Privacy policy
Last updated: September 8, 2026
1. Who we are
RewardSensei ("we," "us," or "our") is a credit card benefits and rewards optimization tool operated by an independent developer. We may incorporate as a separate legal entity in the future; if we do, this policy will be updated accordingly.
2. Information we collect
When you use RewardSensei, we may collect or process the following types of information:
- Waitlist information: the email address you submit, the time and version of your consent, and limited campaign attribution included in the page URL.
- Account and profile information: your email address, account settings, household membership and sharing choices, and saved trip details such as destinations and dates.
- Card metadata: the credit cards you add to your wallet (card name, last four digits, issuing bank). We never store full card numbers, CVVs, or bank login credentials.
- Offer and benefit data: credit card offers, benefit usage, and reward point balances synced from bank websites via our browser extension.
- Spending data: raw individual transaction descriptions stay in extension storage. When you use account sync, the extension may derive and sync monthly category totals, transaction counts, the month, and the relevant card or account last four digits. These aggregates support portfolio guidance without syncing raw merchant descriptions.
- Advisor questions and context: when you use Advisor or Ask RewardSensei, the question you type and the relevant RewardSensei context needed to answer it are sent to the AI provider configured for the service. Depending on your question, that context can include card names and last four digits, credit limits and current balances, reward rates, benefits and usage, offers, spending-category totals, loyalty balances, point-value settings, household member labels and information they chose to share, and saved-trip destinations and dates. Do not put bank passwords, MFA codes, or full card numbers in an Advisor question.
- Usage analytics: explicit app interactions and limited technical context collected through PostHog. Signed-in web and mobile events use an app-scoped pseudonymous identifier; extension events remain anonymous. Automatic page views, autocapture, session recordings, performance capture, and exception capture are disabled. We do not add emails, names, card numbers, bank credentials, or free-form financial text to PostHog events.
- Diagnostic data: crash, error, and limited performance details sent to Sentry after sensitive properties are removed. Reports may include app, device, operating-system, and runtime context plus an app-scoped pseudonymous account identifier. Default personal-information collection and session replay are disabled. Sentry may also process technical connection data, such as an IP address, when it receives a report even though RewardSensei does not deliberately add an IP address to the report.
- Purchase and subscription data: RevenueCat processes an app account identifier, product and transaction identifiers, purchase and renewal history, subscription status, entitlements, refunds, and restore status. Apple or Google processes native purchases, and eligible web checkout may use Stripe. RewardSensei does not receive or store your full payment card details.
- Push-notification identifiers: if you enable mobile notifications, RewardSensei associates your account and platform with an Expo push token. Expo and the Apple or Google notification service process that app-installation or device delivery identifier to route notifications.
- Location data: if you enable mobile location recommendations, the app can receive approximate or precise device location in the background, including when the app is closed or not in use. It uses that location on the device to identify nearby airports and rank nearby places. For merchant lookup, it rounds the coordinates before sending them to the OpenStreetMap Overpass service. RewardSensei does not save location coordinates in your account database.
- Support communications: messages and verification information you provide when you contact support, including an account-deletion request.
3. How we use your information
- To confirm waitlist registration and send the Closed Beta or launch updates you requested.
- To provide and personalize the RewardSensei service (benefit tracking, card recommendations, offer syncing).
- To answer questions you submit to Advisor or Ask RewardSensei using the relevant account context described above.
- To send notifications that you enable, such as benefit, trip, annual-fee, statement, or location reminders.
- To process purchases, restore access, and keep subscription entitlements current.
- To improve the product and fix bugs using privacy-safe analytics.
- To respond to support, privacy, and account-deletion requests.
4. Browser extension
The RewardSensei Chrome extension accesses bank websites using your existing browser sessions. This means:
- RewardSensei does not ask for or store your bank username, password, or MFA code.
- The extension reads offer, benefit, and reward data only while you are actively logged in to your bank's website.
- You can use the extension in local-only mode without creating an account. In this mode, bank-derived data stays in your browser's local storage and is not synced to RewardSensei's cloud database. Anonymous product analytics and sanitized diagnostics may still be sent to PostHog and Sentry as described in this policy.
- If you create an account, supported offer, benefit, loyalty, and derived monthly spending-category data may sync to our cloud database. Raw transaction descriptions stay in extension storage.
5. Third-party services
We use the following third-party services:
- Supabase: database hosting, authentication, and serverless functions (data stored in the US).
- RevenueCat: app account identifiers, product and transaction identifiers, purchase history, subscription status, entitlements, refunds, and restore status across supported purchase platforms.
- Stripe: payment processing beneath eligible web checkout flows.
- Apple and Google: native-app distribution, store purchase processing and purchase history, and device notification delivery.
- Configured AI provider: Advisor questions and the relevant card, rewards, financial, household, and trip context described above, only when you use Advisor or Ask RewardSensei.
- Resend: delivery of account confirmation, password recovery, waitlist confirmation, and other transactional email, including delivery and bounce events.
- Zoho Campaigns: storage and delivery of waitlist and launch communications after a waitlist registration is recorded.
- PostHog: explicit product interactions using app-scoped pseudonymous identifiers and sanitized event properties.
- Sentry: crash, error, and limited performance monitoring using pseudonymous account identifiers, sanitized diagnostic data, and technical connection data that may be processed when a report is received.
- Meta: script-free advertising measurement on public marketing pages only. Meta does not run on authenticated, onboarding, invitation, beta, privacy, or terms pages, and receives no RewardSensei account, card, trip, or bank data.
- Expo: mobile push-token registration and notification delivery.
- OpenStreetMap Overpass: nearby-place lookup using rounded coordinates when you enable mobile location recommendations.
We do not sell or rent your personal data. Public marketing-page visits may be measured by Meta as described above; authenticated product activity and financial data are never shared with advertisers.
6. Affiliate links
RewardSensei may include affiliate or referral links to credit card application pages. If you apply for a card through one of these links, we may receive compensation from the card issuer. Affiliate availability does not change recommendation order. Recommendations use the relevant card, reward-rate, offer, fee, point-value, spending, and benefit inputs; a compensated action is disclosed near the link when it is available.
7. Data security
We use access controls, authenticated sessions, database row-level security policies, telemetry sanitization, and security controls provided by our infrastructure and payment processors. Access to account data is restricted by user and household permissions. No electronic transmission or storage method is completely secure, and we cannot guarantee absolute security.
8. Data retention
We retain account data while your account is active and as needed to provide the Service. Waitlist contact status and consent history are retained as needed to send the requested Closed Beta and launch communications, honor unsubscribe requests, and meet limited security or compliance needs. When account deletion succeeds, it deletes your RewardSensei sign-in, active cloud account, and account-linked rows through the deletion workflow. Limited security, fraud-prevention, financial-reconciliation, and backup records may remain where needed, and identifiers in retained billing-webhook records are removed. This does not cancel external billing or delete records independently controlled by Apple, Google, RevenueCat, Stripe, PostHog, Sentry, Expo, the configured AI provider, your browser, or our email provider. Those services may retain purchase, transaction, telemetry, diagnostic, request, delivery, or support records under their own legal and operational policies. You can clear local extension data in extension settings or remove it by uninstalling the extension, subject to your browser's storage behavior. See the public account-deletion instructions for the in-app steps, email-request fallback, and deletion details.
9. Your choices and rights
Depending on where you live, privacy law may give you rights over your personal data. You can use RewardSensei controls or contact us to:
- Ask for access to the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and RewardSensei data, subject to the limited retention described above.
- Export your account data in a portable format.
- Manage notification and location permissions in RewardSensei or device settings.
- Unsubscribe from waitlist or launch emails using the link in those messages.
- Ask about available choices for non-essential communications and analytics.
To exercise any of these rights, visit RewardSensei support or contact us at rewardsensei@myhappy.family.
10. Children's privacy
RewardSensei is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this privacy policy from time to time. We will notify you of material changes via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.
12. Contact us
If you have questions about this privacy policy, please contact us at rewardsensei@myhappy.family.