Money Moonshot.

Privacy Policy · Effective August 20, 2026

Money Moonshot is operated by Money Moonshot LLC ("Money Moonshot," "we," "us"), a personal budgeting and financial-management app. This policy explains what information we collect, how we use it, and the choices you have. We built this app privacy-first: we do not sell your personal or financial information, and we do not show you third-party ads.

We would rather be plain than flattering. Where something about how we handle data is less tidy than you might expect, this policy says so instead of leaving it out.

Information we collect

We do not collect your bank login credentials. When you connect a bank, you enter those credentials directly with Plaid — we never see or store them.

Demo mode

You can tap Try the demo without creating an account or signing in. When you do, we create a temporary demo account on our server, private to you, filled with made-up sample data. It is a real row in our database, so anything you type while in the demo — a goal name, for example — is stored there until the demo ends. We do not ask for your email, and no real financial information is involved.

A demo session lasts at most 2 hours. We delete the demo account and everything in it when you tap Exit demo, and expired demo accounts are deleted automatically the next time anyone opens a demo. Requests you make during a demo appear in our server logs the same way anyone else's do, including your IP address — see "Technical and security logs" below.

Scanning a statement

The app can read an account statement for you instead of making you type the numbers in. You choose the image: a photo you take with your camera, a picture from your photo library, or a PDF. A PDF is converted to an image on our server first, then handled the same way a photo is.

That image is sent to Google to be read by Google's Gemini model, which returns the account name, balance and rate it found. You review the result before anything is saved. We do not store the image: it is held in memory for the length of the request and is never written to our disk or database. Because we send the whole image, anything else visible in the picture goes with it — so frame the shot, or crop it, before you send.

How we use your information

We use your data only to provide the service to you. We do not sell it, rent it, or use it for advertising.

Plaid

We use Plaid to connect to your financial institutions. By connecting an account, you also agree to Plaid's handling of your information as described in the Plaid End User Privacy Policy. You can learn more about the data Plaid collects and manage your connections through Plaid's Plaid Portal.

One thing about Plaid is not conditional, so we will not describe it as if it were: Plaid's connection script is loaded every time the app opens, from Plaid's own servers, before you have done anything. That means Plaid's servers see your device — its IP address, browser, and the page it came from — even if you are only looking at the demo and never connect an account. Nothing about your budget or your finances goes with it.

How your data is protected

Technical and security logs

Our servers keep technical logs of requests — the date and time, the page or endpoint requested, the response status, and your IP address. We use these only to keep the service running and to detect and block abuse and attacks. These logs do not contain your account balances, transactions, or any financial detail. They are stored on infrastructure we control and are not used for advertising or profiling.

To be straight with you: we do not currently set an expiry on these logs. They are kept until we delete them, and today that is a manual step rather than an automatic one, so please assume a request you make is recorded indefinitely. This applies to demo visitors too, who never sign in and never give us an email address. We intend to cap this; when we do, this paragraph will say what the cap is.

Artificial intelligence features

Some optional features use a third-party AI model — Google Gemini — for example to explain a financial concept, answer a question about your budget, build a payoff plan, or read a statement you scan. When you use one of these features, the information the feature needs is sent to Google for processing and the result is returned to you.

What gets sent depends on the feature, and it can include the names and types of debts you have entered — including one you typed as a medical debt or named after a hospital or clinic — and the contents of a statement image you scan. We do not send your bank credentials or your Plaid access tokens. AI features are optional: if you never use them, none of your information is sent to Google. Google processes what we send under the terms of the Google Gemini API account we use, and under Google's own policies, which we do not control.

Email you receive from us

We email you about your account: sign-in changes, password resets, and household invitations.

Two summaries are optional and off until you switch them on in the app — a weekly one and a monthly snapshot. Both are written to contain only direction, percentages and milestones (for example, "you spent 20% less than last month"), and never contain amounts, balances, account names, or merchant names. You turn them off in the same place you turned them on.

One email does carry real numbers — your spending total for the week, your top categories with amounts, and any budget you went over. It is sent only when you ask for it, by tapping Email me this on the This week card. Nothing sends it on a schedule, so there is no setting to switch off.

We have also built an alert that emails you when a linked bank stops syncing and needs reconnecting. That email names the institution, so it is the one account email that says where you bank. It is on by default and you can switch it off in the app. It is not scheduled to run at the moment, so today it never sends; we are telling you it exists because the switch is in your settings and the code ships with the app.

Our outgoing mail is sent through an ordinary Gmail account, not through a business email service under a data-processing agreement with us. Google handles that mail under its consumer terms. So treat email from us the way you would treat any ordinary email: it is not a private channel, and we keep account emails free of balances and merchant names for that reason.

Sharing

We share data only with the service providers that make the app work: Plaid (to retrieve financial data, and whose connection script loads with the app as described above), Google (for the optional AI features described above, and for our outgoing email), and Cloudflare (which carries traffic between your device and our server). Plaid handles your information under its agreement with us and under the Plaid End User Privacy Policy. Google's handling of AI requests and of our email is governed by Google's own terms, as described above. We may disclose information if required by law. We do not sell your information, and we do not share it with advertisers or data brokers.

Sharing with people you choose

If you invite someone to your household, they receive a one-time invitation code by email and, once they accept, can see a read-only summary of your finances. Only the person who receives that code in their own inbox can accept it. You can revoke this access at any time in the app, and it is revoked automatically if you change your sign-in email address.

Data retention and deletion

We keep your data for as long as your account is active. You can delete your account at any time from Settings → Account → Delete my account, in the app or in a browser at moneymoonshot.com/app. There is also a deletion page you can use without opening the app.

Deleting your account revokes our access at your bank through Plaid first — so no further data is retrieved — and then removes your rows from our live database immediately. Sign-in stops working right away.

Backups are a separate copy and they are not instant. We take one encrypted snapshot of the whole database every night and delete snapshots older than 14 days, which means data you deleted can remain inside an encrypted backup for up to 15 days before it is purged. Backups are encrypted, and the key that decrypts them is never written into the backup, so a backup file on its own is not readable. The limit of that is worth saying plainly: the backups, the live database and the keys all sit on the same server, under the same account. It protects you against someone walking off with a backup file, not against someone who gets into the server itself. We keep no off-site copy. Backups are used only to restore the service after a failure.

You can also disconnect a linked bank at any time. Disconnecting deletes that institution's accounts and transactions from Money Moonshot immediately; export first if you want to keep them.

Your rights and choices

You are in control of your information. Within the app you can:

Depending on where you live (for example, California under the CCPA/CPRA, or the EEA/UK under the GDPR), you may have additional rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. We honor these rights regardless of your location — to make a request, use the form on our support page or Settings → Help & legal → Contact us in the app. We do not sell or share your personal information as those terms are defined under U.S. state privacy laws, and we do not use it for cross-context behavioral advertising.

Age

Money Moonshot is for adults. Our Terms of Service require you to be at least 18, the app is not directed to anyone under 18, and we do not knowingly collect information from anyone under 18.

Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected by updating the effective date above and, where appropriate, notifying you in the app.

Contact

Questions about this policy or your data? Use the form on our support page, or Settings → Help & legal → Contact us in the app. We do not publish a support mailbox, because we would rather have one channel that works than an address that bounces.

Money Moonshot connects to financial institutions in read-only fashion to help you understand and manage your money. It does not move money on your behalf.