Last updated: November 20, 2025
We started How's My Money with a simple premise: You should never be the product. Most "free" financial apps make money by selling your data to lenders and advertisers. We charge a fair subscription fee so that our only customer is you. We don't sell your data, we don't display ads, and we don't "recommend" credit cards you don't need.
We only collect data that is strictly necessary to provide you with financial insights. This falls into three categories:
When you create an account, we collect your name, email address, and billing information. We use Stripe to process payments; we never see your full credit card number.
Through our partner Plaid, we access your account balances and transaction history. This connection is read-only. We cannot move money, and we never see your bank login credentials.
We collect standard logging information such as IP addresses, browser types, and app usage patterns to help us find bugs and improve the user experience.
We believe that sharing data should be rare and highly regulated. We never sell your data to third parties. We only share data in these instances:
With Your Partner: If you use a Household plan, your data is shared with the specific partner you invite. You can choose which accounts are shared and which stay private.
Service Providers: We use industry-leading partners to help run the app. This includes AWS (Hosting), Plaid (Banking Sync), Stripe (Payments), and OpenAI/Google (AI Processing). These partners are strictly forbidden from using your data for their own purposes.
Legal Requirements: We may disclose data if required by a valid legal subpoena. We will always notify you of such requests unless legally barred from doing so.
We use multiple layers of security to protect your household's financial life:
AES-256 Encryption
All sensitive data is encrypted at rest using the same standard as major banks.
TLS 1.3
Data in transit between your phone and our servers is fully encrypted.
Audit Logs
Every access to our backend is logged and monitored for suspicious activity.
Penetration Testing
We conduct regular security audits to ensure our defenses are robust.
You are in control of your data at all times. This includes:
You can export your entire transaction history to CSV at any time from your Settings menu. Your data should never be locked in.
If you close your account, we delete your personal and financial data from our active production databases within 30 days. Backups are purged within 90 days.
You can opt-out of optional data collection, such as analytics, through the settings menu.