Privacy Policy

Personal budgeting tool ("plaid-mcp") · Effective September 2026 · Contact: Kyle Spragg, kylesspragg@gmail.com

Who this applies to

This is a private budgeting tool that Kyle Spragg (the owner) runs for himself and a few family members he invites. Only people whose email address the owner has added can sign in; there is no public sign-up. Everyone, the owner included, accepts the tool's terms before using it. Each user connects only their own financial accounts, and each user's data is kept separate from every other user's: a user sees only their own budget, accounts, approvals and AI app sign-ins.

What data is collected

When an account is connected through Plaid, the tool can read, for that account only:

The tool also stores what the user enters: budget categories and monthly amounts, categorization rules, manually entered cash transactions, savings goals, and the bills and paychecks the user adds (name, amount, how often, the next date, which account pays it, and text to recognise the payment in the bank's list). To draw a net worth trend, it keeps one net worth total per day (not per-account balances) for about 200 days. So that "today" and "this month" match where the user is, it keeps the time zone their browser reported when they last opened the dashboard (for example America/Chicago).

When a user asks an AI assistant to change their budget, the change is not made; it is kept as a proposal (what would change, when it was asked, and whether it was approved) until that user approves or rejects it on the dashboard. Proposals expire after 7 days and are deleted 30 days after they are decided.

An AI app such as Claude or ChatGPT can connect by signing in with an allowed Google account. The tool then keeps a record of that sign-in: the app's name and the address it returns to, the email address that signed in, when, and one-way fingerprints of the app's tokens (not the tokens themselves). A sign-in lasts at most 90 days, and is deleted as soon as its user disconnects the app on the dashboard.

For each user it records their acceptance of the terms: the version, the date, and their email address.

For each connected account it keeps the access token Plaid issues for that connection (a credential that lets the tool read the data above; it is not the bank password). For accounts connected from the dashboard it also keeps the institution's name and Plaid's identifiers for the connection, all encrypted in the data store; otherwise the token is kept in the hosting provider's protected settings. Access tokens are never sent to the browser.

It does not collect identity data (name, address, phone, email from the bank), account or routing numbers, or login credentials. Bank credentials are entered only into Plaid and are never seen or stored by this tool.

How the data is used

Solely to show each user their own budget, spending, bills, balances, investments, and net worth. Data is never sold, used for advertising, or used for any other purpose. The owner runs the servers and holds the encryption keys, so he could technically read what is stored; he does not, except to fix a problem a user asks him about.

Where the data goes

No data is shared with anyone else.

How the data is protected

All connections use HTTPS (TLS 1.2 or later). Stored budget data, and the access tokens of accounts connected from the dashboard, are encrypted at rest with AES-256-GCM, each user's with their own key. Only a user signed in with Google can connect or disconnect their own accounts, and no change requested through an AI assistant takes effect until that user approves it there. An AI app can connect only after someone signs in with an allowed Google account and approves that app by name on this site. Transactions and balances are fetched from Plaid when needed rather than copied into a separate database; the only figure kept is the daily net worth total described above. Access to every system involved is limited to the owner and protected by multi-factor authentication.

Retention and deletion

Data is kept only while an account remains connected. Disconnecting an account (from the dashboard) removes it from Plaid and deletes its access token. Deleting the application deletes all stored data. A user can delete their account at any time from the dashboard (Delete my account, under Connect accounts): each of their connections is removed at Plaid and everything stored for them is deleted at once. They can also ask the owner (kylesspragg@gmail.com), who does the same within 30 days. To stop Plaid's own access, any user can also manage their connections at my.plaid.com.

Changes

Users will be told about changes to this policy. If the tool is ever opened beyond invited family members, this policy will be updated before anyone new connects an account.