Privacy Policy
How we handle your data
Last updated: August 31, 2026
Rikdom Labs LLC, an Oklahoma limited liability company ("Rikdom Labs", "Rikdom", "we", "our", or "us"), is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information.
Information we collect
We collect information you provide directly:
- Account registration information (name, email address)
- Financial account data via Plaid and SnapTrade (account balances, transactions, holdings)
- Real asset information you manually enter
- Budget and transaction files you upload — YNAB and Monarch Money exports — which we read to create your accounts, categories, and transactions. We do not keep the original file.
- Budget allocations and financial goals
- Usage data and analytics
How we use your information
- Provide, maintain, and improve our services
- Run Monte Carlo simulations and financial projections
- Categorize transactions and track spending patterns
- Identify tax-loss harvesting opportunities
- Generate community benchmarks (aggregated and anonymized)
- Respond to your requests and provide customer support
- Detect, prevent, and address fraud and security issues
Data security
We implement industry-standard security measures:
- AES-256 encryption at rest, applied by our database host (Supabase) to database files, indexes, and backups
- TLS 1.3 encryption in transit
- Sensitive credentials, such as bank and brokerage access tokens, are separately encrypted by the application before they are stored
- Read-only OAuth connections via partners who maintain SOC 2 Type II compliance (Plaid, SnapTrade, Supabase)
- Row-Level Security (RLS) to isolate user data in our database
- Optional two-factor authentication (TOTP, with single-use backup codes) on your account
- We never store your bank login credentials
Third-party services
We use third-party services to provide our platform:
Each link above goes to that company’s own privacy policy. Plaid’s is the one worth reading if you connect a bank — it describes what Plaid does with the connection, which is separate from what we do with it.
Cookies
Rikdom uses a minimal set of cookies, all essential for the platform to function. We do not use advertising cookies, tracking cookies, or third-party analytics cookies.
| Cookie | Purpose | Duration |
|---|---|---|
| access_token | Keeps you signed in during a session | 1 hour |
| refresh_token | Renews your session so you are not signed out every hour | 7 days |
| csrf_token | Proves a request came from our own pages, not another site | 7 days |
The two session cookies are HTTP-only, so no script on the page can read them; the CSRF cookie is readable by our own pages because that is how it does its job. All three are Secure and SameSite=Lax. They are required for authentication and cannot be disabled while using Rikdom. No personal financial data is stored in cookies.
We use Umami for analytics, which counts page views and a small number of product events without cookies and without collecting anything that identifies you. It is served from our own domain, so no request leaves for a third-party analytics host. We removed Google Analytics and Google Tag Manager in August 2026. We do not use Facebook Pixel or any advertising tracking scripts. We do not serve ads. We do not sell or share cookie data.
Community benchmarks & privacy
Our Community Benchmarks feature is opt-in and uses privacy-preserving techniques:
- N≥50 threshold — Benchmarks only shown when 50+ users contribute
- Differential privacy — Laplace noise (epsilon=1.0) added to all aggregates
- No individual data — Only aggregated statistics are computed
- You can opt out at any time from your profile settings
Data retention
We retain your data for as long as your account is active. Your full transaction history, budget records, net worth snapshots, and simulation results remain available for as long as you maintain an account.
When you delete your account, we permanently delete all associated personal data from our production systems within 30 days, including:
- Account profile and credentials
- Linked financial account connections and cached data
- Transactions, budgets, goals, and settings
- Simulation results and AI query history
- Community benchmark contributions (removed from future aggregations)
Anonymized, aggregated data already incorporated into community benchmarks (with differential privacy applied) may persist, as it cannot be traced back to any individual.
Backups containing your data are purged within 90 days of account deletion.
Your rights
You have rights over your personal data regardless of where you live. We honor these rights for all users.
California residents (CCPA)
Under the California Consumer Privacy Act, you have additional rights:
- Right to Know — Request categories and specific pieces of personal information collected, sources, purpose, and third parties.
- Right to Delete — Request deletion of your personal information, subject to certain exceptions.
- Non-Discrimination — We will not discriminate against you for exercising your CCPA rights.
- No Sale — We do not sell your personal information. We have not sold personal information in the preceding 12 months.
Contact support@rikdom.io to exercise your CCPA rights. We respond to all verifiable consumer requests within 45 days.
European Economic Area residents (GDPR)
Our legal basis for processing your personal data:
- Contractual necessity — Processing required to provide the Rikdom service.
- Legitimate interest — Processing for platform improvement, security, and fraud prevention.
- Consent — Community benchmarks are an opt-in feature you turn on in your profile, and you can turn them off at any time.
- AI features are not consent-based — AI Insights runs on the question you ask it, and automatic transaction categorization runs as part of providing the service. Both are contractual necessity, not consent. Anthropic processes that data under commercial API terms that do not permit training on it.
You additionally have the right to restrict processing, data portability, object to processing, and lodge a complaint with your local data protection authority.
Our data processor (Supabase/AWS) stores data in the United States. We rely on standard contractual clauses for lawful data transfers.
When you delete your account we delete your data from our systems and instruct our processors to do the same, but data already held by them — Plaid, SnapTrade, Stripe, Anthropic — is removed on their own retention schedules, which we do not control. We also keep security audit records (sign-ins, permission changes) after deletion, with your account identifier removed, because we need them to investigate account-takeover attempts.
Contact support@rikdom.io to exercise any of these rights.
Age requirement
Rikdom is intended for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected data from a user under 18, we will promptly delete the account and all associated data. If you believe a minor has provided us with personal information, please contact us at support@rikdom.io.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the platform.
Contact us
Questions about this Privacy Policy? Reach us at support@rikdom.io.