Privacy Policy

How we handle your data

Last updated: August 31, 2026

Rikdom Labs LLC, an Oklahoma limited liability company ("Rikdom Labs", "Rikdom", "we", "our", or "us"), is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information.

001
Collection

Information we collect

We collect information you provide directly:

  • Account registration information (name, email address)
  • Financial account data via Plaid and SnapTrade (account balances, transactions, holdings)
  • Real asset information you manually enter
  • Budget and transaction files you upload — YNAB and Monarch Money exports — which we read to create your accounts, categories, and transactions. We do not keep the original file.
  • Budget allocations and financial goals
  • Usage data and analytics
002
Usage

How we use your information

  • Provide, maintain, and improve our services
  • Run Monte Carlo simulations and financial projections
  • Categorize transactions and track spending patterns
  • Identify tax-loss harvesting opportunities
  • Generate community benchmarks (aggregated and anonymized)
  • Respond to your requests and provide customer support
  • Detect, prevent, and address fraud and security issues
003
Security

Data security

We implement industry-standard security measures:

  • AES-256 encryption at rest, applied by our database host (Supabase) to database files, indexes, and backups
  • TLS 1.3 encryption in transit
  • Sensitive credentials, such as bank and brokerage access tokens, are separately encrypted by the application before they are stored
  • Read-only OAuth connections via partners who maintain SOC 2 Type II compliance (Plaid, SnapTrade, Supabase)
  • Row-Level Security (RLS) to isolate user data in our database
  • Optional two-factor authentication (TOTP, with single-use backup codes) on your account
  • We never store your bank login credentials
004
Third Parties

Third-party services

We use third-party services to provide our platform:

PlaidBank and brokerage account connections (read-only) Privacy policy
SnapTradeBrokerage account connections (read-only) Privacy policy
StripePayment processing (we never see or store your full card number) Privacy policy
RentCastProperty valuations Privacy policy
AnthropicAI-powered insights and transaction categorization Privacy policy
ResendTransactional email (verification, password reset) Privacy policy
SupabaseDatabase hosting Privacy policy
UmamiPrivacy-friendly analytics — no cookies, no personal data, no cross-site tracking Privacy policy

Each link above goes to that company’s own privacy policy. Plaid’s is the one worth reading if you connect a bank — it describes what Plaid does with the connection, which is separate from what we do with it.

005
Cookies

Cookies

Rikdom uses a minimal set of cookies, all essential for the platform to function. We do not use advertising cookies, tracking cookies, or third-party analytics cookies.

CookiePurposeDuration
access_tokenKeeps you signed in during a session1 hour
refresh_tokenRenews your session so you are not signed out every hour7 days
csrf_tokenProves a request came from our own pages, not another site7 days

The two session cookies are HTTP-only, so no script on the page can read them; the CSRF cookie is readable by our own pages because that is how it does its job. All three are Secure and SameSite=Lax. They are required for authentication and cannot be disabled while using Rikdom. No personal financial data is stored in cookies.

We use Umami for analytics, which counts page views and a small number of product events without cookies and without collecting anything that identifies you. It is served from our own domain, so no request leaves for a third-party analytics host. We removed Google Analytics and Google Tag Manager in August 2026. We do not use Facebook Pixel or any advertising tracking scripts. We do not serve ads. We do not sell or share cookie data.

006
Benchmarks

Community benchmarks & privacy

Our Community Benchmarks feature is opt-in and uses privacy-preserving techniques:

  • N≥50 threshold — Benchmarks only shown when 50+ users contribute
  • Differential privacy — Laplace noise (epsilon=1.0) added to all aggregates
  • No individual data — Only aggregated statistics are computed
  • You can opt out at any time from your profile settings
007
Retention

Data retention

We retain your data for as long as your account is active. Your full transaction history, budget records, net worth snapshots, and simulation results remain available for as long as you maintain an account.

When you delete your account, we permanently delete all associated personal data from our production systems within 30 days, including:

  • Account profile and credentials
  • Linked financial account connections and cached data
  • Transactions, budgets, goals, and settings
  • Simulation results and AI query history
  • Community benchmark contributions (removed from future aggregations)

Anonymized, aggregated data already incorporated into community benchmarks (with differential privacy applied) may persist, as it cannot be traced back to any individual.

Backups containing your data are purged within 90 days of account deletion.

008
Your Rights

Your rights

You have rights over your personal data regardless of where you live. We honor these rights for all users.

AccessRequest a copy of all personal data we hold about you.
CorrectionUpdate inaccurate or incomplete data at any time from your account settings, or by contacting us.
DeletionDelete your account and all associated data. Initiated from account settings or by email. Completed within 30 days.
ExportDownload your transaction history as CSV from the Transactions page.
Opt-outDisable community benchmarks at any time from your profile settings.
DisconnectRemove any third-party account integration (Plaid, SnapTrade) at any time.

California residents (CCPA)

Under the California Consumer Privacy Act, you have additional rights:

  • Right to Know — Request categories and specific pieces of personal information collected, sources, purpose, and third parties.
  • Right to Delete — Request deletion of your personal information, subject to certain exceptions.
  • Non-Discrimination — We will not discriminate against you for exercising your CCPA rights.
  • No Sale — We do not sell your personal information. We have not sold personal information in the preceding 12 months.

Contact support@rikdom.io to exercise your CCPA rights. We respond to all verifiable consumer requests within 45 days.

European Economic Area residents (GDPR)

Our legal basis for processing your personal data:

  • Contractual necessity — Processing required to provide the Rikdom service.
  • Legitimate interest — Processing for platform improvement, security, and fraud prevention.
  • Consent — Community benchmarks are an opt-in feature you turn on in your profile, and you can turn them off at any time.
  • AI features are not consent-based — AI Insights runs on the question you ask it, and automatic transaction categorization runs as part of providing the service. Both are contractual necessity, not consent. Anthropic processes that data under commercial API terms that do not permit training on it.

You additionally have the right to restrict processing, data portability, object to processing, and lodge a complaint with your local data protection authority.

Our data processor (Supabase/AWS) stores data in the United States. We rely on standard contractual clauses for lawful data transfers.

When you delete your account we delete your data from our systems and instruct our processors to do the same, but data already held by them — Plaid, SnapTrade, Stripe, Anthropic — is removed on their own retention schedules, which we do not control. We also keep security audit records (sign-ins, permission changes) after deletion, with your account identifier removed, because we need them to investigate account-takeover attempts.

Contact support@rikdom.io to exercise any of these rights.

009
Age

Age requirement

Rikdom is intended for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected data from a user under 18, we will promptly delete the account and all associated data. If you believe a minor has provided us with personal information, please contact us at support@rikdom.io.

010
Changes

Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the platform.

011
Contact

Contact us

Questions about this Privacy Policy? Reach us at support@rikdom.io.