1. Scope and who we are
This Privacy Policy explains how OnTrack Group, LLC("OnTrack," "we," "us," or "our") handles information when you visit OnTrack Money websites, join the beta list, or use the OnTrack Money budgeting application and related support services (collectively, the "Service").
2. Information we collect
Account and profile information
We collect identifiers and profile details such as your email address, display name, optional phone number and profile photo, authentication identifiers, account membership and invitation records, and records of your acceptance of our Terms.
Budgeting and financial information
We process information you enter, import, or create in the Service, including budgets, categories, line items, financial-account metadata, balances, transaction names, amounts and dates, allocations, rules, notes, and shared-account activity.
Connected-account information
If you connect a financial institution through Plaid, we receive institution and account metadata, balances, transaction information, and connection identifiers and tokens needed to maintain the connection. OnTrack does not receive or store the online-banking credentials you enter in Plaid's connection flow.
Billing information
For mobile subscriptions, we process an OnTrack user identifier, product and entitlement details, purchase status, renewal or expiration information, and related subscription-event metadata. Apple or Google processes the payment transaction; OnTrack does not receive your full payment-card number.
Support, feedback, and beta signup
We collect the contact details and messages you submit, including beta signup answers, support requests, product feedback, and the improvement reason requested during account deletion. These messages may contain information you choose to include.
Preferences, telemetry, and device data
We process settings such as theme, notification, budgeting, and display preferences. Our hosting, performance, analytics, and error-monitoring providers may process IP address, browser or device type, operating system, app or route information, request timing, network information, diagnostics, and error details. We configure Sentry not to send default personally identifiable information and to scrub selected sensitive fields, but diagnostic events can still contain contextual data.
Cookies and client storage
We use authentication cookies and browser or device storage to keep you signed in, preserve theme and app preferences, remember selected accounts and refresh state, and temporarily maintain authentication, app-version, and Plaid Link session context. You can clear this storage through your browser or device, although doing so may sign you out or reset preferences.
3. How we use information
- Provide authentication, budgeting, bank-sync, sharing, billing, and support features.
- Import, organize, categorize, and display financial information you request.
- Operate optional recommendations, OnBot, and voice features described below.
- Send account, invitation, service, support, and transactional communications.
- Maintain entitlements and process subscription events.
- Monitor reliability, troubleshoot errors, prevent abuse, and secure the Service.
- Understand product performance and improve features and usability.
- Comply with law, enforce our agreements, and protect users and the Service.
4. AI recommendations, OnBot, and voice
OnTrack uses OpenAI for certain AI-assisted features. Information sent depends on the feature:
- Category recommendations: merchant names, transaction amounts, candidate budget line-item and category names, and recent merchant and allocation patterns may be sent to suggest a category.
- Optional OnBot: if OnBot is available and you choose to use it, OpenAI may receive your latest question together with your first name, subscription tier, budget structure, merchant names, transaction dates and amounts, transaction status and categories, and notes relevant to the request.
- Optional voice search: when you activate voice input, the audio recording is sent to OpenAI for transcription. The resulting text is returned to support the requested search or interaction.
This data is not necessarily anonymous. Do not include information in prompts, notes, or audio that you do not want processed for the feature. AI output can be incomplete or inaccurate and should not be treated as financial, legal, tax, or investment advice.
5. Service providers and other disclosures
We disclose information as needed to operate the Service. Our current provider categories include:
- Supabase for authentication, databases, storage, and backend infrastructure.
- Plaid for financial institution connections and financial-data aggregation.
- Vercel for hosting and delivery, including Vercel Analytics and Speed Insights for usage and performance measurement.
- Upstash, when configured, for rate limiting and abuse prevention using route-and-IP-derived keys.
- Sentry for application error monitoring and diagnostics.
- Resend for transactional and service email delivery.
- OpenAI for category recommendations and optional OnBot and voice-transcription features.
- RevenueCat for mobile subscription entitlements and purchase lifecycle management, and Apple and Google for app distribution and in-app purchase processing.
- Make.com and Airtable for routing and managing support requests, feedback, and account-deletion feedback.
These providers process information under their own terms and privacy commitments. We may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect rights and safety, investigate abuse, or complete a business transaction such as a merger or acquisition.
6. No sale of personal information
We do not sell or rent your personal or financial information. Our disclosures to providers are for operating, supporting, securing, and improving the Service as described in this Policy.
7. Retention and deletion
We retain information for as long as needed to provide the Service, maintain security and business records, resolve disputes, and meet legal obligations. Retention varies by the type of record and the system that holds it; we do not promise an exact retention period for independently operated provider systems.
You can request account deletion from Settings. Deletion may take up to 30 days to propagate through active OnTrack systems. Information can remain longer in backups, security or fraud records, legally required records, support systems, and systems controlled by third parties, subject to their restoration, retention, and deletion practices. Support, feedback, and account-deletion messages routed through Make.com or Airtable may therefore outlast the active app account.
Data associated with an account that remains available to other shared members may be retained with that account, with your user reference removed where supported. Deleting your OnTrack account does not cancel an Apple App Store or Google Play subscription; you must manage or cancel that subscription with the store where you purchased it. If you want OnTrack to request provider-side disconnection of a Plaid item, disconnect the institution in the app before deleting your account or contact us.
8. Security
We use reasonable administrative and technical safeguards designed to protect information, including encrypted network transport, access controls, row-level database authorization, and restricted server-side credentials. No service can guarantee absolute security. Protect access to your email account and device, and notify us if you suspect unauthorized use.
9. Your choices
- Review or update profile and preference information in Settings.
- Choose whether to connect a bank account or use optional AI and voice features.
- Disconnect a linked financial institution from the Service.
- Control microphone access through your browser or device settings.
- Manage or cancel mobile subscriptions through Apple or Google.
- Delete your account in Settings or contact us about an access, correction, or deletion request.
Rights vary by location. We may need to verify your identity before completing a request, and some information may be exempt from a request where permitted by law.
10. Children
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children through the Service. Contact us if you believe a child has provided information to us.
11. Processing locations
OnTrack and its providers may process information in the United States and other locations where they operate. Laws in those locations may differ from those where you live. We do not represent that all Service data stays in a particular country or data region.
12. Changes to this Policy
We may update this Policy as the Service or our practices change. We will post the revised version and effective date here and provide additional notice when appropriate.
13. Contact us
Questions or privacy requests can be sent to OnTrack Group, LLC at support@ontrackmoney.com.
Read the Terms & Conditions