Moneylight is a forward-looking cash-flow forecasting tool for YNAB users, operated by Sage Canyon Labs LLC ("we," "us," or "our"). This policy explains what data Moneylight collects, how it is stored, how long it is kept, and how you can have it deleted. If anything here is unclear, email hello@moneylight.app.
What we collect
YNAB account data and sign-in
Moneylight uses YNAB as its only sign-in method. When you connect your YNAB account, Moneylight requests access to your YNAB Plan through YNAB's official OAuth API, using YNAB's read-only scope. Moneylight reads your Plan to build your forecast and never writes to it: it cannot create, edit, or delete anything in YNAB. There is no separate Moneylight username or password to create: your identity is your YNAB connection.
The data read for forecasting and planning includes account names and balances, transactions, categories, payees, and scheduled transactions. Moneylight does not copy that data into its database. It is fetched from YNAB each time you load your forecast and held only for as long as it takes to render the page (briefly in memory, for up to a minute, so that editing a bill does not re-fetch your whole Plan on every keystroke). What Moneylight stores is your setup: which Plan you chose, which accounts and categories you selected, the payee names attached to the bills you created, and the bills, paychecks, necessities, and savings rules you entered yourself.
Moneylight never asks for, sees, or stores your YNAB password or your bank login credentials: authorization happens entirely on YNAB's own consent screen, and you can disconnect from inside Moneylight or revoke Moneylight's access at any time from your YNAB account settings. Moneylight also stores the timezone your browser reports, so the forecast can calculate your local week.
Subscription billing
Moneylight offers a free trial followed by a paid subscription. When you start a trial or paid plan, payment is handled entirely by Stripe, our payment processor. Your card details are entered on Stripe's secure checkout and never reach Moneylight's servers. Moneylight stores the Stripe customer and subscription identifiers, your plan, and your subscription status, which together tell Moneylight whether your account has active access. Moneylight also stores the email address you enter at Stripe checkout, and the first name from the billing name you enter there (the first word only, never the full name): the email address so we can contact you about your account and respond when you reach out for support, and the first name only so our service emails can address you by name rather than a bare "Hi." Neither is used for marketing, and neither is shared or sold. Stripe holds your payment details under its own privacy policy.
Transactional email
Moneylight sends a small number of service emails about your account, for example when your free trial ends and a payment is due. These are delivered by Postmark, our email delivery provider, which processes your email address and the message content in order to deliver it. Postmark reports delivery outcomes back to Moneylight (delivered, bounced, or marked as spam) so we know our email is reaching you. These emails contain no tracking: there is no open-tracking pixel, and links are not rewritten or tracked. They are service messages about your account, not marketing email.
Website analytics
This site uses Cloudflare Web Analytics to count visits and understand which traffic sources lead to trial signups. It is a privacy-first, cookieless service: it sets no cookies, stores no identifier on your device, and does not track you across other sites. It collects only aggregate usage data (page views, referrer, approximate location at the country level, and device and browser type), and it never receives your name, email address, or any YNAB or billing data. That applies to this marketing site only. The Moneylight app itself runs no analytics and no third-party scripts, so nothing tracks what you do once you are signed in. Cloudflare's privacy policy is at cloudflare.com/privacypolicy.
Referral program
If you were invited to Moneylight through another user's referral link or code, Moneylight records which account referred you, so that the referrer can earn an account credit once you become a paying subscriber. Moneylight also stores the referral rewards each account has earned. We rely on our legitimate interest in operating the referral program and preventing abuse as the lawful basis for this. This is entirely first-party: no referral or affiliate service is involved, and we do not share this information with any third party. When a referral credit is applied, the referred account's internal Moneylight identifier is recorded on the credit in Stripe (our payment processor); it is an internal identifier, not your name or email, and Stripe retains its billing records under its own policy even after you close your account. If you visit a referral link, the referral code appears in our web server's standard access logs alongside the request, in the ordinary course of serving the page.
How we store and protect your data
- Your YNAB transactions are not stored. There is no copy of them in Moneylight's database and no sync that mirrors them: they are read from YNAB on each page load and discarded. What Moneylight's Render-hosted database holds is your setup, described above, plus the OAuth tokens YNAB issues, which are encrypted at rest and used only to fetch the data described above. All connections use TLS in transit.
- Billing data we hold is the Stripe customer and subscription identifiers, your plan, your subscription status, and the email address and first name you entered at checkout, stored in the same Render database. Your card details are held by Stripe, not by Moneylight.
- Referral data (which account referred you, and the rewards each account has earned) is stored in the same Render database. It is first-party only and never shared with a third party.
- Email delivery data passes through Postmark, which retains message content and delivery metadata for 45 days and then deletes them. Moneylight itself stores only a record of when a service email was sent to your account.
- Analytics data is aggregate and non-identifying, and is retained by Cloudflare for up to six months.
Our access to your data
Moneylight is operated by a single person, and access to the database is limited to that operator. We access the setup stored in your account when you contact us for support, when you report a problem, or when we are investigating a defect that appears to affect your account. We do not browse account data outside those situations. We rely on our legitimate interest in supporting and maintaining the service as the lawful basis for this access.
We also review stored setup in aggregate across accounts, to find and fix problems that affect more than one user: for example, counting how many accounts have bills configured in a way that triggers a known defect. That review works from counts and patterns rather than the contents of any individual account, and anything derived from it is aggregate and does not identify you.
How long we keep it
- Your YNAB connection and forecast setup (the OAuth tokens, your selected Plan, accounts and categories, and the bills, paychecks, necessities, and savings rules you entered) are kept while your Moneylight account exists and deleted on account closure or on request. Your transactions are not kept at all, because they are never stored in the first place.
- Your billing identifiers, checkout email, and first name are kept while your account exists, and are deleted with your account. Stripe retains its own record of your transactions even after you cancel, for as long as tax and anti-fraud law requires.
- Your referral data is kept while your account exists and deleted on account closure or on request. The internal identifier recorded on a Stripe credit remains in Stripe's billing records under its own retention rules.
- Transactional email content and metadata are retained by Postmark for 45 days and then deleted. Moneylight's record of when a service email was sent to you is kept while your account exists and deleted on account closure.
- Analytics data is aggregate and follows the Cloudflare retention window described above.
Third-party data handling
The data obtained through the YNAB API will not unknowingly be passed to any third party.
Moneylight uses the following named third-party service providers:
- Cloudflare (Cloudflare, Inc.; cookieless website usage analytics): cloudflare.com/privacypolicy
- SiteGround (web hosting): siteground.com/privacy.htm
- Render (application hosting and the encrypted database where your YNAB connection and forecast setup are stored): render.com/privacy
- Stripe (Stripe, Inc.; payment processing and subscription billing): stripe.com/privacy
- Postmark (ActiveCampaign, LLC; transactional email delivery): activecampaign.com/legal/privacy-policy
- Sentry (Functional Software, Inc.; application error and performance monitoring, production only): sentry.io/privacy
Sentry captures server-side exceptions so that production failures are visible. It is configured so no user identity is attached to error events (no IP address, no email), and stack-frame local values are suppressed. That means decrypted YNAB access tokens and account balances are never transmitted to Sentry. An exception traceback may incidentally include YNAB request context, which is why Sentry is named here, but it does not carry your decrypted secrets or balances.
Moneylight does not sell user data, and does not aggregate or analyze YNAB-derived data for sale to any third party.
Deleting your data
You do not have to ask us. Your account page has both controls, and neither one waits on us:
- Disconnect deletes the OAuth tokens we hold, so Moneylight can no longer reach your YNAB. Your bills and paychecks are kept, so reconnecting later picks up where you left off. YNAB provides no way for an app to revoke its own grant, so the disconnected token expires on YNAB's side within about two hours; to clear the grant immediately, remove Moneylight from your YNAB account settings.
- Delete account permanently removes your account and everything derived from it at once: the OAuth tokens, your Plan selection, and every bill, paycheck, necessity, savings rule, and override you entered. It takes effect immediately, and any active subscription is canceled as part of it.
If you would rather we did it, or you can no longer sign in, email hello@moneylight.app from inside your Moneylight account or from the email tied to your subscription. We will:
- Confirm receipt within 7 days.
- Delete our stored YNAB tokens and everything else we hold about you within 30 days of your request.
- Cancel any active subscription and delete the Stripe identifiers, the email address, and the first name we store. Stripe keeps its own record of past transactions for as long as the law requires.
You can also revoke Moneylight's YNAB API access at any time from inside your YNAB account, and cancel your subscription at any time from the billing portal linked in your account.
Changes to this policy
If Moneylight changes how it uses YNAB data, accesses new types of data not described above, or adds new third-party processors, this policy will be updated, and where required you will be asked to re-consent before the new use begins. The "Last updated" date at the top of this page will always reflect the most recent revision.
Contact
Questions about this policy: hello@moneylight.app.
Moneylight is operated by Sage Canyon Labs LLC5900 Balcones Drive, Ste 100
Austin, TX 78731
United States