Skip to content

Privacy policy

Last updated:

Cashcade is operated by Joshua Newman in Singapore. This policy covers the Cashcade app, cashcade.ai, our waitlist and related services. For privacy questions or data requests, email nlj587@gmail.com.

Cashcade turns supported bank-alert emails into spending records. You can forward emails without connecting an inbox. Connecting Gmail or Outlook is optional. We do not ask for your bank login.

1. Information we collect

  • Account information: your sign-in email, name or profile details supplied by your sign-in provider, a profile photo if you upload one, household membership and preferences.
  • Financial records: merchants, amounts, currencies, dates, categories, payment-method labels and available card or account endings extracted from alerts or entered or corrected by you.
  • Email information: sender addresses, subjects, dates, message identifiers, relevant message content and attachments needed for the features you use. Connection records include your mailbox address, granted permissions, encrypted refresh tokens and sync status.
  • Optional receipt and insurance information: purchase items, subscriptions, order references, insurer and plan names, policyholder or insured-person names, masked policy identifiers, premiums, coverage and benefit details. Documents may contain sensitive personal information.
  • Coach and support information: questions, conversation history, relevant spending insights and information you send when asking for help.
  • Service information: device notification tokens, settings, sync and error records, and technical information such as IP addresses and browser or device details processed by our hosting and authentication providers.
  • Waitlist information: your email address, signup time, the form used and repeat-signup counts. We use your address for early-access communications, and the operator may receive a signup notification.

2. Gmail and Outlook access

When you connect Gmail, we request Google’s read-only Gmail permission (gmail.readonly). This permission technically allows reading email throughout your mailbox, including message content and attachments. Google does not limit that permission to individual bank senders; Cashcade applies the search limits described here within the application. It does not permit Cashcade to send, change or delete your Gmail messages.

Connected bank-alert searches use the bank senders you select. If you request a historical import, we search the selected period for supported alerts. We use the resulting information to build and update your spending records, categories and card-reward estimates. Outlook connections similarly use read access to email, basic account information and permission to maintain the connection.

Smart Receipts is a separate choice. When enabled, it searches your connected inbox for purchase and subscription emails to enrich recorded transactions. Searches may use earlier receipts to identify recurring charges. Insurance features can read relevant insurer messages and attachments; historical cover searches use the period you choose. We process message content needed for these features and retain extracted records and supporting metadata.

If you choose automatic Gmail forwarding setup, Cashcade separately requests gmail.settings.basic and gmail.labels to create a Cashcade label and a filter for supported bank senders. The filter forwards future matching alerts to your Cashcade address, applies the label, marks them as read and archives them. Updating setup replaces matching Cashcade filters. This setup permission is separate from connecting an inbox for read-only searches; you can instead configure forwarding manually in Gmail.

Forwarding an email gives Cashcade the content of that email without ongoing access to your inbox. Stop or remove any forwarding rule in your email provider when you no longer want to send alerts to us.

3. How we use information

We use information to authenticate you, operate your account, import and categorise spending, match receipts, organise insurance details, estimate supported card rewards, explain spending changes, deliver notifications you enable and provide household features. We also use necessary records to respond to requests, diagnose problems, protect the service and meet applicable legal obligations.

Cashcade does not sell personal information. We do not use Gmail data for advertising, credit scoring or lending decisions, or to train general-purpose AI models.

4. AI processing

We use OpenAI’s API for some extraction, classification and coach features. Depending on the feature, information sent to OpenAI can include email subjects and body text, relevant insurance PDFs or images, merchant and product names, extracted financial facts, and your coach questions and conversation context. Some supported bank alerts are parsed directly without AI; AI may be used when those parsers cannot interpret an alert.

This processing supports the features you use. OpenAI states that API data is not used to train its models by default. Provider retention and abuse-monitoring rules can still apply; this is not a promise of zero retention. See OpenAI’s API data controls. AI output can be inaccurate, so check important information against your original records.

5. Sharing and service providers

Providers process information to run Cashcade: Convex supports our backend and stored records; Supabase supports sign-in; Cloudflare handles forwarded email and related infrastructure; Vercel hosts the website; OpenAI provides the processing described above; and Apple delivers enabled push notifications. Google, Microsoft and Apple also process information when you use their sign-in or connected services. Each receives the information relevant to its function, rather than every category listed in this policy.

If you join a household, shared spending totals and categories are visible to its members. Cashcade applies member and payment-method permissions to individual purchase details. Review your household and card-ownership settings before sharing.

We may disclose necessary information to comply with law or protect the service from abuse. Access by people is limited to authorised purposes. For Google user data, this means your specific consent, necessary security investigations, legal requirements, or aggregated information used for internal operations as permitted by Google’s policies. Any transfer of Google user data in a business acquisition requires your prior consent.

6. Limited use of Google data

We limit Google user data, including information derived from it, to the user-facing Cashcade features described here. Our use and transfer of that data must follow the Google API Services User Data Policy, including its Limited Use requirements, and the Google Workspace user data and developer policy. We do not provide Google user data to advertising platforms or data brokers.

7. Storage and retention

Cashcade stores account, transaction, receipt, insurance and coach records to provide your history and the features you use. Stored records can include email subjects and message metadata; we do not maintain a general archive of your entire inbox. Our service providers may retain processing records, security logs and backups under their own service settings and retention rules.

There is currently no automatic expiry period for your stored financial history. Disconnecting an inbox does not erase previously imported transactions. The app’s “Deactivate household” control deactivates the household and retains its records; it does not permanently erase all data. For permanent deletion, contact us as described below. We will explain any information that must be retained for legal or security reasons and any backup limitations when handling your request.

8. Your choices and deletion requests

  • Disconnect an inbox: use Settings → Email setup in Cashcade. This stops future syncing and removes Cashcade’s stored refresh token for the connection.
  • Revoke Google access: remove Cashcade from your Google Account connections. You can also revoke Outlook access through Microsoft’s account controls.
  • Manage optional features: pause Smart Receipts and adjust notifications in Settings. Turning off notifications does not delete existing records or coach insights.
  • Request access, correction or permanent deletion: email nlj587@gmail.com from your registered address and describe your request. This includes records imported from Google, derived records and your waitlist entry. We may need to verify your identity and distinguish your records from those of other household members.

Withdrawing inbox access limits the features that depend on it. You can continue to use manual forwarding. Deleting information from Cashcade does not delete the original emails in your mailbox. Please do not send passwords or full card numbers in a privacy request.

9. Security and international processing

We use authenticated connections, access controls and encrypted storage for mailbox refresh tokens. These measures reduce risk but cannot guarantee absolute security. Our providers may process information outside Singapore, including in the United States; Cashcade does not promise Singapore-only data storage.

The app may store sign-in sessions, preferences and cached records on your device. Website and service providers may use technical storage and logs for authentication, operation and security. Protect your device and use the app’s available lock settings.

10. Changes and contact

We will update the date above when this policy changes and provide notice of material changes. If a new use of Google data requires additional consent, we will ask before using it for that purpose. Send questions, complaints or requests to Joshua Newman at nlj587@gmail.com.