1. Our Privacy Promise
Your financial data is deeply personal. ThenAllocate is built on a local-first model — your transaction history, allocation tags, Narratives, Provisions, and reflections live on your device, not on our servers.
When you connect a bank account, transaction data flows from your financial institution through Plaid to your device. Our relay server facilitates that connection in real time but does not persistently store your raw financial data. What you tag, how you reflect, and what your spending patterns reveal about your life stays yours.
We collect only what is necessary to deliver the App and its optional premium features. We do not sell your data. We do not share your financial data with advertisers. We do not profile you.
2. What We Collect
Financial Data (Retrieved via Plaid, Stored Locally)
When you connect a bank account, ThenAllocate retrieves the following through Plaid and stores it locally on your device:
- Transactions: Amounts, dates, merchant names, Plaid-assigned categories, and payment channel
- Account Information: Account name, type (checking, credit, etc.), last four digits of account number, institution name
- Balances: Current and available balances at time of sync
This data passes through our relay server in transit (see Section 6) and is stored in a local SQLite database on your device. It is not persistently stored on our servers.
Allocation and Tagging Data (Created by You, Stored Locally)
All data you create within the App is stored locally on your device:
- Narrative labels you assign to transactions
- Alignment tags (Aligned, Reserve, Overhead, Leak)
- Provision categories and names (premium)
- Ledger Tags and groups (premium)
- Transaction notes
- Manual accounts and transactions you enter
- Weekly reflection status and timestamps
- Rules and recurring transaction configurations
Premium Subscription Data
If you purchase ThenAllocate+:
- Transaction Identifiers: RevenueCat processes subscriptions and receives anonymous transaction identifiers to verify your premium status
- Subscription Status: The App stores whether you have an active premium subscription
- No Personal Information: We do not receive your name, email, payment details, or other personal identifiers through the subscription process
Technical Data
- Device Information: Device model and iOS version for compatibility
- Anonymous Crash Reports: Optional crash diagnostics via Apple's standard reporting (opt-in via iOS Settings)
- Anonymous Usage Analytics: Anonymized, non-personally-identifiable signals about feature usage and app lifecycle events. All identifiers are cryptographically hashed before leaving your device. The content of your financial data, tags, or notes is never sent. Analytics are processed by TelemetryDeck, a privacy-focused, GDPR-compliant analytics provider based in the EU.
Support Communications
If you contact us for support, we may receive your email address and any information you choose to include.
3. What We Do NOT Collect
ThenAllocate does not collect, store, or transmit:
- Your banking username or password
- Full account numbers or routing numbers
- Social Security numbers or government identifiers
- Credit scores or credit reports
- Your transaction content, allocation tags, Narratives, or notes (these stay on your device)
- Location data or GPS coordinates
- Contact lists or social graphs
- Health or biometric data
- Third-party advertising identifiers
- Behavioral analytics linked to your identity
- Information about any other apps on your device
4. How We Use Information
Core App Functionality
- Sync transaction data from Plaid to your device when you refresh or open the App
- Store all financial data, allocations, and reflections locally on your device
- Process premium subscription status through RevenueCat
- Deliver local notifications for weekly reflection prompts (if enabled)
- Apply rules to auto-tag incoming transactions on your device
Support and Improvement
- Respond to support requests you initiate via email
- Fix bugs identified through anonymous crash reports
- Ensure App compatibility with iOS updates
- Understand aggregate, anonymous feature usage patterns to improve the App experience
5. Financial Data and Plaid
How Plaid Works
ThenAllocate uses Plaid Technologies, Inc. to connect to your financial institutions. When you connect a bank account:
- Plaid presents a secure authentication interface directly with your financial institution
- Your credentials are entered directly into Plaid's interface — ThenAllocate never sees them
- Plaid retrieves a token that allows ThenAllocate to request your transaction and account data
- That token is stored locally on your device and used for subsequent syncs
- Transaction and account data is retrieved via our relay server and stored locally on your device
Plaid's Data Practices
Plaid has its own privacy policy and data practices independent of House of Then, LLC. You can review Plaid's End User Privacy Policy at https://plaid.com/legal/end-user-privacy-policy. You can manage and revoke Plaid's access to your financial institutions at https://my.plaid.com.
What Happens When You Disconnect
When you disconnect a bank account within ThenAllocate:
- The Plaid Item (connection token) is removed from your device and from Plaid's system via our relay server
- Your existing local transaction history and allocations are preserved on your device
- The active connection between Plaid and your financial institution is severed
- Plaid may retain previously downloaded transaction data per their own retention policy
To fully manage Plaid's access to your data, you can visit your financial institution's connected apps settings or https://my.plaid.com.
6. Relay Server and App Attest
Purpose of the Relay Server
ThenAllocate communicates with Plaid's API through a relay server operated by House of Then, LLC. The relay server exists to:
- Keep Plaid API credentials out of the App binary (they are never included in the App distributed to users)
- Facilitate real-time transaction sync requests between the App and Plaid
App Attest Authentication
All communication between ThenAllocate and the relay server is authenticated using Apple's App Attest framework. This means:
- Only legitimate, unmodified copies of ThenAllocate distributed through the App Store can communicate with our relay server
- Modified or spoofed versions of the App cannot retrieve your financial data through our infrastructure
- Your device generates a cryptographic attestation that is verified by our relay server before any Plaid request is processed
What the Relay Server Does Not Do
- The relay server does not persistently store your raw transaction data
- The relay server does not log or record your financial information beyond what is necessary to process the request in real time
- The relay server does not have access to your allocation tags, Narratives, Provisions, notes, or any data you create within the App
7. Data Storage and Security
Local-First Architecture
All financial data, allocation data, and personal reflections are stored in a SQLite database on your device using iOS secure local storage. No ThenAllocate servers store your personal financial data. Data persists through App updates but is removed when you delete the App.
Security Measures
- Local data is protected by iOS's built-in security and device encryption
- Data is sandboxed and inaccessible to other apps on your device
- Relay server communication is authenticated via App Attest for every request
- No financial data is transmitted to third-party servers beyond the relay server's real-time Plaid API calls
- Regular security reviews of our codebase and relay server infrastructure
Device Security
Your device is the primary security boundary for your financial data. Anyone with access to your unlocked device can view your connected financial data within ThenAllocate. We strongly recommend using a device passcode, Face ID, or Touch ID.
8. Third-Party Services
Plaid Technologies, Inc.
Purpose: Bank account connection and transaction data retrieval
Data Shared: Authentication tokens; Plaid retrieves transaction and account data from your financial institution on your behalf
End User Privacy Policy: https://plaid.com/legal/end-user-privacy-policy
Plaid has its own privacy practices independent of House of Then, LLC. By connecting a bank account, you authorize Plaid to retrieve your financial data on behalf of ThenAllocate. You can manage Plaid's access at https://my.plaid.com.
RevenueCat
Purpose: Premium subscription management and verification
Data Shared: Anonymous app user ID and transaction identifiers
Privacy Policy: https://www.revenuecat.com/privacy
TelemetryDeck (Product Analytics)
Purpose: Anonymous, privacy-first product analytics
Data Shared: Cryptographically hashed identifiers and anonymous event data — TelemetryDeck cannot identify you personally
Privacy Policy: https://telemetrydeck.com/privacy
TelemetryDeck is GDPR-compliant, based in the European Union, and does not sell or share data with third parties. The content of your financial data, allocation tags, or notes is never included in analytics events.
Apple Services
- App Store: App distribution and payment processing
- App Attest: App authenticity verification
- Privacy Policy: https://www.apple.com/privacy
9. Your Privacy Rights
Access and Control
- View: All your financial data and allocations are visible within the App
- Export: Your allocation and transaction data can be accessed at any time within the App
- Delete: Remove individual transactions, allocations, or all data in Settings
- Disconnect: Remove bank connections at any time through the Accounts tab
- Portability: Your local data travels with your device backups
Data Deletion
- Delete Allocations: Remove individual tags and notes within the App
- Disconnect Banks: Remove bank connections through Accounts tab; this revokes Plaid's token
- Delete All Local Data: Deleting the App removes all locally stored financial data permanently
Subscription Management
- Cancel Subscription: Manage ThenAllocate+ through iOS Settings > [Your Name] > Subscriptions
- Restore Purchases: Use "Restore Purchases" in App Settings to restore premium access on a new device
10. Regional Privacy Protections
California Privacy Rights (CCPA)
If you are a California resident:
- Right to Know: You can request details about the personal information we collect
- Right to Delete: You can request deletion of your personal information
- Right to Opt-Out: We do not sell personal information, so no opt-out is required
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Since ThenAllocate stores financial data locally on your device, you already have direct control. Deleting the App or disconnecting accounts exercises your deletion rights. To exercise formal rights, contact privacy@houseofthen.com.
European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland:
- Legal Basis: We process data based on your consent (bank connection, subscription) and legitimate interests (App functionality)
- Data Portability: Your local data is accessible and can be removed at any time
- Right to Erasure: Delete data within the App or by uninstalling
- Data Minimization: We collect only what is necessary for App functionality
To exercise any of these rights, contact privacy@houseofthen.com. We will respond to verified requests within 30 days.
11. Children's Privacy
ThenAllocate is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information or connected bank accounts through ThenAllocate, please contact us immediately at privacy@houseofthen.com.
12. Data Retention
Local Financial and Allocation Data
Transaction data, allocations, Narratives, Provisions, and all other data you create remains on your device indefinitely until you delete it. Deleted data is immediately removed and cannot be recovered. Deleting the App removes all local data permanently.
Support Communications
Support emails are retained for service quality and legal compliance, then deleted after resolution unless legally required to maintain.
Subscription Records
Managed by RevenueCat according to their retention policies, necessary for subscription management and fraud prevention.
Relay Server Logs
The relay server may retain minimal operational logs (request timestamps, error codes) for debugging and security purposes. These logs do not contain your financial data, transaction details, or personal identifiers. Logs are retained for no more than 30 days.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date at the top of this policy, provide in-app notification for significant changes, and request consent where legally required. Your continued use of ThenAllocate after changes indicates acceptance of the updated policy.
14. Contact Us
House of Then, LLCEmail: privacy@houseofthen.com
Website: https://houseofthen.com
For the most responsive support: use the in-app support feature (premium users) or email us directly with "ThenAllocate Privacy" in the subject line.
This Privacy Policy is governed by the laws of California and the United States. By using ThenAllocate, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.
Your financial data is personal. ThenAllocate is built to help you understand your spending with clarity and intention, while keeping your financial life private and secure.