1. Overview
planwithzen is a personal finance application for iPhone, with a supporting website at planwithzen.com. It helps you track what you earn, spend, own, and owe, and build plans for paying down debt and reaching savings goals.
This policy explains what information the app collects, where it is stored, who else can see it, how long it is kept, and what control you have over it.
Financial information you enter or retrieve through planwithzen may be stored on your device and synchronized with planwithzen’s hosted systems. Synchronization allows you to access your information through supported mobile and web applications after signing in and completing any required verification. The rest of this policy explains what we collect, how it is stored, and the controls available to you.
We have written this policy to be read rather than skimmed past. If anything in it is unclear, write to us at hello@planwithzen.com and we will explain it.
2. Who We Are
planwithzen is operated by planwithzen LLC, a Texas limited liability company based in the United States. For the purposes of privacy law, we are the controller (and, under U.S. state privacy laws, the business) responsible for the limited personal information described in this policy.
General contact: hello@planwithzen.com
Security and vulnerability reports: security@planwithzen.com
Mailing address: provided on written request to hello@planwithzen.com.
Because we operate exclusively online and have a direct relationship with the people who use the app, email is our designated method for submitting privacy requests. We aim to respond within five business days and, where a law sets a deadline, within that deadline.
3. What This Policy Covers
This policy covers the planwithzen mobile app for iPhone, the planwithzen.com website, and our support correspondence with you.
It also covers account registration, login, account recovery, and multi-factor authentication services provided through planwithzen.
Which of these apply where. Two-factor authentication and SMS verification are features of the planwithzen web application. Where this policy describes a mobile telephone number, an SMS verification code, SMS consent records, or Twilio, it is describing the web application. The planwithzen iPhone app does not offer two-factor authentication, does not ask for a telephone number, and does not send SMS messages. Everything else in this policy applies to both.
It does not cover third-party services you reach through the app, or your bank, card issuer, or lender. Those operate under their own privacy policies. It also does not cover Plaid's own handling of the information you give directly to Plaid, which is governed by Plaid's end user privacy policy at plaid.com/legal/#consumers.
4. Information We Collect
4.1 Financial information you enter
You may enter income, expenses, assets, debts, budgets, financial goals, and related planning information. This information may be stored on your device and synchronized with planwithzen’s hosted systems so that it is available through supported mobile and web applications. See Section 6.
4.2 Financial information from connected accounts
If you choose to connect a bank, card, loan, or investment account, we may retrieve the financial institution name, account name and type, the last four digits of the account number, account balances, interest rates, minimum payments, and the charges that look like they repeat, for the accounts you connect. We do not retrieve your transaction history. The last four digits help you identify the account within planwithzen. This is done through Plaid, at your instruction. See Section 8.
4.3 A device credential
The first time you open the app, it generates a long random secret on your device and stores it in the device's secure storage (the iOS Keychain). The app presents this secret to our service so the service can recognize that a request comes from your device and return only your device's data.
We describe this as a credential rather than an identifier because that is what it is: it authenticates your device to our service in place of a username and password. It is not derived from your name, email address, mobile telephone number, or any advertising identifier. If you create an account, the credential may be associated with your account and device for authentication and security purposes.
The secret stays on your device. It is not included in device backups and does not transfer to a new phone.
4.4 Account and authentication information
If you create a planwithzen account, we collect the information needed to establish and secure that account. This may include your email address, mobile telephone number, account identifier, authentication status, and records relating to account registration, login, account recovery, and multi-factor authentication.
When you request an SMS verification code, planwithzen uses your mobile telephone number to send a one-time transactional security code. Standard message and data rates may apply. SMS verification messages are sent only when needed to register, verify, recover, or protect your account.
We retain evidence of your consent to receive verification messages, including the telephone number provided, the date and time of consent, the consent language presented, and the method through which consent was provided.
4.5 Subscription status
If you purchase a Momentum subscription, RevenueCat records that a purchase was made and which plan is active, tied to your planwithzen account identifier. RevenueCat does not receive the financial records you enter in planwithzen. Apple processes the payment. We never see your card number, billing address, or the name on the card.
4.6 Support correspondence
If you email us, we have whatever you choose to put in that email, including your email address and anything you write. We ask that you do not send us account numbers, statements, or financial institution credentials; if you do, we will delete them from the correspondence.
4.7 Website usage
The planwithzen.com website may record basic server logs, including IP address, browser type, and the pages requested, for security and reliability. The website does not use advertising cookies, analytics that identify you, or cross-site trackers.
The app records an IP address in one circumstance: when a request to our service fails to authenticate. We keep it, with a one-way hash of the credential that failed, only to limit repeated attempts. It is not linked to your account, is never used to identify you, to advertise, or to personalize anything, and it is deleted after twelve months along with the rest of our security logs.
4.8 Where this information comes from
We obtain the categories above from you directly, from your device, from your financial institution through Plaid at your instruction, and from Apple and RevenueCat in the form of anonymous entitlement records.
5. Information We Limit or Do Not Currently Collect
We want to be specific about the information planwithzen does and does not collect:
We do not currently require your name to use the core financial-planning features. We may collect it if you provide it when creating or updating your account, contacting us, or using a future feature that requires it.
We collect a mobile telephone number when you provide it for account registration, login, account recovery, security, or multi-factor authentication.
Future retirement-planning or estate-planning features may allow you to provide additional information, such as your mailing address, date of birth, or other information needed to use those features. We will disclose what information is requested, why it is needed, and how it will be handled before collecting it.
We never receive or store the username or password you use to access your financial institution. See Section 8.
We never receive or store your full payment card number. Apple processes App Store subscription payments and does not provide your full payment card number to planwithzen.
We do not use advertising trackers, advertising identifiers, or analytics software that transmits your personal information.
We do not collect precise location data.
We do not collect biometric data. Where you unlock the app with Face ID or Touch ID, the check is performed by your phone's operating system and the result, not the biometric itself, is returned to the app.
6. Where Your Information Is Stored
6.1 Device and hosted storage
Information stored locally in the app is kept in the app’s private storage and protected using encryption, your device passcode, and the operating system’s application sandbox. Financial information may also be transmitted to and stored in planwithzen’s hosted systems to support account synchronization and access through supported mobile and web applications.
6.2 What synchronization means for you
When synchronization is enabled, financial information associated with your planwithzen account may be available through supported mobile and web applications after you sign in and complete any required verification. Subscription restoration through Apple and access to synchronized financial information through your planwithzen account are separate processes.
Although synchronization can make information available across supported applications, planwithzen is not a substitute for financial statements, tax records, estate documents, or other records you are required or advised to retain. You should keep independent copies of information you cannot afford to lose.
A connected financial institution may require you to reconnect or reauthorize access for security or technical reasons.
6.3 What is stored in our hosted systems
We use Supabase to host information needed to create, authenticate, recover, and secure planwithzen accounts; synchronize financial information; and support connected financial institutions.
Hosted information may include your account identifier, email address, mobile telephone number, authentication status, SMS consent records, device-credential references, income, expenses, assets, debts, budgets, financial goals, financial information received through Plaid, and encrypted Plaid access tokens.
Our primary hosted environment is located in the United States. Information may also be maintained in operational logs, security systems, and backups as reasonably necessary to operate, protect, and restore the Service. Access is restricted to authorized systems and personnel for legitimate operational, security, support, and legal purposes.
7. How We Use Information
We use the information described above only to:
Show you your own financial picture, budget, payoff plans, and goals
Synchronize your information across supported planwithzen mobile and web applications
Retrieve balances and the charges that look like they repeat from institutions you have connected
Deliver the features included in your subscription
Respond to you when you contact us
Keep the app and our service secure, detect and prevent fraud and abuse, and diagnose faults
Meet legal, tax, and accounting obligations
We do not use your financial information to build advertising profiles, we do not use it to train machine learning models, and we do not use it for any purpose you would not reasonably expect from the description above. If we ever want to use it for a materially different purpose, we will ask first.
8. Connecting a Financial Institution
8.1 Connecting is optional
The app works without connecting anything. You can enter everything by hand and never use this feature. Nothing is connected unless you choose to connect it, and we show you what will be retrieved and why before you start.
8.2 We use Plaid
If you choose to connect an account, we use Plaid Inc. to make that connection. Plaid is a financial data network used by many financial applications.
8.3 We never see your bank credentials
You enter your financial institution username and password directly into Plaid's own secure screen, or you authenticate on your institution's own website. Those credentials go to Plaid and your institution. They are never sent to us, never pass through our systems, and are never stored by us. We will never ask you for them by email, in support correspondence, or anywhere else. If anyone claiming to be planwithzen asks you for them, it is not us.
Plaid’s screens may also ask for whatever your financial institution requires to authenticate you, which can include a telephone number and a one-time code sent to it. That exchange is between you, Plaid and your institution, under Plaid’s own privacy policy, which Plaid shows you before you begin. planwithzen does not ask for a telephone number, does not receive one from Plaid, and does not store one.
8.4 What Plaid does
Plaid collects and processes your information according to its own privacy policy, available at plaid.com/legal. We encourage you to read it. By connecting an account, you also agree to Plaid's end user privacy policy.
8.5 What we receive
We may receive the financial institution name, account name and type, the last four digits of the account number, account balances, interest rates, minimum payments, the charges that look like they repeat, and an access token that lets us retrieve authorized account information again. We do not request or receive your transaction history. We request only the data types needed for the features you use.
We do not receive or store your complete financial account number, routing number, or financial institution username or password.
8.6 Disconnecting
You can disconnect a financial institution at any time using the available planwithzen controls. When you disconnect, we instruct Plaid to remove the connection and revoke the associated access token, and we delete the token from our active systems within 24 hours. Financial information previously synchronized with your planwithzen account may remain until you delete that information or your account, subject to the retention provisions in Section 11.
9. Service Providers
These are the only companies that receive information in connection with the app, and what each one receives:
| Provider | Purpose | What it receives |
|---|---|---|
| Plaid Inc. | Financial account connectivity | Your financial institution credentials directly from you or your institution. Plaid may provide planwithzen with the financial institution name, account name and type, the last four digits of the account number, balances, recurring charges, applicable debt information, and an access token. Plaid does not provide planwithzen with your financial institution username or password. |
| Twilio Inc. | SMS verification and multi-factor authentication | Mobile telephone number, verification request information, message-delivery information, and verification status. Twilio does not receive your financial records. |
| Supabase Inc. | Account authentication, backend hosting, database, synchronization, and key management | Account identifiers, contact information, authentication information, SMS consent records, device-credential references, synchronized financial information, encrypted Plaid access tokens, connected-account information, and operational records. |
| RevenueCat, Inc. | Subscription entitlement management | Your planwithzen account identifier and your plan status. No financial records. |
| Apple Inc. | App distribution and payment processing | Your purchase and payment details, under their own policies. We receive only entitlement status. |
| Expo (650 Industries, Inc.) | App builds and over-the-air updates | Update delivery telemetry. No financial records. |
| Google Workspace | Business email | Support correspondence, if you write to us. |
| Domain, DNS, and website host | Operating planwithzen.com | Website server logs, including IP address. |
Each operates under its own privacy policy and under contractual or published terms that restrict what it may do with information received from us. We do not authorize our service providers to use information we provide for advertising or purposes unrelated to delivering their services to us. Information you provide directly to Plaid or Apple is also governed by their own privacy policies.
10. Sharing and Disclosure
We do not sell your information, and we do not share it for advertising.
We do not sell or share mobile telephone numbers, SMS consent records, or SMS opt-in information with third parties or affiliates for marketing or promotional purposes. We disclose this information only to service providers that help us deliver and secure authentication messages, or when disclosure is required by law.
We disclose information only:
To the service providers listed in Section 9, to operate the app
When you direct us to, such as connecting an institution
If required by law, subpoena, or valid legal process, after reviewing the request and, where we are permitted to do so, notifying you
To protect the rights, safety, or property of planwithzen, our users, or the public
In connection with a sale, merger, or transfer of the business, in which case we will post notice in the app before your information becomes subject to a different policy
Because synchronized financial information may be stored in our hosted systems, it may be subject to a valid legal request. We review legal requests and disclose information only when required by applicable law or when otherwise permitted as described in this policy.
11. Data Retention and Deletion
We keep information only as long as it serves the purpose it was collected for.
| Information | Retention | Notes |
|---|---|---|
| Your financial records on your device | Until you delete them | You can erase everything from within the app, or by uninstalling it. Uninstalling removes the data and its encryption key from your phone. |
| Plaid access tokens | While the connection is active | Revoked and deleted within 24 hours of disconnection. |
| Synchronized financial information | While your account remains active or until you delete the information | Removed from active systems following deletion, subject to reasonable security, legal, fraud-prevention, and backup-retention requirements. |
| Account and authentication information | While your account remains active | Deleted following a verified account-deletion request, except where retention is reasonably necessary for security, fraud prevention, legal compliance, or resolving disputes. |
| SMS consent records | While your account remains active and as reasonably necessary to document consent and compliance | May include the telephone number, consent date and time, consent language presented, and method of consent. |
| Inactive devices | Until you delete them | We do not delete records or revoke connections because a device has been quiet. Disconnecting an institution, deleting your records, or deleting your account is what removes them. |
| Subscription records | As required for tax and accounting | Held by our subscription and payment providers. |
| Support email | 24 months maximum | Deleted sooner where the correspondence is closed and no longer needed. |
| Server logs | 12 months | Security and reliability. |
| Backups | According to our applicable backup schedule | Deleted information may remain in restricted backups until those backups are overwritten or deleted through the normal backup cycle. |
12. Security
We protect information with:
Encryption of your records on your device using AES-256, under a key held in your phone's secure storage and excluded from backups
Encryption and access controls for synchronized information stored in planwithzen’s hosted environment
Encryption of all data in transit using TLS 1.2 or higher, with cleartext connections disabled on iOS
Field-level encryption of access tokens at rest on our servers, with keys held separately from the data
Database authorization controls designed to prevent one account from accessing another account’s information
Multi-factor authentication on every account we use to run the service
Logging and alerting on authentication failures, unusual activity, and administrative access
Regular review of who and what has access, at least quarterly
A written internal information security policy, reviewed at least annually
No method of storage or transmission is completely secure, and we cannot guarantee absolute security. We use layered safeguards intended to protect information stored on your device and in planwithzen’s hosted systems. These safeguards reduce risk, but no storage or transmission method can guarantee absolute security.
If you believe you have found a security vulnerability, please write to security@planwithzen.com. We acknowledge reports within five business days.
13. Your Choices and Controls
13.1 Your financial records
You can view, correct, and delete financial information using the available planwithzen controls. Because synchronized financial information may be stored in our hosted systems, you may also request access to or deletion of that information by contacting hello@planwithzen.com.
We may require verification of your identity or control of the associated account before completing a request.
13.2 What we hold
You can disconnect a financial institution using the in-app controls. To access, correct, or delete account and authentication information held by planwithzen, use the available account controls or contact hello@planwithzen.com. We may require you to verify control of the associated account, email address, mobile telephone number, or device before completing the request.
13.3 An important limitation
We may require you to verify your identity or control of the email address, mobile telephone number, device, or account associated with a request before we disclose, correct, or delete account information. Verification protects your information from unauthorized access or deletion. If you email us a rights request, we will explain what we hold, how your identity must be verified, and what actions are available through your account. We will not delete or disclose records on the basis of unverified information, because doing so would let someone else act on your data.
13.4 Subscriptions
Manage or cancel through your Apple ID subscription settings. Cancelling your Momentum subscription through your Apple ID stops future subscription renewals. At the end of the current billing period, your account will be downgraded to the Free plan and you will lose access to Momentum features. Cancelling Momentum does not delete your planwithzen account or financial information. You can manage or delete your information separately using the available planwithzen account controls.
13.5 Notifications and tracking
The app does not track you across other companies' apps or websites and does not ask for permission to do so. You can control system-level permissions such as notifications at any time in your device settings.
14. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the rights to know, delete, correct, and opt out of the sale or sharing of your personal information, and to limit the use of sensitive personal information.
In the preceding 12 months we have collected the categories described in Section 4, which fall within the statutory categories of identifiers, such as an account identifier, email address, mobile telephone number, and device-bound credential, commercial information (subscription status), internet or network activity (website server logs), and financial information (account balances and recurring charges retrieved at your instruction). We collect them from the sources listed in Section 4.7, for the business purposes listed in Section 7, and disclose them only to the categories of recipients listed in Sections 9 and 10.
We have not sold personal information and have not shared it for cross-context behavioral advertising, in the preceding 12 months or at any other time.
To the extent an access token to a financial account constitutes sensitive personal information, we use it solely to perform the service you have asked for and to maintain security. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit under the CCPA.
We do not discriminate against you for exercising any of these rights, and we offer no financial incentive in exchange for personal information.
You may use an authorized agent to submit a request. We will require the agent to demonstrate authority and may also require verification of your identity or control of the account associated with the requested information.
Our website honors the Global Privacy Control signal. Because we do not sell or share personal information, there is nothing for the signal to opt you out of. We do not respond to browser Do Not Track signals, which have no agreed standard.
To exercise these rights, see Section 13. The limitation in Section 13.3 applies.
15. Other U.S. State Privacy Rights
Residents of Texas, Virginia, Colorado, Connecticut, Utah, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights to access, correct, delete, and obtain a copy of personal information, and to opt out of targeted advertising, sale, and certain profiling.
We do not engage in targeted advertising, we do not sell personal information, and we do not profile you in a way that produces legal or similarly significant effects. The access, correction, and deletion rights are exercised as described in Section 13.
If we decline a request, you may appeal by writing to hello@planwithzen.com with the word “Appeal” in the subject line. We will respond to an appeal within 45 days and, if we again decline, we will tell you how to contact your state attorney general.
Some of these laws may not apply to a business of our size. We honor these rights regardless of whether we are legally obliged to.
16. EEA and UK Rights
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights of access, rectification, erasure, restriction, portability, and objection under the GDPR and UK GDPR.
Our legal bases are: performance of a contract, for delivering the app and your subscription; consent, for connecting a financial institution, which you may withdraw at any time by disconnecting; and legitimate interests, for security, reliability, fraud prevention, and responding to you. Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and have limited what we collect accordingly.
planwithzen is directed to users in the United States and is not marketed in the EEA or the UK. If you use the Service from those regions, the rights above apply to personal information processed by planwithzen, and Section 13.3 explains how we may verify a request.
You may lodge a complaint with your supervisory authority. We would appreciate the chance to address your concern first.
17. International Users and Data Transfers
planwithzen is based in the United States, and our primary hosted systems are located in the United States. If you use the Service from outside the United States, your information may be transferred to, stored in, and processed in the United States, where data-protection laws may differ from those in your location.
Our service providers may process information in other locations as described in their applicable terms and privacy documentation. Where required, we rely on appropriate safeguards for international transfers, including applicable contractual protections.
18. Children
planwithzen is intended for adults. The app is not directed to children, and we do not knowingly collect personal information from anyone under 18, or from children under 13 within the meaning of the Children's Online Privacy Protection Act.
If you believe a person under 18 has created an account or provided personal information through the Service, contact us so that we can investigate and delete the information where appropriate.
19. No Sale or Sharing of Personal Information
We do not sell personal information, and we have never done so. We do not share personal information for cross-context behavioral advertising. We do not disclose personal information to data brokers, and we do not use financial data obtained through Plaid to train machine learning models.
This is a commitment, not a current-practice statement that we reserve the right to change quietly. If it ever changes, we will say so prominently in the app before the change takes effect and give you the opportunity to delete your data first.
20. Automated Decision-Making
The app performs calculations and projections on the figures you provide, such as debt payoff timelines and savings goal forecasts. These are arithmetic tools that you control and can override. We do not make automated decisions about you that produce legal or similarly significant effects, and we do not evaluate your creditworthiness or share any assessment of you with anyone. The financial health score the app shows you is worked out on your device from figures you entered, is shown only to you, and is never sent to us, to a lender, or to anyone else.
The app's projections are estimates, not advice. See our Terms of Use.
21. Data Breach Notification
If a breach affects your information, we will notify you and any required regulators as the law requires, without unreasonable delay.
Notification may be delivered through the app, by email using the address associated with your account, and through a notice published at planwithzen.com, as appropriate. Please keep the app installed and updated if you want to receive such a notice. We will also notify Plaid and any affected provider as our agreements with them require.
22. Changes to This Policy
We may update this policy. If changes are material, we will post notice in the app before they take effect and update the date at the top. Continued use after a change means you accept the updated policy. We will keep prior versions available on request so you can see what changed.
23. Contact
General questions and privacy requests: hello@planwithzen.com
Security and vulnerability reports: security@planwithzen.com
Mailing address: provided on written request.
We aim to respond within five business days.