How Money in Reach uses and protects your information.
See what we collect, why we use it, who may receive it, how long we keep it, and the choices available to you.
Effective: September 12, 2026 · Last updated: September 12, 2026 · Version: 2026-09-12
- We use the information needed to provide the account, planning, Reach Guide, Resolve, billing, and optional connected-account features you choose.
- We do not sell personal information for money or use it for targeted advertising.
- You can review, export, correct, or delete covered account data through signed-in controls or a verified privacy request.
1. Scope and operator
This notice covers the Money in Reach website, mobile app, Money Brief email, accounts, planning tools, Money in Reach Plus, connected-account features, Reach Guide, and Money in Reach Resolve (together, the "Service"). Money in Reach decides why and how personal information is processed for the Service. Submit questions or requests through the contact page or email admin@moneyinreach.net.
Money in Reach does not sell personal information for money. It does not use personal information for targeted advertising or share it for cross-context behavioral advertising. Optional product analytics is off until you choose to allow it and remains off when a supported Global Privacy Control signal is present.
2. Information we collect
Information you provide
- Account: email address, display name, authentication provider, email-verification status, and account identifiers.
- Planning and learning: income and pay-frequency inputs, goals, risk comfort, calculator defaults, scenarios, reviews, debt and home plans, bills, net-worth entries, progress, badges, and learning-path activity you choose to save.
- Reach Guide: questions, recent conversation context, selected profile fields, and aggregate dashboard information used to respond.
- Resolve: case descriptions, confirmed and corrected facts, amounts, dates, companies, timelines, tasks, outcomes, drafts, pasted messages, reminder and inbound-email preferences, feedback, and evidence files you choose to provide.
- Money Brief email: the email address, daily or weekly choice, browser-reported time zone, signup placement, confirmation and unsubscribe times, a one-way email hash, provider message identifiers, delivery status, and suppression reason needed to send and manage the brief. A Money in Reach account is not required.
- Support: name, email address, selected topic, and message submitted through a contact or feature-interest form.
- Consent records: accepted Terms and Privacy versions, acceptance context, authenticated-account hash, time, authentication provider, and a one-way technical evidence hash. Raw IP addresses and full browser strings are not stored in the D1 legal-acceptance table. A server-owned Firestore enforcement document uses the Firebase account identifier as an inaccessible document key so direct account-data writes fail closed until the current account agreement is recorded; that enforcement document is deleted with the account.
Connected financial information
After you choose to connect an institution through Plaid Link, Money in Reach may receive and store the institution name, Plaid item identifier, selected account metadata and masked account identifiers, account type, balances, transaction dates, descriptions, amounts and categories, recurring inflow or outflow summaries, synchronization status, and a transaction cursor. An encrypted Plaid access token is stored server-side. Money in Reach does not receive the bank username or password entered through Plaid Link and does not initiate transfers or payments.
Billing information
Stripe collects payment-card and billing details directly. Money in Reach receives and stores the Stripe customer, checkout, price, subscription, payment, and event identifiers; product and entitlement; payment or subscription status; renewal timing; test/live mode; and the authenticated user identifier and email needed to match access. Money in Reach does not store full payment-card numbers.
Information collected automatically
- Essential delivery and security: Cloudflare and the Service process request time, IP-derived network and approximate location data, browser and device information, security signals, request identifiers, logs, rate-limit counters, and error information needed to deliver and protect the Service.
- Optional analytics: on public educational and product pages only, after consent, Google Analytics may use cookies or similar client identifiers and receive page path without query strings, page title, referring site, device/browser information, approximate location, and allowlisted events such as article reads, calculator use, and public product navigation. Google Analytics does not load on Account, Progress, Connected Dashboard, private Plus workspaces, or signed-in Resolve workspaces. Analytics events must not contain case text, response text, filenames, account numbers, document contents, full URLs with query strings, or sensitive monetary details.
- Device storage: essential browser or app storage maintains authentication, security, entitlement caching, requested preferences, drafts, and offline-friendly progress. Firebase may keep an encrypted or browser-managed offline cache, and the iOS app keeps session credentials in the device Keychain. Optional analytics preference is stored on the device even when analytics is declined so the choice can be honored.
3. Sources
We receive information directly from you; automatically from the browser, app, and Cloudflare security infrastructure; from Firebase when you authenticate; from Stripe when you start or manage a purchase; from Plaid and your selected institution after permission through Plaid Link; from Resend about an opted-in reminder or Money Brief message; and from configured AI providers when they return an output requested by the Service.
4. Why we use information
- provide authentication, cloud synchronization, saved planning, learning progress, Resolve, and connected-account features you request;
- calculate and display estimates and educational summaries;
- process purchases, maintain entitlements, prevent duplicate billing events, support the billing portal, and address disputes or refunds;
- generate user-directed Reach Guide responses, fact candidates, plans, and editable drafts;
- deliver the daily or weekly Money Brief after email confirmation, manage frequency and unsubscribe choices, and prevent sends after a bounce or complaint;
- deliver opted-in reminders and, after separate consent, create a private draft from an authenticated inbound email;
- respond to support, privacy, and feedback submissions;
- protect accounts, enforce ownership, rate-limit abuse, detect malicious files or requests, investigate failures, and maintain audit records;
- measure feature reliability and usefulness through privacy-minimized analytics when allowed; and
- comply with law and establish, exercise, or defend legal claims.
5. When information is disclosed
We disclose only the information reasonably needed for the following recipients and purposes:
- Cloudflare: hosting, private databases and object storage, queues, email routing, security, network logs, and optional Workers AI fallback.
- Google Firebase: authentication and Firestore synchronization; Google Analytics: optional product analytics only after consent.
- Stripe: checkout, subscriptions, receipts, customer portal, fraud controls, and billing support.
- Plaid and selected institutions: the optional connected-account flow and consumer-permissioned account data.
- 1min AI or the configured AI provider: a requested Reach Guide question and context or, for Resolve, structured company, amount, currency, date, description, user-confirmed fact, and pasted-evidence text needed for extraction, classification, planning, or drafting. Automated redaction attempts to remove prohibited identifiers but cannot identify every sensitive value. Raw Resolve documents are not sent under the launch configuration described below.
- Resend: opted-in Money Brief and privacy-minimized reminder delivery, together with delivery-status events used to prevent duplicate or unwanted sends.
- Approved support recipient: a contact submission only if optional support fanout is configured; a secure D1 support copy remains authoritative. A separately configured private support mailbox may also receive an unmatched inbound Resolve message that cannot be safely assigned to an account.
- Authorities, advisers, or transaction parties: when reasonably necessary to comply with lawful process, protect rights and safety, investigate fraud or abuse, or complete a business reorganization subject to appropriate confidentiality and continued protection.
Authorized Resolve administrators may review case records, confirmed facts, drafts, task status, AI failures, and feedback to operate support, investigate a flagged case, or perform an opted-in concierge review. Raw evidence requires a separate elevated permission, a legitimate operational purpose, and an audit event. We do not disclose raw Resolve evidence in general analytics. If content is forwarded to an external support mailbox or optional support provider, deleting the Money in Reach D1 copy does not itself delete the recipient's independent copy; requests concerning that copy will be routed to the recipient when applicable.
6. AI processing
The Reach Guide may send your question, recent conversation context, selected profile information, and aggregate dashboard values to the configured AI provider. Raw transaction lists are not deliberately added to Reach Guide prompts. Resolve may send structured intake fields, automated-redaction output from pasted text, and user-confirmed facts for extraction, classification, plan generation, or a draft you request. Automated redaction is a risk-reduction measure, not a guarantee; review and remove unnecessary sensitive information before submitting it.
At launch, uploaded images and PDFs remain in private Cloudflare storage and are not copied to an AI provider. They require manual confirmation. The Service is configured to fail closed: raw-document AI processing may not be enabled until the provider's retention, deletion, training-use, and security terms are approved; this policy is updated; and a separate, versioned, evidence-specific consent is implemented. Uploaded or pasted material is treated only as untrusted evidence and never as model instructions. Do not provide unnecessary sensitive information.
AI output may be inaccurate and must be confirmed. Money in Reach does not use AI to determine credit, employment, housing, insurance, legal rights, or another eligibility decision.
7. Email services
The Money Brief is optional and does not require an account. A signup records the selected daily or weekly frequency and browser-reported time zone, then sends one confirmation request. Daily or weekly content starts only after the recipient uses that link. Each brief includes frequency controls and an unsubscribe method. A bounce, complaint, or provider suppression stops later sends to that address. The Service does not buy email lists or add an account email to the Money Brief without a separate signup.
Resolve emails are opt-in and sent only to the verified address on the account. Subjects and bodies are deliberately general and exclude evidence, pasted messages, disputed amounts, company responses, and communication drafts. You may choose reminder categories and quiet hours, turn email off, or use the signed unsubscribe link. Delivery events such as sent, delivered, delayed, bounced, complained, failed, or suppressed are used to operate delivery and prevent further sends after certain failures.
If you separately enable inbound Resolve email, a message from your verified sign-in address to resolve@moneyinreach.net may create a private draft and evidence after sender-authentication, file, size, sensitive-data, entitlement, and duplicate checks. It does not approve facts, invoke raw-document AI, generate a final plan, or send anything to a company. Unmatched or unsafe mail may be rejected or forwarded to a private support destination; unmatched raw content is not stored in the Resolve database.
8. Your analytics and privacy choices
Essential authentication, security, billing, requested storage, and network delivery cannot be disabled through the analytics control because they are needed to provide the feature you choose. Google Analytics is optional and is not loaded until you select "Allow analytics." It never loads on Account, Progress, Connected Dashboard, private Plus workspaces, or signed-in Resolve workspaces even after consent. Select "No thanks" or change the setting at any time on Privacy Choices. Declining analytics does not reduce access or change price.
If the browser sends a supported Global Privacy Control signal, Money in Reach treats it as an opt-out of optional analytics, sale, sharing, and targeted advertising and does not override it with a prior device preference. Money in Reach does not currently sell or use data for targeted advertising. A generic Do Not Track signal is not consistently standardized; the explicit Privacy Choices control and supported Global Privacy Control are honored as described.
9. Retention
- Account, planning, learning, and Resolve case data: until you delete the record, delete the account, or request deletion, subject to the limited exceptions below.
- Private Resolve evidence: until the related evidence, case, Resolve data, or account is deleted.
- Free Resolve case eligibility: a limited account-level record of whether the one-time free case was used remains after a case or all Resolve content is deleted. It prevents case deletion from resetting the benefit and is removed when the account is permanently deleted.
- Connected-account cache and encrypted token: until you disconnect, delete the account, or the connection is otherwise removed.
- Contact submissions and read notifications: up to 180 days.
- Resolve email delivery history and security audit events: up to 180 days; processed provider webhook events and inbound-processing metadata are removed after about 30 days.
- Money Brief: an active confirmed subscription is kept until you unsubscribe or request deletion. An unconfirmed signup is removed after about 30 days. Delivery history, unsubscribed rows, and suppressed rows are removed after about 180 days, while a one-way suppression hash may be retained longer to prevent sending to an address that bounced or complained.
- Stripe and entitlement records: for the life of the account and afterward for the period reasonably needed for accounting, tax, fraud, chargeback, and legal obligations. Stripe separately retains records under its policy.
- Pseudonymized D1 legal-acceptance records: at least seven years from acceptance, and longer only when reasonably necessary for an active paid relationship, a dispute, legal hold, or applicable recordkeeping duty, so consent and contract history can be established or defended. These retained records do not contain the raw account ID, IP address, browser string, case content, or evidence. The separate server-owned Firestore enforcement document is deleted with the account.
- Optional analytics: according to the shortest practical property-level retention we configure and Google's independent processing terms; device analytics cookies are limited by the Service configuration and can be removed through browser controls.
- Backups and legal holds: deleted information may persist temporarily in restricted backups or longer when preservation is required by law, a payment dispute, security investigation, or legal claim, after which it is deleted or isolated from ordinary use.
10. Security and incident response
Money in Reach uses authenticated and owner-scoped access, deny-by-default Firestore rules, private object storage, encrypted Plaid tokens, signed and replay-protected webhooks, input and file limits, rate limits, restricted administration, audit events, transport encryption, and data-minimized logging. Administrative access to raw evidence requires elevated permission and is recorded. No system can guarantee absolute security.
If a security incident creates a legal notice obligation, we will notify affected people and authorities in the form and time required by applicable law. Protect credentials, keep devices updated, and sign out on shared devices.
11. Access, correction, export, deletion, and state rights
Signed-in controls allow you to view and update profile and planning data, disconnect Plaid, delete saved planning data, export an individual Resolve case, or download an account-level JSON export covering Money in Reach planning data, Resolve records, free-case eligibility, billing-status metadata, connected-account cache, email preferences, and consent history. Private Resolve evidence is listed with separate recent-authentication download paths rather than embedded into browser memory. Money Brief preferences and deletion are available from the signed link in each message. Public Money Brief and contact-form records are not included automatically in an account export because an email address entered on a public form does not securely prove account ownership; request those records through the verified privacy-request process. If an account is too large for one safe automated download, no partial export is created and we will provide a verified alternative. You may also delete a case or all Resolve data, permanently delete the account by following the account-deletion steps, or request access, correction, deletion, or a portable copy through the contact page or admin@moneyinreach.net. Deleting a case or all Resolve content does not reset the one-time free-case benefit. We may verify account control and may deny or limit a request only when an applicable exception permits or requires it.
Where applicable, state law may also provide rights to know or access categories and specific pieces of personal information; correct inaccuracies; delete; obtain a portable copy; opt out of sale, sharing, targeted advertising, or certain profiling; limit specified uses of sensitive information; use an authorized agent; appeal a request decision; and receive equal service without unlawful discrimination. Money in Reach does not currently sell personal information, use it for targeted advertising, or make decisions through profiling that produce legal or similarly significant effects.
To appeal a denied privacy request, reply to the decision or submit a new request labeled "Privacy appeal" within 45 days and explain the basis. A person acting as an authorized agent must provide signed permission or other legally sufficient authorization; we may also verify the consumer directly when permitted. We will respond within the time required by applicable law. If you remain concerned, you may contact the attorney general or privacy regulator in your state.
12. Account deletion
Permanent account deletion reauthenticates the user and first writes durable security tombstones so an old token or delayed webhook cannot recreate data. It then attempts to cancel active website subscriptions, remove the Firebase sign-in, delete user-owned Firestore and Resolve records and private evidence, and disconnect Plaid. Apple-managed subscriptions must be canceled through Apple subscription settings. If a provider is temporarily unavailable after the tombstone is written, the account enters a blocked, pending-deletion state rather than becoming active again; support must resume the remaining cleanup. Deletion cannot be undone and does not automatically refund prior payments. Limited pseudonymized acceptance, security, audit, Stripe, and App Store entitlement records may remain only for the purposes and periods described above. The protected Firestore tombstone uses the former Firebase account identifier as its inaccessible document key; D1 and KV deletion markers use a one-way derivative. See Delete your Money in Reach account for step-by-step instructions.
13. Children
The Service is not directed to children under 13. Account, paid, connected-account, and Resolve features are for adults at least 18 or the age of legal majority. We do not knowingly permit a child to create such an account or knowingly collect personal information from a child. If you believe a child provided personal information, contact us so we can investigate and delete it as appropriate.
14. United States processing
The Service is operated for the United States, and providers may process information in the United States and other places where they operate. Those locations may have different data-protection laws. If you use the Service outside the United States, you understand that information will be transferred to and processed in the United States.
15. Policy changes
We may update this policy prospectively. The effective date and version will change. For a material change to collection, use, disclosure, AI document processing, retention, or rights, we will provide reasonable notice and request renewed consent when required. We will not use previously collected information for a materially incompatible new purpose without notice and any consent required by law.
16. Contact
Submit privacy questions, requests, or appeals through the contact page or email admin@moneyinreach.net. Use the email address associated with the account when possible. Do not send passwords, full account or card numbers, or sensitive documents through ordinary email.