---
title: "Financier privacy policy"
description: "What Financier collects, why, who processes it, how long it is kept, and how to delete it. Plain language, no data sales."
canonical: https://financier.sh/privacy
updated: 2026-09-22
---

# Financier privacy policy

What Financier collects, why, who processes it, how long it is kept, and how to delete it. Plain language, no data sales.

## What we collect

| | |
| --- | --- |
| Account | Email, name, and a password hash (or your Google identity if you use it). |
| Bank data | Through Plaid: institution names, account names and masks, balances, and transactions for up to two years. |
| Your answers | Merchant categories you choose and the decisions you make on plan actions. |
| Technical | A session cookie, and request logs kept for security and debugging. |

## Why

Only to build and show your plan, keep your connections working, and secure the service. No advertising, no profiling for third parties, no data sales.

## Who processes it

| | |
| --- | --- |
| Plaid | Connects to your bank and returns account and transaction data. Read-only. |
| Railway | Hosts the application and database in the United States. |
| Cloudflare | DNS for financier.sh. |

## Security

- Bank access tokens are encrypted at rest with AES-256-GCM.
- All traffic is HTTPS.
- API keys and OAuth clients are scoped to your account and revocable at any time.

## Retention and deletion

Data is kept while your account exists. Settings, Delete everything revokes every bank connection at Plaid and deletes your account, connections, transactions, rules, decisions and plans immediately.

## Your rights and contact

Ask for a copy of your data, a correction, or deletion at support@financier.sh. Last updated 2026-09-22.
