Legal
Privacy Policy
Last updated: July 22, 2026
This Privacy Policy explains how Sumwright (“we,” “us,” or “our”) collects, uses, and protects information when you use the Sumwright applications and website (the “Service”). We built Sumwright to handle sensitive financial data, and protecting it is core to the product.
The data controller is TMGWRIGHT INC., 21506 Auten Rd, South Bend, IN 46628, USA. Contact: support@sumwright.com.
Information we collect
- Account information — your email and authentication details, managed through our identity provider (Supabase).
- Financial account data — when you link a bank or card, we receive read-only account balances and transaction history through Plaid. We do not receive or store your online-banking password.
- Usage & device data — basic app interactions and, if you opt in, a device push token so we can send you notifications (for example, when a payment you planned is confirmed from your bank transactions).
- Statement & receipt images — when you scan a statement as a PDF or scan a receipt, the file is sent to our AI processing provider (Google, via the Gemini API) to extract the data, and receipt images you save are stored in our file storage. When you scan a paper statement, text is extracted on your device and only that text is sent to us.
- Subscription data — your entitlement status from our billing partners (Apple, Google, Stripe via RevenueCat / Stripe). We do not store full card numbers; payments are processed by those providers.
How we use information
We use your information to provide and improve the Service: to analyze your accounts and build your debt-payoff and cash-flow plans, to plan payments and confirm them from your bank transactions, to categorize transactions, to send notifications you’ve enabled, and to manage your subscription. We do not sell your personal information, and we do not use your financial data for advertising.
Legal basis (EU / UK)
If you are in the EEA or UK, we rely on these lawful bases under the GDPR / UK GDPR: performance of a contract (to provide the Service you sign up for); consent (for optional features such as linking a bank, uploading statements or receipts for AI processing, and push notifications — you may withdraw consent at any time); legitimate interests (to secure the Service, prevent fraud, and debug); and legal obligation (to comply with law).
How we share information
We share data only with service providers that help us run the Service, under agreements that limit their use of it: Plaid (bank connectivity), Supabase (auth, database, and file storage), Google (Gemini API, to read statement PDFs and receipt images you upload), Amazon Web Services (encryption key management), Render (application hosting), and our billing providers (Apple, Google Play, RevenueCat, Stripe). We may disclose information if required by law or to protect rights and safety. If Sumwright is involved in a merger or acquisition, data may transfer as part of that transaction, subject to this Policy.
How we protect it
- Data is encrypted in transit (TLS) and at rest.
- Each user can only access their own records — enforced at the database level with row-level security, not just in the app.
- Sumwright does not move money. It plans your payments and confirms them from your bank transactions — you make each payment yourself at your own bank.
- Multi-factor authentication is required before you connect a bank, and the access tokens that let us refresh your data are additionally encrypted at rest using a managed key service (AWS KMS).
- Bank access via Plaid is read-only.
International data transfers (EU / UK)
Our sub-processors are located primarily in the United States, so using the Service involves transferring your personal data outside the EEA and the UK. Our database is hosted in the US (Supabase, us-east-2), as is our key management (AWS). For these transfers we rely on appropriate safeguards under GDPR Article 46 / UK GDPR — the Standard Contractual Clauses together with the UK International Data Transfer Addendum — as set out in each provider’s data processing agreement, and, where a provider self-certifies, the EU-US Data Privacy Framework.
Your choices & rights
You can disconnect a linked institution at any time, which removes our ongoing access to that account, and you can delete your account and data in-app. If you are in the EEA or UK, you also have the right to access, rectify, erase, restrict, or object to processing of your personal data; to data portability; and to withdraw consent at any time. To exercise any right, email us; we respond within the statutory time (generally one month). In the US, you may have similar rights under laws such as the CCPA/CPRA.
Right to complain. You may lodge a complaint with your local data protection authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in the EEA, your national supervisory authority.
EU / UK representatives
Where required for individuals in the EEA or UK, our GDPR / UK GDPR Article 27 representatives are: to be appointed.
Data retention
We keep your information for as long as your account is active or as needed to provide the Service, and afterward only as required to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we delete or de-identify your personal data within 30 days, except where retention is legally required; data may remain in encrypted backups until the backup-retention period elapses.
Children
Sumwright is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a minor has provided us data, contact us and we will delete it.
Changes
We may update this Policy; material changes will be reflected by the “Last updated” date above and, where appropriate, by additional notice in the app.
Contact
Privacy questions or requests? Email support@sumwright.com.