Last updated July 16, 2026

DimeProof Privacy Policy

DimeProof is a personal finance app that helps users compare read-only bank/card transactions with receipt, invoice, refund, statement, and cancellation evidence from connected email accounts.

Information We Collect

We may collect account profile details such as name and email address; read-only bank/card transaction data such as transaction names, merchants, dates, amounts, categories, account masks, and institution names; and read-only email evidence such as provider account email, selected label or folder, message IDs, sender, subject, received date, attachment-presence metadata, extracted receipt fields, and scan history. The current Gmail service does not download attachments or retain complete email bodies.

How We Use Information

We use data to operate the app, connect accounts at the user's direction, import transactions and receipt evidence, match records by deterministic rules, generate reports, improve reliability, prevent abuse, and respond to support requests. DimeProof does not sell personal financial data.

Plaid

DimeProof uses Plaid Link so users can authorize read-only transaction access. DimeProof does not receive or store bank usernames or passwords. Plaid access tokens are encrypted server-side.

Google and Gmail

DimeProof uses Google Sign-In only for authentication with openid, email, and profile scopes. Gmail scanning is separate and uses https://www.googleapis.com/auth/gmail.readonly to retrieve receipt and invoice evidence from the one category or label the user selects. Gmail data is used only for user-facing app features such as extraction, matching, reports, and review lists.

DimeProof's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft and Yahoo Mail

DimeProof uses delegated Microsoft Mail.Read access and Yahoo mail-r access only when users connect those inboxes. The app reads the selected folder for receipt evidence, stores encrypted OAuth tokens, and does not send, delete, move, mark, relabel, or modify email messages.

Retention and Deletion

Users can disconnect integrations, delete imported mailbox data, or delete their account. Disconnecting removes stored OAuth credentials immediately. User-requested deletion from active systems is completed without undue delay and targeted within 24 hours; encrypted backup copies expire through the backup lifecycle within 30 days, unless law requires longer retention.

Service Providers

Equanth AI LLC uses Cloudflare-hosted infrastructure and D1 account storage for the free OAuth stage, Plaid for read-only transaction connectivity when enabled, and Google, Microsoft, or Yahoo when a user connects those providers. Private attachment storage and optional extraction remain disabled until their security controls are activated. These providers process data only to deliver the requested DimeProof service.

Security

DimeProof uses expiring sessions, account authorization, encrypted provider tokens, rate limits, and logs designed to exclude credentials and complete message contents. The current Gmail service does not retain attachments. No internet service can guarantee absolute security.

Contact

For privacy questions or data requests, contact support@dimeproof.com. Security reports may be sent to security@dimeproof.com. DimeProof is operated by Equanth AI LLC.