Privacy Policy

Sloth Money Privacy Policy

This policy explains how Sloth Money handles data across slothmoney.app and the budget app at budget.slothmoney.app.

Last updated: July 2, 2026

Scope

This policy covers the Sloth Money marketing website and the Sloth Money budget app. The website helps people learn about the product. The app helps users plan budgets, track goals, connect accounts, categorise transactions, invite partners, and manage subscriptions.

The app handles financial data. We only collect that data when you create an account, enter it yourself, connect a provider, or use a feature that needs it.

For UK and EU data protection purposes, Sloth Money is the controller for the personal data described in this policy, except where a provider such as Stripe, GoCardless, SnapTrade, an authentication provider, or another integrated service acts as its own controller for parts of its service.

What we collect

  • Account and sign-in data. This includes your Firebase user ID, email address, sign-in provider, verification status, session tokens, partner connection status, and account settings.
  • Banking and investment data. If you connect accounts, we may receive institution names, account names, account identifiers, masked local account details, IBAN or equivalent aliases when provided, balances, currencies, account types, connection expiry dates, booked transactions, pending transactions, merchant or counterparty details, transaction references, amounts, and dates. Sloth Money currently uses GoCardless Bank Account Data for open banking connections and SnapTrade for brokerage or exchange connections such as the Coinbase pilot.
  • Budget and goal data. This includes budgets, categories, line items, savings and investment plans, goals, contribution scenarios, manual balance entries, transaction assignments, split categories, cash transactions, and forecast settings.
  • Partner and sharing data. If you invite or connect with a partner, we process invitation data, partner IDs, shared budget settings, shared account flags, shared joint-account transaction data, shared goal snapshots, and partner explanation requests or answers.
  • Support and communication data. If you contact support or send an invitation, we process the message, request type, current app path, user agent, viewport, sender and recipient email addresses, and ticket status.
  • Billing data. If you subscribe, Stripe handles checkout and payment details. Sloth Money stores Stripe customer, subscription, plan, status, price, and entitlement references.
  • Analytics and device data. We collect page path, referrer hostname, coarse device type, campaign parameters, explicit app events, CTA clicks, signup and onboarding events, and similar usage data through tools such as PostHog, Sentry, and our minimized visit notification flow.
  • Developer access data. If you create Agent API tokens, we store token metadata, scopes, expiry, revocation status, and secure token hashes. Agents can read transaction and category data or write assignments only within the scopes you create.

We do not receive your online banking password or bank login credentials. Bank and brokerage connection screens are handled by the relevant provider.

How we use it

  • Provide the website, app, authentication, and support.
  • Connect accounts, refresh balances, import transactions, and show linked account status.
  • Build budgets, forecasts, savings plans, goal progress, and category views.
  • Suggest or apply transaction categories using your category setup, transaction details, and prior categorisation patterns.
  • Enable partner invitations, shared views, joint-account workflows, and partner transaction explanations.
  • Manage subscriptions, trials, entitlements, checkout, and billing portal access.
  • Measure marketing, onboarding, signup, and product usage through explicit events so we can improve the service.
  • Debug errors, protect the service, prevent abuse, and meet legal obligations.

Lawful bases

Where UK GDPR or EU GDPR applies, we rely on different lawful bases depending on the purpose:

  • Contract. To provide the app, authenticate you, connect accounts, import transactions, maintain budgets and goals, manage partner features, run Agent API access you request, and provide support.
  • Consent. For optional bank or brokerage connection flows where a provider asks for your permission, for non-essential cookies or similar technologies where consent is required, and for any optional marketing choices that depend on consent. You can withdraw consent at any time, but this does not affect processing that happened before withdrawal.
  • Legitimate interests. To secure the service, prevent abuse, debug errors, measure product performance through explicit telemetry, understand campaign effectiveness, and improve Sloth Money, where those interests are not overridden by your rights.
  • Legal obligation. To keep records or respond to lawful requests when required by law.

You have a right to object to processing based on legitimate interests. This includes objecting to profiling based on those interests.

What we share

We do not sell financial data. We do use service providers that process data for the purposes above:

  • Hosting, authentication, database, backend, and deployment providers for running the website and app.
  • GoCardless Bank Account Data for open banking account, balance, and transaction access when you connect a supported bank.
  • SnapTrade for brokerage or exchange account access when you connect a supported provider such as Coinbase.
  • Stripe for checkout, billing portal access, subscription events, and payment processing.
  • AI and evaluation providers for AI-assisted categorisation, quality checks, and related observability where those features are enabled.
  • PostHog and Sentry for explicit product telemetry, diagnostics, and error-linked replay. Sentry replay is configured to mask text and block media.
  • Email delivery and internal notification providers for invitation emails, support notifications, signup alerts, and operational messages.

We may also disclose information if required by law, to protect rights and security, or as part of a business transfer.

International transfers

Some providers may process data outside the UK, EEA, or your country. Where UK or EU transfer rules apply, transfers should rely on an adequacy decision, standard contractual clauses, the UK International Data Transfer Addendum or Agreement, or another recognised safeguard.

Contact us if you need more detail about the transfer safeguards used for a specific provider.

Partner sharing

Sloth Money is built for solo and shared money planning. If you connect with a partner, they may see shared budgets, shared goals, shared contribution details, accepted joint-account transactions, and shared categorisation or explanation information.

Personal account data is not automatically shared just because you invite a partner. Sharing depends on the app settings and account flags you choose.

Cookies and similar technologies

We use cookies, pixels, local storage, and similar technologies for authentication, security, preferences, analytics, attribution, diagnostics, and operational visit notifications.

Essential technologies are used to provide the service you ask for. Advertising pixels are disabled. PostHog is limited to explicit events, does not use autocapture or cross-domain cookie stitching, and is used for product and marketing telemetry under legitimate interests.

You can block or delete cookies in your browser, but some app features may not work without essential storage.

Your UK and EU rights

  • You choose whether to create an account, connect a bank, connect a brokerage or exchange, invite a partner, create an Agent API token, or subscribe.
  • You can disconnect a linked provider in the app. Disconnects stop future sync for that connection, but they do not automatically delete historical app data already stored in Sloth Money.
  • You can ask for access, correction, deletion, restriction, portability, or export of data we can identify.
  • You can object to processing based on legitimate interests, including related profiling.
  • Where we rely on consent, you can withdraw that consent at any time.
  • You can complain to a supervisory authority. In the UK, that is the Information Commissioner's Office. In the EU, you can complain to the supervisory authority where you live, where you work, or where you think an infringement happened.

Some browsers send Do Not Track signals. We do not currently respond to those signals because there is no single accepted technical standard for them.

We aim to respond to rights requests within one month where UK or EU data protection law applies.

Security and retention

We use authentication gates, backend token checks, database security rules, server-side provider secrets, scoped Agent API tokens, and provider-managed connection flows to protect user data.

We keep data for as long as needed to provide Sloth Money, maintain security, support users, comply with legal obligations, and preserve ordinary backups or operational records. If you ask us to delete identifiable account data, we will handle the request subject to legal, security, billing, and backup constraints.

AI-assisted categorisation can profile transaction patterns to suggest categories or line items, but Sloth Money does not make legal or similarly significant decisions about you solely by automated means.

Contact

For privacy questions or requests, contact Sloth Money through the support channel in the app.

We may update this policy as the product, providers, analytics setup, or legal requirements change. The date at the top shows the latest version.