The short version, in plain English
- We’re a ledger, not a bank. We never hold your money.
- We never see your bank passwords. In the US you connect through Plaid or Apple’s on-device FinanceKit with your consent, or you import a statement that is read on your device, or add spends by hand. Your transaction history lives on your device; our servers keep only encrypted Plaid access tokens, account details and sync markers.
- Your partner sees Joint transactions and their own Personal ones, never yours. You can optionally share a monthly Personal total (no merchants, no line items).
- We do not sell or share your personal information. Ever.
- Ads are labelled and kept out of your money screens. Perks say “Ad · Sponsored by” and the brand. There are no third-party ad networks or ad SDKs: Perks are a catalog ranked on your device, so no personal data goes to advertisers. Duo Max is ad-free.
- AI runs on your device. Insights use Apple’s on-device Foundation Models, and nothing is sent to a cloud AI provider today.
- You’re in control. Access, export, correct, delete or opt out any time at privacy@pairpot.app.
- 18+ only.
1.Who we are
Wemakesense LLC (“PairPot”, “we”, “us”) provides a couples’ finance app that keeps a shared, virtual “joint pot” ledger between two partners, each of whom keeps their own bank accounts. We launch in the United States first. We are the “business” under California’s CPRA and similar US state laws, and (for people outside the US) the data controller or Data Fiduciary for the personal data described here.
Wemakesense LLC7901 4th St N, Ste 300, Saint Petersburg, FL 33702-4399, United States
Privacy contact: privacy@pairpot.app
“You” means the person using PairPot. “Your partner” means the other person you link with inside PairPot.
2.The data we collect
- Account information. Display name, emoji or avatar, sign-in identifier (for example your Apple ID relay email or phone number), home currency, cycle start day, and an optional payment handle (Venmo, PayPal.Me or Cash App; or a UPI ID if you use INR) if you add one to settle up.
- Partner link and agreement. The pair code used to link you with your partner, link status, your partner’s display name, and the household agreement: contribution ratio, monthly budget, change proposals, and the cryptographic signatures that approve them.
- Money sources, with your consent. At launch, your transaction data comes from:
- Plaid (US live bank connections).
- Apple FinanceKit (US; read on your device with your permission).
- Statement import (CSV or OFX files you choose), parsed on your device.
- Manual entry (spends you add yourself).
- Data we derive. Categories, Joint/Personal tags and classification confidence, merchant rules learned from your re-tags, split overrides, settlements, savings balances, monthly close results, and insights computed from the above. These are computed on your device.
- Device public keys (PairKey). To let you and your partner approve agreement changes, we store the public key of a key pair created on your device. The private key is held in your device’s secure hardware and never leaves it.
- Support messages. What you send us, plus any details you choose to share.
- No analytics or crash reporting. PairPot does not run its own analytics or crash-reporting tools today. The only diagnostics are Apple’s own App Store and TestFlight diagnostics, which Apple shares with us only if you opt in on your device. PairPot contains no third-party advertising SDKs or ad networks.
- Purchase status from Apple. Your subscription tier, trial status and renewal or expiry dates. We do not receive your card number or payment details.
- Website and waitlist data. See section 13.
Financial account information is “sensitive personal information” under CPRA and some other state laws. We use it only to provide PairPot to you, as described in this policy.
3.What your partner can and can’t see
PairPot is built so that privacy is the default: your Personal transactions are never shown to your partner.
| Data | You | Your partner |
|---|---|---|
| Joint transactions | Yes | Yes |
| Your Personal transactions | Yes | Never |
| Your monthly Personal total | Yes | Only if you switch on “Share my personal total”. Total only: no merchants or line items. Off by default. |
| Ratio, budget, change proposals and who signed | Yes | Yes |
| Your display name, emoji and (if added) payment handle | Yes | Yes |
| Your email or phone, and your linked-account credentials | Yes | No |
Re-tagging a transaction between Joint and Personal changes what your partner can see and the pot’s totals. You can move a transaction between Joint and Personal without your partner’s approval, and every Joint transaction is visible to both of you, so please tag with care. Changing how a transaction is split (a split override) is different: it needs your partner’s OK before it counts. Transactions from an account you both own (a “shared” account) are visible to both of you and counted as paid by ratio.
4.How we use your data
- To run PairPot: link you and your partner, read your transactions, tag them, apply your ratio, close each month, track settlements and savings, and show you who owes who.
- To keep it secure and working: prevent fraud and abuse, debug and improve reliability.
- To process subscriptions and check your entitlement with Apple.
- To support you and respond to requests.
- To show clearly labelled Perks (section 6), unless you are on Duo Max.
- To meet legal obligations and handle legal claims.
We do not make decisions about you that have legal or similarly significant effects solely by automated means, and we do not use your personal information to build advertising profiles.
5.AI features
- Numbers are calculated by PairPot, not by AI. Category totals, pace, recurring charges and fair-ratio suggestions are deterministic. AI only helps phrase insights.
- On-device. Insights and recaps are written by Apple’s on-device Foundation Models where your device supports them. That processing stays on your device.
- No cloud AI today. Nothing about you or your money is sent to a cloud AI provider. If we add a cloud-based AI coach in the future, we will update this policy first, and it will be opt-in.
- Not advice. AI features give budgeting insight only. They are not financial, investment, credit or tax advice.
6.Sponsored Perks
On Duo and (less often) Duo+, PairPot may show “Perks”: native cards from partner brands, from our own first-party catalog of direct sponsors and affiliate offers.
- Always labelled as ads. Every Perk carries a visible label reading “Ad · Sponsored by” followed by the brand’s name, plus “Why this?” and “Hide”.
- Never in your money screens. Perks never appear in your transactions list or transaction details, Review inbox, Pot ledger numbers, Monthly Close, Settle Up, PairKey or consent flows, onboarding, or the paywall. They may appear in the Insights feed (at most one card, at the bottom), Goals/Savings (at most one), and a dedicated Perks section, with a cap of three per day.
- No third-party ad networks. PairPot does not use ad SDKs or ad exchanges. Your device downloads the Perk catalog in bulk, and the ranking happens on your device using coarse category signals computed there (for example “groceries is your top category”). Because nothing is requested on a per-user basis, no personal data goes to advertisers, and no transaction data leaves your device for advertising. We never share your transactions, merchants or amounts with advertisers.
- Your choice. You can hide any Perk and turn off Perk personalisation in Us → Perks. Duo Max is ad-free.
- If you tap a Perk, you leave PairPot. The sponsor’s site or app (or an affiliate network it uses) will see your visit, may be told it came from PairPot, and handles it under its own privacy policy.
8.How long we keep it
- While your account is active, we keep the data needed to run PairPot.
- If you delete your account, we delete or irreversibly anonymise your personal information within 30 days, except what we must keep by law. Backups are purged within 90 days. This includes your Plaid connections, which we remove with Plaid.
- If you disconnect a linked account, we stop fetching data, remove the connection with Plaid, and delete its stored access token and account details. Transactions already on your device stay on your device under your control.
- If you and your partner unlink, the pot stops syncing. Each of you keeps your own Personal data and it is never shown to the other. Pending PairKey proposals are cancelled.
- Support emails for 24 months. Security logs for 12 months. Waitlist emails until launch, or until you ask us to delete them.
9.Security
We use administrative and technical safeguards appropriate to the sensitivity of your financial data. In practice that includes encryption in transit, Plaid access tokens encrypted at rest with AES-256-GCM, short-lived signed session tokens, Personal records kept out of your partner’s view, device-held keys (secure hardware, protected by Face ID or Touch ID) for PairKey approvals, and keeping transaction history on your device rather than on our servers. Bank credentials never reach our servers.
No system is perfectly secure. If a breach affects you we will notify you without undue delay, and notify regulators as the law requires (for example under state data-breach notification laws, and for people outside the US as described in section 11).
10.Your US privacy rights
Depending on your state (including California, Colorado, Connecticut, Virginia, Texas, Oregon and others), you may have the right to:
- Know and access the personal information we collect, use and disclose about you, and receive a portable copy;
- Delete your personal information (subject to legal exceptions);
- Correct inaccurate information;
- Opt out of the sale or sharing of your personal information and of targeted advertising or profiling: we do not sell or share personal information and we do not engage in targeted advertising, so there is nothing to opt out of. We still honour “Do Not Sell or Share My Personal Information” requests and Global Privacy Control signals;
- Limit the use of sensitive personal information (we use it only to provide the service);
- Not be discriminated against for exercising these rights.
How to ask. Email privacy@pairpot.app or use the in-app privacy controls when available. We may verify your identity (for example through your signed-in account). You may use an authorised agent. We respond within 45 days, and may extend once by another 45 days where permitted. Appeals: if we decline a request you can reply to our message with the word “Appeal” and we will review it and respond within 45 days (60 where your state allows).
Categories collected in the past 12 months (none sold or shared): identifiers (name, email, device keys); commercial information (subscription status); financial information (account details and sync markers on our servers; transaction data on your device); inferences we compute about your spending categories; and your communications with us. We disclose them only to the service providers and parties in section 7.
Nevada and other states. We do not sell covered information as defined by Nevada law. California “Shine the Light”: we do not disclose personal information to third parties for their direct marketing.
11.If you live outside the US
PairPot works anywhere, but live bank connections are US-only at launch; elsewhere you import statements or add spends manually. If you are in the EEA, UK, Switzerland or India, these additional terms apply.
- Legal bases (GDPR / UK GDPR). Contract (providing the app you asked for), consent (connecting accounts, optional sharing of your Personal total, waitlist emails), legitimate interests (security, fraud prevention, product reliability), and legal obligation. In India (DPDP Act, 2023) we rely on your consent and the Act’s limited “legitimate uses”. You can withdraw consent at any time, as easily as you gave it; some features may then stop working.
- Your rights. You can ask to access, correct, complete, update or delete your data; restrict or object to processing; receive your data in a portable format; and withdraw consent. In India you also have the right to grievance redressal and to nominate another person to exercise your rights if you die or become unable to. Email privacy@pairpot.app. We respond within the time the law requires and in any event within 30 days.
- Complaints. You can complain to your local authority, for example the UK Information Commissioner’s Office, your EU data protection authority, or (after using our grievance process) the Data Protection Board of India.
- International transfers. Our servers (Cloudflare) are in the United States, so the data we store is transferred there. For transfers from the EEA, UK or Switzerland we use safeguards such as Standard Contractual Clauses and the UK International Data Transfer Addendum; transfers of data about people in India follow the DPDP Act and any restrictions the Government of India notifies.
- Breach notification. Where required we notify affected people and the relevant authority (for example within 72 hours to GDPR supervisory authorities, and to the Data Protection Board of India and affected Data Principals under the DPDP Act).
- Representatives and grievances. We will appoint an EU/UK representative if and when the law requires one. For India, our grievance contact under the DPDP Act is the PairPot privacy team at privacy@pairpot.app, Wemakesense LLC, 7901 4th St N, Ste 300, Saint Petersburg, FL 33702-4399, United States.
12.Children
PairPot is for adults aged 18 and over. It is not directed to children (including under COPPA) and we do not knowingly collect their data. If you believe a child has used PairPot, contact privacy@pairpot.app and we will delete the account and data.
13.This website & the waitlist
- Waitlist. The waitlist form opens a pre-filled email in your own mail app (a “mailto” link), so what we receive is what you choose to send. We keep waitlist emails until launch, or until you ask us to delete them, and use them only to tell you about PairPot.
- Cookies and storage. This website does not use advertising or analytics cookies. It stores your light/dark theme choice in your browser’s local storage, only on your device.
- Fonts. To display the rounded typeface on devices that don’t have it, the site may load the Nunito font from Google Fonts, which means your IP address is sent to Google.
- Server logs. Our hosting provider, Cloudflare Pages, keeps standard technical logs (IP address, browser, pages requested) for security and reliability.
14.Changes to this policy
If we make material changes we will tell you in the app or by email before they take effect, and where the law requires it we will ask for your consent again. The “effective” date at the top shows the current version.
15.Contact
Privacy questions and requests: privacy@pairpot.appGeneral: hello@pairpot.app
Post: Wemakesense LLC, 7901 4th St N, Ste 300, Saint Petersburg, FL 33702-4399, United States