Privacy Policy
SwipeFund — operated by Karr Consultants, LLC Tustin, California, United States
| Version | 1.0 |
| Effective | 29 July 2026 |
| Contact | privacy@getswipefund.com |
The short version
SwipeFund reads the transactions on cards you already carry so we can tell you which card to use, and how long your ordinary spending takes to reach something you're looking forward to.
- We never see your bank password. Plaid collects it directly; we receive only a token.
- We cannot move your money. We hold no capability to initiate a payment or transfer, and never will.
- We do not sell your data. Not to advertisers, not to data brokers, not to anyone. We do not use it to train AI models.
- You can leave with your data. Disconnect a bank or delete your account at any time, and it's gone.
Our revenue comes from a subscription you pay us. That is the whole business model. We have no incentive to do anything else with your information, and this policy is written to reflect that.
The rest of this document is the detail behind those four statements.
1. Who we are
SwipeFund is a product of Karr Consultants, LLC, a California limited liability company. In this policy, "we," "us," and "SwipeFund" mean Karr Consultants, LLC. We are the business responsible for the personal information described here.
Questions, requests, or complaints: privacy@getswipefund.com
2. What we collect
2.1 Information you give us
| What | Why |
|---|---|
| Email address and Google account identifier | To create and authenticate your account |
| Cards you tell us you carry | To calculate which card earns most where |
| Travel goals and destinations | To project how long your spending takes to reach them |
| Points balances you enter or correct | To keep your progress accurate when a program can't be read automatically |
2.2 Information from your financial institutions, through Plaid
When you connect an institution, we receive:
- Transactions — amount, date, merchant name, and category
- Account details — account name, type, the last four digits, and the institution's name
That's the complete list. We request one Plaid product, Transactions, and nothing else.
2.3 Information collected automatically
Basic technical data needed to operate a website — IP address, browser type, and pages visited — along with authentication events such as sign-in and sign-out. We do not use advertising trackers or third-party analytics that build profiles across other sites.
3. What we never collect
These are structural exclusions, not promises about restraint. In most cases we could not obtain this information even if we wanted to.
- Your bank or card login credentials. Plaid Link collects these directly inside its own interface. They never pass through SwipeFund's website, servers, database, or logs. We could not produce your banking password under any circumstance, including a court order.
- Full account numbers. We receive four digits — enough to tell your cards apart, useless for anything else.
- Your credit or debit card number, CVV, or PIN.
- Your Social Security number, date of birth, or government ID. We request no Plaid product that returns them.
- Your airline, hotel, or credit card program logins. We will not build a feature that stores them.
4. Why we use your information
We use your information for one purpose: to deliver the product to you. Specifically:
- To determine which of your cards earns the most in each spending category
- To flag purchases where a lower-earning card was used
- To project how long your real spending takes to reach a goal you've set
- To keep your account working — authentication, support, and security
We do not use your information to:
- Sell or rent it to anyone
- Serve you advertising, or help anyone else do so
- Train artificial intelligence or machine learning models
- Make any decision about your credit, employment, insurance, or housing
- Build profiles for anyone other than you
We are not a credit reporting agency. We furnish no information to lenders and make no eligibility determination about you.
5. Who we share it with
We do not sell your personal information. We have never sold it, and we do not share it for cross-context behavioral advertising.
We use a small number of service providers who process data strictly on our instructions:
| Provider | Role | What it handles |
|---|---|---|
| Plaid Inc. | Connects your financial accounts | Your bank credentials, entered directly with Plaid; transaction data |
| Supabase Inc. (on AWS, United States) | Database and authentication | Stored account and transaction data |
| Vercel Inc. | Website hosting | Request data in transit |
| Google LLC | Sign-in provider | Confirms who you are; receives no financial data |
Plaid handles your information under its own End User Privacy Policy, available at plaid.com/legal. We encourage you to read it, since Plaid — not SwipeFund — is who your bank credentials are given to.
Beyond these providers, we disclose personal information only where legally compelled — a valid subpoena, court order, or lawful government demand — or where necessary to protect someone's safety. If we are ever compelled to disclose your information, we will tell you unless prohibited by law from doing so.
If this business is ever sold or merged, your information may transfer to the new owner. We will notify you before that happens, and the commitments in this policy will bind whoever takes it on.
6. How long we keep it, and how to make us delete it
We keep your data only while it's serving you.
| Data | Deleted when |
|---|---|
| Plaid access token | You disconnect that institution, delete your account, or the bank revokes access |
| Transaction records | You disconnect that institution or delete your account |
| Connected account details | You disconnect that institution or delete your account |
| Cards, goals, spending profile, points ledger | You delete your account |
| Email and account identity | You delete your account |
Disconnecting one institution removes that institution's data and leaves your other connections untouched. Deleting your account removes everything, enforced by the database itself rather than by a cleanup routine that might miss something.
Deleted data may persist in encrypted backups until those expire on their normal schedule, after which it is unrecoverable. We are not able to search those backups in the ordinary course, and we never use them to restore data you asked us to delete.
7. Your rights
Everyone, regardless of where you live, may:
- See what we hold about you
- Correct anything that's wrong
- Disconnect any bank at any time
- Delete your account and all its data
- Take your data with you in a portable format
Email privacy@getswipefund.com and we'll take care of it. There's no charge, and we won't degrade your service for asking.
7.1 California residents
Under the CCPA as amended by the CPRA, you have the right to know, delete, correct, and obtain a portable copy of your personal information; to opt out of sale or sharing; and to limit the use of sensitive personal information.
Applied to us:
- Sale or sharing: none. We do not sell or share personal information for cross-context behavioral advertising, and we have not in the preceding twelve months. There is nothing to opt out of.
- Sensitive personal information. Financial account information is treated as sensitive under California law. We use it solely to provide the service you asked for — the sole permitted purpose — and never to infer characteristics about you.
- Categories collected: identifiers, commercial information (transaction history), internet activity, and sensitive personal information (financial account information), as described in §2.
- No discrimination. We will not deny service, charge a different price, or provide a lesser experience because you exercised a privacy right.
We respond to verifiable requests within 45 days, extendable once by another 45 where the law allows. You may designate an authorized agent to make a request on your behalf.
7.2 Residents of other states
Virginia, Colorado, Connecticut, Utah, Texas, and a growing number of other states grant comparable rights. We extend the rights in this section to every user, so you do not need to determine whether your state's law applies.
8. How we protect it
Everything travels over encrypted connections (TLS 1.2 or higher) and is encrypted at rest. Plaid access tokens carry an additional layer of encryption and are never sent to your browser.
Your data is isolated from every other user's at the database level, not merely by application code — meaning another user could not reach your records even if they bypassed our application entirely. Access to production systems is limited to one person and requires multi-factor authentication.
Our full information security policy is available on request.
No system is perfectly secure, and we will not claim otherwise. If a breach ever affects your information, we will notify you as required by California Civil Code §1798.82 and any other applicable law, and we will tell you what happened rather than issue a form letter.
9. Children
SwipeFund is not directed to anyone under 18, and we do not knowingly collect information from children. If we learn that we have, we will delete it.
10. Changes
If we change this policy in a way that materially affects how we handle your information, we will notify you before the change takes effect — by email or in the product — rather than quietly updating a page. The effective date at the top always reflects the current version.
11. Contact
Karr Consultants, LLC Tustin, California, United States privacy@getswipefund.com
Write to us with any question about this policy, any request regarding your data, or any concern about how we've handled it. A real person reads that address.