1. Who We Are
GhostMoney AI is a personal finance tool developed by Keith Crisologo, Oregon. Questions about this policy can be directed to
hello@ghostmoney.app.
2. Data We Collect
When you use GhostMoney, we collect the following:
• Full name, email address, phone number (optional), and IP address — collected when you create your account
• Extracted transaction data from bank statements you upload — merchant names, amounts, dates, and spending categories
• Sinking fund goals and contributions you create manually
• Monthly spending snapshots (summaries derived from your transactions)
• Feedback you submit through the in-app feedback form (your IP address is recorded with it)
• Your IP address and browser/device information (user-agent) each time you log in — retained briefly for security (rate limiting and fraud prevention), not for tracking
• Session identifiers stored in browser cookies
• A unique access code generated at signup and associated with your account record
We do NOT store account numbers, routing numbers, bank login credentials, Social Security numbers, or your original bank statement files. (For what is transmitted to our AI while your statement is read — which differs for text files vs. photos/scans — see Section 3.)
In the event of a breach, no bank credentials, account numbers, routing numbers, or original statement files could be exposed, because we never store them. What could be exposed is the data listed above: transaction records (merchant names, amounts, dates, categories), anything you have typed into the app yourself — savings-goal names and notes, financial-coaching conversations, and feedback — and the IP address and device information recorded when you sign in. Your name, email address, and phone number are encrypted at rest.
3. AI Processing — What Is Sent to Anthropic (Claude)
To read your statement, GhostMoney sends it to Anthropic PBC's API (Claude AI). What gets sent depends on the file type:
• Text-based files (CSV, and PDFs with selectable text): personal details — account and routing numbers, Social Security numbers, phone numbers, email addresses, and street addresses — are stripped BEFORE the text is sent to Anthropic. Only the de-identified text is transmitted.
• Photos and scanned (image-only) PDFs: Claude reads these as images, so the document image itself is sent to Anthropic to be read. These images are not pre-redacted, so personal details visible on the statement are transmitted to Anthropic while it reads them.
• Free-text you type into the AI Coach or Scenario Planner: this is sent to Anthropic to generate your reply, but the same personal-identifier redaction (account/routing numbers, SSNs, card numbers, emails, phone numbers, and street addresses) is applied first. Merchant names and dollar amounts you mention are kept — they are what the coaching is about.
In every case, GhostMoney does not store the original file — only the extracted transaction rows (merchant, amount, date, category) are saved, with identifying details scrubbed from those stored rows. Anthropic does not use API data to train its models by default and retains it only briefly for abuse monitoring. Anthropic's privacy policy governs data sent to their API.
Want to keep it fully private? Export your statement as a CSV and use the free browser audit — it analyzes the file entirely on your device, with nothing sent to any server or to Anthropic.
4. How We Store Your Data
Your data is stored via Turso (a managed SQLite service running on AWS US-West-2 infrastructure). Your most sensitive personal identifiers — full name, email address, and phone number — are additionally encrypted at the application level (AES-256-GCM) before they are written, so they are not readable even in the raw database. Extracted transaction rows are stored with identifying details already scrubbed. Each user's data is isolated by a unique account identifier derived from your email address; no user can access another user's data.
5. Service Providers (Sub-processors)
GhostMoney shares data with the following service providers only as necessary to operate the service. This is the complete list:
• Anthropic PBC — AI parsing of your statement text and AI coaching analysis of your transaction data
• Helicone Inc. — AI-request observability, used only when AI-request logging is enabled. It receives metadata only (timing, token counts, model). Prompt and response bodies — your statement text and transaction content — are omitted and are not logged by Helicone
• Sentry — error monitoring and crash diagnostics. Error reports may incidentally include technical data or fragments of application data present at the moment of an error; session replay is disabled and we do not send personal-data fields to Sentry by default
• Vercel Inc. — application hosting, serverless functions, and cookieless analytics (Speed Insights — aggregate page-load timing; Web Analytics — aggregate page views, referrers, approximate country, and device/browser type; no cookies, no cross-site tracking; page URLs are recorded with campaign parameters only (utm_source, utm_medium, utm_campaign, utm_content, utm_term, each truncated and limited to safe characters); every other query-string value — including referral codes and checkout session identifiers — is removed before recording)
• Turso — database storage (AWS infrastructure)
• Resend — transactional and product email delivery (access code, welcome, snapshots, nudges)
• Cloudflare — bot protection via Turnstile (no financial data shared)
Each provider is bound by its own privacy policy. Anthropic processes data sent to its API as a data processor under its Commercial Terms of Service and Data Processing Addendum (DPA); it does not train its models on API data by default and retains it only briefly for abuse monitoring. We do not sell, rent, or share your data with advertisers, data brokers, or any other third parties. If we add or change a sub-processor, we will update this list and notify you of material changes. A standalone summary is also available at ghostmoney.app/subprocessors.
6. Data Retention
Your data is retained for as long as your account is active. Your signup record (your signed Terms of Service acceptance) is retained permanently as a legal record of the agreement (it cannot be deleted). Everything else — transactions, statements, funds, snapshots, feedback, login/device logs, saved Scenario Planner conversations, email preferences, and any waitlist entry tied to your email — is deleted when you use the "Delete All Data" feature or submit a deletion request.
7. Your Rights
You have the following rights regarding your personal data:
Right to Delete: You may delete all your data at any time directly from the dashboard using the "Delete All Data" button. This immediately and permanently removes all transactions, statements, funds, and snapshots. If you cannot access your account, email
hello@ghostmoney.appwith the subject line "Data Deletion Request" and we will process it within 7 days. Note: your signup record (your signed Terms of Service acceptance) is retained permanently as a legal record and cannot be deleted.
Right to Know: You may email
hello@ghostmoney.app to ask what data we hold about you.
Right to Correct: You may email
hello@ghostmoney.app to request corrections to your name or email address on file.
8. Data Breach Notification
Because GhostMoney never stores bank credentials or raw statement files, a breach would expose only transaction metadata (merchant names, amounts, dates) — not anything that could be used to access your bank account. In the event of a data breach affecting your personal information, GhostMoney will notify affected users within 72 hours of discovery, or as soon as practicable. Notification will be sent to the email address associated with your account. We will describe what data was affected, the nature of the breach, and the steps being taken to address it.
9. Cookies
GhostMoney uses three httpOnly, secure session cookies: one to record your Terms of Service acceptance, one to store your unique account identifier, and one to maintain your login session (tied to your individual access code). Sessions expire after 30 days and require re-entry of your access code to renew. These cookies cannot be read by JavaScript and are only transmitted over HTTPS. For performance and usage measurement we use Vercel Speed Insights (aggregate page-load timing) and Vercel Web Analytics (aggregate page views, referrers, approximate country, and device/browser type — page URLs are recorded with campaign parameters only (utm_source, utm_medium, utm_campaign, utm_content, utm_term, each truncated and limited to safe characters); every other query-string value — including referral codes and checkout session identifiers — is removed before recording). Both are cookieless: they set no cookie and do not track you across sites. No advertising or cross-site tracking cookies are used.
10. Changes to This Policy
GhostMoney may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. You will be notified of material changes.
11. Anonymized Aggregate Analysis
Only with your explicit opt-in — the consent box at signup is unticked by default, or you can opt in later from the "Data & Privacy" prompt in the dashboard — GhostMoney may use anonymized, aggregate statistics derived from your spending data to improve the accuracy of the service for all users. If you never opt in, none of your data is used for aggregate analysis.
What this means in practice:
• Only category-level summaries are used (e.g., median grocery spend across users in a given month) — never individual transaction details, merchant names, or dollar amounts tied to you
• A minimum cohort floor of 5 consenting users is required before any aggregate statistic is computed or surfaced — single-user statistics are never published
• Your name, email, account identifier, or any other personal identifier is never included in or derivable from aggregate computations
• This analysis is used solely to improve GhostMoney's coaching accuracy — it is never sold, shared with advertisers, or used for any other purpose
• You can opt out at any time from the "Data & Privacy" section of your dashboard. Withdrawal applies to future aggregation only — previously computed aggregate rows (which contain no individual user data) are unaffected.
This data use is disclosed in our Terms of Service (Section 11) and this Privacy Policy.
12. Children’s Privacy
GhostMoney is for adults only — you must be at least 18 years old to use it (see Terms of Service, Section 3). We do not knowingly collect personal information from anyone under 18. If we learn that we have collected data from a person under 18, we will delete it. If you believe a minor has provided us data, email us and we will remove it.
13. Electronic Communications
By creating an account you consent to receive electronic communications from GhostMoney, including your access code, welcome email, monthly snapshots, and product/engagement emails. Every non-essential email includes an unsubscribe link, and you can manage preferences from your dashboard. Essential account and security emails (such as your access code or a data-deletion confirmation) may still be sent while your account is active.
14. Governing Law
This Privacy Policy is governed by the laws of the State of Oregon. Any disputes will be resolved in the courts of Washington County, Oregon.