Privacy Policy
Effective July 30, 2026
1. Introduction
Fountain ("we," "us," or "our") is a personal project developed by Andrew Schauer that provides a mobile application to help you track your finances, including bank accounts, balances, transaction history, and investments (the "Service"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the choices you have.
Fountain is currently distributed only to a small group of invited testers via Apple TestFlight and is not available on the public App Store.
By using Fountain, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
2. Information we collect
2.1 Information you provide directly
- Email address — required to create an account. We use passwordless sign-in: you enter your email and we send a one-time code to verify it. We do not collect or store a password.
- Sign in with Apple (planned, not yet live) — Fountain intends to also support Sign in with Apple. If you use this option, Apple may share your name and either your real email address or a private relay address you control, depending on your choice during sign-in. This section will be updated with final details once the feature ships.
- Display name — optional, set during onboarding.
- Financial planning inputs — optional figures you enter yourself, such as an emergency fund target and a target range for your checking account balance.
2.2 Information from linked financial accounts
When you connect a bank, investment, or credit account, we use Plaid Inc. ("Plaid") to securely link your account. You enter your bank credentials directly into Plaid's interface — Fountain never receives or stores your bank login credentials.
Once an account is linked, we receive and store the following from Plaid:
- Account details: institution name, account name, account type and subtype (e.g., checking, savings, credit card, 401(k), IRA, brokerage), and the last 4 digits of the account number
- Balances: current balance, available balance, and credit limit
- Transactions: your transaction history — the amount, date, and pending status of each transaction, and the name of the merchant you paid. Plaid also supplies a spending category for most transactions. This is a detailed record of where and when you spend your money, and it is the most revealing information Fountain holds about you.
- Liabilities: for credit accounts, APR — including any promotional rate and the balance it applies to — principal balance, minimum payment, and next payment due date
- Investments: your holdings, including quantity, current value, and cost basis (what you originally paid, which reflects your unrealized gains and your tax position); security details (name, ticker, price); and investment transactions (buys, sells, dividends, contributions, withdrawals)
- Connection status: which institutions you have connected, whether each connection is currently working, and technical error codes and timestamps when a sync fails
Your Plaid access token. Linking an account also gives Fountain a Plaidaccess token for that institution. This is not a copy of your data — it is a credential that lets Fountain re-read your account on an ongoing basis without asking you again, and it stays valid until it is revoked. Fountain stores this token so it can keep your balances and transactions up to date. It is not your bank login, it cannot move money, and it permits only reading the data described above.
We do not request or store your bank account's full account number or your bank login credentials. Fountain does not request Plaid's Identity product, so we do not receive your name, address, date of birth, or Social Security number from your bank. Plaid's own use of your data is governed by Plaid's privacy policy.
2.3 Information collected automatically
Fountain does not use analytics or crash-reporting services. We do not collect usage data about which screens you visit or which features you use, and no third party receives that information.
We do not use advertising trackers, and we do not use cookies (the Service is a mobile app, not a website). We do not collect device advertising identifiers.
If we add error monitoring or product analytics in the future, we will update this policy and notify you before that collection begins.
2.4 Biometric authentication (on-device only)
If you enable Face ID or Touch ID as an app lock, your device's operating system handles the biometric match. Fountain never receives, transmits, or stores your biometric data — only a local on/off preference is saved on your device.
3. How we use your information
We use the information described above to:
- Create and maintain your account
- Display your linked accounts, balances, transactions, and investment holdings
- Calculate the planning figures and guidance shown in the app (e.g., emergency fund progress, checking account ranges)
- Sync your data with your financial institutions through Plaid
- Communicate with you about your account (e.g., sign-in codes, email change confirmations)
- Maintain the security and integrity of the Service
We do not use your information for advertising, and we do notsell your personal data.
4. Who we share information with
We share information only as needed to operate the Service:
| Recipient | What they receive | Why |
|---|---|---|
| Plaid, Inc. | Requests to link and sync your financial accounts | To connect to your bank and retrieve account data |
| Supabase, Inc. (our database and authentication provider) | All account data described in Section 2, stored on our behalf | Hosting our database, authentication, and backend infrastructure |
| Postmark (email delivery) | Your email address | To send sign-in codes and account notifications |
We do not share your data with advertisers or data brokers, and we do not sell your personal data.
Planned, not yet live: Fountain intends to offer a paid subscription (with a free trial) in the future, billed through Apple's App Store in-app purchase system. When that launches, Apple will process your payment information directly — Fountain does not see or store your card details — and this section will be updated to name Apple (and any subscription-management vendor, such as RevenueCat) as a data recipient for billing-related data.
We may also disclose information if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Fountain, our users, or others.
If Fountain is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will notify you if this occurs.
5. Data storage and security
Your data is stored in a managed PostgreSQL database operated by Supabase, hosted in the United States (AWS us-west-2, Oregon). Data is encrypted in transit (TLS) and at rest using Supabase's standard infrastructure protections.
Your Plaid access tokens are held in a separate table that no signed-in user can read. Database access rules grant zero client access to it; only Fountain's own server-side sync functions can use those tokens.
No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
6. Data retention and deletion
We retain your information for as long as your account is active.
You may permanently delete your account at any time from within the app. Deleting your account will:
- Disconnect and revoke access to all linked financial institutions
- Permanently delete your balances, transactions, liabilities, investment holdings, account goals, financial preferences, and profile information
- Permanently delete your authentication record
Account deletion is immediate and irreversible — once you confirm, your data is permanently removed from our live database and cannot be recovered by you or by us. As with any hosted database, residual copies of deleted data may persist briefly in routine system backups until those backups themselves are rotated out; we do not use backups to restore or reconstruct deleted accounts.
We retain a small amount of de-identified, shared reference data (e.g., public security/ticker information not tied to any individual) that is not personal data and is not affected by account deletion.
7. Your choices and rights
- Access and correction: You can view and edit your profile and financial preferences directly in the app.
- Account deletion: You can delete your account and associated data at any time in the app (see Section 6).
- Disconnecting an institution: You can disconnect a linked institution at any time without deleting your Fountain account. Doing so permanently deletes that institution's accounts, balances, and transaction history from Fountain, along with our access token for it.
Disconnecting does not currently revoke the authorization you granted at your bank. Fountain deletes its own copy of your data and stops retrieving anything new, but the connection remains active on Plaid's side until you revoke it. You can do that atmy.plaid.com or in your bank's own connected-apps settings. Deleting your entire Fountain account (Section 6) does revoke every connection automatically.
7.1 California and other U.S. state privacy rights
Fountain is currently a small-scale, invitation-only application (a small number of TestFlight testers) and has not launched publicly. Most U.S. state privacy laws (including the CCPA) only apply once a business crosses certain revenue or user-volume thresholds, which Fountain does not currently meet.
Regardless of those thresholds, we do not sell personal data and do not use it for cross-context behavioral advertising, and you can already exercise the practical equivalent of access, correction, and deletion rights directly in the app (see Section 7 above).
8. Children's privacy
Fountain is intended for users who are at least 18 years old (or the age of majority in your jurisdiction) and is not directed to children. We do not knowingly collect personal data from anyone under that age. This restriction also reflects the requirements of the third-party services Fountain relies on, including Plaid's own age requirements for linking financial accounts. If we learn that we have collected personal data from someone under the minimum age, we will delete it.
9. International users
Fountain is intended for use by residents of the United States and currently supports linking U.S. financial institutions only. If you access the Service from outside the United States, your information will still be processed and stored in the United States. We do not currently support, and this policy does not address, the requirements of non-U.S. data protection laws (such as the GDPR).
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and/or an in-app notice before the changes take effect. The effective date at the top of this policy reflects the most recent revision.
11. Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
Andrew Schauer (Fountain)
support@fountain-money.com