← Boosteate

Privacy Policy

Effective: September 15, 2026 · Operated by SAMYCA LLC (doing business as Boosteate) · support@boosteate.app

This Privacy Policy explains how SAMYCA LLC ("Boosteate", "we", "us") collects, uses, shares and protects personal information when you use the Boosteate mobile app and website (the "Service"). Because Boosteate helps you manage money, obtain credit information and connect financial accounts, we are a "financial institution" under the Gramm‑Leach‑Bliley Act (GLBA) and this document also serves as our GLBA privacy notice.

In short: we collect only what the Service needs; we never sell or share your information for advertising; sensitive identifiers (Social Security number, bank account numbers) are encrypted field by field with keys held in a separate key‑management service; your credit report is pulled only with your written instruction and shown only to you; and you can export or delete everything.

1. Information we collect

CategoryExamplesSource
IdentityName, email address, mobile phone number, preferred language, state of residence. At sign‑up we ask your date of birth to confirm you are 18 or older and to identify you with a credit bureau later if you request your report; it is stored encrypted field by field (see §7) and is never shown in full in the app.You; Google or Apple sign‑in (name and email only)
Identity verificationAddress and Social Security number (SSN) — only when you request your credit report. By default we keep only the last four digits of your SSN after the request is completed (see §6).You
Credit informationCredit score, score factors and report summary from a consumer reporting agencyCredit bureau or reseller, with your consent (§3)
Financial dataExpenses, receipts, income, debts, goals, mileage and trips; if you connect a bank account: institution, account name, last four digits, balances and transactionsYou; the banking aggregator you authorize
LocationGPS position while you measure a work trip, only if you enable mileage trackingYour device, with your permission
Device and securityDevice type and OS version, app version, a per‑device cryptographic signing key (public part only), session and sign‑in events, whether the device appears rooted or jailbroken, IP address at the time of a request (not stored with crash reports)Your device; our servers
DiagnosticsCrash and error reports: device model, OS, app version, the screen where the error happened and a coarse location (country/state/city) derived from the IP address at ingestion. The IP address itself is not stored.Our crash‑reporting provider
CommunicationsEmails and SMS we send you (verification codes), and messages you send to supportYou; our delivery providers
WebsiteThe email address you give to join the waiting list, and your language choice (stored only in your browser). The website uses no advertising or analytics cookies.You

We do not collect full card numbers (only the last four digits you enter to identify a card), bank credentials (you enter them in the aggregator's secure widget, never in our app), biometric templates (Face ID / fingerprint stays on your device) or precise location outside mileage tracking.

2. How we use information

We do not use your financial or credit information to build advertising profiles, to sell you third‑party products or to train third‑party AI models.

Automated processing

Estimates, deduction totals, debt plans, alerts and the ordering of educational content and offers are computed automatically from the data in your account. None of this produces a decision with legal or similarly significant effects on you (we do not approve or deny anything), and you can always see the inputs behind a figure. If we introduce assistants based on artificial intelligence, they will run under this same policy: your data will not be used to train models available to third parties, and we will tell you before any such feature processes your information.

3. Credit reports (Fair Credit Reporting Act)

When you ask to see your credit score in the app, you give us written instruction under FCRA §604(a)(2) to obtain your consumer report from a consumer reporting agency, solely to display it to you inside the app and to refresh it periodically while your authorization remains active. We record the exact text you accepted, its version, the language, the date, your IP address and device. The request is a soft inquiry and does not affect your score; we will never make a hard inquiry without a separate, explicit authorization for a specific purpose. You can withdraw the authorization at any time from the app or by email; withdrawal stops future requests but does not undo those already made. We do not use your report for marketing, for pre‑screened offers or to make any decision about you. If you believe information in your report is inaccurate, you have the right to dispute it directly with the credit bureau; the app tells you which bureau supplied the data.

4. SMS and mobile information

We use your phone number exclusively to send one‑time verification codes that you request from within the app. Consent is collected when you enter your number, check the consent box and tap "Send code". Message frequency is typically 1 message per sign‑in; message and data rates may apply. Reply STOP to opt out and HELP for help. Codes expire after 10 minutes. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text‑messaging originator opt‑in data and consent will not be shared with any third parties, except for the service providers strictly necessary to deliver the messages. See also our SMS consent page.

5. How we share information

We share personal information only in these cases:

We do not sell personal information and we do not share it for cross‑context behavioral advertising. We disclose nonpublic personal information to nonaffiliated third parties only under the exceptions in GLBA §502(e) (15 U.S.C. §6802(e)) and Regulation P, 12 CFR §§1016.13–1016.15 (service providers, legal requirements and similar), so there is no GLBA opt‑out right to exercise. Because our sharing stays within those exceptions and this notice is always available here, we do not mail annual copies of it (15 U.S.C. §6803(f)); we will notify you in the app if our practices change.

6. Retention

DataHow long
Date of birthWhile your account is active, encrypted; deleted with the account.
Full SSNDeleted as soon as the credit request completes. If you turn on periodic score updates and the credit bureau requires your SSN for each update, we keep it encrypted only while updates are on, and delete it within 7 days after you turn them off (or after 90 days without a successful update). The last four digits are kept, encrypted, while your account is active.
Full credit report dataWe do not store the full report by default — only your score, score factors and account summaries, which stay in your history while your account is active. If a bureau reseller requires us to keep the delivered report for dispute handling, we keep it encrypted for no more than 30 days.
Credit authorizations and inquiry records5 years after the last related request, in a restricted archive, so we can show that each report was requested with your authorization (FCRA).
Verification codes10 minutes, stored only as a hash.
Bank connection tokensUntil you disconnect the account or delete yours; we then revoke the token at the aggregator.
Security and access audit logs3 years.
Crash reports90 days.
Inactive accountsIf you do not sign in for 23 months we email you; at 24 months the account is closed and treated like a deletion request below (GLBA Safeguards Rule).
Encrypted backups35 days. When you delete your account we remove your data from our live systems right away; copies inside encrypted backups are destroyed automatically within 35 days and are not restored.

7. How we protect your information

No system is perfectly secure. If a breach affects your unencrypted personal information we will notify you and the relevant authorities as required by applicable state and federal law, without unreasonable delay.

8. Your rights and choices

To exercise a right, use the app or email support@boosteate.app from the address on your account. We verify requests using your account sign‑in and respond within 45 days (extendable once by 45 days where the law allows). An authorized agent may submit a request for you with your signed written permission (or a power of attorney); we may also ask you to confirm the request directly with us.

State‑specific notices

California (CCPA/CPRA): most of the information we process is covered by GLBA and exempt from the CCPA, but you have the right to know, delete and correct any other personal information, and the right to opt out of sale or sharing — which we do not do. We have not sold or shared personal information in the preceding 12 months, and we honor the Global Privacy Control browser signal as an opt‑out. We use sensitive personal information (SSN, financial account data, precise location) only for the purposes permitted by Cal. Code Regs. tit. 11 §7027(m) — providing the Service you requested and protecting its security — so no "Limit the Use of My Sensitive Personal Information" choice is required. Under California's "Shine the Light" law (Civ. Code §1798.83) you may ask once a year whether we disclosed personal information to third parties for their direct marketing; we do not. Nevada: we do not sell covered information. Virginia, Colorado, Connecticut, Texas, Oregon and other states with comprehensive privacy laws: you may appeal a decision on your request by replying to our response; we will answer within the period your state's law requires (45 to 60 days) and tell you how to contact your attorney general if you disagree. Massachusetts and New York residents: we maintain a written information‑security program consistent with 201 CMR 17.00 and the SHIELD Act.

9. Children

The Service is intended for adults. It is not directed to anyone under 18 and we do not knowingly collect information from children under 13. If you believe a child has provided us data, contact us and we will delete it.

10. Where data is processed

Our servers and service providers are located in the United States. If you use the Service from elsewhere, your information will be transferred to and processed in the United States.

11. Third‑party services

Sign‑in with Google or Apple, banking aggregators and credit bureaus are governed by their own privacy policies. The app shows the aggregator's end‑user policy before you connect an account.

12. Changes and contact

We may update this policy. Material changes will be announced in the app before they take effect, and the date above will change. Questions, requests and complaints: support@boosteate.app.