This disclosure describes how Delta handles personal information for the goMoney consumer app. It is not legal advice and does not claim SOC 2 certification.
1. Who we are
Delta operates goMoney, a consumer mobile app that helps people build better financial habits (budgets, coaching, and optional bank-connected transaction history for premium users). We are not a bank, broker, or payment processor; we do not move money, originate loans, or offer investing or trading.
2. Scope
This policy covers personal information processed when you use the goMoney mobile application and related API services operated by Delta under the goDelta.us domain family.
3. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account / identity | Email or other sign-in identifiers; authentication subject id | You; Clerk |
| App usage / coaching | Savings mission, budgets, manual ledger entries, category overrides, coaching choices | You |
| Bank connection (premium) | Institution label, connection status, Plaid Item id; encrypted access token on our servers only | Plaid Link + our API |
| Transaction data (premium) | Merchant/name, amount, date, category signals mapped into your private ledger | Plaid → our database |
| Device / technical | App version, request metadata, coarse diagnostics | Device / infrastructure |
| Screen Time protection (optional) | Opaque Apple Family Controls tokens for apps/sites you select to pause (on-device only). Confirmed catalog labels for those pairings may be stored with your watch list — not bundle ids or hostnames | You (system picker); iOS on-device; watch labels on our API |
| Support | Messages you send to our privacy or security contact | You |
The mobile app does not store Plaid access tokens, account or routing numbers, or PANs. Access tokens remain on our servers, encrypted.
4. How we use information
- Provide and secure goMoney accounts and coaching features
- Authenticate you (via Clerk) and authorize API access
- For premium users who connect a bank: sync transactions into your private ledger and coach budgets and habits
- If you opt in to protection: place Screen Time shields on apps/sites you selected so you can pause before impulse spend (self-control / digital wellbeing on your own device)
- Operate, debug, and protect the service
- Respond to privacy, security, and support requests
- Comply with law and enforce terms
We do not sell your personal information, and we do not sell Plaid-sourced consumer data. We do not use Screen Time / Family Controls data for advertising, ad targeting, or unrelated profiling.
5. How we share information
We use service providers to run goMoney. They process data only for the purposes we specify:
| Processor | Role |
|---|---|
| Clerk | Consumer identity and session (no ledger or Plaid tokens in Clerk) |
| Plaid | Bank Link / connection and transaction payloads we request (Transactions) |
| RevenueCat | In-app purchase entitlement (Apple IAP). Receives our opaque user id, not ledger or Plaid tokens |
| PostHog | Product analytics. Opaque user UUID plus allowlisted event properties (no amounts, merchants, or tokens) |
| Sentry | Crash / error diagnostics. Opaque user UUID; payloads scrubbed |
| Amazon Web Services (AWS) | Hosting, database, secrets, and encryption keys for staging/production |
| Cloudflare | DNS and delivery for goDelta.us hostnames (including this page) |
We may also disclose information if required by law, to protect rights and safety, or in connection with a corporate transaction (with appropriate protections).
6. Bank linking (Plaid)
If you choose Connect bank (premium):
- You complete Plaid Link and authorize sharing of the data categories Plaid shows you.
- Our servers exchange a short-lived public token and store an encrypted access token plus Item metadata.
- We call Plaid APIs to sync transaction fields we need for coaching into your ledger.
- On Disconnect bank, we remove the Plaid Item, destroy local token material, and keep historical synced ledger rows by default (unless you also request account deletion).
Plaid’s own privacy disclosures apply to data Plaid processes as described in their notices.
7. Screen Time / Family Controls (optional protection)
If you choose Activate protection, goMoney uses Apple’s Family Controls, ManagedSettings, and DeviceActivity APIs (plus Shield Action / Shield Configuration extensions) so iOS can show a pause shield when you open an app or website you selected:
- iOS asks you to authorize Screen Time access for goMoney.
- You pick specific apps and/or websites in Apple’s system picker. Selected targets are represented as opaque tokens — we do not scrape your full install list for advertising.
- Shields apply only to those tokens. Completing a short budget-aware cool-down in goMoney (wait or temporary override) is how you continue.
- You can turn protection off or change selections anytime in Settings. If you decline Screen Time, goMoney remains usable via in-app Pause and optional notifications (Protection limited).
This is a self-control / personal digital wellbeing feature on your device — not parental control of another person’s device, and not a card or Apple Pay freeze. Opaque selection tokens and local shield/unlock flags stay on-device (App Group); they are not sold or used for ad targeting. Bundle ids and website hostnames of the apps or sites you shield are not stored on our servers.
8. Retention
- Plaid access tokens: only while a bank connection is active; destroyed on disconnect, Item remove, or account deletion
- Synced and manual ledger / coaching data: while your account is active; deleted or irreversibly anonymized when you Delete account in Settings (usually immediately; within 30 days at latest)
- Screen Time OS selection / shield state: on-device while protection is active; cleared when you turn protection off or uninstall
- Urge windows: deleted automatically about 7 days after they end
- Application logs: short operational window (typically 90 days or less unless investigating an incident); designed not to contain access tokens or full account numbers
9. Your choices and rights
- Disconnect bank in Settings (removes the live connection; history kept by default — this is not account deletion)
- Delete account in Settings (Apple 5.1.1(v)): removes your goMoney account, bank connection, and personal data in primary systems (usually immediately; within 30 days at latest). Sign-in identity is revoked.
- Turn off or change protection in Settings (clears or updates Screen Time shields)
- Sign out or stop using the app
- Other privacy requests (access, correction, portability, appeal, or deletion if you cannot use the app): email [email protected] from the address on your account; we verify and process per this policy and applicable U.S. state privacy laws. Target: 45 days
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of certain personal information, and to appeal a denial. We will not discriminate against you for exercising privacy rights.
10. Security
We use technical and organizational measures appropriate to the sensitivity of financial coaching data, including TLS in shared environments, encryption of Plaid access tokens at rest (AWS KMS on staging/production), server-side authorization, and log redaction. No method of transmission or storage is 100% secure.
11. Children
goMoney is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Screen Time protection is a self-control tool for the signed-in user, not a parental-control product for another person’s device. We delete any account we learn belongs to a child under 13.
12. International users
goMoney is built for U.S. consumers (iOS-first). If you access the service from elsewhere, you understand your information may be processed in the United States.
13. Changes
We may update this policy. The effective date above will change when we do. Material changes will be reflected at this URL and, when appropriate, via in-app notice.
14. Contact
Privacy / security: [email protected]
Vulnerability disclosure: gomoney.godelta.us/security
Product: goMoney by Delta · godelta.us
15. U.S. state privacy
We do not sell your personal information and we do not share it for cross-context behavioural advertising. Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of certain personal information, and to appeal a denial. Email [email protected] from the address on your account (target 45 days). We will not discriminate against you for exercising privacy rights.