Legal

Privacy Policy

Last updated: July 23, 2026  ·  Effective: July 23, 2026

Overview

OssFin LLC ("OssFin," "we," "our," or "us") is a personal finance application that helps you understand and manage your financial life. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding your information.

By creating an account and using OssFin, you agree to the collection and use of information as described in this policy.

The short version: We collect only what's necessary to run the app. We do not sell your data. Your bank credentials are never stored — we use Plaid's bank-level API to securely access your accounts. Documents you upload for AI analysis are transmitted to Anthropic's API only to produce your result; Anthropic does not use them to train its models and retains them only transiently per its API terms. You can delete all your data at any time.

1. Information We Collect

Account information. When you sign in with Google, we receive your name, email address, and profile picture from Google's OAuth service. We use this to create and identify your account.

Financial data via Plaid. When you connect a bank account or brokerage, we use Plaid Technologies, Inc. to retrieve:

Your bank login credentials are entered directly into Plaid's secure interface — they are never transmitted to or stored by OssFin.

Uploaded documents. When you use the AI Document Analysis feature, you upload financial statements (bank statements, investment statements, credit card statements) that are transmitted to Anthropic's Claude AI for processing. Extracted data (account balances and transactions) is stored in your OssFin account. The raw document file is not stored by OssFin.

Billing information. If you subscribe to a paid plan, your payment is processed by Stripe. OssFin receives only a billing confirmation and your subscription status — your card number and full payment details are never transmitted to or stored by OssFin.

Usage data. We may collect standard server logs including IP address, browser type, and pages visited for security monitoring and debugging purposes.

2. How We Use Your Information

We do not use your financial data for advertising, credit scoring, or any purpose beyond operating OssFin for your benefit.

Any aggregate or anonymized usage data we generate is used solely to operate and improve OssFin. We do not sell, license, or otherwise disclose anonymized or aggregated data to third parties.

3. How We Store and Protect Your Data

OssFin applies the following security controls to your data:

4. AI Document Analysis

OssFin's Document Analysis feature is powered by Anthropic, PBC (Claude AI). When you upload a financial document for analysis:

You are responsible for ensuring that any documents you upload contain only your own financial information or information you have permission to share.

5. Third-Party Services

Plaid. We use Plaid to connect to financial institutions. When you connect an account, you also agree to Plaid's End User Privacy Policy. Plaid is SOC 2 Type II certified and subject to its own security and privacy obligations.

Stripe. Payment processing for OssFin subscriptions is handled by Stripe, Inc. Your payment information is transmitted directly to Stripe and governed by Stripe's Privacy Policy. OssFin does not store your card details.

Anthropic. AI document analysis is powered by Anthropic's Claude API. Documents are transmitted to Anthropic only to produce your result; Anthropic does not use them to train its models and retains them only transiently per its API terms.

Google OAuth. Sign-in is handled by Google. We receive only your profile information (name, email, picture) — we do not receive your Google password or access to other Google services.

Resend. Transactional emails (such as billing receipts or account notifications) may be delivered via Resend. We share only your email address with Resend for the purpose of delivering these messages.

Sentry. We use Sentry for application error monitoring. Sentry may capture error context including partial request data. We configure Sentry to minimize personally identifiable information in error reports.

Railway / Vercel. OssFin's backend API and database are hosted on Railway. The frontend is hosted on Vercel. These providers maintain their own security certifications and do not have access to your unencrypted financial data.

We do not sell, rent, or share your personal or financial data with any third party for marketing or advertising purposes.

6. Business Transfers

If OssFin is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, your information may be transferred to a successor or affiliated entity as part of that transaction. If your personal information would, as a result, become subject to a materially different privacy policy, we will notify you (by email or in-app notice) before the transfer takes effect. Any successor entity will be required to honor the commitments in this Privacy Policy or to provide you notice and choice as required by law.

7. Data Retention

We retain your data for as long as your account is active. If you delete your account, all stored data — including Plaid access tokens, linked account records, and uploaded document data — is permanently deleted from our systems within 24 hours.

Plaid may retain data per their own retention policies. You can revoke Plaid's access to your accounts at any time via the Plaid Portal or from within OssFin (Settings → Connected Accounts).

Stripe retains transaction records as required for financial and legal compliance. Contact Stripe directly for questions about their retention practices.

8. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights regarding your personal information:

How to exercise your rights. Submit a request from within the app or by emailing evan@ossfin.com. To protect your account, we will take reasonable steps to verify your identity before fulfilling a request — typically by confirming control of the email address associated with your account.

Authorized agents. You may designate an authorized agent (such as a family member or an attorney) to submit a request on your behalf. We may require the agent to provide proof of your written authorization to act for you, and we may still ask you to verify your own identity or confirm the agent's authority directly.

No discrimination. We will not deny you service, charge you a different price, or provide you a different level of service because you exercised any of your privacy rights.

Appeals. If we deny your request, you may appeal by emailing evan@ossfin.com with the subject line "Privacy Appeal." We will review and respond to your appeal within 45 days (or as otherwise required by your state's law). If your appeal is denied, applicable state law may allow you to submit a complaint to your state Attorney General.

State-specific rights. Residents of California (under the CCPA/CPRA) and residents of other U.S. states with comprehensive consumer-privacy laws — including Colorado, Connecticut, Delaware, Florida, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia — have the rights described above to the extent those laws apply to you, and may exercise them as set out in this section. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under these laws.

9. Cookies and Local Storage

OssFin does not use tracking or advertising cookies. To keep you signed in and to make the app load quickly between visits, we store limited session state locally in your browser. This data stays on your device and is not shared with third parties. Clearing your browser's local storage will sign you out.

10. Children's Privacy

OssFin is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at evan@ossfin.com and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify you by email or in-app notification at least 7 days before the changes take effect. Changes become binding when they take effect, and your continued use of OssFin after that date constitutes acceptance of the updated policy — whether or not you received or opened the email notification. It is your responsibility to keep the email address associated with your account current.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of your rights, please contact us: