Privacy Policy
Effective July 24, 2026
MoneyPortal ("the app") is a self-hosted, single-user personal finance dashboard operated by Adam Lauper. It exists to display the operator's own financial information in one place. It has no other users, no customers, and no commercial use of data of any kind.
What data the app collects
With your explicit authorization through Plaid, the app retrieves read-only financial data from linked institutions: account names and types, balances, investment holdings, and transactions. The app requests only Plaid's data-retrieval products — it cannot move money, initiate transfers, or trade, and no such capability exists in its code.
The app never sees or stores your bank username or password. Credentials are entered directly with your bank or with Plaid; the app receives only an access token scoped to read-only data.
How data is used
Retrieved data is used solely to render the dashboard: net-worth totals, balance history, budgets, and transaction lists. Data is never sold, rented, shared, or used for advertising, profiling, or model training. There are no analytics or tracking scripts.
Where data lives and how it's protected
- All data is stored locally in the app's own database on hardware controlled by the operator — not in a shared cloud service.
- Plaid access tokens and MFA secrets are encrypted at rest.
- The app is served over HTTPS and requires sign-in with a password plus a one-time code from an authenticator app (MFA).
Third parties
The only third party involved is Plaid Inc., which provides the connection to financial institutions. Plaid's handling of your data is described in the Plaid End User Privacy Policy. You can review and revoke Plaid connections at any time at my.plaid.com.
Cookies
The app sets a single session cookie used for authentication. There are no advertising, analytics, or cross-site cookies.
Data retention and deletion
Data is kept until the operator deletes it. Unlinking an institution in the app immediately
revokes its Plaid access token at the source (via Plaid's /item/remove), and
deleting an account or institution removes its stored history. Access can also be revoked
from the bank's side or at my.plaid.com, which the app honors automatically.
Contact
Questions about this policy: adamlauper@hey.com.
Changes
If this policy changes, the effective date above will be updated. Since the app has a single user who is also its operator, no further notice mechanism is needed.