Skip to main content

Privacy Policy

Effective 6 August 2026 · Last updated 6 August 2026

Citadel Money is a budgeting web application published by Yost Group LLC (“we”, “us”) that helps couples and individuals build a monthly zero-based spending plan, track transactions, and work through the Citadel Map financial phases together. Unlike our on-device iOS apps, Citadel Money is a hosted service: the budget and financial information you enter is stored on our servers so it can sync between your devices and, if you choose, be shared with your partner. This policy explains exactly what we collect, how we protect it, and what we will never do with it.

1. Information we collect

1.1 Account information

When you create an account we collect your email address, a password (stored only as a modern salted hash — we cannot read it), your country, currency, and timezone. If you enable multi-factor authentication, we store the enrolment data needed to verify you.

1.2 Financial information you enter

The heart of the app is data you type in yourself: budget categories and planned amounts, income, transactions and payees, savings funds, debts and balances, goals, insurance inventory entries, notes, and due dates. This data belongs to your household and exists so the app can do budget maths for you.

1.3 Household and Couple Accord information

If you invite a partner, we store the household relationship between your two accounts. The Couple Accord feature asks each partner to privately record money-story reflections, ranked financial values, and an independent financial snapshot. These responses are private by default and encrypted. Your partner cannot see them — and we do not surface, summarise, or infer anything from them — until you explicitly choose to share them. See section 5.

1.4 Bank connection data (optional)

If you choose to connect a bank account, the connection is made through a regulated financial data aggregation provider (such as Plaid). You authenticate directly with your bank through the provider — we never see, receive, or store your bank username or password. We receive account names, types, balances, and transaction records (date, amount, merchant or payee description) for the accounts you authorise. Access tokens from the provider are encrypted with dedicated keys, separate from other data.

1.5 Payment information (paid plans)

Subscriptions are processed by our billing provider (such as Stripe). Card numbers are entered directly into the billing provider’s secure components and never touch our servers. We receive only your subscription plan, status, and billing period.

1.6 Technical and usage data

Like most web services, our servers log IP address, browser type, and request metadata for security, fraud prevention, and troubleshooting. We record a limited set of product-usage events (for example, “budget balanced” or “next month created”) to understand which features work. These events are deliberately stripped of financial content — see section 7.

1.7 What we do not collect

We never collect or store: your bank credentials, full card numbers, your partner’s unshared Couple Accord responses in readable form, advertising identifiers, or data from third-party ad or tracking networks. Citadel Money contains no advertising SDKs and does not track you across other companies’ apps or websites.

2. How we use your information

  • To run the service: calculate your budget, sync your data across devices, and keep your household’s plan current for both partners.
  • To import and categorise transactions from bank accounts you have connected.
  • To send transactional emails: verification, password reset, partner invitations, sign-in alerts, export-ready notices, and deletion confirmations. These emails never contain your transaction details or balances.
  • To send optional budget reminders you control — channel, timing, and cadence are set by you and can be turned off.
  • To manage your subscription and unlock paid features.
  • To secure the service: detect fraud, enforce rate limits, and investigate abuse.
  • To respond to support requests you initiate.
  • To improve the product using the sanitised usage events described in section 7.

What we will never do: we do not sell, rent, or lease your data. We do not use your financial data for advertising or allow anyone else to. We do not build marketing profiles from your transactions. The app never moves your money, and no automated guidance is applied without your explicit decision.

3. Where your data lives

  • On our servers — your budget, transactions, and household data are stored in our database, encrypted at rest and in transit, so they can sync between your devices and your partner.
  • With our service providers — the specific sub-processors listed in section 6, each under a data-processing agreement, and each receiving only what its function requires.
  • Nowhere else — your financial data is not distributed, syndicated, or made available to data brokers, advertisers, or analytics firms.

4. Bank connections

Connecting a bank account is always optional — Citadel Money works fully with manual entry. If you do connect:

  • You authenticate directly with your bank through the aggregation provider’s secure interface. Your credentials never pass through Yost Group systems.
  • Access tokens are encrypted with dedicated, rotated keys, and decryption is restricted to the sync process alone.
  • We display only account names and the last four digits — full account numbers are never shown or written to our application logs.
  • You can disconnect an institution at any time in Settings. Disconnecting stops all future imports; previously imported transactions remain in your budget history unless you delete them.
  • You may also revoke the provider’s access directly through your bank or through the provider’s own privacy portal.

The aggregation provider’s handling of your data is governed by its own privacy policy, which is presented to you before you connect your first account.

5. Sharing between partners

Citadel Money is built for couples, so it is worth being precise about what your partner can and cannot see:

  • Shared by design: the household budget, transactions, accounts, funds, debts, goals, and phase progress. Both members of a household see the same plan — that is the point of the product.
  • Private by default: your Couple Accord money-story reflections, ranked values, and draft financial snapshot. Each partner controls if and when these are shared, and can edit before sharing. Unshared responses cannot be retrieved, queried, or inferred by the other partner — this isolation is enforced in our systems and covered by our security testing.
  • Personal spending: households can set up personal spending categories for each partner. Your partner sees the allocation totals; transaction-level visibility within those categories is configurable by the household.
  • Access control: the household owner can revoke a partner’s access at any time. Material changes to the budget are recorded in an audit trail visible to the household.

6. When we share information

We share data only with the service providers required to operate Citadel Money, and only the minimum each needs:

  • Hosting and database providers — store the service’s encrypted data.
  • Bank data aggregator — facilitates the account connections you authorise (section 4).
  • Billing provider — processes subscription payments (section 1.5).
  • Email delivery provider — sends the transactional emails described in section 2.
  • Error-tracking and monitoring tools — receive technical diagnostics with financial data redacted.
  • Legal requirement — we would disclose information only if compelled by valid legal process directed at us, and we would notify you unless legally prohibited.

Every provider operates under a data-processing agreement. None may use your data for its own purposes. We do not sell or share personal information for cross-context behavioural advertising as defined by the CCPA/CPRA.

7. Analytics

We measure how the product is used so we can improve it — but our analytics are deliberately blind to your finances. Usage events are limited to feature actions and coarse buckets (for example, “transaction created — split: yes”).

Analytics events never include: dollar amounts, balances, payee or merchant names, transaction descriptions, notes, account names or identifiers, email addresses, or anything from Couple Accord responses.

8. Data retention and deletion

  • Deleted transactions: recoverable by you for 30 days, then permanently removed.
  • Export: you can export your budgets and transactions to CSV, and request a complete copy of all personal data we hold, at any time from Settings.
  • Account deletion: you can delete your account and household data from Settings. Deletion requires identity re-verification (to protect you from someone else destroying your financial records), followed by a short recovery window, after which data is permanently removed from production systems and rotated out of backups on our standard backup schedule.
  • Bank connection tokens: deleted when you disconnect an institution or delete your account.
  • Billing records: retained as required by tax and accounting law.
  • Households with two members: deleting your own account removes your personal data; shared household records that your partner also owns (the joint budget) remain with the household unless the household itself is deleted by its owner.

You may also email us to request access, correction, or deletion of any data we hold. We respond within 30 days.

9. Security

  • TLS encryption for all traffic; encryption at rest for databases, backups, and file storage.
  • Passwords hashed with a modern memory-hard algorithm (Argon2id class); we never store or transmit them in readable form.
  • Bank provider tokens and private Couple Accord responses encrypted with separate, rotated keys.
  • Multi-factor authentication available, and required for sensitive actions such as changing your email, exporting all data, deleting your household, or managing bank connections.
  • Authorisation checks on every request so one household can never read another’s data — verified by automated security tests.
  • No full account numbers or financial details in application logs or error reports.
  • Independent penetration testing and continuous dependency and secret scanning.

No online service can promise perfect security. If a breach affects your personal data, we will notify you and the appropriate authorities as required by law, and tell you plainly what happened and what we are doing about it.

10. Not financial advice

Citadel Money provides budgeting tools and educational guidance built on the Citadel Map framework. It does not provide individualised investment, tax, insurance, or legal advice, and it never executes trades, changes payroll contributions, cancels insurance, refinances loans, or moves money. Every recommendation in the app requires your explicit decision before anything is applied to your plan.

11. Children’s privacy

Citadel Money is a financial service intended for adults. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Education-planning features may store information about your children that you enter (such as a name and target college year) — that data is part of your household record and is protected and deletable like everything else. If you believe a child has created an account, contact us and we will delete it promptly.

12. Your rights (GDPR / CCPA)

If you reside in the EEA, UK, or California, you have the right to:

  • Access the personal information we hold about you.
  • Correct or delete it.
  • Object to or restrict processing.
  • Receive a copy in a portable format (available directly in Settings as CSV and full export).
  • (CCPA) Opt out of “sale” or “sharing” of your data — we do neither.

To exercise any of these rights, use the tools in Settings or email us at the address below. We do not discriminate against users who exercise these rights. Note that one partner cannot use these rights to obtain the other partner’s private, unshared Couple Accord responses.

13. Changes to this policy

We will update this page when we make material changes and revise the “last updated” date above. Material changes — especially anything affecting bank data, partner sharing, or retention — will be announced inside the app before they take effect.

Contact

Questions, requests, or concerns about this policy or your data? Reach out directly — we respond to every message.

Yost Group LLC — Rick Yost
rick@yost.group

RLTW!