Privacy Policy
Last updated: 2026-08-27
Who we are
FinChatly ("we", "us") provides a mobile app that lets you ask natural-language questions about your own bank transactions. Contact: support@finchatly.com.
What we collect
- Identity: when you sign in with Apple or Google, we store the stable identifier the provider gives us for your account (for Google, this includes the email address associated with the account; we do not store your Apple ID email or either provider's password).
- Bank transaction and account data: with your explicit consent via Plaid Link, we connect read-only to your bank account through Plaid and store a minimal subset of your transactions — date, amount, merchant, and category — plus each linked account's name, type, and current/available balances so the assistant can answer what you have on hand. We do not request or store account or routing numbers, or the ability to move money. We cannot initiate transfers or payments; the connection is read-only.
- Chat messages: the questions you ask and the assistant's replies, so you can see your conversation history.
How we use it
- Bank transaction data, account balances, and chat history are sent to a third-party AI provider that powers the chat assistant, solely to generate answers to your questions. That provider's own privacy policy governs how they handle API data.
- We do not sell your data or use it for advertising.
- We do not use your data to train AI models.
Where it's stored
- Transaction and chat data live in a cloud database, encrypted at rest, accessible only by our backend.
- Your Plaid access token is stored on the server in our database (encrypted at rest), never on your device. AI provider API keys live only in backend server environment variables.
Third parties we share data with
- Plaid — to connect to your bank and retrieve transactions. Plaid's own handling of your data is governed by Plaid's End User Privacy Policy.
- AI provider — to generate chat answers from your questions and transaction data, per "How we use it" above.
- Cloud infrastructure providers — to host our database and application.
- Apple — for Sign in with Apple.
- Google — for Sign in with Google.
We do not share your data with any other third party, and we do not sell it.
Your controls
- You can delete your account at any time from within the app. This removes your Plaid bank connection and permanently deletes your stored transactions and chat history from our database.
- You can revoke FinChatly's access to your bank at any time through your bank or through Plaid, independent of deleting your FinChatly account.
Data retention
We retain your data for as long as your account is active. Deleting your account deletes your data; see "Your controls" above.
Security
- All data in transit is encrypted (HTTPS/TLS).
- All data at rest is encrypted (Supabase's infrastructure-level encryption).
- We follow the principle of least privilege: our Plaid access is limited to read-only transaction data, and we store the minimum transaction fields needed to answer your questions.
- Because FinChatly connects to your bank account through a data aggregator (Plaid), aspects of the Gramm-Leach-Bliley Act's Safeguards Rule may apply to how we're required to protect your data. We've designed our security practices — encryption in transit and at rest, least-privilege access, minimal data retention — with that in mind.
Data breach notification
If we become aware of a security breach affecting your personal information, we will notify affected users without unreasonable delay, consistent with applicable law.
Children's privacy
FinChatly is not directed at children under 13 (or the relevant age of digital consent in your jurisdiction), and we do not knowingly collect data from them.
Changes to this policy
We'll update the "Last updated" date above when this policy changes, and notify you with an in-app notice when a change is material.
Contact
Questions about this policy: support@finchatly.com.