Privacy Policy
Effective August 22, 2026
Operator: Apps4Households (a sole proprietorship)
1. Scope
This Privacy Policy explains how Apps4Households ("Apps4Households," "we," "our," or "us") collects, uses, discloses, and protects information when you use the Vylo application and related services (collectively, the "Services").
Vylo is a product operated by Apps4Households.
This Policy applies to information collected through:
- the Vylo web and mobile experiences;
- support interactions; and
- related Services.
2. Information We Collect
We may collect the following categories of information.
A. Account and Profile Information
- Name
- Email address
- Authentication and account security metadata
B. Financial and Transaction Information
When you choose to connect financial accounts through our integration partners, including Plaid and Quiltt (including Quiltt's Finicity by Mastercard connectivity integration), we may receive:
- linked account metadata (for example, account type, mask, institution details);
- transaction history;
- balances;
- categories and budgeting data; and
- notes and categorization preferences.
Important: Vylo does not receive or store your bank login credentials when you connect accounts through provider-hosted connection flows.
Financial Connectivity Providers
Vylo uses financial connectivity providers, including Plaid and Quiltt (including Quiltt's Finicity by Mastercard connectivity integration), to gather data from financial institutions at your direction. By using our Services to connect a financial account, you authorize Apps4Households and the applicable provider to access and transmit your financial data so Vylo can provide the Services.
Your use of those providers may be subject to their own terms and privacy policies. Plaid's legal terms are available at: https://plaid.com/legal
We share only the data necessary to provide the Vylo Services and do not sell your financial data.
C. Billing and Purchase Information
If you subscribe or use an introductory offer, we may process billing status, subscription identifiers, purchase state, introductory-offer eligibility and status, renewal status, cancellation status, payment method metadata, invoice metadata, and related support details.
Web billing is processed through Stripe. App Store subscriptions are processed by Apple. Vylo does not store full card numbers or bank payment credentials.
D. Household and Collaboration Data
- Household membership details
- Invitations and role/access information
E. Device and Usage Information
- Log and event data (for example, IP address, browser/device type, timestamps);
- diagnostic and security telemetry; and
- cookie and session data necessary to operate and secure the Services.
If you enable notifications, we may process device identifiers, push tokens, notification preferences, and delivery status so we can send account, security, import, and product notifications.
F. Communications
Information you provide when contacting support or submitting feedback.
G. Optional OpenAI Categorization
Vylo offers an optional OpenAI-assisted transaction categorization feature. Before this feature is used, the person who connected the applicable financial account must make an explicit choice. A household member cannot grant consent for financial accounts connected by another person.
If you allow this feature, the only information from your account that OpenAI receives is one cleaned, provider-classified commercial merchant label so OpenAI can select an existing Vylo category. Vylo does not add or send separate profile, household-member, or contact-name fields for this feature. It also does not send the transaction amount, currency, transaction direction or channel, original bank description, account or card details, account identifiers, transaction or Vylo identifiers, merchant domain, category history, budget data, financial snapshots, email addresses, phone numbers, or other household-member data.
If a suitable cleaned merchant label is unavailable, or if you decline or withdraw consent, Vylo uses its built-in categorization rules and manual review instead. Declining does not prevent you from using the Services.
H. Merchant Logo Service
To display merchant logos, Vylo may send Logo.dev only the persisted, normalized website domain associated with a merchant. A logo request also carries ordinary network metadata needed to deliver the image, such as the requesting IP address and, on the web, the Vylo origin/referrer.
Vylo does not send Logo.dev raw transaction descriptions, merchant display names, amounts, categories, transaction or account identifiers, user or household identifiers, or bank credentials for this purpose. If no normalized domain is available, Logo.dev is not contacted. Logos are optional visual enhancements; transactions remain usable and show a local fallback if the service is unavailable. Logo.dev's privacy policy is available at: https://www.logo.dev/privacy
3. Sources of Information
We collect information:
- directly from you;
- automatically through your use of the Services; and
- from authorized third-party integrations when you choose to connect external accounts, subscribe, receive notifications, or contact support.
4. How We Use Information
We use personal data to:
- provide, operate, and improve the Services;
- synchronize account and transaction data;
- power budgeting, categorization, and insights features;
- secure accounts and detect fraud or abuse;
- communicate with you about account, product, and security matters;
- comply with legal obligations; and
- enforce our Terms.
Vylo uses built-in automated rules to organize transactions. If the connected-data owner explicitly allows optional OpenAI categorization, Vylo uses the limited merchant-label process described in Section 2(G). Vylo does not use OpenAI for budgeting, financial snapshots, or Insights under this permission.
5. Legal Bases / Permission Model
Where applicable, we process personal data based on:
- your consent (for example, when connecting financial accounts);
- performance of our contract with you;
- legitimate interests (including security, reliability, and product improvement); and
- legal compliance obligations.
OpenAI categorization is based on the connected-data owner's explicit consent. You may decline it, or withdraw a prior choice in Settings, without losing access to built-in categorization. A withdrawal stops new OpenAI categorization requests for that person's connected accounts and removes owner-scoped reusable model cache and queued work. Category choices already applied to transactions remain part of the account data unless you change or delete them.
6. How We Share Information
We do not sell your financial data.
Vylo sends persisted normalized merchant domains to Logo.dev solely to load merchant logos as described in Section 2(H). Those image requests also include ordinary network metadata needed to deliver the image. No other transaction or account context is sent for this purpose.
We may share information with:
- service providers who process data on our behalf, including hosting, database infrastructure, diagnostics, analytics where enabled, communications, and email delivery;
- OpenAI, as a service provider and processor, only when the connected-data owner allows optional OpenAI categorization and only for the limited merchant-label process in Section 2(G);
- Logo.dev, solely for the limited merchant-domain logo request described in Section 2(H);
- financial connectivity providers, including Plaid and Quiltt (including Quiltt's Finicity by Mastercard connectivity integration), at your direction;
- payment and subscription processors, including Stripe and Apple, when you subscribe, restore a purchase, or manage billing;
- push notification services, including Apple Push Notification service, if you enable notifications;
- household collaborators you explicitly authorize;
- legal or regulatory authorities when required by law; and
- a successor entity in connection with a merger, acquisition, financing, or asset sale, subject to appropriate safeguards.
7. Data Security
We implement administrative, technical, and organizational safeguards designed to protect personal data, including:
- encryption in transit;
- access controls;
- monitoring and logging; and
- secure credential and token handling practices.
However, no method of transmission or storage is completely secure.
8. Data Retention
We retain personal data only as long as reasonably necessary to:
- provide the Services;
- comply with legal, regulatory, tax, or accounting requirements;
- resolve disputes; and
- enforce agreements.
When data is no longer needed, we delete or de-identify it in accordance with our retention practices.
Vylo sets store: false on optional categorization requests, so OpenAI does not create a stored Responses API application-state record. OpenAI states that API data is not used to train its models unless the customer explicitly opts in. OpenAI may retain abuse-monitoring logs, which may include request and response content, for up to 30 days by default, unless a different legally permitted retention setting applies. Temporary encrypted prompt-cache state follows OpenAI's model and organization policy. Vylo's minimized owner-scoped categorization cache and operational result log expire after 30 days and are removed when the connected-data owner declines or withdraws consent. Vylo retains the consent choice and its minimal decision history while the account exists, then deletes those records with the account unless retention is required by law.
If you request account deletion, Vylo disables app access after recording a recoverable deletion job and begins provider disconnection, billing cleanup, and deletion or de-identification of account data. Operational cleanup is scheduled to complete within 7 calendar days, and Vylo emails the account address when deletion is complete. While deletion is pending, Vylo retains only the information needed to complete and reconcile the request. After completion, Vylo removes contact and account identifiers from the operational deletion record. Separate minimized security, fraud-prevention, tax, accounting, dispute, or legally required records may be retained only as permitted or required by law.
9. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- access your personal data;
- correct inaccurate data;
- request deletion of your data; and
- receive a portable copy where applicable.
You may also close your account at any time.
Vylo will not deny service, charge a different price, or provide a different level or quality of service solely because you exercised an applicable privacy right, except where permitted by law.
You may review, grant, decline, or withdraw optional OpenAI categorization in Settings. Withdrawing consent does not affect the lawfulness of processing completed before withdrawal. For more information about OpenAI API data controls, visit OpenAI API data controls.
Vylo provides account export and account deletion controls in the Services where available. Export files are prepared for your access and download access expires after a limited period. Deletion disconnects or revokes connected providers where supported and removes or de-identifies account data except where retention is required or permitted by law.
To submit a privacy request, contact: support@myvylo.com
10. Cookies and Similar Technologies
We use cookies and similar technologies for:
- authentication;
- session management;
- security; and
- product performance and analytics.
You can manage cookies through your browser settings, but disabling certain cookies may affect functionality.
11. Children
Vylo is not intended for individuals under 18, and we do not knowingly collect personal data from children under 18.
If we learn such data has been collected, we will take steps to delete it as required by law.
12. International Transfers
Vylo and its service providers may process personal data outside your province, state, or country. If you allow optional OpenAI categorization, the limited cleaned merchant label and resulting category output may be processed by OpenAI in the United States or other locations where OpenAI or its subprocessors operate. Logo.dev logo requests may also be processed where Logo.dev or its content-delivery providers operate, limited to the information described in Section 2(H). Information may therefore be subject to the laws of those jurisdictions. Where personal data is transferred across borders, we apply reasonable safeguards consistent with applicable legal requirements.
13. Changes to This Policy
We may update this Privacy Policy periodically.
If changes are material, we will provide notice through the Services and/or by email where appropriate.
Continued use after the effective date constitutes acceptance of the updated Policy.
14. Contact Us
Apps4Households
support@myvylo.com