Legal
Privacy Notice
Last updated: August 6, 2026 · Version 2026-08-06
This Privacy Notice describes how MoneyYogi LLC, a Texas limited liability company ("MoneyYogi", "we"), collects and uses personal information when you use the MoneyYogi service. MoneyYogi LLC is the data controller for the personal information described here.
1. Information we collect
- Account information: name, email, password hash, profile preferences.
- Linked financial data: account balances, transaction history, and institution metadata received read-only from Plaid when you connect a bank.
- Manual entries: accounts, transactions, budgets, goals, tags, and notes you create.
- AI conversations: prompts you send to the in-app chat and the responses generated, along with the minimum context needed to answer. AI chat is a shared surface within a Space — see Section 5.
- Usage data: log data, device identifiers, IP address, and feature interactions.
- Support communications: messages you send to us.
2. How we use it
- To create and operate your account and provide the service.
- To organize and display your financial picture.
- To power the in-app AI chat and related AI skills. Transaction categorization is rules-based and deterministic — see Section 4.
- To improve the product, debug issues, and prevent fraud and abuse.
- To respond to support requests.
- To send service-related communications.
3. Scope
MoneyYogi is offered to residents of the United States. This Privacy Notice describes our practices under U.S. federal and state law. If you access the service from outside the U.S., you do so on your own initiative and are responsible for compliance with local laws.
4. AI features
When you use MoneyYogi's in-app AI chat or a related AI skill, your prompt and the minimum context needed to answer (for example a date range, a category, or a small set of transactions) are sent to our AI gateway, which routes the request to a large language model provider (currently Google's Gemini family of models) strictly to generate a response. Transaction categorization is different: it is a deterministic, rules-based cascade (your rules, then remembered merchant assignments, then Plaid's personal-finance category codes). Categorization does not send transaction context, merchant names, or amounts to a large language model.
- Your data is not used to train third-party AI models.
- Your chat history is stored encrypted inside your Space so members can revisit past conversations. Service logs are retained briefly for debugging, safety, and abuse review, then purged on a rolling basis.
- AI output may be inaccurate or out of date and is not financial, investment, legal, or tax advice.
- Please do not paste content into the chat that you do not want processed by a large language model or seen by other members of the same Space.
4a. Third-party AI clients (MCP)
MoneyYogi offers an optional interface (the "Model Context Protocol" or "MCP" endpoint) that lets you connect an external AI client — for example a third-party AI assistant or agent — to your MoneyYogi account. When you connect and authorize a client, the client can call the read-only tools MoneyYogi's MCP endpoint currently exposes. Today those tools are limited to identifying your account (your user id and email) and listing your Spaces (id, name, kind, and creation date). We may add additional read-only skills over time; when we do, this section will be updated to describe them. We transmit data to the client only in response to its authorized request.
Once data is delivered to an external AI client, it is stored and processed by that client according to its own privacy notice and terms, which we do not control. To revoke a client's access, email josh@moneyyogi.ai from the address on your account and we will revoke the authorization; a self-serve control is not yet available. Revocation stops future requests but does not recall data already delivered.
5. Shared workspaces (Spaces)
MoneyYogi organizes data into Spaces (e.g. a Personal space and one or more Business spaces). Data inside a Space is visible to every member of that Space according to their role, owner, editor, or viewer. The Space owner controls billing, membership, and deletion of the Space. Inviting a member grants them access to that Space's financial data; removing a member revokes it going forward.
AI chat is a shared surface within a Space. Anything an owner or editor types into the in-app AI chat, and the AI's response, is stored in the shared chat history and is visible to owners and editors of that Space. Viewers do not have access to the chat surface. Do not use chat for anything you do not want other owners or editors of the same Space to see. Personalization notes set in Settings are the exception — they are stored per-account and are not visible to other Space members.
6. Sharing
We share information with a limited set of sub-processors that help us operate the service. A full, current list, with purpose, data categories, and links to each provider's terms, is published on our Sub-processors page. At a high level:
- Stripe, Inc.: payment processor for subscriptions and one-time coaching-call purchases; stores the payment method and provides the billing portal. MoneyYogi LLC is the seller and is responsible for billing, refunds, and support.
- Plaid Inc.: to enable read-only connections to your financial institutions.
- Lovable Cloud: hosting, database, authentication, file storage, transactional email, and the AI Gateway that routes requests to Google's Gemini family of models. Per the Lovable AI Gateway and Google Gemini API terms, your prompts and responses are not used to train AI models.
- Perplexity AI, Inc.: web search for the assistant's search tool when it needs current external information (for example contribution limits or rates). Only the search query text is sent, never your account, transaction, or balance data.
- Google Calendar: solely if you book a coaching call via the link on the in-app coaching page (scheduling only).
- Professional advisors and authorities: where required by law.
We do not sell personal information and do not share it for cross-context behavioral advertising.
7. Security
We use appropriate technical and organizational measures to protect your information, including:
- TLS 1.2+ for data in transit;
- AES-256-GCM encryption at rest for account names and balances, transaction details, AI conversation content, merchants, and recurring streams;
- Row-level access controls so each Space's data is isolated;
- Optional two-factor authentication (TOTP): strongly recommended, available to every account from Settings → Security;
- Audit logging of sensitive administrative actions.
7a. Security incidents
If we determine that a security incident has compromised your personal information, we will notify you and applicable authorities without undue delay and consistent with applicable state breach-notification laws.
8. Retention
- Active accounts: we retain your data for as long as your account is active.
- After deletion: soft-deleted data is purged from production within approximately 30 days.
- Financial records: we may retain certain transaction and billing records for up to 7 years to comply with tax, accounting, and audit obligations.
- Service logs: retained for approximately 90 days for security and debugging.
9. Children's privacy
MoneyYogi is offered only to users 18 years of age or older. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe we have collected personal information from a minor, please contact us and we will delete it.
10. Your rights
Depending on the state you live in, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Delete your personal information;
- Port your information to another service in a machine-readable format;
- Limit our use of sensitive personal information (financial account information is sensitive PI under CPRA); and
- Opt out of any sale, sharing, or targeted advertising use of your personal information, although we do none of these.
How to exercise these rights. You can export your own data at any time from Settings → Privacy & Data (a 6-digit verification code is emailed to the address on your account before the download is generated). For access, correction, deletion, portability, or any other request, email josh@moneyyogi.ai from the address associated with your account. We will respond within 45 days (and may extend by an additional 45 days when reasonably necessary, with notice to you). We verify requests using information already associated with your account; we will not disclose personal information to anyone we cannot reasonably verify.
Authorized agents. You may designate an authorized agent to exercise these rights on your behalf. We will require written permission signed by you and verification of the agent's identity.
Right to appeal. If we decline a privacy request, you may appeal our decision by replying to our response email. We will respond to appeals within 45 days.
Your privacy choices / Global Privacy Control (GPC). We do not sell or share your personal information for cross-context behavioral advertising and we do not engage in targeted advertising. We use Google Analytics for basic measurement on public pages, on by default, and you can turn it off for this browser below. We honor the Global Privacy Control signal automatically as an opt-out.
11. U.S. state privacy rights
California residents (CCPA/CPRA): you have the rights described in Section 10, including the right to limit the use of sensitive personal information. We do not sell personal information and do not share it for cross-context behavioral advertising.
Texas residents (TDPSA) and residents of other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Montana, Oregon, Delaware, New Hampshire, New Jersey, Minnesota, Iowa, and Maryland) have analogous rights to access, correct, delete, port, and appeal as described in Section 10.
12. Cookies and analytics
We use strictly necessary cookies and similar technologies required to operate the service (authentication, session management, and security). We do not use advertising or behavioral-tracking cookies, and we do not share data for cross-context behavioral advertising.
On public marketing and onboarding pages we use Google Analytics for basic measurement of how visitors discover MoneyYogi. For U.S. visitors it loads by default. You can opt out at any time using the control in Your Privacy Choices above; the change takes effect immediately on that browser. We also honor the Global Privacy Control browser signal automatically — when it is present, no analytics loads at all. Google Analytics receives only a page-view or event signal; it never receives your balances, transactions, institutions, or any other financial data.
No analytics or marketing scripts run on signed-in /dashboard pages past the paywall.
13. Contact
MoneyYogi LLC, privacy questions can be sent to josh@moneyyogi.ai or through in-app support.