Privacy Policy

Effective August 22, 2026

Operator: Apps4Households (a sole proprietorship)

1. Scope

This Privacy Policy explains how Apps4Households ("Apps4Households," "we," "our," or "us") collects, uses, discloses, and protects information when you use the Vylo application and related services (collectively, the "Services").

Vylo is a product operated by Apps4Households.

This Policy applies to information collected through:

2. Information We Collect

We may collect the following categories of information.

A. Account and Profile Information

B. Financial and Transaction Information

When you choose to connect financial accounts through our integration partners, including Plaid and Quiltt (including Quiltt's Finicity by Mastercard connectivity integration), we may receive:

Important: Vylo does not receive or store your bank login credentials when you connect accounts through provider-hosted connection flows.

Financial Connectivity Providers

Vylo uses financial connectivity providers, including Plaid and Quiltt (including Quiltt's Finicity by Mastercard connectivity integration), to gather data from financial institutions at your direction. By using our Services to connect a financial account, you authorize Apps4Households and the applicable provider to access and transmit your financial data so Vylo can provide the Services.

Your use of those providers may be subject to their own terms and privacy policies. Plaid's legal terms are available at: https://plaid.com/legal

We share only the data necessary to provide the Vylo Services and do not sell your financial data.

C. Billing and Purchase Information

If you subscribe or use an introductory offer, we may process billing status, subscription identifiers, purchase state, introductory-offer eligibility and status, renewal status, cancellation status, payment method metadata, invoice metadata, and related support details.

Web billing is processed through Stripe. App Store subscriptions are processed by Apple. Vylo does not store full card numbers or bank payment credentials.

D. Household and Collaboration Data

E. Device and Usage Information

If you enable notifications, we may process device identifiers, push tokens, notification preferences, and delivery status so we can send account, security, import, and product notifications.

F. Communications

Information you provide when contacting support or submitting feedback.

G. Optional OpenAI Categorization

Vylo offers an optional OpenAI-assisted transaction categorization feature. Before this feature is used, the person who connected the applicable financial account must make an explicit choice. A household member cannot grant consent for financial accounts connected by another person.

If you allow this feature, the only information from your account that OpenAI receives is one cleaned, provider-classified commercial merchant label so OpenAI can select an existing Vylo category. Vylo does not add or send separate profile, household-member, or contact-name fields for this feature. It also does not send the transaction amount, currency, transaction direction or channel, original bank description, account or card details, account identifiers, transaction or Vylo identifiers, merchant domain, category history, budget data, financial snapshots, email addresses, phone numbers, or other household-member data.

If a suitable cleaned merchant label is unavailable, or if you decline or withdraw consent, Vylo uses its built-in categorization rules and manual review instead. Declining does not prevent you from using the Services.

H. Merchant Logo Service

To display merchant logos, Vylo may send Logo.dev only the persisted, normalized website domain associated with a merchant. A logo request also carries ordinary network metadata needed to deliver the image, such as the requesting IP address and, on the web, the Vylo origin/referrer.

Vylo does not send Logo.dev raw transaction descriptions, merchant display names, amounts, categories, transaction or account identifiers, user or household identifiers, or bank credentials for this purpose. If no normalized domain is available, Logo.dev is not contacted. Logos are optional visual enhancements; transactions remain usable and show a local fallback if the service is unavailable. Logo.dev's privacy policy is available at: https://www.logo.dev/privacy

3. Sources of Information

We collect information:

4. How We Use Information

We use personal data to:

Vylo uses built-in automated rules to organize transactions. If the connected-data owner explicitly allows optional OpenAI categorization, Vylo uses the limited merchant-label process described in Section 2(G). Vylo does not use OpenAI for budgeting, financial snapshots, or Insights under this permission.

5. Legal Bases / Permission Model

Where applicable, we process personal data based on:

OpenAI categorization is based on the connected-data owner's explicit consent. You may decline it, or withdraw a prior choice in Settings, without losing access to built-in categorization. A withdrawal stops new OpenAI categorization requests for that person's connected accounts and removes owner-scoped reusable model cache and queued work. Category choices already applied to transactions remain part of the account data unless you change or delete them.

6. How We Share Information

We do not sell your financial data.

Vylo sends persisted normalized merchant domains to Logo.dev solely to load merchant logos as described in Section 2(H). Those image requests also include ordinary network metadata needed to deliver the image. No other transaction or account context is sent for this purpose.

We may share information with:

7. Data Security

We implement administrative, technical, and organizational safeguards designed to protect personal data, including:

However, no method of transmission or storage is completely secure.

8. Data Retention

We retain personal data only as long as reasonably necessary to:

When data is no longer needed, we delete or de-identify it in accordance with our retention practices.

Vylo sets store: false on optional categorization requests, so OpenAI does not create a stored Responses API application-state record. OpenAI states that API data is not used to train its models unless the customer explicitly opts in. OpenAI may retain abuse-monitoring logs, which may include request and response content, for up to 30 days by default, unless a different legally permitted retention setting applies. Temporary encrypted prompt-cache state follows OpenAI's model and organization policy. Vylo's minimized owner-scoped categorization cache and operational result log expire after 30 days and are removed when the connected-data owner declines or withdraws consent. Vylo retains the consent choice and its minimal decision history while the account exists, then deletes those records with the account unless retention is required by law.

If you request account deletion, Vylo disables app access after recording a recoverable deletion job and begins provider disconnection, billing cleanup, and deletion or de-identification of account data. Operational cleanup is scheduled to complete within 7 calendar days, and Vylo emails the account address when deletion is complete. While deletion is pending, Vylo retains only the information needed to complete and reconcile the request. After completion, Vylo removes contact and account identifiers from the operational deletion record. Separate minimized security, fraud-prevention, tax, accounting, dispute, or legally required records may be retained only as permitted or required by law.

9. Your Rights and Choices

Depending on your jurisdiction, you may have the right to:

You may also close your account at any time.

Vylo will not deny service, charge a different price, or provide a different level or quality of service solely because you exercised an applicable privacy right, except where permitted by law.

You may review, grant, decline, or withdraw optional OpenAI categorization in Settings. Withdrawing consent does not affect the lawfulness of processing completed before withdrawal. For more information about OpenAI API data controls, visit OpenAI API data controls.

Vylo provides account export and account deletion controls in the Services where available. Export files are prepared for your access and download access expires after a limited period. Deletion disconnects or revokes connected providers where supported and removes or de-identifies account data except where retention is required or permitted by law.

To submit a privacy request, contact: support@myvylo.com

10. Cookies and Similar Technologies

We use cookies and similar technologies for:

You can manage cookies through your browser settings, but disabling certain cookies may affect functionality.

11. Children

Vylo is not intended for individuals under 18, and we do not knowingly collect personal data from children under 18.

If we learn such data has been collected, we will take steps to delete it as required by law.

12. International Transfers

Vylo and its service providers may process personal data outside your province, state, or country. If you allow optional OpenAI categorization, the limited cleaned merchant label and resulting category output may be processed by OpenAI in the United States or other locations where OpenAI or its subprocessors operate. Logo.dev logo requests may also be processed where Logo.dev or its content-delivery providers operate, limited to the information described in Section 2(H). Information may therefore be subject to the laws of those jurisdictions. Where personal data is transferred across borders, we apply reasonable safeguards consistent with applicable legal requirements.

Logos provided by Logo.dev

13. Changes to This Policy

We may update this Privacy Policy periodically.

If changes are material, we will provide notice through the Services and/or by email where appropriate.

Continued use after the effective date constitutes acceptance of the updated Policy.

14. Contact Us

Apps4Households
support@myvylo.com