Overview
OssFin LLC ("OssFin," "we," "our," or "us") is a personal finance application that helps you understand and manage your financial life. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding your information.
By creating an account and using OssFin, you agree to the collection and use of information as described in this policy.
1. Information We Collect
Account information. When you sign in with Google, we receive your name, email address, and profile picture from Google's OAuth service. We use this to create and identify your account.
Financial data via Plaid. When you connect a bank account or brokerage, we use Plaid Technologies, Inc. to retrieve:
- Account balances and metadata (account name, type, institution)
- Transaction history (merchant name, amount, date, category)
Your bank login credentials are entered directly into Plaid's secure interface — they are never transmitted to or stored by OssFin.
Uploaded documents. When you use the AI Document Analysis feature, you upload financial statements (bank statements, investment statements, credit card statements) that are transmitted to Anthropic's Claude AI for processing. Extracted data (account balances and transactions) is stored in your OssFin account. The raw document file is not stored by OssFin.
Billing information. If you subscribe to a paid plan, your payment is processed by Stripe. OssFin receives only a billing confirmation and your subscription status — your card number and full payment details are never transmitted to or stored by OssFin.
Usage data. We may collect standard server logs including IP address, browser type, and pages visited for security monitoring and debugging purposes.
2. How We Use Your Information
- To display your financial data within the OssFin dashboard
- To calculate budgets, net worth, tax estimates, and financial projections
- To authenticate your session and maintain account security
- To process subscription payments and manage your plan
- To send transactional emails (account confirmation, billing receipts) via our email service provider
- To monitor application errors and performance
- To respond to support requests
- To improve the application based on aggregate, anonymized usage patterns
We do not use your financial data for advertising, credit scoring, or any purpose beyond operating OssFin for your benefit.
Any aggregate or anonymized usage data we generate is used solely to operate and improve OssFin. We do not sell, license, or otherwise disclose anonymized or aggregated data to third parties.
3. How We Store and Protect Your Data
OssFin applies the following security controls to your data:
- Encryption at rest: Plaid access tokens (which allow us to retrieve your account data) are encrypted using AES-256-GCM before being written to our database. The plaintext token is never stored.
- Encryption in transit: All data is transmitted over HTTPS/TLS.
- Authentication: Your session is protected by a signed JSON Web Token (JWT) with expiry and inactivity timeout controls.
- Access control: Only you can access your data. User IDs are derived from verified session tokens — never from user-supplied input.
- Database: Your financial data is stored in a PostgreSQL database hosted by Railway on infrastructure with their own security certifications.
- Field-level encryption of sensitive content: Data extracted from uploaded statements, imported CSV transactions, manually entered accounts, and your edits are encrypted at the field level (AES-256-GCM) before being stored.
- Internal access: Access to the production systems and databases that hold user data is restricted to authorized personnel on a need-to-know basis.
- Breach notification: If a data breach affects your personal information, we will notify affected users and applicable regulators without undue delay, in accordance with applicable law.
4. AI Document Analysis
OssFin's Document Analysis feature is powered by Anthropic, PBC (Claude AI). When you upload a financial document for analysis:
- The document is transmitted to Anthropic's API over an encrypted connection.
- Anthropic processes the document to extract financial data and returns the result. Anthropic does not use this content to train its models and retains it only transiently in accordance with its API terms, per their Privacy Policy.
- The extracted data (account balances, transactions) is stored in your OssFin account database.
- The raw document file is not stored by OssFin after processing.
You are responsible for ensuring that any documents you upload contain only your own financial information or information you have permission to share.
5. Third-Party Services
Plaid. We use Plaid to connect to financial institutions. When you connect an account, you also agree to Plaid's End User Privacy Policy. Plaid is SOC 2 Type II certified and subject to its own security and privacy obligations.
Stripe. Payment processing for OssFin subscriptions is handled by Stripe, Inc. Your payment information is transmitted directly to Stripe and governed by Stripe's Privacy Policy. OssFin does not store your card details.
Anthropic. AI document analysis is powered by Anthropic's Claude API. Documents are transmitted to Anthropic only to produce your result; Anthropic does not use them to train its models and retains them only transiently per its API terms.
Google OAuth. Sign-in is handled by Google. We receive only your profile information (name, email, picture) — we do not receive your Google password or access to other Google services.
Resend. Transactional emails (such as billing receipts or account notifications) may be delivered via Resend. We share only your email address with Resend for the purpose of delivering these messages.
Sentry. We use Sentry for application error monitoring. Sentry may capture error context including partial request data. We configure Sentry to minimize personally identifiable information in error reports.
Railway / Vercel. OssFin's backend API and database are hosted on Railway. The frontend is hosted on Vercel. These providers maintain their own security certifications and do not have access to your unencrypted financial data.
We do not sell, rent, or share your personal or financial data with any third party for marketing or advertising purposes.
6. Business Transfers
If OssFin is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, your information may be transferred to a successor or affiliated entity as part of that transaction. If your personal information would, as a result, become subject to a materially different privacy policy, we will notify you (by email or in-app notice) before the transfer takes effect. Any successor entity will be required to honor the commitments in this Privacy Policy or to provide you notice and choice as required by law.
7. Data Retention
We retain your data for as long as your account is active. If you delete your account, all stored data — including Plaid access tokens, linked account records, and uploaded document data — is permanently deleted from our systems within 24 hours.
Plaid may retain data per their own retention policies. You can revoke Plaid's access to your accounts at any time via the Plaid Portal or from within OssFin (Settings → Connected Accounts).
Stripe retains transaction records as required for financial and legal compliance. Contact Stripe directly for questions about their retention practices.
8. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
- Access / Know — request a copy of the personal information we hold about you and how we use it
- Correction — request correction of inaccurate personal information
- Deletion — delete your account and all associated data from within the app (Settings → Delete account) or by emailing evan@ossfin.com
- Portability — request an export of your data in a machine-readable format
- Opt out of sale or sharing — we do not sell or share your personal information, so there is nothing to opt out of
- Withdraw consent — disconnect any linked account at any time from within the app
How to exercise your rights. Submit a request from within the app or by emailing evan@ossfin.com. To protect your account, we will take reasonable steps to verify your identity before fulfilling a request — typically by confirming control of the email address associated with your account.
Authorized agents. You may designate an authorized agent (such as a family member or an attorney) to submit a request on your behalf. We may require the agent to provide proof of your written authorization to act for you, and we may still ask you to verify your own identity or confirm the agent's authority directly.
No discrimination. We will not deny you service, charge you a different price, or provide you a different level of service because you exercised any of your privacy rights.
Appeals. If we deny your request, you may appeal by emailing evan@ossfin.com with the subject line "Privacy Appeal." We will review and respond to your appeal within 45 days (or as otherwise required by your state's law). If your appeal is denied, applicable state law may allow you to submit a complaint to your state Attorney General.
State-specific rights. Residents of California (under the CCPA/CPRA) and residents of other U.S. states with comprehensive consumer-privacy laws — including Colorado, Connecticut, Delaware, Florida, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia — have the rights described above to the extent those laws apply to you, and may exercise them as set out in this section. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under these laws.
9. Cookies and Local Storage
OssFin does not use tracking or advertising cookies. To keep you signed in and to make the app load quickly between visits, we store limited session state locally in your browser. This data stays on your device and is not shared with third parties. Clearing your browser's local storage will sign you out.
10. Children's Privacy
OssFin is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at evan@ossfin.com and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify you by email or in-app notification at least 7 days before the changes take effect. Changes become binding when they take effect, and your continued use of OssFin after that date constitutes acceptance of the updated policy — whether or not you received or opened the email notification. It is your responsibility to keep the email address associated with your account current.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise any of your rights, please contact us:
- Email: evan@ossfin.com
- Company: OssFin LLC, Florida
- Website: ossfin.com