Skip to main content

Privacy Policy

Last updated August 22, 2026

This Privacy Policy explains how Cashly ("Cashly", "we", "us") collects, uses, shares, retains, and protects information when you use the Cashly mobile and web application (the "Service"). By using Cashly you agree to the practices described here.

1. Information we collect

  • Account information you provide directly: name, email address, password hash, and optional profile details.
  • Financial data retrieved from your financial institutions through Plaid: account names and masks, balances, transaction history, and institution metadata.
  • User-generated content: budgets, savings goals, bills, debts, notes, and chats with our AI coach.
  • Device and usage data: IP address, device type, browser, pages viewed, and diagnostic events used to keep the Service reliable and secure.

2. How we use Plaid data

Cashly uses Plaid to securely connect to your financial institutions. When you link an account:
  • Your bank credentials are entered in Plaid's interface and are never seen or stored by Cashly.
  • Plaid returns read-only tokens that allow Cashly to fetch balances and transactions on your behalf. These access tokens are stored encrypted at rest on our servers and are never exposed to the browser or any third party.
  • We use Plaid data solely to power features you have requested — dashboards, budgeting, cash-flow insights, alerts, and AI coaching. We do not sell financial data and do not use it for advertising.
  • You can disconnect an institution at any time from Profile → Connected bank accounts. Disconnecting revokes the Plaid access token and stops further syncs.

3. How we protect your information

  • All traffic between your device, Cashly, Supabase, and Plaid is encrypted in transit using HTTPS with TLS 1.2 or higher. HTTP is not accepted in production.
  • All data stored in our managed database and object storage is encrypted at rest using AES-256 by our infrastructure providers.
  • Row-Level Security is enabled on every table that holds user data. Each row is scoped to the owning user; administrative access uses separate, audited service credentials.
  • Plaid access tokens and third-party API keys are stored as managed secrets and are only readable from server-side code. They never leave the server and are never included in responses to the browser.
  • We enforce strong password requirements, offer multi-factor authentication (TOTP and email OTP), and require re-authentication before destructive actions such as account deletion.
  • Dependencies are monitored for known vulnerabilities and updated on a regular cadence.

4. AI features and third-party AI processing

Who processes the data

Cashly's AI features (AI Insights, AI Coach report and chat, and "Can I buy this?") are powered by OpenAI, a third-party AI provider. Cashly reaches OpenAI's models through the Lovable AI Gateway, which forwards the request on Cashly's behalf. OpenAI is not owned or operated by Cashly.

Permission is required first

No personal or financial information is sent to OpenAI until you affirmatively tap “Allow Cashly AI” on the Cashly AI Data Sharing screen. Consent is never pre-selected. If you choose “Not Now”, AI features stay switched off and the rest of Cashly — dashboards, budgets, bills, goals, transactions, and bank syncing — continues to work normally. You can review or change this permission at any time in Profile → Privacy & security → Cashly AI data sharing. Turning it off stops further AI requests.

What may be sent

  • Transaction descriptions, merchant names, dates, and amounts
  • Spending categories and category totals
  • Budgets and budget limits
  • Savings goals and progress
  • Recurring bill and subscription information
  • Account balances and cash-flow figures used by the feature you opened
  • Your coaching preferences and anything you type into the AI Coach or “Can I buy this?”

Why it is sent

Only to generate the personalized insight, report, chat answer, or purchase recommendation you requested. AI features are not used for advertising, and we do not sell your data.

Limits

Your bank login credentials are never sent to the AI provider. OpenAI's handling of the data it receives is governed by its own terms and privacy policy. AI outputs are educational insights, not financial, investment, tax, or legal advice, and may contain errors — you are responsible for decisions you make. Please do not type information into the AI Coach that you would not want processed by an AI system.

5. Push notifications and email

With your permission, Cashly sends push notifications for bill reminders, budget alerts, low-balance warnings, sync issues, and security events (new sign-in, MFA changes). You can turn categories on or off from Profile → Notifications, or revoke system permission entirely. Transactional emails (password resets, MFA codes, receipts, security alerts, account-deletion confirmations) are required for account security and cannot be turned off while your account is active. Every non-transactional email includes an unsubscribe link.

6. Device, analytics, and crash data

To keep Cashly reliable we collect a limited set of technical data: device type, operating system, app version, browser, IP address, coarse location derived from IP, and diagnostic events describing how features are used (for example, "opened Budget", "connected bank via Plaid"). We also collect crash reports and application error logs — including a stack trace and the URL where the error occurred — so we can diagnose bugs. Analytics and crash data are keyed to your account only where necessary and are never sold, never shared with advertisers, and never used for advertising profiling.

7. How we share information

We do not sell personal information and do not share it with advertisers. We share data only with service providers we rely on to operate the Service, under contract, and only for the purposes below:
  • Plaid — connecting your financial institutions and syncing balances and transactions.
  • Supabase — managed authentication, database, storage, and edge runtime that hosts the Service.
  • Lovable Cloud — application hosting and AI Gateway routing.
  • OpenAI — model provider for AI Coach responses and AI-generated insights, under a zero-retention, no-training data-processing agreement.
  • Stripe — subscription billing for Cashly Gold. Card details are entered in Stripe and never touch Cashly servers.
  • Apple App Store / Google Play — where subscriptions are purchased in-app, the applicable store processes the transaction and shares limited receipt and status data with us for entitlement.
  • Email delivery provider — sending transactional and notification email.
  • Google (OAuth) — optional sign-in; we receive your name, email, and avatar only.
  • Law-enforcement or regulatory authorities where legally required, and only to the extent required.

8. Data retention and deletion

Cashly retains user data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed for these purposes, it is deleted or de-identified.

What we retain and for how long

  • Account identity (profile, email, name, avatar) — retained while your account is active, then deleted within 30 days of account deletion.
  • Financial data (budgets, savings goals, bills, debts, monthly plans, manual transactions) — retained while your account is active, deleted within 30 days of account deletion.
  • Bank data from Plaid (accounts, up to 24 months of transactions, balances) — retained while the bank connection is active; deleted when you disconnect the bank or delete your account. Plaid access tokens are revoked and deleted immediately on disconnect.
  • Security and audit logs (sign-ins, MFA events, bank-link events, administrator actions) — retained for up to 12 months (security events) or up to 3 years (admin audit log) to support incident response, fraud investigation, and regulatory compliance.
  • Application error logs — retained for 90 days for debugging, then deleted.
  • Support requests — retained for 2 years after resolution.
  • Encrypted database backups — retained for 30 days on a rolling schedule; deleted data ages out of backups on the same schedule.
  • Consent records (timestamp and version of Terms and Privacy Policy you accepted) — retained for the life of the account plus 12 months as evidence of consent.
  • Aggregated or de-identified data that cannot reasonably be linked back to you may be retained longer for product analytics.

Why we retain it

To operate features you rely on, secure your account, meet audit obligations, protect against fraud, and comply with tax, anti-money-laundering, and other applicable laws.

How to request deletion

You may delete your Cashly account at any time from Profile → Danger zone → Delete account. You can also file a request from Profile → Danger zone → Request deletion, which places your account in read-only pending-deletion state until an administrator processes it. You may also email privacy@mycashlyapp.com to request deletion; we honour verified requests within 30 days.

When your account is deleted, Cashly:

  • Revokes and deletes all Plaid access tokens and disconnects linked banks.
  • Deletes your profile, budgets, goals, bills, debts, monthly plans, transactions, and chat history from our production database.
  • Signs you out on every device and cancels active subscriptions at period end.
  • Ages out the same data from encrypted backups on the normal 30-day rotation.

Data we may need to retain

We may retain limited information after deletion where legally required — for example, records needed for tax reporting, anti-fraud investigations, response to a lawful subpoena, or defence of legal claims. Retained data is minimized to what the obligation requires and remains protected by the same access controls.

9. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, email privacy@mycashlyapp.com. We will respond within the time required by applicable law and never more than 30 days from a verified request.

10. Children

Cashly is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided personal information to Cashly, contact us and we will delete it.

11. International users

Cashly is operated from the United States. If you access the Service from another jurisdiction, you consent to the transfer, storage, and processing of your information in the United States and other countries where our service providers operate.

12. Consent to these terms

You are asked to accept this Privacy Policy and the Terms of Service before creating an account, and again before connecting a financial institution through Plaid. Cashly records the timestamp and version of the policies you accepted so we have an auditable record of your consent. You can withdraw consent at any time by deleting your account.

13. Periodic review of our policies

Cashly reviews this Privacy Policy, our Terms of Service, our Data Retention Policy, and our internal security practices at least annually — and sooner when we launch new features, change vendors, or become aware of legal or regulatory changes — to ensure they remain accurate and compliant with applicable privacy and consumer-finance laws.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced in-app before they take effect, and where required by law we will ask you to re-accept the updated policy. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

15. Contact us

Questions, requests, or complaints about this policy or our privacy practices? Email privacy@mycashlyapp.com. For security issues, email security@mycashlyapp.com. For billing, subscription, or payment questions, email billing@mycashlyapp.com.