenticate to view a plan shared with them.
- Purpose
- Apply, verify, and secure the sharing choices you make.
- Recipients
- Cloud providers and the recipients you designate.
Community submissions
- Examples
- Feature requests, comments, and votes on the public feature-request board, shown beside your display name. A new request is reviewed before it appears on the board.
- Source
- You.
- Purpose
- Operate the feature-request board and plan the Service's roadmap.
- Recipients
- Readers of the board, for approved requests, comments, and vote counts; board moderators, for requests awaiting review.
Technical and security data
- Examples
- IP address, browser and device characteristics, request time, authentication events, and error or security records.
- Source
- Your browser, device, and network, and our service providers.
- Purpose
- Deliver the Service, prevent abuse, diagnose failures, and maintain security.
- Recipients
- Authentication, hosting, database, and security providers.
Communications
- Examples
- Your contact details and the content of support, privacy, or security messages.
- Source
- You, or an authorized person contacting us on your behalf.
- Purpose
- Respond to the request, verify authority, and keep an appropriate record.
- Recipients
- The email and support providers used to receive and answer the message.
Sign-in credentials
Firebase Authentication handles email-and-password and Google sign-in, and, where you enable it, a second factor through an authenticator app. MoneyWhatIf does not receive or store your password, and the secret behind an authenticator app is generated by Firebase and shown once to you; it is never stored by the Service.
Information we ask you not to provide
Please do not place Social Security numbers, government identifiers, passwords, authentication codes, or full financial account numbers in plan labels, community posts, or support messages. The Service does not need them, and a forecast is just as accurate without them.
Connected financial accounts
Connecting a financial account is optional. Where the Service offers it, the connection is made through Plaid Inc. You authenticate with your financial institution inside Plaid’s own interface, and your banking credentials go to Plaid and your institution rather than to MoneyWhatIf. We never receive, store, or have any way to see your banking username, password, or multi-factor code. What we receive is the account information you authorize, which is the institution and account names, balances, and, where you request it, transaction history, together with a token that lets us refresh those figures until you disconnect. Plaid handles that information under its own privacy policy as well as ours, and we encourage you to read it before connecting an account.
04
How we use information
We use your information to run the Service for you: to calculate and save your forecast, keep your account secure, carry out your sharing and billing instructions, and answer your requests. Nothing else.
We process personal information only as reasonably necessary to:
- provide, authenticate, save, synchronize, and support the Service;
- perform the calculations and apply the plan settings you request;
- retrieve and refresh the account information you authorize when you connect a financial account, and stop doing so when you disconnect it;
- carry out and secure your plan-sharing instructions;
- administer your subscription, apply the access it provides, and keep the records that tax and accounting law require;
- operate the feature-request board and plan improvements to the Service;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- diagnose failures and maintain the reliability of the Service;
- respond to support, legal, security, and privacy requests; and
- comply with law and establish, exercise, or defend legal claims.
Where the law of the European Economic Area, the United Kingdom, or Switzerland applies, our legal bases are the performance of our contract with you, compliance with our legal obligations, and our legitimate interests in operating and securing the Service. We rely on consent only where we specifically request it, and consent may be withdrawn prospectively at any time.
A forecast is generated entirely from the assumptions you select. We do not use your information to make a solely automated decision about you that produces a legal or similarly significant effect, and we do not use it for any purpose incompatible with those listed above.
05
When we disclose information
A small number of providers help us run the Service, each bound to handle your information only on our instructions. Beyond them, your plan is disclosed only to people you choose, or where the law leaves us no choice.
We do not disclose personal information except in the limited circumstances described in this section. A “service provider” is a processor or contractor that handles information on our behalf, under contractual and legal restrictions that confine its use to the services it performs for us.
Google Firebase
Authenticates accounts, maintains sign-in sessions, and holds any second sign-in factor you enroll.
Vercel and DigitalOcean
Serve the web application and host the API, the database, and related infrastructure.
Plaid
Connects a financial account you choose to link and returns the account information you authorize. Receives your banking credentials directly; we never do.
Stripe
Processes subscription payments on its own pages. We hold a customer identifier and a subscription status, never a card number.
Plan recipients
Receive access to a plan only when you designate them or enable link access, and only for as long as you leave that access in place.
Authorities and protected parties
Receive only what is reasonably necessary in response to valid legal process, or to protect the rights, safety, and security of any person or of the Service.
We may also disclose information at your separate direction or with your consent. If MoneyWhatIf is ever involved in a merger, acquisition, or transfer of assets, personal information would be transferred only subject to this Policy, and you would be notified before any different policy applied to it. Our service providers are not authorized to sell your personal information or to use your financial plan for their own purposes, including advertising.
06
No sale, advertising, or profiling
We have never sold personal information, and we never will. There is no advertising in the Service and no profile of you built for marketing.
We are paid by subscription, not by advertisers. In the preceding 12 months we have not sold personal information or shared it for cross-context behavioral advertising, and we have not knowingly sold or shared the personal information of anyone under 16 for those purposes.
Because we do not engage in those activities, the Service does not present a “Do Not Sell or Share My Personal Information” link. Should our practices ever change, we will update this Policy and provide the legally required choices before applying any change to information we already hold.
07
Retention and deletion
We keep your plans for as long as your account exists, so you can come back to them. Delete a plan, disconnect a bank, or delete your whole account whenever you like, and the data goes with it.
We retain account and plan information while your account is active so that your plans can be reopened and synchronized. Sharing data is retained until access is removed or the related plan is deleted. A plan or questionnaire begun before signing in is retained until you claim it by signing in or it is deleted. Support and security records are retained only for as long as reasonably needed to answer the request, protect the Service, meet a legal obligation, or establish and defend a claim.
If you connect a financial account, the access token and the imported account information are retained until you disconnect that account or delete your account. Disconnecting revokes the token so that no further information can be retrieved, and removes the imported account data from active application data. Figures you have already saved into a plan remain part of that plan, and you can edit or remove them as you would any other figure. Plaid’s own retention of the information it collected is governed by its policy and by the rights it makes available to you directly.
Billing records are retained for the period that tax and accounting law requires. After account deletion, we retain hashes of the email address and sign-in identifier used to redeem a referral reward to prevent repeated claims. Referral credits already earned by another member remain on their account. Contributions to the feature-request board remain on the board after an account is deleted, attributed to a former member rather than to a name, unless you ask us to remove them.
Deleting a plan removes it from active application data. You can delete your account, and every plan on it, yourself from the Delete account section of your profile page; doing so also cancels any subscription immediately. Plans that other people have shared with you belong to them and are unaffected. You may also request deletion using the methods in this Policy. Residual copies may remain for a limited period in backups and security records until their ordinary rotation or deletion, unless longer retention is required by law or is reasonably necessary to document and protect the integrity of a completed request.
08
Your privacy rights
You may ask to see, correct, delete, or receive a copy of your personal information, and to object to or restrict how it is used. Email us from your account address, and we will act within the time the law allows.
Depending on where you live, and subject to applicable exceptions, you may have the right to request access to, confirmation of, correction of, deletion of, or a portable copy of your personal information, and to restrict or object to its processing. You may also have the right to withdraw consent, to appeal a decision we make on a request, and to lodge a complaint with a privacy regulator. We will never discriminate against you for exercising a privacy right.
European Economic Area, United Kingdom, and Switzerland
If you are located in one of these jurisdictions, you hold the rights described above under the General Data Protection Regulation or its local equivalent, and you may complain to the supervisory authority of your place of residence or work.
California
If the California Consumer Privacy Act applies, you may request to know, access, correct, or delete covered personal information, and receive a portable copy of it. An authorized agent may submit a request on your behalf where the law permits. We do not sell or share personal information as those terms are defined for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for any purpose other than providing the Service you request.
How to submit a request
Email team@moneywhatif.com from the address associated with your account, or use our privacy request form. Describe the right you wish to exercise and the account involved. We may verify your identity or authority in a manner proportionate to the request, and we will respond within the period required by applicable law. Information collected for verification is used only for that purpose.
09
Browser storage and privacy signals
Your browser keeps you signed in, remembers your display preferences, and saves a referral invitation for two days if you open one. There are no advertising cookies, so there is nothing for a “Do Not Track” signal to switch off.
MoneyWhatIf does not use advertising cookies. Firebase Authentication uses browser storage to maintain a secure sign-in session. The Service stores your light, dark, or system theme preference locally. It records the signed-in account’s choice to show future values in today’s money, and whether the setup and projection guides have been completed, so that those choices follow you across browsers and devices; guide status may also be cached locally. A plan begun before signing in is identified by a value held in your browser. A development-only preview may use session storage and is disabled in ordinary production builds.
If you open a member referral invitation, we save its code in a first-party cookie for up to two days (48 hours), or until it is attached to your new account or you sign out. The cookie lets us attribute a signup during that period to the member who invited you. An eligible new account receives signup credit toward its next subscription invoice. We retain the saved attribution to award the inviting member's credit after your first successful subscription payment, even if that payment occurs after the cookie expires. Email verification is not required for signup credit. A free trial alone does not earn the inviting member's reward.
Because we do not sell personal information or use it for targeted advertising, Global Privacy Control and “Do Not Track” signals do not alter practices we do not engage in. We will honor legally required signals should our practices ever make that necessary.
10
Security
Plans are locked to their owner, every request is authenticated, and traffic is encrypted in transit with an additional encrypted envelope around plan data. Bank tokens are encrypted at rest and never leave the server.
We use administrative, technical, and access-control measures designed for the nature of the information the Service handles. Plans start restricted to their owner. API requests carry Firebase ID tokens and are subject to server-side authorization checks. HTTPS protects traffic in transit. In production, plan request and response bodies also use an application-layer encrypted envelope based on ephemeral ECDH, HKDF-SHA-256, and AES-256-GCM.
This is strong encryption in transit, but it is not zero-knowledge end-to-end encryption. The MoneyWhatIf API decrypts plan data in order to validate, store, and return it. No online service can guarantee absolute security, and we will not claim otherwise.
Where you connect a financial account, the token that authorizes the connection is treated as one of the most sensitive values the Service holds: it is encrypted at rest, is never returned to your browser or written to a log, and is revoked at Plaid when you disconnect. Your banking credentials are never part of this, because they never reach us.
You are responsible for protecting your credentials, your email account, your devices, and any links you share. We encourage you to enable a second sign-in factor from your profile page. Please notify us promptly if you reasonably suspect unauthorized access to your account or to a plan.
11
International processing
The Service runs in the United States. If you use it from elsewhere, your information is transferred there under the safeguards the law requires.
The Service and its providers may process personal information in the United States and in other countries where they operate. Those countries may provide privacy protections that differ from those of your own. Where applicable law requires a transfer mechanism, we rely on an approved mechanism, such as standard contractual clauses, and on supplementary safeguards appropriate to the transfer.
12
Children
MoneyWhatIf is for adults. We do not knowingly collect information from anyone under 18.
The Service is intended for adults and is not directed to anyone under 18 years of age. We do not knowingly collect personal information from a child. If you believe a child has provided personal information to us, please contact us so that we can investigate and delete it where appropriate.
13
Changes to this Policy
When this Policy changes, the date at the top changes with it. A change that affects how your existing data is used will be announced beforehand.
We may update this Policy to reflect changes in the Service, in our practices, or in applicable law. The effective date at the top of the page identifies the current version. If a change materially expands how personal information we already hold is used or disclosed, we will provide additional notice, and obtain consent where the law requires it, before that change applies.
14
Contact and privacy requests
Questions about this Policy and requests to exercise a privacy right may be sent to MoneyWhatIf at team@moneywhatif.com or through the contact page. Requests are handled without charge, subject to the limits the law permits for manifestly unfounded or excessive requests.