Skip to content

Security & privacy

What we access, why we access it, and what we keep.

Every statement on this page is written to match what the product actually does. We make no certification, audit, or “bank-grade security” claims.

Read-only connections

Email access is requested with read scopes, and Plaid account access is requested for balances and transaction history. The app has no ability to send email, move money, or initiate payments.

We do not sell your personal data

Your mailbox content, transactions and findings are not sold, rented, or shared with data brokers or advertisers.

Never used for advertising

Connected-account data is used only to identify potentially recoverable value for you, and to operate and support the service.

Credentials stay with the provider

You enter bank credentials with your institution inside Plaid Link, not with us. Provider access tokens are held server-side and are never sent to the browser.

Minimum necessary storage

The app stores the structured facts that describe a finding — merchant, amount, dates, status, a reference and a short evidence snippet — rather than retaining full email bodies.

Disconnect and delete, any time

Disconnecting a source stops further access immediately. A deletion request removes your findings, evidence, imported transactions and connection records.

Why you would connect a financial account

Connecting a bank or card account is optional. Without it, Lost Money Detective can still review your email history — but it cannot confirm whether promised money ever arrived.

Confirm a refund actually posted
An email may promise money back. Transaction history is the only way to check whether the credit arrived.
Avoid false positives
If the credit did post, the item is closed instead of being shown to you as outstanding.
Match partial and split credits
Merchants sometimes refund in pieces. Comparing amounts and dates against real activity keeps the math honest.
Identify the right destination
Knowing which card a refund was expected on makes the follow-up with the merchant or issuer far more specific.

The Plaid connection, in plain language

Plaid Inc. is an independent service that connects apps to financial institutions. When you choose to link an account, Lost Money Detective opens Plaid Link. You pick your institution and sign in with Plaid and your institution, not with us. We never see or store your online banking username or password.

If your institution and Plaid complete the connection, Plaid returns an access token to our servers. We use it to request the information you consented to share:

  • account identity basics such as the institution name, account name, type and the last four digits
  • current and available balances
  • transaction history — date, amount, description, merchant and category

That information is used for one purpose: to reconcile promised or issued value found in your other authorized evidence against what actually reached your accounts. It is not used for advertising, credit decisions, scoring, or resale.

The access token is stored server-side only and is never exposed to the browser. Disconnecting an account in the app revokes our access and removes the imported transaction data associated with it. Plaid’s own handling of your data is governed by Plaid’s End User Privacy Policy.

Bank connections are only available in the app when the owner of this deployment has configured live Plaid credentials. Until then, the connection screen says so plainly rather than pretending to work. We do not claim any Plaid production approval status on this site.

Storage, retention and deletion

Data is stored in a managed Postgres database with row-level security, so each account can only read its own records. Traffic is encrypted in transit with TLS, and our database and storage providers encrypt data at rest. We do not claim any independent security certification or audit.

Email evidence is reduced to structured fields plus a short snippet. You can set snippet retention to 30, 90 or 365 days in the app, and you can delete stored snippets at any time while keeping the amounts and dates that describe a finding.

Owner confirmation needed: the overall account-level retention period after an account is closed should be stated here once the operator finalizes it.

What is live today

We publish this so there is no ambiguity about which parts of Lost Money Detective operate on real data.

  • Mailbox review — live. Gmail and AOL Mail connect through our email connectivity provider and are read-only.
  • Bank and card connections — live where enabled. Account connectivity is provided by Plaid. Whether an environment can reach real institutions depends on the Plaid access granted to this deployment; in a test environment only Plaid's sample institutions can be linked, and the app tells you when live credentials are not configured.
  • Demo data — clearly labeled. Sample findings only appear when you turn demo mode on, a banner stays visible while it is on, and demo values are never written to your account.
  • Government resources — a directory. We link to official state and federal search tools. Lost Money Detective is not a government agency and cannot file claims for you.

Provider access tokens are held server-side only, never sent to the browser, and are additionally encrypted at the application layer when an encryption key is configured for the deployment.