Draft — not yet reviewed by a lawyer
This describes what the app actually collects and does with your data today, written so there’s something honest here rather than nothing. It has not been reviewed by legal counsel and should not be treated as a binding privacy notice until it has been.
Privacy Policy
Last updated: see the app’s commit history.
What we collect
- Account info you provide directly: name, email, password (stored hashed, never in plain text).
- Financial data from banks you connect via Plaid: account balances, types, and transaction history. We store an encrypted Plaid access token, never your bank login credentials.
- Anything you type into the “Ask AI” chat, and the assistant’s replies.
- Basic activity logs (login, password changes, entity access grants/revocations, data exports) for security and troubleshooting.
- Your theme preference and other lightweight app settings.
How we use it
To show you your own financial picture, detect recurring charges, track budgets and goals, and answer questions you ask the AI assistant. We don’t sell your data, and don’t use it for advertising.
Third parties we share data with
Only the services required to provide the features you use:
- Plaid — to connect and sync your bank accounts. See Plaid’s own privacy policy.
- Anthropic— to power the “Ask AI” chat feature. A summary of your accessible accounts/budgets/recent transactions, plus your message, is sent to generate a response.
- Twilio— to deliver SMS codes if you enable SMS-based two-factor verification.
Sharing within your household
If you belong to a household or have been granted access to an entity, the accounts, transactions, and budgets scoped to that entity are visible to everyone else with active access to it. This is a feature of the product (shared household finances), not a third-party data share — see the Terms of Service for who controls that access.
Data export and deletion
You can export everything you have access to as JSON or CSV from Settings > Data & Privacy at any time. Account deletion isn’t self-serve yet — contact your app administrator to request it.
Security
Passwords are hashed, never stored in plain text. Bank access tokens are encrypted at rest. Two-factor verification (authenticator app or SMS) is available and recommended. Repeated failed logins lock the account temporarily. This app is under active development and, like any software, cannot guarantee perfect security.
Children’s privacy
This service isn’t directed at children and isn’t knowingly used to collect data from anyone under 18.
Changes
This policy may change as the app changes. Material changes will be reflected here.
Contact
Questions about this policy, or requests regarding your data, go to your app administrator.