Privacy Policy

AccountMap — last updated 5 September 2026

The short version. AccountMap reads your email headers on your phone to work out which financial institutions you deal with. Your email never leaves your device. Only the resulting list of institution names is stored, and only you and people you explicitly invite can see it.

What we access

With your permission, AccountMap uses read-only access to your Gmail account (the gmail.readonly scope). For each message in a recent date range we request only these headers:

We never request message bodies or attachments, and we never send, modify, or delete anything in your mailbox.

Where processing happens

All matching happens on your phone. Headers are compared against a list of known institution sending domains held in the app itself. Nothing about your email is transmitted to us or to any third party for this purpose — we operate no server that reads your mail.

What leaves your device

Only derived facts about institutions are stored in our database, so that they can be shown to a trusted contact you invite:

StoredNever stored
Institution name (e.g. "Chase")Email content or headers
Account type (banking, insurance…)Sender addresses
Customer service phone numberAccount numbers
First and last seen datesBalances or transactions
Notes you write yourselfPasswords or login details

AccountMap has no ability to access your financial accounts. It records only that a relationship appears to exist.

Sharing with a trusted contact

You may invite one or more people to view your list. When you do, we create a private link for that person. Opening the link is not enough to see anything: a one-time code is emailed to the address you nominated, and must be entered first. Codes expire after 15 minutes and can only be used once.

You can remove a contact at any time in Settings, which revokes their access immediately.

Who else sees your data

We use two service providers, and nothing else:

We do not sell, rent, or share your information with anyone else, and we do not use it for advertising or analytics profiling. Google's use of data from its APIs is governed by the Google API Services User Data Policy, including its Limited Use requirements, which we adhere to.

Retention and deletion

Your institution list is kept until you delete it. Signing out clears the data held on your device. To delete everything stored on our servers, including your account, email the address below and we will remove it.

Security

Children

AccountMap is not intended for anyone under 18.

Changes

If this policy changes in a way that affects how your data is handled, we will update the date at the top and notify you in the app.

Contact

Questions, or a deletion request: support@jaredco.com