Privacy Policy
BountyHound, a Belanor Company service · Effective September 25, 2026 · Version 1.1
Belanor Company ("Belanor", "we"), operating as BountyHound, runs a service that lets you share a protected, de-identified view of your bank transaction history in exchange for rewards in a participating app. This policy explains what we collect, what we do to it, and the rights you have. It applies to the connection flow you are using and to the data handled behind it.
What we collect, and how
- We collect your bank transaction and account data only after you explicitly consent in the connection flow, and only through Plaid, the service you use to link your bank. We never see or store your bank username or password — those go to Plaid, whose handling of your data is described in the Plaid End User Privacy Policy.
- We also hold a minimal connection record: which participating app you came from, which bank you linked, and the version and time of the consent you gave. We use this to operate your connection, credit your rewards, and honor revocation and deletion.
What we do to your data before storing it
We never store your raw transactions. Before anything is saved:
- Identifying details are deleted — names, memos, payment metadata, account numbers, and everything in the transaction text except the merchant's name are discarded, permanently.
- Amounts and dates are deliberately blurred with statistical noise, so no stored record exactly matches a real transaction.
- Your identity is replaced with a random code that is not derived from you or your accounts and cannot be reversed into you.
- Sensitive categories (such as medical transactions) are discarded entirely, and no location below country level and no demographic information is kept.
The exact parameters of this protection are published, machine-readable, at /v1/privacy-manifest on our service, so anyone can verify them against the running system.
How we use and share data
- The de-identified records are used to build aggregate spending-pattern datasets for business customers (for example, market research). Customers access only this blurred, de-identified data — never your identity, your bank login, or your raw transactions.
- We do not sell or share data that identifies you. We do not use your data for advertising, and we do not keep profiles of you as an individual.
- Your money checkup. If you connect through our checkup, we read your transactions from Plaid at that moment to show you a summary: your subscriptions and where to cancel them, price increases, bank fees, spending by category, charges worth a second look, and open class-action settlements whose covered merchants appear in your history. That summary is built on the spot, shown only in the browser that started the connection, readable for one hour, and never saved. Unless you opt in to settlement alerts (below), the only copy of your data we keep is the de-identified, blurred one described above.
- Settlement alerts (optional). If — and only if — you type your email address into the settlement-alerts box and tick its consent checkbox, we store two things: your email address, encrypted, and a list of merchant names from your history with the first and last month we saw each — no amounts, no transaction dates, no account details. We use them for exactly one purpose: emailing you, at most once a week, when an open class-action settlement covers a merchant on your list. Every email contains a one-click unsubscribe; unsubscribing stops the emails immediately and your address and merchant list are deleted within 30 days. Deleting your data (below) deletes them too. If you never opt in, none of this is collected.
- We share data with service providers only as needed to run the service — Plaid (bank connectivity) and our hosting provider (encrypted storage) — under this policy's protections.
How we protect it
- All connections use encryption in transit (TLS 1.2 or better); stored data is encrypted at rest, and bank access tokens carry an additional layer of AES-256 encryption.
- Access to our systems is restricted, key-based, and audited; the mapping between your connection and the de-identified records is held separately and is unreachable through the dataset our customers use.
Your rights and choices
- Disconnect any time. You can revoke your bank connection from the app you connected in. Revoking immediately invalidates our access at Plaid and destroys the stored access token.
- Request deletion, access, or correction. Email [email protected] from the account you used, or ask through the app you connected in. We honor deletion requests within 30 days — sooner where the law requires — covering your connection record and your records in the de-identified dataset. We respond to access and correction requests in the same window.
- Depending on where you live (for example, California), you may have additional rights under local privacy law; contact us at the address above to exercise them, and we will not discriminate against you for doing so.
Retention
We keep de-identified records only while your connection is active and the purpose you consented to continues; bank access tokens are destroyed the moment you revoke; a minimal record of your consent and revocation is kept for three years as legal evidence. Details are in our Data Retention & Disposal Policy, available on request.
Changes and contact
If we change this policy, we will post the new version here with a new effective date, and material changes will be presented for fresh consent before they apply to you. Questions, requests, or complaints: [email protected].