Last updated: September 22, 2026 · Effective: June 14, 2026
liway ("we", "our", or "us") provides a personal-finance tool that helps you see how much money is safe to spend before your next paycheck. This Privacy Policy explains what information we collect, how we use it, who we share it with, where it is stored, how long we keep it, and the choices you have. By creating a liway account or using the liway website or mobile apps, you agree to the practices described here.
If you have questions, contact connect@liway.app.
liway is operated by Liway LLC, a Colorado limited liability company. We can be reached at connect@liway.app for any privacy questions, data requests, or general support. The product is currently available only in the United States.
If you want the short version:
Detailed disclosures follow.
We collect only what we need to compute your leeway and operate the service. There are six categories.
These values are editable from inside the app at any time.
If you choose to link a bank account, our integration partner Plaid handles the bank login on our behalf. Plaid returns the following to liway:
We never see, store, or transmit your bank login credentials. Those go directly from your device to Plaid. See Plaid's End User Privacy Policy at plaid.com/legal for how Plaid handles bank credentials.
We access your bank-account transaction history through Plaid for two purposes: to automatically detect the recurring patterns that drive the leeway calculation, and to show you your own activity.
Your transactions are shown only to you. They are never used for advertising, profiling, or shared with any third party. The transactions table stores the rows needed to show you that history and to re-run detection if Plaid sends an update; nothing else is done with that data.
Where a purchase happened. For some transactions your bank also reports the merchant's address or website. We keep that with the transaction so the transaction's detail can show it to you. Together with the date, a merchant's address can say where you were, so it gets the same protection as the rest of your transactions: it is shown only to you, and only when you open that transaction. Open in Maps hands the address to the maps app you choose (Apple Maps or Google Maps) only when you tap it; no map service receives it before then. This is the merchant's location as your bank reports it, never your device's location: liway never asks for location permission.
You can disconnect your bank at any time (Settings → Disconnect). On disconnect we revoke the Plaid connection at Plaid before removing the local record.
We log a small set of operational events to keep the service secure and observable. None of this is sold or shared for advertising; it stays inside our hosting providers' logs:
Notifications are off until you enable them. If you do, your device gives us a push token — the address the operating system uses to deliver a message to that one installation of the app. We store it alongside the platform (iOS or Android) and the time we last saw it, linked to your account so we know where to send your alerts. We do not attach a device identifier to it.
A push token is not an advertising identifier and cannot be used to follow you across other apps or websites. We remove it when you turn notifications off, when you delete your account, and automatically when Apple or Google tells us the app is no longer installed.
Notifications never contain amounts. An alert tells you something needs attention; the figures stay inside the app, behind your lock screen.
Check In is free, and if you never subscribe there is nothing in this section to collect. If you do subscribe to Full liway, we record what we need to know whether your account currently has access:
This is linked to your liway account, because its entire purpose is to decide what your account can open.
We never see your card. Apple and Google take the payment under their own terms; no card number, expiry or billing address ever reaches liway. We cannot charge you, refund you, or cancel your subscription — those all happen at the store.
Subscription records are deleted with your account, along with everything else. One exception, described under When you delete your account: we keep a one-way fingerprint of your email address so a single free trial cannot be claimed repeatedly. It cannot be reversed to recover your address.
We do not collect your device's location, contacts, photos, advertising identifiers, or any signal from advertising or cross-site tracking SDKs (we run none), and we do not fingerprint your device. The web and mobile apps do use a first-party product-analytics SDK (PostHog) for aggregate usage events — see Product analytics below.
To understand how the product is used, the liway web app (my.liway.app) and mobile apps (iOS + Android) use PostHog, a product-analytics service hosted in the United States.
Separately, our public marketing site (liway.app) uses a cookieless, privacy-friendly analytics tool for aggregate page-view counts only. It sets no cookies, collects no personal information, and does no cross-site tracking or device fingerprinting. It is entirely separate from the product and never sees any account or financial data.
We use the information described above to:
We do not use your information for advertising, profiling, behavior modeling, or selling to third parties.
We share information only with the service providers that make liway work. These providers are bound by their own privacy policies and security commitments, and they act as data processors on our behalf. Every provider that handles production user data holds a current SOC 2 Type II report.
We rely on the following categories of providers (and we name the ones you interact with directly, plus the ones the app stores require us to name):
A complete, named list of subprocessors — including provider identity, role, data scope, current certifications, and the U.S. region each one operates in — is maintained internally and made available on request to connect@liway.app. We update the internal list whenever a vendor is added, replaced, or removed; this privacy policy does not need to be re-issued for vendor changes.
We do not sell or rent your information to anyone. We do not share it with advertisers, data brokers, or marketing partners. We do not participate in any data co-op, lookalike-audience program, or attribution exchange. This stance also reflects our obligations under the Plaid Developer Policy, which prohibits the sale of data accessed through Plaid.
All production data is stored and processed in the United States. Application servers and the primary database both run in U.S. East regions. Email-delivery and DNS providers use globally distributed networks, but neither processes data-bearing user content beyond what is necessary for delivery. Specific region details for each subprocessor are available on request at connect@liway.app.
If you access liway from outside the United States, your data is still transmitted to and stored in the United States.
We keep your data while your account is active. Two events cause deletion.
You can delete your account from the Settings screen at any time. Deletion is gated by password reauthentication, a one-time email code (six-digit OTP), and a type-to-confirm step. On confirmation, the deletion cascade fires immediately:
/item/remove) before removing the connection record on our side.There is no recovery window today. We are evaluating adding a 30-day soft-delete grace period in a future release; if added, this policy will be updated.
If you can no longer sign in — you uninstalled the app, or lost the device — you can still have the account deleted. Delete your account explains how to request it by email, and what we verify before acting on it.
We do not automatically delete inactive accounts today. If you have not signed in for an extended period and would like your data removed, contact connect@liway.app.
You have the following rights for as long as you have an account with us. We honor them for all users, regardless of state of residence:
We do not have a built-in data-export feature today. If you would like a complete export of the data we hold about you, contact connect@liway.app; we will fulfill the request manually within 30 days. The export covers all data described under "Information we collect".
The fastest way to exercise any of the rights above is connect@liway.app. Please indicate (a) the right you are exercising, and (b) the email address on the account. We may ask you to verify the request by clicking a link sent to that email address.
liway does not currently meet the revenue or data-volume thresholds that trigger formal CCPA / CPRA applicability. As a posture choice, we honor the underlying consumer rights described above for all users, regardless of California residency. If liway grows past the thresholds, this policy will be updated to add the formal CCPA-mandated disclosures.
If you are a California resident and would like to exercise any of the rights described above, contact connect@liway.app.
Several states (Colorado, Connecticut, Virginia, Utah, Texas, others) have enacted comprehensive privacy laws. As above, our user-facing rights and operational posture (no data sale, no targeted advertising, full deletion right) apply to all users regardless of state. We update this section as state-specific obligations crystallize.
liway is available only in the United States. We do not knowingly collect data from users outside the U.S. GDPR is not in scope today. If liway expands to the EU or UK, this section is updated before any non-US launch.
liway is not intended for children under 13. We do not knowingly collect personal information from anyone under 13. If you become aware that a child under 13 has provided us with personal information, please contact connect@liway.app and we will delete it. We do not target advertising to children — we do not run advertising at all.
We take reasonable measures to protect your information:
liway.app subdomains.No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you in accordance with applicable law, with a target customer-notification time of 72 hours from the time the breach is confirmed.
We may update this policy from time to time. Material changes will be communicated by updating the "Last updated" date at the top of this page and, for significant changes, by emailing you at the address on your account before the change takes effect. Older versions are preserved in the project's source-control history.
For privacy questions, support, or data-rights requests:
Liway LLC
Colorado, USA