Privacy
What we hold, and what we don’t
Last updated 25 September 2026 · privacy@unspent.finance
The short version
- We hold your email address, and the amounts, plans, categories and notes you save. That is the product: we cannot show you your own history without keeping it.
- Financial values and challenge content do not go to Mixpanel. App analytics uses coarse screens, selections and outcomes. It does not send amounts, notes, categories, balances, challenge names or identifiers, dates, push tokens, notification text, invite links or other user content.
- In a challenge, members can see the display name you choose, your individual challenge total and progress, and the descriptions and exact amounts of entries linked to that challenge, including shared day and group totals. Your email and entries outside the challenge remain private.
- Challenge notifications are optional. If enabled, we keep an app installation identifier and push-delivery identifiers. Saving a share image adds only that image to Photos on your device; Unspent does not read your photo library.
- Product analytics is used only to improve Unspent. It tells us which screens and pages people use, which buttons they tap, and where they stop, so we can understand product habits and make the product better — not for advertising. App analytics is currently on by default. Website analytics stays off unless you choose to allow it.
- We don’t sell your data, we don’t share it for advertising, and we don’t track you across other companies’ apps or sites.
- You can delete your account from the app’s menu. You can also ask for a copy of your data or contact us about any privacy choice at privacy@unspent.finance.
Who we are
Unspent is an app for recording money you decided not to spend, made by Meanwhile Agency LLC (“Meanwhile”, “we”, “us”), of 44 Montgomery Street, San Francisco, CA 94104, United States. Meanwhile Agency LLC is the controller of the data described here. This policy covers the Unspent iOS app, this website at unspent.finance, and the API behind them. Write to us at privacy@unspent.finance about anything on this page.
Unspent does not hold or move money yet. The app records amounts you chose not to spend and shows what they would be worth on a savings plan. No bank account is connected to it, no funds are transferred, and the rates it shows describe a product we are still building. That is the plan, though, and we are in active discussions with regulated partners to provide it — which matters here because moving money means collecting things this policy does not yet mention, identity documents among them. When that arrives it will need its own disclosures and its own consent, and this policy will be updated before it does rather than after.
Earning the displayed yield requires joining the waitlist, connecting a bank account, and moving funds when bank connections become available. The main Home screen marks its “Grows to” total and states that condition at the end of the ledger. Recording an amount by itself does not earn the displayed yield.
What we collect
Set out by what it is and why we have it, rather than as one list. We do not buy information about you. Mixpanel receives the app, device and approximate-location metadata described below, but no financial values, challenge content or notification delivery identifiers.
- Your email address
- From whoever you signed in with — Apple or Google — and never a password, because we never see one. Held so we can reach you about your own account and your own money. If you use Apple’s Hide My Email, we hold the relay address Apple gives us and never your real one. Apple sends an address only on the first authorisation, so if you have signed in before and we do not have one, we cannot recover it without you telling us.
- An account identifier
- The subject identifier from your sign-in provider, and an identifier of our own. This is what ties your entries to you. Our identifier also becomes Mixpanel’s user identifier after sign-in, linking app analytics across your sessions and devices without sending Mixpanel your email address.
- What you save
- For each entry: the amount, the plan you chose and the rate that applied when you chose it, one of eight fixed categories, the date, and a note if you wrote one. The categories are Unlabeled, Coffee, Food, Shopping, Ride, Fun, Tech and Other. Notes are free text, so please don’t type anything into one you would not want us to hold — we do not read them routinely, but they are stored as written.
- What challenge members share
- Creating or joining a challenge stores its title, dates and time zone, the display name you choose for that challenge, an optional shared goal, membership and mute state, and challenge totals. Other active members can see your chosen display name, individual challenge total and progress, and the category or note description and exact amount of entries linked to the challenge after you join. The shared feed also shows day and group totals derived from those linked entries. They cannot see your email or entries elsewhere in your ledger. If you leave, entries already linked to the challenge remain visible, but later entries are not added. You can rejoin with a valid invitation while the challenge is active.
- Invitations and push notifications
- Challenge invitation URLs are bearer links: anyone who receives a live link can preview the invitation and use it to join. We store only a one-way digest of the invite token; the usable token travels in the link and expires when the challenge ends. If you choose challenge notifications, APNs supplies a device token. Amazon SNS holds that token; our database holds its digest, an app-generated installation UUID and an SNS endpoint identifier linked to your account. Notification payloads contain a challenge route and event type, not amounts, notes, balances or invitation links.
- Share images and Photos
- Share images are rendered on your device. Choosing Share presents Apple’s native share sheet; Unspent records only that the sheet was presented and cannot claim that a share completed. Choosing Save image requests add-only Photos access and writes the image you selected. The app does not read, browse or upload your photo library.
- Feedback and contact details
- If you use the signed-in feedback form, we receive the note you submit. You may also provide an email address and phone number; the app sends those contact details only after you select “I agree to be contacted.” Feedback is delivered through Amazon SES to two members of the Unspent product team. It is not sent to Mixpanel, added to your ledger or used for advertising.
- What happened, on our side
- When an entry is saved or reversed, the server records it in our own audit trail, inside the same transaction — and that record includes the amount, the plan, the category, the rate and the maturity value, tied to your account. It does not include your note. This is financial data about you and remains in our own cloud account. The app sends selected terms and coarse interaction outcomes to Mixpanel as described below, but no financial values and none of this server audit record.
- Technical records
- API Gateway and application logs record the time, route, response code and source IP. Authenticated requests also carry the account subject identifier. Those configured log groups use a 30-day retention period. They exist for security and debugging and are not joined to a marketing profile. Deliberately not logged: request bodies and query strings, because that is the easiest way for an amount to end up somewhere it does not belong.
- Product analytics: app default-on, website opt-in
- Product analytics consists of interaction events such as screens and pages viewed, buttons tapped, which call to action was used, which question was opened, and where a session stops. We look at these events in aggregate to understand how people use Unspent, where they get stuck or leave, and which parts of the product should be improved. We do not use them for advertising, personalisation, credit decisions or tracking you across other companies’ apps or websites.
- Before sign-in, Mixpanel assigns the app installation a random identifier. After the ledger loads, the app identifies Mixpanel with our account UUID, joining those events to the account and linking later activity across sessions and devices. Mixpanel receives selected plan terms, coarse interaction outcomes, app version and build, operating-system and device-model information, screen dimensions, its SDK metadata, persistent random identifiers and source IP, which it may use to infer approximate location. Event properties do not contain amounts, notes, categories, balances, challenge titles, display names, challenge or invite identifiers, push tokens, notification text, exact dates or raw URLs.
-
The app currently includes Mixpanel, and app analytics is on by default.
There is no separate consent popup or in-app analytics switch; this is first-party
product measurement processed by Mixpanel, not advertising or cross-app tracking.
We have disabled Mixpanel People profiles and its automatic app-lifecycle events. The
app’s allowlist does not send your name, email, financial values, notes, categories,
challenge content, push-delivery identifiers, dates, raw URLs or entry IDs. This
website loads a
Google Tag Manager container only when one is configured and you allow
it. Your website choice is remembered in your browser’s local storage under
unspent.consent; tags loaded after consent may use additional browser storage as described by the services configured in that container.
What we deliberately do not collect
- No advertising identifier and no cross-app tracking. The app’s privacy manifest declares no tracking. The app does not request App Tracking Transparency permission because it does not combine your data with data from other companies’ apps or websites for advertising or measurement.
- No bank credentials and no card details, because nothing connects to a bank yet. If that changes, it will be described here first.
- No contacts, camera, precise location or health data. The app asks for notification permission only after an explanation and for Photos add-only permission only when you choose Save image. It never reads Photos and has no Contacts or Camera usage description.
- No third-party fonts, and no website analytics before consent. The typefaces are served from our own origin. Unless you opt into the Google analytics described above, loading this page tells no analytics company that you read it.
Signing in with Apple or Google
Sign-in is handled by Apple, by Google, and by Amazon Cognito, which issues the token your app carries. Both sign-in methods are available. Apple generally supplies an email address only on the first authorization; Google supplies a verified email on each sign-in. We do not receive your contacts, calendar, files or password from either provider.
When you use Apple, we exchange its one-use authorization code and retain the resulting provider refresh token, encrypted at rest, solely so we can revoke Unspent’s Apple authorization if you delete your account. We do not use that token to fetch additional information.
The app does not request your Apple profile name. A display name you type for a challenge is separate from your sign-in identity and is visible only as described above.
Google authorization requests only openid and email. Our backend
retains Google’s subject identifier and verified email. The app uses Google’s browser-based
OAuth service directly and does not include the Google Sign-In SDK. The information we
retain is used to create and secure your account and reach you about it, not for
advertising.
Who your data goes to
The service providers below process data to run Unspent. Their handling of data is also governed by their own terms and privacy obligations.
- Amazon Web Services
- All of it. The database, the API, the sign-in directory and this website run in a single AWS account in the US East (Northern Virginia) region. The database is encrypted at rest, everything is encrypted in transit, and backups are kept for seven days. Feedback is transmitted through Amazon SES to the fixed internal recipients named above.
- Apple, Google, Mixpanel and Amazon Push Notification Services
- Apple and Google are sign-in providers, for whichever one you choose. Mixpanel processes the default-on app analytics described above. Apple Push Notification service and Amazon SNS route challenge notifications only after opt-in. Google processes website analytics only if a container is configured and you allow it. Apple tells us nothing about you beyond what sign-in and push delivery require.
- A savings partner, once there is one
- Holding money will involve a regulated financial institution, and that will mean identity information we do not collect today. We are in active discussions with several, and none has been given anything: no data has been shared with any prospective partner, and none will be without telling you what and why first.
We may also disclose data if the law requires it, and we would tell you unless we were forbidden to. If the company is ever sold or merged, your data may transfer with it, under this policy until you are told otherwise.
Because this website is delivered from a global content network, a request for a page may be served by an edge location outside the United States. Your account data itself is stored only in the US region named above, though Meanwhile staff outside the United States may reach it in the course of running the product and answering you. If you are in the UK, Switzerland or the European Economic Area, that means your data is transferred to the United States; where such a transfer needs a legal mechanism, we rely on the European Commission’s standard contractual clauses with our providers.
How long we keep it
Your account and your entries are kept while your account exists, because a savings history you cannot see is not a history. Two details are worth stating plainly, because they follow from how the product is built:
- The financial fields in the ledger are append-only. An amount, term or rate is not edited in place, and undoing an entry writes an opposite entry so the history stays honest. You may correct the date on which an entry happened, its category and its note; we retain the separate timestamp recording when the entry was created. Deleting your account still deletes its ledger, as described next.
- Configured API logs go on a 30-day cycle, and automated database backups are retained for seven days. Deleted data can therefore remain in protected backups or security records for a limited period after it leaves the live database.
- Challenge invites expire when their challenge ends. Leaving a challenge revokes invitations you created there and stops new entries from being linked while you are away; entries already linked remain in its shared feed. Push device records remain while the account and installation are registered; sign-out unregisters that installation, and account deletion removes all of the account’s push device records.
- Feedback is not stored in the Unspent database. The submitted message is retained in the product team’s business mailboxes only as long as needed to review, respond to and learn from it. You may ask us to delete that correspondence.
Your choices, and how to use them
Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or ask us to stop using it. Write to privacy@unspent.finance. We will confirm we have your request within 48 hours and aim to answer it within 45 days, or sooner when the law requires. We will ask you to sign in, or to write from the address on the account, because we are not willing to hand your savings history to whoever emails us about it.
You can delete your account from the Unspent menu. After you confirm, this removes the Cognito sign-in identity, account record, email address, waitlist status, entries, notes, challenge membership and push device records, revokes Unspent’s Apple authorization if you signed in with Apple, and submits the account UUID to Mixpanel’s privacy API for deletion of linked analytics records. Mixpanel processes that request asynchronously. We keep de-linked server audit events without the account or entry reference and an irreversible digest of the former Cognito subject to stop an already-issued token from recreating the deleted account.
The current app does not provide an analytics setting. You can object to this processing or request deletion by writing to us. Website analytics is off until you allow it; after allowing it, you can opt out by clearing this site’s data in your browser, reloading the page, and choosing “No thanks” when asked again.
If you are in the European Economic Area or the UK, our legal bases are: performing our contract with you, for your account and your entries; your consent, for website analytics; and our legitimate interests, for app product analytics, security logs and defending ourselves in a dispute. You can object to app analytics by contacting us, and you have the right to complain to your data protection authority.
If you are in California, we do not sell your personal information and do not share it for cross-context behavioural advertising, and we have not in the last twelve months. Asking us to exercise any right above will never make the product worse for you. You can complain to the California Privacy Protection Agency, 400 R Street, Suite 350, Sacramento, CA 95811.
Children
Unspent is not for children. You must be at least 18 to have an account, and we do not knowingly collect anything from anyone under 13. If you believe a child has an account, write to us and we will delete it.
Security
The app’s sign-in tokens live in the iOS Keychain, not in ordinary app storage. The Apple provider token retained for deletion is held in the encrypted database and is never sent back to the app. Every request is over HTTPS. The database is not publicly network-accessible, is encrypted at rest, and the API reaches it through AWS’s IAM-authorized Data API. Every route that touches your data is scoped to your own account by the token you present: no route takes a user identifier, so there is no address at which one person’s history can be asked for with another person’s token.
Challenge membership deliberately grants access to the shared challenge fields described above. Invitation URLs are bearer credentials: forward one only to someone you intend to invite, and treat a live link like access to the invitation preview.
None of which is a promise that nothing can go wrong. If a breach affects you, we will tell you and the relevant regulator as quickly as the law requires, and sooner if we can.
Changes
When this policy changes we will update the date at the top, and for anything that materially affects you — a new kind of data, a new recipient, a new purpose — we will tell you in the app or by email before it takes effect.