Poise.

Privacy Policy

Last updated 22 July 2026

Poise is a private household budgeting app. It connects to your bank accounts to help you track spending, plan bills, save toward goals, and pay off debt. This policy explains what we collect, how it’s used, who else touches it, and the choices you have. Written in plain English — no dark patterns.

What we collect

  • Account info — your email address and a display name, so we can sign you in and other household members can recognise you.
  • Bank & transaction data — via Plaid, we receive your connected accounts’ balances, account names, last-four digits, and transaction history (merchant, amount, date, and Plaid’s category). We never see or store your bank login credentials— they go directly to Plaid and stay with your bank.
  • Data you add — budgets, tags, goals, events, bill amounts, interest rates, notes, and any receipt images you upload.
  • Payment info — if you subscribe, Stripe collects and stores your card details; we only see the last four digits and the plan you’re on.

How we use it

Your data is used solely to run the app: showing your transactions, categorising them, tracking budgets and goals, forecasting cashflow, and calculating figures like safe-to-spend and payoff timelines. Transaction descriptions and merchant names are sent to an AI model (see “Sub-processors” below) so we can suggest an expense category — you can always override it.

We do not sell your data. We do not use it for advertising. We do not use it to train AI models — the AI provider we use runs your data through inference only, with a zero-retention agreement.

Sub-processors

Poise relies on a small number of vetted service providers to operate. Each has its own privacy policy and processes your data only under our instructions.

  • Supabase — hosts our Postgres database and authentication (US, AWS us-east-1). Storage encrypted at rest and in transit. See supabase.com/privacy.
  • Plaid — securely connects to your bank and delivers transaction data. Your bank login credentials go directly to Plaid; we never receive them. See plaid.com/legal.
  • Anthropic — runs the Claude Haiku model that suggests categories for your transactions. We send merchant names and short descriptions; no account numbers, balances, or personal identifiers. Zero data retention on our API tier — nothing you send is stored or used to train models. See anthropic.com/legal/privacy.
  • Stripe — processes subscription payments (US). We never see full card numbers. See stripe.com/privacy.
  • Resend — delivers transactional email (signup confirmations, password resets, household invites). See resend.com/legal/privacy-policy.
  • Netlify — hosts the app itself (US). See netlify.com/privacy.

We don’t share your data with any other party. We don’t use analytics or advertising trackers.

Where your data lives

All data is stored in the United States (Supabase, hosted on AWS us-east-1) and travels across US-hosted sub-processors as described above. If you’re outside North America, please be aware your data crosses borders to reach us. We rely on Standard Contractual Clauses with our sub-processors where applicable.

How long we keep it

We keep your data for as long as your account is active. When you delete your account, your profile is removed immediately. For any household where you’re the only member, the household’s data (accounts, transactions, budgets, goals) is removed with it. Where other members remain, they retain the household data — your personal association with it is removed.

Encrypted database backups may retain a copy of your data for up to 30 days after deletion before being permanently overwritten, as part of our disaster-recovery policy.

Security

Data is stored in Supabase (Postgres) with row-level security, so each household can only access its own data. Bank access tokens are encrypted with a rotating key at the application layer, in addition to disk-level encryption at rest. Data in transit is protected by TLS (HTTPS). We follow the principle of least privilege for internal access, and we’ll notify affected users within 72 hours if we discover a data breach that materially affects them.

Your rights

You can, at any time:

  • Access & export your data — download a machine-readable copy from Settings → Security → Export my data.
  • Correct your data — edit account details, categories, budgets and allocations from within the app.
  • Disconnect a bank at any time from Settings → Banks. We stop receiving new data from that institution immediately.
  • Delete your account from Settings → Danger zone. Instantly removes your profile; household data is cleaned up as described above.

Depending on where you live (GDPR/UK, CCPA/CPRA, PIPEDA), you may also have the right to lodge a complaint with your local data protection authority. We’d rather hear from you first — email us and we’ll work to make it right.

Children

Poise is not directed at children under 13, and we don’t knowingly collect information from them. If you believe a child has created an account, email us and we’ll remove it.

Changes to this policy

We may update this policy as the product evolves. Material changes will be flagged in the app before they take effect. The “Last updated” date at the top always reflects the current version.

Contact

Questions about your privacy? Email hello@poise.money. We read everything.