On this page (21 sections)
- Plain-English summary
- 1. Who we are and what this Policy covers
- 2. Key roles and definitions
- 3. Product overview: how GuardRail works
- 4. Age rules and the Minor Family Feature
- 5. Personal information we collect and where it comes from
- 6. How we use personal information
- 7. Risk Scores, warning signals, and automated analysis
- 8. What Accountability Partners receive - and do not receive
- 9. Notifications and communication settings
- 10. How we disclose personal information
- 11. Sale, advertising, and AI restrictions
- 12. Monitoring controls, disconnection, and deletion
- 13. Data retention
- 14. Security and incident response
- 15. Privacy rights, corrections, and requests
- 16. Cookies and limited product analytics
- 17. U.S. processing and cross-border access
- 18. Changes to this Policy
- 19. Contact us
- Appendix A. Notice at Collection
Plain-English summary
GuardRail is a financial-accountability and early-warning service for Members age 18 or older and for families with Minor Participants ages 13 through 17. In the standard adult flow, a Member age 18 or older creates a GuardRail account, completes Quiltt Link for an eligible financial account, selects the financial activity GuardRail may analyze, and then invites an Accountability Partner, who accepts the invitation. In the Minor Family Feature, a parent or legal guardian serves as the Accountability Partner, the Minor Participant receives a separate notice and agrees to participate, and the Accountability Partner completes Quiltt Link for an eligible financial account or card account jointly owned by the parent or legal guardian and the Minor Participant. GuardRail provides Risk Information according to each participant's role and permissions.
What GuardRail receives
Read-only account and transaction information from selected financial accounts connected through Quiltt (a data-access provider running on Finicity, a Mastercard company), plus account, consent, device, and notification information needed to operate the Service. This may include up to 12 months of available transaction activity from before the connection date.
What GuardRail creates
A Risk Score from 0 to 100, a Green, Yellow, or Red Risk Status, trends, warning flags, explanations of meaningful changes, weekly summaries, qualifying alerts, and monitoring-status information. When history is available, GuardRail may also create an initial baseline and historical assessment.
What GuardRail receives
Read-only account and transaction information from selected financial accounts connected through Quiltt, plus account, consent, device, and notification information needed to operate the Service. This may include up to 12 months of available transaction activity from before the connection date.
What GuardRail creates
A Risk Score from 0 to 100, a Green, Yellow, or Red Risk Status, trends, warning flags, explanations of meaningful changes, weekly summaries, qualifying alerts, and monitoring-status information. When history is available, GuardRail may also create an initial baseline and historical assessment.
What a partner receives
Enough information to understand meaningful risk changes and start a conversation - not a complete bank feed. GuardRail may display limited details only for transactions on the connected card that it classifies as possible gambling-related purchases. Those details may include the merchant or app, amount, date, and time when available. Ordinary or unrelated transaction details are not displayed.
What GuardRail cannot do
GuardRail cannot see bank passwords, move money, block transactions, freeze accounts, diagnose gambling addiction, or guarantee that all gambling activity will be detected.
How Members age 18 or older participate
A Member creates a GuardRail account, confirms that they are at least 18, accepts the Terms and Privacy Policy, and completes Quiltt Link for an eligible account they own or are legally authorized to connect. The Member then invites an Accountability Partner, who must also be at least 18 and accepts the invitation and applicable notices. Nothing is shared until the Member chooses to invite someone.
How minors participate
A person age 13 through 17 participates through a parent or legal guardian who serves as the Accountability Partner. The Accountability Partner starts the Family Account and completes Quiltt Link for an eligible financial account or card account jointly owned with the Minor Participant; the Minor Participant receives a separate plain- language notice and must agree before monitoring begins. The notice may be completed through the app, a secure web page, a one-time code, or a shared-device flow. A personal email address or mobile number is not required.
Core privacy promise
GuardRail does not sell personal information, use linked financial data or Risk Information for targeted advertising, or use raw financial data to train general-purpose AI models.
Important limitation
Risk Scores and alerts are estimates based on the data GuardRail receives. They may be delayed, incomplete, misclassified, or wrong. A Green status does not prove that no gambling occurred. A Red status does not prove that a person has a gambling disorder.
1. Who we are and what this Policy covers
This Privacy Policy explains how GuardRail ("GuardRail," "we," "us," or "our") collects, receives, derives, uses, discloses, retains, and protects personal information through the GuardRail mobile application, website, secure invitation and consent pages, dashboards, alerts, reports, and related services (collectively, the "Service"). GuardRail is currently operated jointly by Jake Capps and Simon Capps. When GuardRail forms a legal entity, this Policy will be updated to identify that entity and its contact information. This Policy applies to Members age 18 or older, Minor Participants ages 13 through 17 who participate through the Minor Family Feature, Accountability Partners, parents and legal guardians, people who visit GuardRail websites, and people who contact GuardRail for support or privacy requests.
GuardRail is a financial-accountability and early-warning service focused on transaction-based indicators of gambling-related financial risk. GuardRail is not a bank, money transmitter, payment processor, gambling operator, lender, credit-reporting agency, financial adviser, healthcare provider, treatment provider, emergency- monitoring service, or substitute for professional care.
2. Key roles and definitions
Term Meaning Member A person age 18 or older whose selected financial activity GuardRail analyzes to create Risk Information. The Member accepts an invitation from an Accountability Partner and completes Quiltt Link for an eligible account the Member owns or is legally authorized to connect. Accountability Partner A person age 18 or older who creates a GuardRail account, initiates the relationship, and is authorized to receive the limited Risk Information described in this Policy after the Member accepts. In the Minor Family Feature, the enrolling parent or legal guardian serves as the Accountability Partner and completes Quiltt Link only for an eligible financial account or card account jointly owned with the Minor Participant. Minor Participant A person who is at least 13 but younger than 18 and participates through GuardRail's parent- or legal-guardian-led Minor Family Feature. Family Account The GuardRail relationship connecting a Minor Participant with the parent or legal guardian serving as the Accountability Partner. Risk Information The Risk Score, Green/Yellow/Red Risk Status, trend, score change, warning flags, general explanations, weekly summaries, qualifying alerts, selected supporting details, and monitoring- status information generated by GuardRail.
3. Product overview: how GuardRail works
GuardRail offers two onboarding paths. In the standard adult flow, a Member age 18 or older connects the eligible financial account first and then initiates the relationship by inviting an Accountability Partner, who accepts. Minor Participants ages 13 through 17 use the parent- or legal-guardian-led Minor Family Feature. Both paths are designed to help identify meaningful changes in financial behavior before those changes become more serious. The Service is built around accountability, not unrestricted financial surveillance.
3.1 Member and Accountability Partner onboarding and use
- The Member creates a GuardRail account, confirms that they are at least 18, and accepts the Terms, Privacy Policy, and applicable information-sharing disclosures.
- The Member completes Quiltt Link for an eligible financial account they own or are legally authorized to connect and selects the account or card activity designated for analysis.
- The Member invites an Accountability Partner to join the GuardRail relationship. Nothing is shared with anyone until the Member does so.
- The Accountability Partner accepts the invitation, creates their own GuardRail account, confirms that they are at least 18, and accepts the Terms and Privacy Policy.
- When available, GuardRail may analyze up to 12 months of transaction activity from before the connection date to establish an initial baseline and identify historical patterns or changes over time. The amount of available history varies by financial institution and account.
- After the eligible connection is active, GuardRail receives read-only information, calculates Risk Information, and provides the Member with the applicable dashboard, alerts, history, and controls. The Accountability Partner receives only the limited Risk Information described in this Policy.
3.2 Minor Family Feature onboarding and use
- The parent or legal guardian creates the Family Account, serves as the Accountability Partner, identifies the Minor Participant, confirms the relationship, and provides the required adult authorization.
- The Minor Participant receives a separate plain-language notice explaining the designated activity, Risk Score, information-sharing rules, limitations, controls, and transition at age 18. The Minor Participant must affirmatively agree before monitoring begins.
- The parent or legal guardian serving as the Accountability Partner completes Quiltt Link only for an eligible financial account or card account jointly owned by the parent or legal guardian and the Minor Participant. The Minor Participant does not complete Quiltt Link or provide financial-institution credentials.
- When available for the eligible connection, GuardRail may analyze up to 12 months of transaction activity from before the connection date to establish an initial baseline and identify historical patterns or changes over time.
- Monitoring begins only after adult authorization, Minor Participant assent, and an eligible financial connection are complete. The Minor Participant and parent or legal guardian then receive the role-based dashboards, alerts, and controls described in this Policy.
3.3 What the dashboard may show
- A current Risk Score from 0 to 100 and a Green, Yellow, or Red Risk Status.
- The change from a previous period, such as "up 7 points from last week."
- Risk history and trend views, including weekly, seven-day, or thirty-day views when available.
- An initial historical assessment showing the period of available pre-connection transaction activity analyzed, when available.
- Warning flags, such as gambling activity detected, repeated peer-to-peer transfers, a new gambling merchant, increasing gambling frequency, late-night activity, ATM activity, or account-balance pressure.
- A plain-language explanation of the main factors that increased, reduced, or stabilized the score.
- Limited details for transactions on the connected card that GuardRail classifies as possible gambling-related purchases, such as the merchant or app, amount, date, time when available, number of qualifying purchases, and total amount. Ordinary or unrelated transaction details are not displayed.
- The connected-account status, monitoring status, last successful data refresh, partner connection status, and the last alert sent.
- General recommended next steps, such as continue monitoring, schedule a conversation, or seek immediate attention. These suggestions are not medical, legal, or financial advice.
3.4 Signals GuardRail may analyze
Signal category Examples Confirmed gambling activity Known or reasonably identified sportsbooks, casinos, fantasy-wagering services, prediction markets or event-contract platforms, sweepstakes casinos, video-game wagering services, and other gambling-related merchants. Gambling intensity Transaction count, amount, frequency, average transaction size, concentration of activity, and multiple transactions within a short period. Escalation and recurrence Increases over time, activity continuing across multiple periods, recurring or repeated gambling-merchant payments, and a new gambling merchant appearing. Merchant and timing patterns Merchant diversity, unusual timing, and late-night activity when available and relevant.
Signal category Examples Peer-to-peer and cash patterns Venmo, Zelle, Cash App, other transfers, ATM withdrawals, cash advances, or repeated recipients when these patterns occur with stronger gambling-related signals. These events are not treated as gambling by themselves. Financial-stress indicators Overdrafts, failed payments, declining balances, large transfers out, or cash advances when the information is enabled and relevant to the disclosed purpose. Monitoring integrity Whether the account is connected, stale, disconnected, requires reauthentication, or no longer has active monitoring.
3.5 Alerts and weekly reports
GuardRail does not promise to notify an Accountability Partner about every transaction. The Service is designed to notify partners when a meaningful threshold, Risk Status change, escalation, or monitoring event occurs.
- Weekly Risk Score summary, when enabled.
- Any change between Green, Yellow, and Red, including improvement from Red to Yellow or Yellow to Green.
- Qualifying confirmed-gambling or material-escalation alerts.
- Monitoring-integrity alerts when monitoring is disabled, a financial connection is disconnected, data becomes stale, reauthentication is required, the GuardRail account is deleted, or monitoring associated with a Minor Participant ends.
- A best-effort app-status notice if a registered app installation appears unable to receive GuardRail notifications. This signal is not guaranteed and does not prove the app was uninstalled. Data timing GuardRail can generate an alert only after it receives and processes updated information. Financial institutions and Quiltt may provide transaction updates on a delay. GuardRail is not a real-time bank feed, and the dashboard should display the last successful refresh time. When historical transaction information is requested, GuardRail may display an analyzing state until the available historical update has been received and processed.
4. Age rules and the Minor Family Feature
4.1 Adults, Minor Participants, and children under 13
Only a person age 18 or older may participate as a Member or Accountability Partner. In the standard adult flow, the Accountability Partner initiates the relationship and the Member completes Quiltt Link. Neither person needs parent or legal guardian authorization or a Minor Participant notice. A person age 13 through 17 may participate only as a Minor Participant through the Minor Family Feature. The parent or legal guardian begins enrollment, while the Minor Participant receives a separate invitation, notice, and assent experience. GuardRail is not available to children under 13, even with parental consent. If GuardRail learns that a child under 13 submitted personal information, GuardRail will stop the registration process and delete the information, except for a minimal record retained when reasonably necessary for security, legal compliance, or documentation of the incident.
4.2 Member and Accountability Partner onboarding
In the standard adult flow, the Member creates a GuardRail account, accepts the applicable Terms, Privacy Policy, and information-sharing disclosures, and completes Quiltt Link for an eligible account the Member owns or is legally authorized to connect. The Member then invites an Accountability Partner, who accepts the invitation, creates their own account, and accepts the Terms and Privacy Policy. Monitoring for the Member begins once the eligible financial connection is active; sharing with an Accountability Partner begins only after the Member has invited them and they have accepted. The Member controls the connected financial account and the available monitoring and account controls. The Accountability Partner receives only the limited Risk Information described in this Policy. The parent- or legal-guardian authorization and separate Minor Participant assent requirements do not apply to this adult flow.
4.3 Parent or legal guardian enrollment
The adult enrolling a Minor Participant must confirm that the adult is the Minor Participant's parent or legal guardian and is authorized to establish the GuardRail relationship. The adult creates the Family Account, accepts the applicable Terms and notices, completes the connection for the eligible financial account or card account jointly owned with the Minor Participant, and serves as the sole Accountability Partner connected to the Minor Participant profile in the initial Minor Family Feature. GuardRail may request additional information when reasonably necessary to confirm the adult's identity, the Minor Participant's age, or the adult's parental or guardianship authority. GuardRail may refuse or suspend enrollment if required information cannot be verified or if the Minor Participant disputes the claimed relationship.
4.4 Separate notice and assent for the Minor Participant
Before GuardRail begins creating Risk Information associated with a Minor Participant, GuardRail provides the Minor Participant with a separate, plain-language notice explaining:
- which financial account or card activity is designated for analysis and which adult connected it;
- what transaction patterns GuardRail analyzes and what the Risk Score means;
- what the parent or legal guardian may receive;
- what the parent or legal guardian will not receive;
- that transaction classification, attribution, and Risk Scores may be incomplete or wrong;
- that available transaction activity from before the GuardRail connection date may be included in the initial analysis;
- how the Minor Participant can stop monitoring associated with the Minor Participant profile;
- that the parent or legal guardian will be notified if monitoring ends;
- how GuardRail will handle the transition after the Minor Participant turns 18. The Minor Participant must affirmatively agree before monitoring associated with the Minor Participant begins. The notice and assent may be completed through the GuardRail app, a secure browser page, a one-time code, or a secure shared-device session. The Minor Participant does not need a personal email address, mobile number, mobile device, or app installation and does not enter financial-institution credentials into GuardRail or Quiltt Link. GuardRail records the notice version, date, time, access method, and assent status.
4.5 Financial account connection for the Minor Family Feature
For the Minor Family Feature, the parent or legal guardian serving as the Accountability Partner completes Quiltt Link and connects only an eligible financial account or card account jointly owned by the parent or legal guardian and the Minor Participant. The Minor Participant does not independently complete Quiltt Link or provide banking credentials. During setup, the adult identifies the account, card, or account activity intended for the Minor Participant. GuardRail analyzes only the selected connection and the data made available by the financial institution and Quiltt.
For an eligible jointly owned financial account or card account used in the Minor Family Feature, GuardRail may analyze up to 12 months of available historical transaction activity from before the connection date, as well as ongoing activity after connection. The amount and completeness of available history vary by financial institution, account, and Quiltt coverage. A transaction record may relate to more than one person. If the institution does not provide a reliable card, subaccount, authorized-user, or similar identifier, GuardRail will not state that a particular shared-account transaction was completed by the Minor Participant. GuardRail may label the activity as shared or account-level activity, reduce the confidence assigned to the signal, or decline to use the activity in a Minor Participant-specific score.
4.6 What a Minor Participant can control
A Minor Participant may use the available GuardRail control or contact GuardRail to stop monitoring associated with the Minor Participant profile. After the request is processed, GuardRail will stop using newly received financial activity to create or share new Risk Information about that Minor Participant. GuardRail will notify the parent or legal guardian that monitoring is no longer active. The Minor Participant cannot use this GuardRail control to disconnect, close, or otherwise control the underlying financial account and cannot independently change the adult sharing relationship. The parent or legal guardian serving as the Accountability Partner may separately disconnect the financial account or delete the Family Account.
4.7 When a Minor Participant turns 18
The GuardRail account does not automatically end on the person's eighteenth birthday. At or shortly after age 18, GuardRail will ask the individual to accept the Terms and Privacy Policy applicable to Members and confirm whether the existing Accountability Partner relationship should continue. GuardRail may provide a reasonable transition period. If the individual does not confirm continued participation, GuardRail will stop creating and sharing new Risk Information about that individual and notify the former Accountability Partner only that monitoring has ended.
5. Personal information we collect and where it comes from
5.1 Information provided by participants
- Identifiers and access details. Name; email address or mobile number if provided; username, login, or authentication information; a separate Minor Participant access identifier or one-time code where used; and optional profile details. A Minor Participant is not required to provide a personal email address or mobile number.
- Age and relationship information. Date of birth or age confirmation, Member, Minor Participant, or Accountability Partner role, parent or legal guardian status, and the GuardRail relationship.
- Onboarding and profile information. GuardRail may ask an Accountability Partner to provide observations, concerns, relationship information, and other context regarding a Member or Minor Participant. GuardRail may separately ask a Member or Minor Participant to provide information about financial habits, gambling-related activity or concerns, personal goals, preferences, and other relevant context. The specific questions may change as GuardRail develops the Service. GuardRail records the source of this information and does not necessarily treat participant-provided information as independently verified.
- Consent and permission records. Invitations, acceptance status, parent authorization, Minor Participant assent, notice and policy versions, timestamps, access method, selected accounts, sharing settings, notification preferences, and changes to those settings.
- Subscription information. Plan, billing status, renewal date, and payment-provider references. GuardRail generally does not store full payment-card details.
- Support and privacy communications. Information provided when contacting GuardRail for technical support, reporting an error, disputing a merchant classification or attribution, making a privacy request, or otherwise communicating with GuardRail.
5.2 Information received through Quiltt and financial institutions
In the standard adult flow, the Member completes Quiltt Link. In the Minor Family Feature, the parent or legal guardian serving as the Accountability Partner completes Quiltt Link. When the applicable person connects a selected financial account through Quiltt, GuardRail may receive:
- financial-institution name, account type, account name, and masked account or card identifiers;
- transaction date, amount, merchant or payee, description, category, transaction identifier, and pending, posted, reversed, or removed status;
- available card, subaccount, account-owner, or authorized-user indicators supplied by the financial institution;
- recurring or repeated transaction information, including recurring gambling-merchant patterns, when available;
- balances, overdraft indicators, cash-advance information, or similar financial-stress data when enabled and relevant;
- connection status, last update time, stale-data status, reauthentication requirements, and disconnection events. Historical transaction information. When an eligible financial account is connected, GuardRail may receive and analyze up to 12 months of available transaction information from before the connection date, along with transaction information received after connection. The amount and completeness of available historical information depend on the financial institution, account, Quiltt coverage, and other factors. GuardRail receives transaction data needed to perform the disclosed analysis, but it does not display ordinary or unrelated transaction details in user-facing dashboards, alerts, or partner views. GuardRail displays limited details only for transactions on the connected card that it classifies as possible gambling-related purchases. Those details may include the merchant or app, amount, date, and time when available. Bank credentials Financial-institution usernames, passwords, one-time passcodes, and similar credentials are entered into Quiltt or the financial institution's authentication flow. GuardRail does not receive or store those credentials. GuardRail also does not need complete account or card numbers to provide the Service.
5.3 Information collected automatically
- Device and network information, such as IP address, device type, operating system, browser, app version, language, and general location derived from IP address.
- Service-use information, such as screens viewed, feature interactions, login events, consent events, account changes, settings changes, and timestamps.
- Security and diagnostic information, such as authentication attempts, error logs, crash data, notification-delivery status, and suspicious activity signals.
- App and notification status information, such as push-notification tokens and whether a registered device appears reachable. This information may support a best-effort app-status notice but cannot reliably prove that an app was uninstalled.
5.4 Information from service providers
GuardRail may receive information from providers that support authentication, hosting, payment processing, communications, customer support, analytics, cybersecurity, fraud prevention, and other operational functions. Providers may use information only to perform their contracted services or as otherwise permitted by law and applicable agreements.
5.5 Data minimization
Version 1 is not designed to collect precise geolocation, contact lists, social-media account content, photographs, calendars, government identification numbers, credit reports, medical records, web-browsing history, or unrelated private financial information. GuardRail will not add a materially different category of information without updating its notices and obtaining additional authorization when required.
6. How we use personal information
GuardRail uses personal information to:
- create and secure accounts, authenticate participants, verify eligibility, and administer Member, Minor Participant, and Accountability Partner relationships;
- present required notices and record Member acceptance, Accountability Partner acceptance, parent or legal guardian authorization, Minor Participant assent, and settings;
- use onboarding and profile information provided by Members, Minor Participants, and Accountability Partners to establish an initial baseline, provide context for transaction analysis, personalize Risk Information, tailor alerts and explanations, and operate the Service;
- connect selected financial accounts through Quiltt and maintain read-only access while monitoring remains active;
- use available historical transaction information to establish an initial financial-risk baseline, identify prior gambling- related patterns, measure escalation or improvement over time, generate initial Risk Information, and compare subsequent activity with available historical activity associated with the Member or Minor Participant;
- classify transactions, identify recurring or escalating patterns, and generate Risk Scores, statuses, trends, warning flags, and explanations;
- provide dashboards, alert history, weekly summaries, Risk Status change notices, qualifying gambling-related purchase alerts, and monitoring-integrity notices;
- show connection status, last refresh time, partner status, and other operational information;
- deliver push notifications, email, SMS, or in-app messages according to settings and operational requirements;
- respond to support requests, investigate disputed classifications or attribution, and correct errors where appropriate;
- detect fraud, protect accounts, investigate misuse, maintain audit records, and secure the Service;
- comply with law, enforce agreements, resolve disputes, and protect the rights and safety of GuardRail, participants, and others;
- improve the Service using information that is aggregated, de-identified, or otherwise processed under strict data- minimization controls.
7. Risk Scores, warning signals, and automated analysis
7.1 How Risk Information is created
The initial GuardRail model is designed to use explainable rules, calculations, merchant classifications, thresholds, and comparisons over time. The exact weighting and scoring formula are proprietary and may be adjusted to improve accuracy, reduce false alerts, or reflect changes in data availability. GuardRail will not materially expand the purpose of the analysis without updating this Policy and providing additional notice when required. The Risk Score is designed to summarize the strength and combination of observed warning signals on a scale from 0 to 100. The score is paired with a color status: Green for lower observed risk signals, Yellow for elevated signals, and Red for stronger or multiple signals. A score can move up or down as activity changes. GuardRail may generate an initial Risk Score and historical assessment using available transaction information from before the financial account was connected. Historical activity may be weighted differently based on its age,
relevance, completeness, and relationship to more recent activity. Older activity may provide context without necessarily indicating the Member's or Minor Participant's current level of risk.
7.2 Confidence levels and corroborating signals
Confidence level How GuardRail treats the information Higher confidence A known or strongly identified gambling merchant or gambling- category transaction. GuardRail displays limited details only when the transaction is classified as a possible gambling-related purchase on the connected card. Those details may include the merchant or app, amount, date, and time when available. Medium confidence A merchant or pattern that appears likely to be relevant based on description, category, enrichment, timing, or repetition. GuardRail should explain uncertainty and avoid stating that the activity is confirmed gambling. Lower confidence Peer-to-peer transfers, ATM withdrawals, cash activity, or balance pressure that may have many legitimate explanations. These signals generally should not be treated as proof of gambling or create a direct alert by themselves.
7.3 Data and scoring limitations
Risk Information may be affected by delayed or missing transactions, pending or reversed charges, incorrect merchant names or categories, shared accounts, cash activity, unconnected accounts, payment-app limitations, financial-institution outages, changes in Quiltt coverage, and changes to GuardRail's methodology. Historical transaction information may cover less than the requested period, may be incomplete, and may be unavailable for some financial institutions or accounts. GuardRail will describe the period of available history analyzed and will not represent that the historical information is complete. GuardRail may miss gambling activity and may incorrectly flag lawful or unrelated activity. GuardRail does not use a Risk Score to make credit, insurance, employment, housing, education-admission, or similar eligibility decisions. GuardRail does not make medical or legal determinations and does not automatically punish, block, or restrict a person based on a score.
8. What Accountability Partners receive - and do not receive
8.1 Information an Accountability Partner may receive
- The current Risk Score and Green, Yellow, or Red Risk Status.
- The change from a previous period and whether the trend is increasing, stable, or improving.
- Meaningful warning categories and a general explanation of why the score changed.
- An optional weekly summary showing the current score, status, trend, major changes, and whether monitoring is active.
- A notification whenever the color status changes in either direction, including improvement.
- A qualifying confirmed-gambling or material-escalation alert.
- A monitoring-integrity notice when monitoring is disabled, the connection is disconnected, data becomes stale, reauthentication is required, the GuardRail account is deleted, or monitoring associated with a Minor Participant ends.
- Limited supporting details for a transaction on the connected card that GuardRail classifies as a possible gambling-related purchase, such as the merchant or app, amount, date, time when available, number of qualifying purchases, total amount, and relevant period.
- For a peer-to-peer, ATM, cash-related, balance, or other lower-confidence pattern, the Accountability Partner may receive only a general warning category and explanation of its effect on the Risk Score. GuardRail does not display the underlying recipient, note, merchant, amount, date, time, or other transaction details unless the transaction itself is classified as a possible gambling-related purchase on the connected card.
- The connection and monitoring status, last successful refresh time, Accountability Partner status, and last alert sent.
8.2 Information an Accountability Partner does not receive
- Financial-institution usernames, passwords, one-time security codes, or similar credentials.
- Full account or card numbers.
- Direct access to the financial institution or the ability to move, freeze, block, reverse, approve, or decline money.
- An unrestricted feed of every transaction, every ordinary merchant, every transfer, every unrelated purchase, or transaction-level details for any ordinary or unrelated purchase.
- A statement that a specific person completed a shared-account transaction when the available data does not reasonably support that conclusion.
- The exact proprietary scoring formula.
- A diagnosis of gambling addiction or a guarantee that the person is or is not gambling.
8.3 Partner responsibilities and previously delivered information
An Accountability Partner must use Risk Information only for the supportive accountability purpose presented in GuardRail, keep the information confidential, and avoid using it to harass, threaten, discriminate against, or unlawfully control the Member or Minor Participant. Removing an Accountability Partner or ending monitoring stops future access after the change is processed. GuardRail cannot necessarily recall information that was already delivered, viewed, copied, photographed, forwarded, or stored outside GuardRail.
9. Notifications and communication settings
Notification When it may be sent Typical contents Weekly Risk Summary Only when the feature is enabled. Score, color status, change from the prior period, trend, meaningful warning categories, monitoring status, and a general recommended next step. Risk Status change When the status moves between Green, Yellow, and Red in either direction. Previous and new status, score change, and general reason for the change. Confirmed gambling or escalation When confirmed gambling activity, a material increase, or multiple warning signals meet GuardRail's threshold. Merchant or app, amount, date, time when available, count, total, relevant period, and general Risk Score impact for qualifying possible gambling-related purchases only. Ordinary or unrelated transaction details are not displayed. Monitoring integrity When monitoring is disabled, disconnected, stale, requires reauthentication, the account is deleted, or the required monitoring relationship ends. The type of monitoring event and the time it was detected or processed. App status Best effort, when a registered device appears unable to receive required GuardRail notifications. A neutral notice that the registered device may no longer be reachable. It does not state that uninstall is proven.
GuardRail may deliver communications through the app, push notifications, email, or SMS. Message timing depends on when GuardRail receives data, processes the event, and successfully delivers the communication. Delivery is not guaranteed. GuardRail should offer a privacy-sensitive notification setting. A private notification may say only that GuardRail has an important update, while detailed merchant or amount information is shown after authentication. Detailed lock-screen notification content should be off by default for Minor Participants. Participants may turn off optional reports and nonessential notifications. GuardRail may continue to send security, consent, account, billing, legal, and monitoring-integrity notices necessary to operate the Service or document that monitoring changed.
10. How we disclose personal information
10.1 Within the authorized GuardRail relationship
GuardRail discloses Risk Information to the Member or Minor Participant and the authorized Accountability Partner only as described in this Policy and the applicable consent flow. GuardRail does not grant an Accountability Partner unrestricted access to the underlying financial account.
10.2 Quiltt and financial institutions
Quiltt and connected financial institutions process information needed to establish and maintain the authorized read-only connection. Their handling of information is governed by their own agreements and privacy notices in addition to GuardRail's agreement with Quiltt.
10.3 Service providers
GuardRail may disclose information to service providers that perform hosting, data storage, authentication, payment processing, communications, customer support, product analytics, security, fraud prevention, and professional services. GuardRail requires providers to protect information and use it only for contracted purposes or as otherwise permitted by law.
10.4 Legal, security, and corporate events
GuardRail may disclose information when reasonably necessary to comply with law, respond to lawful process, investigate fraud or security incidents, enforce agreements, protect rights or safety, or obtain legal, accounting, insurance, or other professional advice. Information may also be transferred in connection with a merger, financing, acquisition, sale of assets, reorganization, bankruptcy, or similar transaction, subject to applicable safeguards and notice requirements.
10.5 Aggregated or de-identified information
GuardRail may use or disclose information that has been aggregated or de-identified so that it no longer reasonably identifies a person. GuardRail will not attempt to re-identify de-identified information except as permitted by law for testing safeguards or security.
11. Sale, advertising, and AI restrictions
- GuardRail does not sell personal information.
- GuardRail does not share personal information for cross-context behavioral advertising or targeted advertising.
- GuardRail does not use linked financial information, Risk Information, or Minor Participant information to target advertisements.
- GuardRail does not disclose linked financial information or Risk Information to data brokers.
- GuardRail does not use raw financial data, Minor Participant information, or Risk Information to train general- purpose artificial-intelligence models.
- GuardRail does not use Risk Information for credit, insurance, employment, housing, education-admission, or similar eligibility decisions.
12. Monitoring controls, disconnection, and deletion
12.1 Member and Accountability Partner controls
In the standard adult flow, the Member may change available monitoring settings, disconnect the selected financial account, or request account deletion. The Accountability Partner may manage their own account, notification settings, and participation in the GuardRail relationship. In the Minor Family Feature, the parent or legal guardian serving as the Accountability Partner may disconnect the selected financial account or delete the Family Account. GuardRail may notify the applicable Accountability Partner when monitoring or sharing is no longer active.
12.2 Minor Participant control
A Minor Participant may stop monitoring associated with the Minor Participant profile as described in Section 4.6. The parent or legal guardian will be notified that monitoring ended. The Minor Participant does not gain control over the underlying financial account through GuardRail.
12.3 Disconnection and reauthentication
Disconnecting the selected financial account stops new data collection after the request is processed. A connection may also stop or become stale because of a financial-institution change, Quiltt control, revoked permission, expired authorization, or required reauthentication. GuardRail may preserve the last Risk Score as historical and mark it as no longer current rather than treating the lack of data as a new gambling-risk finding.
12.4 Deleting the app versus deleting the account
Removing the GuardRail app from a device does not necessarily close the GuardRail account or disconnect Quiltt. If the account and connection remain active, monitoring and permitted alerts may continue. GuardRail provides separate controls to disable monitoring, disconnect the account, and request deletion of the GuardRail account. When an account-deletion request is processed, GuardRail stops new monitoring, ends future partner access, and may notify active Accountability Partners that coverage ended. The deletion request does not necessarily recall information previously delivered outside GuardRail.
12.5 Quiltt and financial-institution controls
The Member in the standard adult flow, or the parent or legal guardian serving as the Accountability Partner in the Minor Family Feature, may also terminate the financial connection through the connected financial institution or available Quiltt privacy controls. GuardRail may retain limited records needed to process the disconnection, document consent, prevent fraud, resolve disputes, or meet legal and contractual obligations.
13. Data retention
Implementation note
The schedule below is the proposed production schedule for risk review. Before publication, GuardRail must confirm that its database, vendors, backups, logs, and deletion workflow can meet these periods. The final public policy must match the actual system.
Information Proposed retention approach Reason Quiltt access tokens While the connection is active and for a short period needed to process disconnection or deletion. Maintain the authorized connection and document its termination. Raw transaction data Generally a rolling period of no more than 12 months while the account is active, unless a shorter period is sufficient or a longer period is required for a specific dispute or legal obligation. Calculate trends, identify recurrence, investigate errors, and provide the approved Service. Risk Scores, trends, alerts, and weekly summaries While the account is active and generally no more than 180 days after closure, unless deletion is requested or a legal exception applies. Maintain history, resolve disputes, and support corrections. Consent, assent, Terms, partner, and security records Up to six years after the relationship ends where reasonably necessary. Demonstrate authorization, protect participants, and meet legal or contractual requirements. Active-system deletion Applicable information deleted or de-identified generally within 30 days after a verified deletion request, subject to legal, fraud, security, dispute, and backup exceptions. Honor deletion while preserving narrowly necessary records. Backups Overwritten or expired under the normal backup cycle, generally within 90 days. Disaster recovery and security. Aggregated or de-identified information May be retained longer when it no longer reasonably identifies a person. Security, product quality, and research without identifying participants.
14. Security and incident response
GuardRail uses administrative, technical, and organizational safeguards designed to protect personal and financial information. No security system can guarantee absolute protection. Before GuardRail accepts live financial data, the production system is intended to include:
- official Quiltt Link for financial authentication and no GuardRail collection of bank passwords;
- encryption in transit and at rest using current industry-standard methods;
- backend-only storage of Quiltt secrets and access tokens, separate from public client code;
- role-based access, least privilege, multifactor authentication for administrative access, and prompt access removal;
- family-level data isolation and authorization checks so one family cannot access another family's data;
- verified webhooks, audit logging, duplicate-event protection, and handling of pending, posted, reversed, and removed transactions;
- security monitoring, vulnerability management, backups, incident response, and documented deletion procedures;
- contractual restrictions on service providers and controls designed to keep raw financial data out of ordinary analytics, logs, support tickets, advertising tools, and general-purpose AI systems;
- no session-replay technology on screens containing linked financial information, Risk Information, or Minor Participant information.
GuardRail maintains an incident-response process to investigate suspected unauthorized access, contain incidents, preserve relevant records, correct vulnerabilities, and notify affected individuals, Quiltt, Finicity, service providers, regulators, or others when required by law or contract. Participants are responsible for protecting their GuardRail credentials, securing their devices, and notifying GuardRail promptly if they suspect unauthorized access.
15. Privacy rights, corrections, and requests
Depending on where a person lives and whether applicable law covers GuardRail, the person may have the right to request information about processing, access personal information, correct inaccurate information, delete information, receive a portable copy, withdraw consent, opt out of certain processing, or appeal a denied request. GuardRail intends to provide reasonable access, correction, deletion, and withdrawal controls even where a particular statutory right does not strictly apply, subject to verification and lawful exceptions.
15.1 Requests by role
- Members may make requests concerning their account, financial connection, Risk Information, and Accountability Partner relationship.
- Minor Participants may request access to information associated with their Minor Participant profile, dispute an attribution or classification, and stop monitoring associated with that profile.
- A parent or legal guardian may make a request on behalf of a Minor Participant, subject to verification and the Minor Participant controls described in this Policy.
- Accountability Partners may make requests concerning their own account, invitation, notification settings, and personal information, but do not receive unrestricted access to the Member's or Minor Participant's underlying financial data.
15.2 Merchant classification and attribution corrections
A participant may report that a merchant was incorrectly classified, that a transaction was attributed to the wrong person, or that information displayed by GuardRail is inaccurate. GuardRail may review the available source information, update the classification or attribution where appropriate, and reflect the correction in future scoring when technically possible. If a material prior alert was incorrect, GuardRail may notify the affected Accountability Partner that the information was corrected.
15.3 Verification, agents, and appeals
GuardRail may verify email or mobile number where available, login or separate access credentials, identity, age, relationship, account authority, or other information before acting on a request. Where required by law, GuardRail may accept requests from authorized agents with written proof of authority and may separately verify the affected person. GuardRail will not unlawfully discriminate against a person for exercising an applicable privacy right. Requests may be submitted through available privacy controls or to [PRIVACY EMAIL]. GuardRail may deny or limit a request where permitted by law, including when information is needed for security, fraud prevention, dispute resolution, legal compliance, or protection of another person's rights. A person may appeal a denied request by replying to the decision or contacting the Privacy address below.
16. Cookies and limited product analytics
GuardRail may use first-party cookies, mobile software-development kits, and similar technologies necessary for authentication, session continuity, security, preferences, error detection, notification delivery, and limited product analytics.
GuardRail does not use linked financial data, Risk Information, or Minor Participant information for advertising analytics. Analytics should be configured to avoid collecting raw transaction descriptions, merchant details, masked bank identifiers, or privacy-request content. GuardRail does not use session replay on pages or screens containing linked financial information or Risk Information.
17. U.S. processing and cross-border access
GuardRail is operated from the United States. GuardRail and its service providers may process information in the United States and other locations where providers operate, subject to contractual, security, and legal safeguards. Information may be subject to lawful access by courts, regulators, or law-enforcement authorities in those jurisdictions.
18. Changes to this Policy
GuardRail may update this Policy as the Service, law, or GuardRail's approved use of Quiltt changes. GuardRail will update the effective date and provide additional notice through email, the app, or the website when a change is material. GuardRail will request renewed authorization or assent when required, including before materially expanding the categories of information associated with a Minor Participant or the information shared with an Accountability Partner.
19. Contact us
Privacy questions and requests may be directed to: GuardRail Privacy [PRIVACY EMAIL] GuardRail Support [SUPPORT EMAIL] Mailing address [MAILING ADDRESS] Website [WEBSITE URL]
Appendix A. Notice at Collection
This summary is designed to make GuardRail's collection and disclosure practices easier to review. It does not replace the full Policy. Context Information Purpose Recipients Proposed retention Member and Accountability Partner onboarding Names, contact details, age confirmations, roles, authentication, subscription, invitation, acceptance, consent records, and onboarding or profile information such as observations, concerns, financial habits, gambling- related concerns, goals, and preferences. Create and secure the Accountability Partner and Member accounts; verify eligibility; administer the invitation, acceptance, and information-sharing relationship; establish an initial baseline; personalize analysis; provide the Service. Authentication, hosting, payment, communications, security, and support providers. Account life plus applicable legal, security, and consent-record periods. Minor invitation and assent Minor Participant name, age confirmation, relationship, contact information if provided, shared-device or separate access credential where used, notice, assent, monitoring status, and onboarding observations or concerns regarding the Minor Participant. Provide the separate notice; record assent; administer the Minor Family Feature; provide separate access; establish an initial baseline; personalize analysis; honor a request to stop monitoring. Parent or legal guardian, GuardRail processors, and service providers only as described. Account life; shorter for operational data; longer for consent and compliance records. Quiltt connection Account metadata, masked identifiers, transactions, merchant data, recurring activity, balances where enabled, and connection status. Transactions may include up to 12 months of available activity from before the connection date. Read-only monitoring; classification; trend, Risk Score, dashboard, and alert generation; historical and ongoing transaction analysis; establishment of an initial baseline. Quiltt, financial institutions, hosting/security providers, and authorized GuardRail participants as described. Proposed rolling 12 months for raw transactions while active; see Section 13. Risk analysis Derived score, color status, score change, trend, warning flags, explanations, alerts, summaries, and monitoring state. Provide accountability dashboards, weekly reports, status changes, and qualifying alerts. Provide an initial historical assessment when sufficient history is available. Member or Minor Participant and authorized Accountability Partner; contracted processors. While active and generally up to 180 days after closure; see Section 13. Support and privacy requests Messages, identity- verification information, disputed classifications, corrections, and diagnostic data. Support, correct errors, respond to privacy requests, and resolve disputes. Support, hosting, security, and professional advisers as needed. As needed to resolve the request and meet legal or security obligations. Website and app use IP address, device/browser/app information, authentication events, settings, notification delivery, security events, and limited analytics. Authentication, security, diagnostics, notification delivery, and limited product improvement. Hosting, authentication, communications, analytics, and security providers. Short operational periods unless needed for security, fraud, or legal records.
No sale or targeted advertising
GuardRail does not sell personal information or use linked financial information, Risk Information, or Minor Participant information for targeted advertising. GuardRail does not use raw financial data to train general- purpose AI models.
Back to top