Pace Privacy Policy

Effective date: June 30, 2026
Contact: patrickrgloria@gmail.com

Overview

Pace is a personal budgeting and cash-flow management application. This policy explains what information we collect, why we collect it, how it is stored, and how users can request deletion.

Information We Collect

We collect information users provide directly, including name, email address, account settings, budget categories, manual transactions, CSV imports, and support or security communications.

When a user connects an account through Plaid or another financial data provider, we may collect read-only financial account data authorized by the user, including account metadata, account balances, transaction history, transaction categories, merchant names, dates, amounts, pending status, and recurring transaction signals when available.

We also collect limited operational metadata such as request timestamps, API paths without query strings, response status, duration, and content length. We do not intentionally log cookies, request bodies, response bodies, provider access tokens, API keys, bank credentials, or full financial payloads.

How We Use Information

We do not use Plaid data for investment advice, brokerage, lending decisions, payment initiation, ACH transfers, KYC/AML screening, eligibility decisions, or unrelated advertising.

Financial Data Providers

When Plaid Link is enabled, users will be asked to authorize access before any provider data is collected. Plaid may collect and process information according to its own end-user privacy policy. Pace receives only the data authorized for the selected product scope.

Provider access tokens are stored server-side and encrypted before database storage. Provider tokens are not returned to the browser in API responses.

Storage and Security

Production data is stored in Google Cloud services. Cloud Run provides HTTPS for client traffic, Cloud SQL provides encrypted database storage, and GCP Secret Manager stores production secrets. Provider access tokens are encrypted at the application layer using AES-256-GCM before storage.

Financial application state is stored server-side. The application does not intentionally store sensitive financial state in browser localStorage.

Sharing

We share information only with service providers needed to operate the application, such as Google Cloud Platform for hosting and storage, Plaid for user-authorized financial account connectivity, OpenAI for assistant responses using limited app context when enabled, and source-control or security tooling used to operate the service.

We do not sell consumer financial data.

User Choices

Users can disconnect linked accounts, reset app data, or request deletion of account data. Disconnecting a linked account removes the stored provider token and stops future syncing for that account. Deletion requests remove application financial data and active sessions, subject to backup retention, security, legal, and operational requirements.

Data Retention

We retain user data while the account is active and while needed to provide the budgeting service. Backup copies may remain for a limited retention period before aging out automatically. See the Data Retention and Deletion Policy.

Children

Pace is not intended for children under 13 and does not knowingly collect information from children under 13.

Changes

We may update this policy as the application, provider scope, or legal requirements change. Material changes will be reflected by updating the effective date and policy text.

Contact

Patrick Gloria
patrickrgloria@gmail.com