Privacy policy
splurn tells you which of your credit cards to use and tracks the perks on them. This page says what we collect, why, how long we keep it, and how to delete it. splurn is run by Wonchan Kim ("we"). Questions: wonchankim97@gmail.com.
What we never collect
Card numbers, security codes, bank usernames or passwords, and account or routing numbers. When you connect a bank, you sign in on Plaid's screen; splurn never sees those credentials.
What we collect and why
| Data | Why | Where it lives |
|---|---|---|
| Which card products you hold, perk usage, preferences, saved stores | To rank your cards and track credits | On your phone. On our server only if you save your wallet. |
| Email address or Apple ID identifier | To sign you in and sync your wallet | Our server |
| Card transactions from Plaid (date, merchant, amount, category) | To mark credits as used and count bonus caps. Only if you connect an account. | Our server and your phone |
| Your location, while the app is open | To find the store you are in | Used on your phone only. Never sent to or stored by us. |
| Your consent to connect accounts, with the date and policy version | To show you agreed, and to let you withdraw | Our server |
| Premium subscription status | To unlock Premium | Apple handles payment; we see only whether you subscribe |
How we use Plaid
We use Plaid to connect your card accounts with read-only access to transactions. By connecting, you also agree to Plaid's End User Privacy Policy. We cannot move money. The key Plaid gives us for your connection is encrypted on our server and never stored on your phone.
What we do not do
We do not sell your data, share it with advertisers, or use it to track you across other apps or websites. We do not use it to decide credit. If splurn shows a card you could apply for, the order is never changed by any fee we may earn.
How long we keep it
| Data | Kept for |
|---|---|
| Card transactions | 180 days, then deleted automatically |
| Sign-in sessions | 90 days, then you sign in again |
| Email sign-in codes | Deleted within a day |
| Your saved wallet and account | Until you delete your account |
Deleting your data
- Disconnect a bank: Wallet › Settings › Linked accounts › Disconnect. We revoke the connection at Plaid and delete its transactions.
- Withdraw consent: Wallet › Settings › Withdraw consent disconnects every bank and deletes their data.
- Delete your account: Wallet › Settings › Delete account removes your account, saved wallet, connections, and transactions from our server immediately. We keep only a one-way hash of your account ID and the date, as proof the deletion happened.
- Or email us and we will do it within 30 days.
Security
Data travels over HTTPS only. Plaid connection keys are encrypted with AES-256-GCM, and our database sits on an encrypted volume. On your phone, transactions are stored in a file that iOS keeps encrypted while the phone is locked, and your sign-in token is in the Keychain. Connecting a bank needs Face ID or your passcode and a recent sign-in.
Your rights
You can see, correct, export, or delete your data at any time. California residents have these rights under the CCPA, and we honor them for everyone. We do not knowingly serve anyone under 13.
Changes
When this policy changes we update the version and date above. If the change affects connected accounts, the app asks for your consent again before syncing.