1. Scope and who controls your data
MAM Development Studio, LLC is responsible for the processing described in this Policy. This Policy applies to the Statera app and website, including support communications. It does not govern services that you access independently under another company’s terms.
2. Information we collect
Account and profile
Your name, email address, authentication provider and identifiers, preferred language, country or region, currency, and account settings. Authentication may be provided by Apple, Google, or Supabase email authentication.
Financial content you provide
Account names and balances; transactions, amounts, dates, merchants, categories and notes; budgets; recurring rules; challenges; and the results Statera calculates from that information, such as your five-pillar Score, stage, margin, and trends. Statera does not currently offer savings goals.
Assisted entry
Text you paste or dictate and receipts, images, or files you intentionally submit for parsing. These inputs are sent for AI processing only when you use the feature and grant its separate permission. Statera saves the resulting account or transaction data only after you review and confirm it.
Coach and AI features
After you grant permission before first use, your question and a limited, structured financial context needed to answer it are processed by the Coach provider. Statera retains questions and answers as history linked to your account for continuity and response recovery. Optional Audience Signals classify at most one closed topic without retaining the question, answer, request ID, financial context, or a stable user identifier. Technical diagnostics may be linked to your account to investigate failures and protect the service. They are separate from optional Audience Signals. The current chat does not offer the retired feedback and voluntary case-report feature.
Purchases and entitlements
Product, entitlement, trial, renewal, cancellation, and transaction-status information needed to unlock paid features. Apple processes payment credentials; Statera does not receive your full card or bank details.
Usage and diagnostics
Feature interactions, app version, operating system, device and performance characteristics, language, country, acquisition attribution when available, and crash or performance records. Sentry is configured without screenshots, view hierarchy, session replay, request bodies, or default personally identifiable information.
Website activity
The website uses PostHog for limited events such as page views, language changes, CTA clicks, and FAQ interactions. It uses in-memory persistence, no autocapture, and no session recording. We do not use this website analytics setup to build an advertising profile.
Support communications
The email address, message, and attachments you choose to send when you contact us.
3. What we do not collect or do
- We do not move money, hold funds, or execute financial transactions.
- We do not collect precise location, contacts, health data, or advertising identifiers.
- We do not sell personal information or share it for cross-context behavioral advertising.
- We do not use IDFA or track activity across third-party apps or websites.
3a. Bank connections through Plaid
Bank connections are optional and available only to users aged 18 or older, subject to supported countries, institutions and account types. When you authorize Plaid Link, Statera receives information for the checking, savings and credit-card accounts you select. This includes institution and connection identifiers and status; account identifiers, names, types and masked account numbers; balances and currency; and transaction identifiers, dates, amounts, descriptions, merchants, categories and pending or posted status, as available from your institution. We retain connection authorization records and access credentials needed to operate the connection. Statera does not receive your online-banking password; authentication is handled by Plaid or your institution.
We use these data to import and update your accounts and transactions, organize and categorize financial activity, calculate balances, budgets and other Statera results, and maintain and secure the connection. Your authorization permits recurring synchronization while the connection and your access remain active, without approving every imported transaction individually. Bank data may be included in the limited financial context of the Coach only when you choose to use that feature and grant its separate permission.
You may request disconnection from Bank connections in Statera. Statera stops future synchronization and requests removal of its access through Plaid; provider removal may take time and require retries. Imported financial records remain in Statera until you delete them using the applicable record or account controls. Disconnecting does not cancel an Apple subscription or close your account at your bank.
Plaid also handles personal information under its own End User Privacy Policy, including for purposes for which it determines the processing. This Policy describes Statera’s handling of data and does not replace Plaid’s policy. You can use Plaid Portal, where available, or Plaid’s privacy-request form to manage connections or exercise rights directly with Plaid. Disconnecting Statera does not remove connections you authorized for other apps; Plaid may retain information under its own policy, including for other active connections, legal obligations and security.
4. How and why we use information
Where applicable, we rely on performance of our contract, our legitimate interests in securing and improving the Services, your consent for optional processing, and compliance with legal obligations. You may withdraw consent at any time without affecting earlier lawful processing.
- Provide authentication, sync, budgeting, transaction management, the five-pillar Score, challenges, insights, and Coach features.
- Parse content you deliberately submit and return proposed records for your approval.
- Manage subscriptions, paid entitlements, trials, and purchase restoration.
- Operate local reminders and preferences that you enable on your device.
- Secure the Services, prevent abuse, diagnose failures, and maintain reliability.
- Understand feature adoption and improve the product, subject to applicable privacy rights and your separate Coach privacy choices.
- Respond to support, rights, safety, and legal requests.
5. AI processing
Statera asks separately for permission to use Coach, AI-assisted entry and bank AI categorization. Each permission covers only its feature; none authorizes the others. Before allowing a feature, you can read about its data, providers and retention. Depending on your app version, these controls appear in the feature flow and its settings or together under Settings → AI & Privacy. Declining a permission leaves that AI feature off. Optional Audience Signals and authorization to connect a bank remain separate.
Bank-transaction categorization with AI is optional and off by default. With your separate permission, Statera uses OpenAI or TypeSafe (Jev), depending on the configured service, to suggest categories. OpenAI receives a transaction description, its income-or-expense type, standard category options and a temporary random reference. TypeSafe receives the transaction description and direction, temporary references, and category names, groups, descriptions and types, including custom categories. Requests do not include separate amount, balance, bank-account-number or Statera user-identifier fields. Descriptions and custom categories may themselves contain personal information, so the data are not anonymous. This permission covers both providers and is independent of Coach permission. Declining or withdrawing it stops new bank AI categorization requests without disabling bank synchronization, your category rules or manual categorization. You can change this choice in Bank connections or, where available, Settings → AI & Privacy. Previously assigned categories remain until you change or delete the records.
Before a Coach request is transmitted, Statera asks for permission to use OpenAI for responses and TypeSafe (Jev) to classify the question and determine the tools and conversation history needed. TypeSafe receives your question and limited context, including your preferred name if available, language, currency, time zone and financial profile, to select the information needed. OpenAI receives your question, this basic context, relevant authorized financial results and any conversation history needed. Statera also stores questions and answers for conversation continuity and response recovery. We send only the content and structured context needed for the requested feature. AI providers act under their applicable commercial service terms and are not authorized by Statera to use your content for advertising.
AI-assisted entry (voice transcription, scan, pasted text or files) requires its own permission, separate from Coach and bank AI categorization. Before sending content, Statera asks you to authorize OpenAI and TypeSafe (Jev) for this feature. Depending on the flow, OpenAI receives the text you submit, a voice transcription, or receipt, image or document content, together with category information and account names and currencies needed to propose records. TypeSafe may classify eligible structured CSV/TSV transaction rows when that processing route is enabled; it does not process every assisted-entry request. The submitted content and category or account labels may contain personal and financial information. Declining keeps manual entry and the rest of Statera available. You can withdraw it in Settings → AI-assisted entry permissions or, where available, AI & Privacy. Withdrawal stops future requests; it does not recall requests already sent or immediately delete provider records.
AI output may be incomplete or wrong. Statera presents proposed records for review and limits Coach to informational, read-only guidance; the Coach cannot move money or edit your financial records.
7. Product analytics and no cross-app tracking
Statera uses Mixpanel for first-party product analytics. Mixpanel receives your Statera User ID plus allowlisted, non-sensitive context such as app version, language, country or region, plan, subscription state, feature, surface, and categorical outcomes. We disable Mixpanel IP-based geolocation and do not send your name, email address, raw financial amounts, balances, transaction or merchant details, account data, Coach questions or answers, receipt content, or uploaded files to Mixpanel. Statera does not use IDFA, does not request App Tracking Transparency permission, and does not use this analytics data for third-party advertising or tracking across other companies’ apps or websites.
8. Retention and deletion
When you confirm in-app account deletion, Statera initiates a deletion process that restricts account access, retires bank connections through Plaid, removes the authentication account and active cloud data, and then clears local app data. Provider disconnection and deletion may take time and require retries; a pending request is not confirmation that every step has finished. Limited residual copies may remain in encrypted backups or security logs until they rotate, generally within 30 days, unless retention is required by law, dispute, fraud prevention or security. This period does not govern Plaid’s own records, which follow its policy. Deleting an account does not cancel an App Store subscription.
- Bank permissions: we retain your age-and-authority confirmation (without collecting a date of birth for this purpose) and the status, version and dates of bank AI permission linked to your account, until account deletion. For bank AI requests sent to OpenAI, response storage for later retrieval is disabled; OpenAI may still retain content in abuse-monitoring logs for up to 30 days, or longer where legally required. TypeSafe retains data as necessary to provide and secure its service and meet legal obligations under its applicable terms. Withdrawal stops new requests but does not immediately delete provider records already created. Limited, restricted deletion-completion records may be retained as needed to demonstrate completion, resolve requests or meet legal and security obligations.
- Account and confirmed financial data: while your account is active, until you delete individual records or the account, subject to narrow legal exceptions.
- AI choices: the status, notice version and dates of your choices for Coach, Smart Transactions and bank AI categorization are linked to your account until account deletion. Confirmed records follow the account and financial-data lifecycle; AI provider records follow the separate retention terms below.
- Assisted-entry source content: only for the time required to process the request; Statera does not keep the original receipt, image, file, audio, or pasted text as a permanent record unless another feature clearly tells you otherwise.
- Coach: questions, answers and replay responses are kept temporarily for 24 hours from creation, with automatic cleanup every five minutes, or deleted with your account if earlier. This window supports conversation continuity and recovery, not an indefinite chat archive. Diagnostic copies follow the same short window; an in-flight turn finishes before cleanup. Operational results and technical traces are separate from optional topic contributions. Optional Audience contributions remain temporary for no more than eight days; only weekly topic-language groups with at least 10 distinct contributors are released and retained for 24 months. Legacy content-free technical events are retained for 14 days, daily technical counters for 90 days, and aggregated ratings for 12 months. Any cases voluntarily shared through previous versions, plus their separate deletion locators, remain subject to deletion after 30 days.
- AI provider retention: the 24-hour Coach window applies to Statera systems. Under standard OpenAI service settings, content may remain in abuse-monitoring logs for up to 30 days, or longer where legally required. TypeSafe retains data as necessary to provide and secure its service and meet legal obligations under its applicable terms. Deletion in Statera does not immediately delete every provider record; we do not promise zero data retention by these providers.
- Product analytics: no longer than 24 months unless a shorter configured period applies. Website identifiers exist only in memory during the browser session, although event records are retained for product analysis.
- Crash and performance records: only as long as reasonably necessary to diagnose reliability and security issues under the configured provider retention period.
- Support and legal records: as needed to resolve the request, establish compliance, prevent abuse, or meet legal obligations.
9. Your choices and privacy rights
The location of AI permission controls depends on your app version: they may appear separately or together in AI & Privacy. If your version lacks a control required for an AI feature, you may need to update the app to use that feature. The absence of a control never grants permission on your behalf.
Email us to exercise a right. We may verify your identity and will respond within the time required by applicable law. California residents may request to know, correct, or delete personal information and may exercise these rights without discrimination. Because we do not sell or share personal information for targeted advertising, there is no sale or sharing to opt out of.
- Choose whether to allow AI-assisted entry when prompted before use. You can withdraw permission in Settings → AI-assisted entry permissions or, where available, AI & Privacy; manual entry remains available.
- Grant or withdraw optional bank AI categorization permission in Bank connections or, where available, AI & Privacy. This is separate from Coach permission and does not stop bank synchronization or manual categorization.
- Manage or disconnect bank access in Bank connections. To exercise rights regarding Plaid’s own processing, use the Plaid links in Section 3a.
- Access and correct app data using Statera’s account and record controls.
- Delete your account in the app from Settings → Account → Delete Account.
- Decline Coach permission to keep using the rest of Statera without sending a Coach request. You can grant it when Coach prompts you and withdraw it in Settings → Coach permissions; versions with AI & Privacy may also provide these controls there. Withdrawing it stops new Coach messages to OpenAI and TypeSafe; existing history follows the retention window above. Account deletion removes active account-linked history. You must grant permission again to resume chatting. This choice does not change Audience Signals.
- Enable or disable optional Audience Signals in Settings → Coach permissions without changing access to the Coach.
- Manage notification permissions in iOS Settings and contact us to exercise applicable privacy rights or object to analytics processing.
- Request access, correction, deletion, portability, restriction, or objection where your law provides those rights.
- Appeal a privacy-request decision or complain to your local data-protection authority.
10. International transfers
Statera and its providers primarily process data in the United States. Where required for transfers from the EEA, United Kingdom, Switzerland, or another jurisdiction, we use recognized safeguards such as standard contractual clauses and apply supplementary protections appropriate to the data.
11. Security
We use safeguards designed for the sensitivity of financial information, including encrypted transport, provider encryption at rest, authenticated access, row-level database security, least-privilege service access, and privacy-restricted diagnostics. No security measure can guarantee absolute protection. Protect your device, Apple or Google account, and Statera credentials.
12. Children
Statera is not directed to children under 13 and we do not knowingly collect their personal information. Users below the age of legal majority must have permission from a parent or legal guardian. Contact us if you believe a child provided information improperly.
Bank connections through Plaid are restricted to users aged 18 or older, even when a parent or guardian authorizes use of other Statera features.
13. Changes to this Policy
We may update this Policy as the Services, providers, or law change. We will post the new date here and provide additional in-app or email notice when a change is material. Where consent is required for new processing, we will ask before it begins.
14. Contact
MAM Development Studio, LLC · Delaware, United States. For privacy questions, rights requests, or complaints, contact: