Privacy Policy
Sloth Money Privacy Policy
This policy explains how Sloth Money handles data across slothmoney.app and the budget app at budget.slothmoney.app.
Last updated: July 2, 2026
Scope
This policy covers the Sloth Money marketing website and the Sloth Money budget app. The website helps people learn about the product. The app helps users plan budgets, track goals, connect accounts, categorise transactions, invite partners, and manage subscriptions.
The app handles financial data. We only collect that data when you create an account, enter it yourself, connect a provider, or use a feature that needs it.
For UK and EU data protection purposes, Sloth Money is the controller for the personal data described in this policy, except where a provider such as Stripe, GoCardless, SnapTrade, an authentication provider, or another integrated service acts as its own controller for parts of its service.
What we collect
- Account and sign-in data. This includes your Firebase user ID, email address, sign-in provider, verification status, session tokens, partner connection status, and account settings.
- Banking and investment data. If you connect accounts, we may receive institution names, account names, account identifiers, masked local account details, IBAN or equivalent aliases when provided, balances, currencies, account types, connection expiry dates, booked transactions, pending transactions, merchant or counterparty details, transaction references, amounts, and dates. Sloth Money currently uses GoCardless Bank Account Data for open banking connections and SnapTrade for brokerage or exchange connections such as the Coinbase pilot.
- Budget and goal data. This includes budgets, categories, line items, savings and investment plans, goals, contribution scenarios, manual balance entries, transaction assignments, split categories, cash transactions, and forecast settings.
- Partner and sharing data. If you invite or connect with a partner, we process invitation data, partner IDs, shared budget settings, shared account flags, shared joint-account transaction data, shared goal snapshots, and partner explanation requests or answers.
- Support and communication data. If you contact support or send an invitation, we process the message, request type, current app path, user agent, viewport, sender and recipient email addresses, and ticket status.
- Billing data. If you subscribe, Stripe handles checkout and payment details. Sloth Money stores Stripe customer, subscription, plan, status, price, and entitlement references.
- Analytics and device data. We collect page path, referrer hostname, coarse device type, campaign parameters, explicit app events, CTA clicks, signup and onboarding events, and similar usage data through tools such as PostHog, Sentry, and our minimized visit notification flow.
- Developer access data. If you create Agent API tokens, we store token metadata, scopes, expiry, revocation status, and secure token hashes. Agents can read transaction and category data or write assignments only within the scopes you create.
We do not receive your online banking password or bank login credentials. Bank and brokerage connection screens are handled by the relevant provider.
How we use it
- Provide the website, app, authentication, and support.
- Connect accounts, refresh balances, import transactions, and show linked account status.
- Build budgets, forecasts, savings plans, goal progress, and category views.
- Suggest or apply transaction categories using your category setup, transaction details, and prior categorisation patterns.
- Enable partner invitations, shared views, joint-account workflows, and partner transaction explanations.
- Manage subscriptions, trials, entitlements, checkout, and billing portal access.
- Measure marketing, onboarding, signup, and product usage through explicit events so we can improve the service.
- Debug errors, protect the service, prevent abuse, and meet legal obligations.
Lawful bases
Where UK GDPR or EU GDPR applies, we rely on different lawful bases depending on the purpose:
- Contract. To provide the app, authenticate you, connect accounts, import transactions, maintain budgets and goals, manage partner features, run Agent API access you request, and provide support.
- Consent. For optional bank or brokerage connection flows where a provider asks for your permission, for non-essential cookies or similar technologies where consent is required, and for any optional marketing choices that depend on consent. You can withdraw consent at any time, but this does not affect processing that happened before withdrawal.
- Legitimate interests. To secure the service, prevent abuse, debug errors, measure product performance through explicit telemetry, understand campaign effectiveness, and improve Sloth Money, where those interests are not overridden by your rights.
- Legal obligation. To keep records or respond to lawful requests when required by law.
You have a right to object to processing based on legitimate interests. This includes objecting to profiling based on those interests.
International transfers
Some providers may process data outside the UK, EEA, or your country. Where UK or EU transfer rules apply, transfers should rely on an adequacy decision, standard contractual clauses, the UK International Data Transfer Addendum or Agreement, or another recognised safeguard.
Contact us if you need more detail about the transfer safeguards used for a specific provider.
Partner sharing
Sloth Money is built for solo and shared money planning. If you connect with a partner, they may see shared budgets, shared goals, shared contribution details, accepted joint-account transactions, and shared categorisation or explanation information.
Personal account data is not automatically shared just because you invite a partner. Sharing depends on the app settings and account flags you choose.
Your UK and EU rights
- You choose whether to create an account, connect a bank, connect a brokerage or exchange, invite a partner, create an Agent API token, or subscribe.
- You can disconnect a linked provider in the app. Disconnects stop future sync for that connection, but they do not automatically delete historical app data already stored in Sloth Money.
- You can ask for access, correction, deletion, restriction, portability, or export of data we can identify.
- You can object to processing based on legitimate interests, including related profiling.
- Where we rely on consent, you can withdraw that consent at any time.
- You can complain to a supervisory authority. In the UK, that is the Information Commissioner's Office. In the EU, you can complain to the supervisory authority where you live, where you work, or where you think an infringement happened.
Some browsers send Do Not Track signals. We do not currently respond to those signals because there is no single accepted technical standard for them.
We aim to respond to rights requests within one month where UK or EU data protection law applies.
Security and retention
We use authentication gates, backend token checks, database security rules, server-side provider secrets, scoped Agent API tokens, and provider-managed connection flows to protect user data.
We keep data for as long as needed to provide Sloth Money, maintain security, support users, comply with legal obligations, and preserve ordinary backups or operational records. If you ask us to delete identifiable account data, we will handle the request subject to legal, security, billing, and backup constraints.
AI-assisted categorisation can profile transaction patterns to suggest categories or line items, but Sloth Money does not make legal or similarly significant decisions about you solely by automated means.
Contact
For privacy questions or requests, contact Sloth Money through the support channel in the app.
We may update this policy as the product, providers, analytics setup, or legal requirements change. The date at the top shows the latest version.