This Privacy Policy explains how Cashly ("Cashly", "we", "us") collects, uses, shares, retains, and protects information when you use the Cashly mobile and web application (the "Service"). By using Cashly you agree to the practices described here.
1. Information we collect
- Account information you provide directly: name, email address, password hash, and optional profile details.
- Financial data retrieved from your financial institutions through Plaid: account names and masks, balances, transaction history, and institution metadata.
- User-generated content: budgets, savings goals, bills, debts, notes, and chats with our AI coach.
- Device and usage data: IP address, device type, browser, pages viewed, and diagnostic events used to keep the Service reliable and secure.
2. How we use Plaid data
- Your bank credentials are entered in Plaid's interface and are never seen or stored by Cashly.
- Plaid returns read-only tokens that allow Cashly to fetch balances and transactions on your behalf. These access tokens are stored encrypted at rest on our servers and are never exposed to the browser or any third party.
- We use Plaid data solely to power features you have requested — dashboards, budgeting, cash-flow insights, alerts, and AI coaching. We do not sell financial data and do not use it for advertising.
- You can disconnect an institution at any time from Profile → Connected bank accounts. Disconnecting revokes the Plaid access token and stops further syncs.
3. How we protect your information
- All traffic between your device, Cashly, Supabase, and Plaid is encrypted in transit using HTTPS with TLS 1.2 or higher. HTTP is not accepted in production.
- All data stored in our managed database and object storage is encrypted at rest using AES-256 by our infrastructure providers.
- Row-Level Security is enabled on every table that holds user data. Each row is scoped to the owning user; administrative access uses separate, audited service credentials.
- Plaid access tokens and third-party API keys are stored as managed secrets and are only readable from server-side code. They never leave the server and are never included in responses to the browser.
- We enforce strong password requirements, offer multi-factor authentication (TOTP and email OTP), and require re-authentication before destructive actions such as account deletion.
- Dependencies are monitored for known vulnerabilities and updated on a regular cadence.
4. AI features and third-party AI processing
Who processes the data
Cashly's AI features (AI Insights, AI Coach report and chat, and "Can I buy this?") are powered by OpenAI, a third-party AI provider. Cashly reaches OpenAI's models through the Lovable AI Gateway, which forwards the request on Cashly's behalf. OpenAI is not owned or operated by Cashly.
Permission is required first
No personal or financial information is sent to OpenAI until you affirmatively tap “Allow Cashly AI” on the Cashly AI Data Sharing screen. Consent is never pre-selected. If you choose “Not Now”, AI features stay switched off and the rest of Cashly — dashboards, budgets, bills, goals, transactions, and bank syncing — continues to work normally. You can review or change this permission at any time in Profile → Privacy & security → Cashly AI data sharing. Turning it off stops further AI requests.
What may be sent
- Transaction descriptions, merchant names, dates, and amounts
- Spending categories and category totals
- Budgets and budget limits
- Savings goals and progress
- Recurring bill and subscription information
- Account balances and cash-flow figures used by the feature you opened
- Your coaching preferences and anything you type into the AI Coach or “Can I buy this?”
Why it is sent
Only to generate the personalized insight, report, chat answer, or purchase recommendation you requested. AI features are not used for advertising, and we do not sell your data.
Limits
Your bank login credentials are never sent to the AI provider. OpenAI's handling of the data it receives is governed by its own terms and privacy policy. AI outputs are educational insights, not financial, investment, tax, or legal advice, and may contain errors — you are responsible for decisions you make. Please do not type information into the AI Coach that you would not want processed by an AI system.
5. Push notifications and email
6. Device, analytics, and crash data
7. How we share information
- Plaid — connecting your financial institutions and syncing balances and transactions.
- Supabase — managed authentication, database, storage, and edge runtime that hosts the Service.
- Lovable Cloud — application hosting and AI Gateway routing.
- OpenAI — model provider for AI Coach responses and AI-generated insights, under a zero-retention, no-training data-processing agreement.
- Stripe — subscription billing for Cashly Gold. Card details are entered in Stripe and never touch Cashly servers.
- Apple App Store / Google Play — where subscriptions are purchased in-app, the applicable store processes the transaction and shares limited receipt and status data with us for entitlement.
- Email delivery provider — sending transactional and notification email.
- Google (OAuth) — optional sign-in; we receive your name, email, and avatar only.
- Law-enforcement or regulatory authorities where legally required, and only to the extent required.
8. Data retention and deletion
Cashly retains user data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed for these purposes, it is deleted or de-identified.
What we retain and for how long
- Account identity (profile, email, name, avatar) — retained while your account is active, then deleted within 30 days of account deletion.
- Financial data (budgets, savings goals, bills, debts, monthly plans, manual transactions) — retained while your account is active, deleted within 30 days of account deletion.
- Bank data from Plaid (accounts, up to 24 months of transactions, balances) — retained while the bank connection is active; deleted when you disconnect the bank or delete your account. Plaid access tokens are revoked and deleted immediately on disconnect.
- Security and audit logs (sign-ins, MFA events, bank-link events, administrator actions) — retained for up to 12 months (security events) or up to 3 years (admin audit log) to support incident response, fraud investigation, and regulatory compliance.
- Application error logs — retained for 90 days for debugging, then deleted.
- Support requests — retained for 2 years after resolution.
- Encrypted database backups — retained for 30 days on a rolling schedule; deleted data ages out of backups on the same schedule.
- Consent records (timestamp and version of Terms and Privacy Policy you accepted) — retained for the life of the account plus 12 months as evidence of consent.
- Aggregated or de-identified data that cannot reasonably be linked back to you may be retained longer for product analytics.
Why we retain it
To operate features you rely on, secure your account, meet audit obligations, protect against fraud, and comply with tax, anti-money-laundering, and other applicable laws.
How to request deletion
You may delete your Cashly account at any time from Profile → Danger zone → Delete account. You can also file a request from Profile → Danger zone → Request deletion, which places your account in read-only pending-deletion state until an administrator processes it. You may also email privacy@mycashlyapp.com to request deletion; we honour verified requests within 30 days.
When your account is deleted, Cashly:
- Revokes and deletes all Plaid access tokens and disconnects linked banks.
- Deletes your profile, budgets, goals, bills, debts, monthly plans, transactions, and chat history from our production database.
- Signs you out on every device and cancels active subscriptions at period end.
- Ages out the same data from encrypted backups on the normal 30-day rotation.
Data we may need to retain
We may retain limited information after deletion where legally required — for example, records needed for tax reporting, anti-fraud investigations, response to a lawful subpoena, or defence of legal claims. Retained data is minimized to what the obligation requires and remains protected by the same access controls.