Layaside Privacy Policy
DRAFT — NOT LEGAL ADVICE — NOT CLEARED BY COUNSEL
Peak Lit Tech LLC published this draft on David’s GO (PEA-49, 22 September 2026) so Apple, Plaid, and partners can crawl a real privacy URL. It is not legal advice, not a Plaid security-questionnaire answer, not Apple App Review clearance, and not a substitute for a lawyer. Outside counsel has not cleared this policy.
Effective date (published draft): 22 September 2026
Product: Layaside (https://layaside.com)
Operator: Peak Lit Tech LLC
1. Who we are
Layaside is a personal budgeting product operated by Peak Lit Tech LLC, a Florida limited liability company.
- Mailing address: 5842 Sunberry Cir, Fort Pierce, FL 34951
- Contact: hello@peaklittech.com
- Website / app: https://layaside.com
This policy is for Layaside consumers (you, as an individual using a personal-finance app). It is not the privacy policy for Peak Lit’s HR product (Drelvo / PeopleOS). Layaside data is not governed by that HR policy.
We do not publish our EIN in this policy.
2. What Layaside is — and is not
Layaside helps you see accounts, balances, and transactions so you can budget.
Layaside is not:
- a bank, credit union, or depository institution
- FDIC-insured (we do not hold your money)
- a money transmitter
- an investment adviser, broker-dealer, or source of investment, tax, or legal advice
- a consumer reporting agency, and we do not use your data for FCRA credit scoring or to furnish consumer reports
- a product that moves money (no ACH, no Plaid Transfer, no payments to other people through Layaside)
Bank balances you see in Layaside remain at your financial institution.
We do not claim SOC 2 certification or GDPR “adequacy.”
3. Notice and consent before connecting a bank (Plaid Link)
If you choose to connect a bank or other financial institution, we use Plaid to let you authenticate with that institution through Plaid Link.
Before Link opens, we will present notice so you can decide whether to connect. Completing Link is how you authorize Plaid and Layaside to receive the financial data described below, subject to this policy and Plaid’s terms.
Plaid is an independent company. Please read:
- Plaid’s End User Privacy Policy: https://plaid.com/legal/#end-user-privacy-policy
- Manage or disconnect Plaid connections: https://my.plaid.com
Plaid’s policy applies to Plaid’s own processing. This policy applies to what we receive and store after you connect.
4. Information we collect
4.1 Account information you give us
When you register, we collect:
- Email address
- Password (stored as a password hash, not in plaintext)
- A user identifier we assign
- Session tokens so you stay signed in (sessions currently last about 30 days)
Sign-up is email and password. We do not currently offer Google, Apple, or other social login.
You may also enter budgeting content you create: category names, budget amounts, notes, debts you type in, household name/timezone, and similar.
4.2 Financial information via Plaid (if you connect a bank)
If you complete Plaid Link, we may receive read-only data such as:
- Account identity — institution name, account name/mask, account type (for example checking or savings)
- Balances
- Transactions — dates, amounts, merchant/description, and categories Plaid or we assign for budgeting
We request Transactions and Balance-style account data so the app can show your budget. We do not request Plaid Transfer. We do not initiate ACH or other money movement. We do not pull credit files or FCRA scores.
You may also add manual accounts and transactions without using Plaid.
4.3 Household sharing (optional)
If you invite someone to a household, we process their email and role (for example editor) so they can share that household’s budget view. Do not invite people who have not agreed to use Layaside with you.
4.4 Billing (if you pay for Plus)
If you start a paid plan or trial checkout, Stripe processes payment on a hosted checkout page. We may receive billing status, plan, customer/subscription identifiers, and limited payment metadata. We do not intend to store full card numbers on Layaside servers. Whether Stripe checkout is live in production is marked [[STRIPE_BILLING_LIVE]].
4.5 Technical and support data
We may collect IP address, device/browser type, timestamps, request IDs, and similar logs needed to run and secure the service. If you email hello@peaklittech.com, we receive whatever you send.
We do not currently use third-party advertising SDKs, App Tracking Transparency (ATT) tracking, or consumer analytics products (for example Mixpanel, Amplitude, Firebase Analytics) in the Layaside app as of this draft. If that changes, we will update this policy.
4.6 Information we do not seek
We do not ask for Social Security numbers as part of ordinary budgeting. We do not want your bank password stored in Layaside — Plaid Link is designed so you authenticate with your institution through Plaid.
4.7 Browser extension (optional Amazon order import)
If you install the optional Layaside browser extension and choose to sync, the extension runs in your browser and may read Amazon.com order pages that you can already see while you are signed into Amazon in a normal tab. It may send structured order metadata (for example order id, date, line items, quantities, prices, and tax/shipping/discount or shipment/payment amounts when shown) to Layaside so we can help match those orders to Amazon charges already in your Layaside household (including via Plaid) and prefill category splits.
- We do not ask for your Amazon password.
- We do not send Amazon cookies or a cookie jar to Layaside servers.
- We do not use this path to create extra bank transactions that would double-count spend already imported.
- Category assignment remains in Layaside; the extension does not decide your budget categories.
- Locally, the extension may store a Layaside session token and sync progress/cursor in browser extension storage.
Using the extension is optional. If you never install it or never sync, we do not receive Amazon order rows through this path. Imported order metadata is retained with the household. To request deletion of imported order metadata, email hello@peaklittech.com. Engineering must confirm whether account deletion cascades Amazon order rows before we use stronger wording. [[AMAZON_ORDER_DELETE_CASCADE]]
Peak Lit Tech LLC is not affiliated with, endorsed by, or a partner of Amazon.com, Inc. or its affiliates.
5. How we use information
We use the information above to:
- create and secure your account
- display budgets, balances, and transactions
- sync and update linked Items (including Plaid webhooks)
- let you disconnect a bank or delete your account
- operate optional household sharing and exports you request
- process paid plans if billing is enabled
- provide support
- maintain security, prevent abuse, and comply with law
We use financial data for app functionality (budgeting), not to sell it, not to score credit, and not to target third-party ads.
6. How we share information (we do share with service providers)
We do not claim that we never share information with third parties. We share what is needed to run Layaside, as follows.
6.1 Service providers (subprocessors)
| Provider | Role |
|---|---|
| Plaid Inc. | Bank connection (Plaid Link); read-only Transactions / Balance-style data |
| IONOS (VPS) | Hosting for the Layaside website, API, and related infrastructure. Confirm contracting entity: [[HOSTING_CONTRACTING_ENTITY]] |
| Stripe | Payment processing for Plus checkout/portal, if/when [[STRIPE_BILLING_LIVE]] is yes |
| [[TRANSACTIONAL_EMAIL_PROVIDER]] | Password-reset and similar mail, if/when configured (Postmark appears in server config; production mail may still be unconfigured) |
Postgres and Redis currently run as Peak Lit infrastructure on the same hosting environment, not as a separate consumer-facing product.
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, sale, or financing of Peak Lit Tech LLC, subject to this policy.
6.2 What we do not do with financial data
- We do not sell your financial data.
- We do not share it for third-party cross-app advertising.
- We do not use it to furnish consumer reports or FCRA credit scores.
“Sell” here means selling personal information for money or analogously treating financial data as a data-broker product. We do not do that.
7. Token storage and encryption (high level)
When you link an institution, Plaid access tokens stay on our servers. They are not returned to the browser or mobile client.
At rest, those tokens are stored in encrypted form using AES-GCM (versioned ciphertext). Encryption is only as strong as our key handling and hosting controls. This paragraph is a high-level description, not a security certification.
Plaid webhooks (for example transaction updates) are received at an HTTPS endpoint on layaside.com and used to refresh your data.
8. Disconnecting a bank (Plaid Item remove)
You can disconnect a linked institution in Layaside (Settings / Connect accounts → Remove linked item). That calls our server, which tells Plaid to remove the Item and deletes the local Item record.
You can also manage Plaid connections at https://my.plaid.com.
Disconnecting a bank is not the same as deleting your Layaside account. After disconnect, budgeting data you typed yourself may remain until you delete it or delete your account.
9. Account deletion (Apple Guideline 5.1.1)
Layaside lets you create an account, so you must be able to request deletion.
Public request path (use this until an in-app control ships): email hello@peaklittech.com from the address on the account, subject line Delete my Layaside account, and we will process deletion.
We aim to complete deletion within [[ACCOUNT_DELETION_SLA_DAYS]] days except where we must keep limited records (for example billing, security, or legal holds).
Engineering note (not a user instruction): the API already supports authenticated DELETE /me, but the app UI reviewed for this draft (More / Settings) exposes Sign out and bank Remove linked item, not a Delete account button. Do not tell App Review that users can find in-app deletion until that button exists.
If you own a household that still has other members, we may need those members removed or the household wound down before the owner account can be fully deleted.
10. Retention
We keep account and budgeting data while your account is open. After deletion we remove or de-identify personal data except what we must retain. Default retention for logs and backups: [[DATA_RETENTION_PERIOD]].
Plaid may retain data under Plaid’s own policy even after we delete our copy.
11. Security
We use HTTPS, hashed passwords, session tokens, access controls, and encrypted Plaid tokens at rest as described above. No method of transmission or storage is 100% secure. We do not claim SOC 2, ISO 27001, or similar.
12. Children
Layaside is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe we have, email hello@peaklittech.com.
13. Your choices and US state privacy notes
You can:
- access and update much of your budgeting data in the app
- disconnect banks (section 8)
- export transactions (CSV) if that feature is available in your build
- request account deletion (section 9)
- email us to ask what we hold about you
Depending on your US state, you may have additional rights (access, deletion, correction, appeal). We will not discriminate against you for exercising those rights. We do not sell personal information as described in section 6.2.
This draft is written for a US consumer product. We do not claim GDPR applicability, EU adequacy, or that we have appointed an EU representative. If you use Layaside from outside the United States, [[INTERNATIONAL_TRANSFER_NOTE]].
14. Changes
We may update this policy. The effective date above will change. Material changes will be posted on https://layaside.com/privacy (once that URL serves this text — today it is an empty app shell; see the README).
15. Contact
Peak Lit Tech LLC
5842 Sunberry Cir
Fort Pierce, FL 34951
hello@peaklittech.com
Layaside support is the same address. There is no separate /support page on peaklittech.com as of this draft.