Guardian
Privacy Policy

What we see, and what we never will.

Last updated 8 August 2026

Guardian reads the transactions on the cards you connect and tells you which of them went to gambling platforms. This page describes everything we collect, why, who else touches it, how long we keep it, and how you delete it.

The short version.

We read transactions on the accounts you connect, and nothing else. Your bank login goes to Plaid and never to us, and what we hold can only read. We do not sell your data, we do not run ads, there are no analytics or tracking SDKs in the app, and nothing from Guardian feeds the merchant intelligence Detect The Bet sells to banks. You can delete everything from Settings, immediately, without asking us.

  1. What we collect
  2. Where it comes from
  3. What we never collect
  4. Your bank login never reaches us
  5. Why we use it
  6. Who else touches it
  7. What we do not do with it
  8. How the analysis works
  9. The person you are watching for
  10. Children
  11. Gambling data and health privacy laws
  12. What we cannot see
  13. How long we keep it
  14. Deleting your data
  15. Withdrawing consent
  16. Security
  17. Your privacy rights
  18. Where your data is processed
  19. Changes
  20. Contact

1. What we collect

Under California law these fall into the categories of identifiers, commercial information, financial information, internet or app activity, and inferences. Financial information is the sensitive one, and we treat it that way.

2. Where it comes from

We do not buy personal information, and we do not receive it from data brokers, advertising networks, or social platforms.

3. What we never collect

Not messages, not location, not browsing history, not photos, not calls, not contacts, not app usage, and not anything at all from anybody's phone but your own. Guardian is not installed on anybody else's device and cannot be. There are no advertising identifiers, no third-party analytics SDKs, and no tracking pixels in the app.

4. Your bank login never reaches us

Connecting a card goes through Plaid Inc., which handles the login with your bank inside its own interface. We never see, receive or store your banking credentials.

What Plaid gives us is read-only. We request transaction data and nothing else. We did not request, and therefore cannot use, the permissions that would let us move money, read the account and routing numbers used to move it, or open, close or change anything about your account. That is a property of how the connection was built, not a policy we could quietly relax.

Plaid's own handling of your information is described at plaid.com/legal.

5. Why we use it

We process this information to provide a service you asked for, on the consent you gave when you connected an account, and to meet our legal obligations. We do not process it for advertising, because we do not advertise.

6. Who else touches it

We keep this list short on purpose, and we name every processor rather than describing them as a category:

Each is bound by contract to protect what we give them, to use it only to provide their service to us, and not to use it for their own purposes. We may also disclose information if the law requires it, to protect someone's safety, or in connection with a merger or sale of the business, in which case this policy continues to apply until you are told otherwise.

7. What we do not do with it

8. How the analysis works

Guardian compares the descriptor your bank sent against a registry of gambling and gambling-adjacent merchants that we maintain, and applies rules about naming patterns. When it matches, we record what matched and how strongly, and the app shows you that reasoning rather than a bare verdict.

This is automated, and it is fallible. It produces an opinion about a charge, not a finding of fact about a person. It does not score anyone, does not build a behavioural profile of the person named on a label, and does not make any decision that produces a legal or similarly significant effect. Every decision that follows is yours. If you think we got a charge wrong, tell us and we will look at it.

9. The person you are watching for

This is the part most privacy policies get to describe simply and Guardian does not, so we will be exact about it.

Guardian shows you activity on your own account. Where a teenager in your household spends from a card you hold, their spending appears on your statement, and so it appears in Guardian. That means the app produces information about a person who is not you, and often about a minor.

10. Children

Guardian is for adults. You must be 18 or older to use it, and the app enforces this rather than asking. Guardian is not directed to children, is not in the Kids Category, and collects nothing from a child: the person whose spending appears in the app does not have an account, does not install anything, and is never contacted by us.

Because no child ever registers, uses, or gives information to Guardian, we do not knowingly collect personal information from a child. If we learn that someone under 18 has created an account, we will close it and delete the information associated with it. If you believe that has happened, write to support@detecthebet.com.

11. Gambling data and health privacy laws

Some state laws, including Washington's My Health My Data Act, define consumer health data broadly enough that information about gambling behaviour may fall within it. We would rather address that directly than hope it does not apply.

12. What we cannot see

We cannot see cash, accounts you have not connected, or money moved inside an app we are not connected to. We do see money leaving a connected account, including money sent to another person, and the app says so on the screens that report what we found. Finding nothing is not proof that nothing happened.

13. How long we keep it

We keep each kind of information for as long as we have a stated reason to, and no longer. We do not set a single expiry across everything, because the reasons differ: the record of what we found is what the product is for, and the ordinary spending underneath it is not.

WhatHow longWhy
Transactions While your account is open History is the product. The app can only tell you what it did and did not review if it still holds the rows it reviewed.
Findings, and the record of what we reviewed While your account is open This is what we told you we found. Removing it would take back something you were shown and may be relying on.
Account details While your account is open To keep you signed in and to reach you.
Device token Until notifications are turned off, or the device stops accepting them A token for a device that no longer exists is deleted when we learn that.
Technical and error logs A short operational window To keep the service working and to investigate faults.
Records we are required to keep As long as the law requires Limited, and only where a legal or regulatory obligation applies.

In deciding how long is appropriate for anything not fixed above, we consider the amount, nature and sensitivity of the information, the harm that could come from it being seen by the wrong person, what we are using it for, and any legal or regulatory obligation that applies to it.

When information reaches the end of its period, or we no longer have a reason for it, we securely delete it.

Backups, stated plainly

When you delete something it is removed from the live service straight away, and you stop seeing it immediately. Encrypted backups of the database are kept for a short period so we can recover from a failure, and a deleted record can persist in those backups until they rotate, which is currently within 30 days. Backups are not used to serve the app, are not searchable, and a record removed from the live service is not restored to it. We say this because "deleted instantly, everywhere, including from disaster recovery" is not true of any service that keeps backups, and we would rather tell you what actually happens.

14. Deleting your data

In the app: Settings, then Delete my account. That disconnects every card at Plaid first, then permanently deletes your account and everything attached to it: transactions, findings, labels, notes and settings. It cannot be undone, and we cannot recover it for you afterwards.

It leaves the live service immediately. As section 13 explains, encrypted backups rotate within 30 days, and deleted records are not restored from them.

You can also disconnect a single card at any time from Settings, which stops us reading it while keeping what you have already been shown.

If you would rather we did it, write to support@detecthebet.com and we will action it and confirm when it is done.

15. Withdrawing consent

Disconnecting a card withdraws the permission you gave to read it. Deleting your account withdraws everything. Neither requires you to contact us, and neither is delayed.

16. Security

Data is encrypted in transit and at rest. Access to your data is scoped to your account at the database level, not merely in the app, so a bug in the interface cannot show you somebody else's findings. Bank access tokens are held server-side only and are never present on your phone. We maintain a written information security program appropriate to our size and the sensitivity of what we hold.

No system is perfectly secure, and we will not pretend otherwise. You are responsible for the security of your own sign-in and your own device.

17. Your privacy rights

Depending on where you live, you may have the right to know what we hold about you, to get a copy of it, to correct it, to delete it, to limit how sensitive information is used, and not to be discriminated against for exercising any of these.

Guardian is built so that most of these do not need our involvement. Everything we hold about you is visible in the app, and deletion is a button in Settings that works immediately. For anything else, write to support@detecthebet.com.

As a company handling financial information we are also subject to federal financial privacy rules, and we do not disclose your information to anyone for marketing purposes.

18. Where your data is processed

Guardian is operated from the United States, and your information is stored and processed in the United States by us and by the providers named in section 6. If you use Guardian from outside the United States, your information will be processed there, where privacy laws may differ from those where you live.

19. Changes

If this policy changes in a way that affects what we collect or who sees it, we will say so in the app rather than quietly updating this page, and we will change the date at the top.

20. Contact

support@detecthebet.com