Layaside Privacy Policy

DRAFT — NOT LEGAL ADVICE — NOT CLEARED BY COUNSEL

Peak Lit Tech LLC published this draft on David’s GO (PEA-49, 22 September 2026) so Apple, Plaid, and partners can crawl a real privacy URL. It is not legal advice, not a Plaid security-questionnaire answer, not Apple App Review clearance, and not a substitute for a lawyer. Outside counsel has not cleared this policy.

Effective date (published draft): 22 September 2026
Product: Layaside (https://layaside.com)
Operator: Peak Lit Tech LLC


1. Who we are

Layaside is a personal budgeting product operated by Peak Lit Tech LLC, a Florida limited liability company.

This policy is for Layaside consumers (you, as an individual using a personal-finance app). It is not the privacy policy for Peak Lit’s HR product (Drelvo / PeopleOS). Layaside data is not governed by that HR policy.

We do not publish our EIN in this policy.

2. What Layaside is — and is not

Layaside helps you see accounts, balances, and transactions so you can budget.

Layaside is not:

Bank balances you see in Layaside remain at your financial institution.

We do not claim SOC 2 certification or GDPR “adequacy.”

3. Notice and consent before connecting a bank (Plaid Link)

If you choose to connect a bank or other financial institution, we use Plaid to let you authenticate with that institution through Plaid Link.

Before Link opens, we will present notice so you can decide whether to connect. Completing Link is how you authorize Plaid and Layaside to receive the financial data described below, subject to this policy and Plaid’s terms.

Plaid is an independent company. Please read:

Plaid’s policy applies to Plaid’s own processing. This policy applies to what we receive and store after you connect.

4. Information we collect

4.1 Account information you give us

When you register, we collect:

Sign-up is email and password. We do not currently offer Google, Apple, or other social login.

You may also enter budgeting content you create: category names, budget amounts, notes, debts you type in, household name/timezone, and similar.

4.2 Financial information via Plaid (if you connect a bank)

If you complete Plaid Link, we may receive read-only data such as:

We request Transactions and Balance-style account data so the app can show your budget. We do not request Plaid Transfer. We do not initiate ACH or other money movement. We do not pull credit files or FCRA scores.

You may also add manual accounts and transactions without using Plaid.

4.3 Household sharing (optional)

If you invite someone to a household, we process their email and role (for example editor) so they can share that household’s budget view. Do not invite people who have not agreed to use Layaside with you.

4.4 Billing (if you pay for Plus)

If you start a paid plan or trial checkout, Stripe processes payment on a hosted checkout page. We may receive billing status, plan, customer/subscription identifiers, and limited payment metadata. We do not intend to store full card numbers on Layaside servers. Whether Stripe checkout is live in production is marked [[STRIPE_BILLING_LIVE]].

4.5 Technical and support data

We may collect IP address, device/browser type, timestamps, request IDs, and similar logs needed to run and secure the service. If you email hello@peaklittech.com, we receive whatever you send.

We do not currently use third-party advertising SDKs, App Tracking Transparency (ATT) tracking, or consumer analytics products (for example Mixpanel, Amplitude, Firebase Analytics) in the Layaside app as of this draft. If that changes, we will update this policy.

4.6 Information we do not seek

We do not ask for Social Security numbers as part of ordinary budgeting. We do not want your bank password stored in Layaside — Plaid Link is designed so you authenticate with your institution through Plaid.

4.7 Browser extension (optional Amazon order import)

If you install the optional Layaside browser extension and choose to sync, the extension runs in your browser and may read Amazon.com order pages that you can already see while you are signed into Amazon in a normal tab. It may send structured order metadata (for example order id, date, line items, quantities, prices, and tax/shipping/discount or shipment/payment amounts when shown) to Layaside so we can help match those orders to Amazon charges already in your Layaside household (including via Plaid) and prefill category splits.

Using the extension is optional. If you never install it or never sync, we do not receive Amazon order rows through this path. Imported order metadata is retained with the household. To request deletion of imported order metadata, email hello@peaklittech.com. Engineering must confirm whether account deletion cascades Amazon order rows before we use stronger wording. [[AMAZON_ORDER_DELETE_CASCADE]]

Peak Lit Tech LLC is not affiliated with, endorsed by, or a partner of Amazon.com, Inc. or its affiliates.

5. How we use information

We use the information above to:

We use financial data for app functionality (budgeting), not to sell it, not to score credit, and not to target third-party ads.

6. How we share information (we do share with service providers)

We do not claim that we never share information with third parties. We share what is needed to run Layaside, as follows.

6.1 Service providers (subprocessors)

Provider Role
Plaid Inc. Bank connection (Plaid Link); read-only Transactions / Balance-style data
IONOS (VPS) Hosting for the Layaside website, API, and related infrastructure. Confirm contracting entity: [[HOSTING_CONTRACTING_ENTITY]]
Stripe Payment processing for Plus checkout/portal, if/when [[STRIPE_BILLING_LIVE]] is yes
[[TRANSACTIONAL_EMAIL_PROVIDER]] Password-reset and similar mail, if/when configured (Postmark appears in server config; production mail may still be unconfigured)

Postgres and Redis currently run as Peak Lit infrastructure on the same hosting environment, not as a separate consumer-facing product.

We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, sale, or financing of Peak Lit Tech LLC, subject to this policy.

6.2 What we do not do with financial data

“Sell” here means selling personal information for money or analogously treating financial data as a data-broker product. We do not do that.

7. Token storage and encryption (high level)

When you link an institution, Plaid access tokens stay on our servers. They are not returned to the browser or mobile client.

At rest, those tokens are stored in encrypted form using AES-GCM (versioned ciphertext). Encryption is only as strong as our key handling and hosting controls. This paragraph is a high-level description, not a security certification.

Plaid webhooks (for example transaction updates) are received at an HTTPS endpoint on layaside.com and used to refresh your data.

8. Disconnecting a bank (Plaid Item remove)

You can disconnect a linked institution in Layaside (Settings / Connect accounts → Remove linked item). That calls our server, which tells Plaid to remove the Item and deletes the local Item record.

You can also manage Plaid connections at https://my.plaid.com.

Disconnecting a bank is not the same as deleting your Layaside account. After disconnect, budgeting data you typed yourself may remain until you delete it or delete your account.

9. Account deletion (Apple Guideline 5.1.1)

Layaside lets you create an account, so you must be able to request deletion.

Public request path (use this until an in-app control ships): email hello@peaklittech.com from the address on the account, subject line Delete my Layaside account, and we will process deletion.

We aim to complete deletion within [[ACCOUNT_DELETION_SLA_DAYS]] days except where we must keep limited records (for example billing, security, or legal holds).

Engineering note (not a user instruction): the API already supports authenticated DELETE /me, but the app UI reviewed for this draft (More / Settings) exposes Sign out and bank Remove linked item, not a Delete account button. Do not tell App Review that users can find in-app deletion until that button exists.

If you own a household that still has other members, we may need those members removed or the household wound down before the owner account can be fully deleted.

10. Retention

We keep account and budgeting data while your account is open. After deletion we remove or de-identify personal data except what we must retain. Default retention for logs and backups: [[DATA_RETENTION_PERIOD]].

Plaid may retain data under Plaid’s own policy even after we delete our copy.

11. Security

We use HTTPS, hashed passwords, session tokens, access controls, and encrypted Plaid tokens at rest as described above. No method of transmission or storage is 100% secure. We do not claim SOC 2, ISO 27001, or similar.

12. Children

Layaside is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe we have, email hello@peaklittech.com.

13. Your choices and US state privacy notes

You can:

Depending on your US state, you may have additional rights (access, deletion, correction, appeal). We will not discriminate against you for exercising those rights. We do not sell personal information as described in section 6.2.

This draft is written for a US consumer product. We do not claim GDPR applicability, EU adequacy, or that we have appointed an EU representative. If you use Layaside from outside the United States, [[INTERNATIONAL_TRANSFER_NOTE]].

14. Changes

We may update this policy. The effective date above will change. Material changes will be posted on https://layaside.com/privacy (once that URL serves this text — today it is an empty app shell; see the README).

15. Contact

Peak Lit Tech LLC
5842 Sunberry Cir
Fort Pierce, FL 34951
hello@peaklittech.com

Layaside support is the same address. There is no separate /support page on peaklittech.com as of this draft.