Last updated: 24 July 2026. Version 1.0.
Guarded reads your bank transactions to show you what you have spent on gambling, and what
you have kept since. This policy explains exactly what we collect, what we do with it, and
what we will never do. We have tried to write it so that every sentence is checkable
against the app's actual behaviour, because a privacy policy that overstates is worse than
one that admits something uncomfortable.
If you want the short version: **we never sell or share your transactions, we show them to
nobody but you, and you can disconnect or delete everything at any time.**
Guarded is operated by Detect The Bet. You can reach us at the contact address in the App
Store listing and in the app under Profile.
Guarded is for people 18 and over. We ask your date of birth before we will connect a
bank account, we refuse the connection if you are under 18, and the refusal is enforced on
our servers and in our database, not just in the app.
Information you give us
birthday").
Apple and choose Hide My Email, we receive only Apple's relay address.
you make when you tell us a charge was not gambling.
Information from your bank, through Plaid
We use Plaid to connect to your bank.
Your bank login credentials go to Plaid and never to us. We receive a token that can
only read.
For each transaction in the window your bank releases, we store: the date, the amount,
whether it was money in or money out, the merchant name, the raw description your bank
provides, the category your bank or Plaid assigns, whether the charge is still pending, and
our own assessment of whether it relates to gambling. We also store the name of your
institution and the last few digits of the account. **We do not store your full account
number, and we cannot move money.**
We store every transaction in the window, not only the gambling ones. We would rather
say this plainly than sound better. A charge only looks ordinary next to everything around
it, and the transfers we cannot see past are found the same way. Your groceries are in
there. Nothing in the app is built to look at them.
Information we generate
is.
What we do not collect: we do not use advertising identifiers, we do not embed
third-party advertising or analytics trackers that profile you, and we do not buy data
about you from anyone.
1. To show you your own numbers. This is the product.
2. To improve how well Guarded detects gambling charges, including for other users. See
section 5, which explains the limits on this carefully.
3. To keep the service secure and working, including fraud and abuse prevention.
4. To meet legal obligations.
We do not use your data for advertising, we do not sell it, and we do not share
your transactions with anyone.
| Who | What | Why |
|---|---|---|
| Plaid | Bank connection | To read transactions with your permission |
| Supabase | Hosting, database, authentication | To run the service |
| Apple | Sign-in, app distribution | If you use Sign in with Apple |
| Twilio or an equivalent SMS provider | Your phone number | Only if you sign in by phone |
These are service providers acting on our instructions. They are not permitted to use your
data for their own purposes.
We may disclose information if required by law, or to protect someone's safety. If we are
ever involved in a merger or acquisition, your data may transfer, and this policy continues
to apply until you are told otherwise.
We do not sell your personal information. We do not share it for cross-context
behavioural advertising.
Guarded gets better at spotting disguised gambling charges when it can see which merchants
turn out to be gambling and which do not. That improvement benefits you directly: fewer
wrong flags, fewer questions, a more accurate number.
To do this we may build aggregate statistics about merchants, never about people. The
design is deliberately constrained:
registry were written by a person.
cleaned-up version, not a hashed version. This matters because bank descriptions often
contain other people's names, for example on a transfer to a friend. Those people are
not our users and could never consent, so the only safe answer is that the text does not
travel at all.
from this entirely.
counts are recorded in ranges (5-9, 10-24, 25-99, 100+) rather than exact numbers.
suppressed instead.
**We publicly commit that we will maintain and use this aggregate data only in
de-identified form, that we will not attempt to re-identify any individual from it, and
that we will contractually require the same of anyone who ever receives it.**
What we do not do today: we do not send any of this to our merchant-intelligence
business or to any bank. If that ever changes, we will ask you separately and specifically,
it will be off unless you turn it on, it will not be a condition of using Guarded, and you
will be able to withdraw it at any time.
Guarded infers something about gambling behaviour from financial data. Some state laws,
including Washington's My Health My Data Act and Nevada's SB 370, treat information
inferred by an algorithm about a person's mental health as health data. We think it is
right to treat what Guarded produces with that seriousness, whether or not a court would
require it.
Practically: we do not track merchants relating to healthcare, pharmacies, reproductive or
sexual health, mental health providers, or gender-affirming care. Our registry is about
gambling platforms only, so those merchants are outside it by design.
already shown to you remains until you delete it.
corrections, profile and the account itself, and we remove the connection at Plaid. This
cannot be undone.
You can do both from Profile inside the app.
Depending on where you live you may have the right to access, correct, delete, or obtain a
copy of your information, to opt out of sale or sharing (we do neither), and to appeal a
refusal. Delete is available directly in the app under Profile. For anything else, contact
us and we will respond within the time your local law allows.
We will not discriminate against you for exercising any of these rights.
Nevada and Washington residents: you have specific rights concerning consumer health
data, including the right to withdraw consent and to have such data deleted. Contact us and
we will honour these.
Your session is stored in the device keychain. Traffic is encrypted in transit and data is
encrypted at rest. Access to your records is enforced by the database itself, so each
account can read only its own rows. Bank access tokens are readable only by our servers and
are never sent to the app.
No system is perfectly secure. If a breach affecting your information occurs, we will
notify you and the relevant regulators as required by law.
Guarded is not for anyone under 18 and we do not knowingly collect information from
under-18s. If you believe a minor has provided us information, contact us and we will
delete it.
If we make a material change we will raise the version of this policy and ask you to accept
it again in the app before you continue. We will not quietly widen what we do with data you
already gave us.
Questions, requests, or complaints: the contact address in the App Store listing, or via
Profile in the app.