Privacy and data use
Last updated August 20, 2026
MyCrumbs is a private household recordkeeping application. It organizes expenses, receipts, students or beneficiaries, budgets, and possible 529 reimbursement records for people invited to a household. It is not a bank, brokerage, tax adviser, or payment service.
Information MyCrumbs handles
Account information includes your name, email address, profile image when supplied by Google, authentication method, and active sign-in sessions. Site administrators can maintain an email access list and review recent sign-in and access-control events. Those administrative logs do not contain receipt contents or financial values.
Household records can include expenses, merchants, dates, amounts, categories, payment-method descriptions, notes, students or beneficiaries, academic terms, budgets, receipts, eligibility reviews, reimbursements, and an audit history of important changes.
Household owners can view consolidated household records. A household member can view only expenses they entered and the receipts, 529 review, and reimbursement history attached to those expenses. Linking a member to a student profile does not reveal expenses entered by another person.
If you connect a financial institution through Plaid, MyCrumbs may receive the institution and account names, masked account identifiers, account type, balances, and read-only transaction details such as date, amount, merchant, description, pending status, and Plaid category. MyCrumbs does not receive your bank username or password.
Connected institutions, account details, balances, and bank-feed transactions are visible only to the person who connected them. Household owners do not receive access to another member’s bank connections. An expense deliberately added to the household ledger follows the household visibility rules above without exposing the source account name or masked number.
If you email a MyCrumbs support, privacy, or security address, MyCrumbs stores the sender, recipients, subject, plain-text message, threading details, and attachment metadata so a site administrator can respond. Resend retains the received email and attachment bytes as the email provider.
Support, privacy, and security email
Only site administrators can open the administrative mailbox. MyCrumbs displays message bodies as text and does not render received HTML. Attachments are retrieved from Resend only after an administrator is authorized; temporary provider download addresses are not exposed.
MyCrumbs may send a short automatic acknowledgement or, for an unknown address, directions to the correct mailbox. Automatic messages do not make account, privacy, security, or financial decisions. Do not email passwords, bank credentials, Social Security numbers, magic sign-in links, or full account numbers.
When an administrator chooses to request reply suggestions, MyCrumbs sends the message subject, the sender's first name when available, and a limited portion of the recent plain-text conversation to Amazon Bedrock in the same AWS Region. MyCrumbs removes common email addresses, government and financial identifier patterns, and external links from that copy before it is sent. Attachment contents and envelope email addresses are not included. The model is given a fixed summary of MyCrumbs features and limitations, and its output is validated before it appears as a draft.
Suggested replies are not sent automatically. An administrator must review and either edit the draft or deliberately choose to send the displayed response. If AI suggestions are unavailable, MyCrumbs uses local support, privacy, and security templates. Validated suggestions are cached against the exact conversation contents for up to 24 hours, and are removed when a new message is received or sent. Local fallback drafts expire after 15 minutes.
How the information is used
Information is used to provide the household ledger, attach receipts to expenses, reduce manual entry, suggest categories, track available funding and possible 529 records, create exports, prevent duplicate imports, and protect access to household data.
Imported transactions and OCR suggestions are reviewable. A category suggestion is not a financial, legal, or tax determination.
Plaid and connected accounts
Connected-account access is read-only. MyCrumbs does not use Plaid Transfer, Payment Initiation, or another product that can move money. Plaid access tokens stay on the server and are encrypted before database storage. They are never returned to the browser.
Disconnecting an institution will revoke its Plaid Item and stop future synchronization. Previously imported records remain in the household ledger until they are separately removed so exports and audit history do not change silently.
A new connection does not synchronize transactions until a person making the connection chooses at least one account to include. MyCrumbs does not retain transactions from excluded accounts. It keeps basic account details for excluded accounts so that person can revise that choice. Cancelling before making the first selection revokes the Plaid connection and removes the pending institution, its account details, and any associated bank-feed data from MyCrumbs.
Receipts and document processing
Production receipts are stored in private object storage and retrieved through an authenticated MyCrumbs route. Household membership is checked before a receipt can be viewed or removed.
Uploaded receipt images are rotated, resized when necessary, stripped of embedded metadata, and re-encoded before storage. MyCrumbs stores the smaller processed image rather than the original image bytes. PDFs are size- and format-checked but are retained in their submitted format. Per-file, daily-upload, and household-storage limits reduce accidental or abusive storage use.
When you choose receipt reading, the receipt is sent to Amazon Textract for extraction. Suggested merchant, date, total, line items, and category remain editable before saving. MyCrumbs does not use receipt contents to train a custom model.
When AI-assisted suggestions are configured, MyCrumbs sends a limited set of extracted text lines, merchant candidates, purchased-item descriptions, and the household's available category names to Amazon Bedrock in the same AWS Region. The receipt image is not sent to Bedrock. Model output is validated and remains a suggestion that you can change before saving.
If you choose an AI-assisted spending forecast explanation, MyCrumbs sends aggregate forecast totals, model diagnostics, aggregate exclusion counts, and the type, dates, and percentage adjustment of any calendar scenarios to Amazon Bedrock in the same AWS Region. Category labels and event names are replaced or omitted. Merchant names, receipts, notes, student names, payment methods, and bank data are not sent for this explanation. Forecast amounts and prediction ranges are calculated by MyCrumbs before the request; the model cannot change them.
Service providers and disclosure
MyCrumbs uses service providers only to operate the application, including hosting and private file storage, PostgreSQL database hosting, Google authentication, Resend email delivery, Amazon Textract receipt extraction, Amazon Bedrock receipt, forecast explanation, and administrator email-reply assistance when enabled, and Plaid financial connectivity when enabled.
MyCrumbs does not sell household or connected financial data, use it for advertising, or disclose it to data brokers. Information may be disclosed when legally required or when necessary to protect the application and its users.
Retention, correction, and deletion
You can correct imported or extracted expense information from the ledger. Household owners control membership. Connected institutions can be disconnected from account settings once financial connections are enabled.
Financial audit records are retained when an expense is voided rather than silently rewritten. Requests to delete an account or its associated household data should be sent to privacy@email.mycrumbs.app. Identity and household ownership may need to be verified before deletion.
Security and limitations
MyCrumbs uses authenticated server-side authorization, private document retrieval, encrypted transport, restricted service credentials, and short-lived production AWS credentials. No system can guarantee absolute security; report suspected unauthorized access promptly.
529 labels and reviews are organizational records only. MyCrumbs does not determine whether an expense is legally qualified and does not provide tax, investment, or legal advice.
Children and student records
MyCrumbs is intended for adults managing their own household records. Student or beneficiary information should be limited to what the household needs for recordkeeping. The service is not directed to children and should not be used by a child to connect a financial account.
Questions and changes
Questions, access requests, or deletion requests can be sent to privacy@email.mycrumbs.app. Material changes to this notice will update the date shown above.