Legal
Privacy Policy
How Vekfinance collects, uses, and shares information. Written to be specific rather than reassuring: every claim below is something we can point to in the codebase.
We never sell your data
No advertisers, no data brokers, no advertising trackers, no cross-site profiling. The one analytics processor we use, PostHog Cloud US, receives only an internal user id and event name, never PII or financial values.
AI never trains on your data
Anthropic processes snapshots only to generate the response you asked for. They state they do not train on API submissions.
Delete in one click
Account deletion from Settings removes your account, all financial data, sessions, and rules.
Jump to a section
This Privacy Policy describes how Vekfinance ("we", "our") collects, uses, and shares information about you when you use the Vekfinance application at vekfinance.com (the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.
Information we collect
In plain English
Your account info, the financial data you choose to import, a couple of essential first-party cookies, privacy-friendly first-party usage analytics, anonymized funnel events sent to PostHog Cloud US (no PII, no transactions), and standard server logs. No advertising or cross-site tracking.
We collect the following information:
- Account information. Your display name, username, and a bcrypt-hashed password. We never store your plaintext password.
- Email address. If you provide one (at signup or later from Settings), we use it for account verification, security notifications, password resets, and product and lifecycle messages, plus any optional alerts or newsletter you turn on. You can opt out of non-essential mail at any time from Settings; essential security and transactional messages always send. We never sell it or share it with advertisers, and you can remove it from Settings whenever you like.
- Email-delivery provider. When we send you email (account verification, security notifications, password resets, product and lifecycle messages, or any alerts and newsletter you opted into), we deliver it via Resend. Resend receives only your email address and the message body. See Resend's privacy policy at https://resend.com/legal/privacy-policy.
- Financial information. Bank, credit, and loan accounts (name, type, balance, interest rate, minimum payment), transactions (date, amount, description, category), investment holdings, budget targets, debts, savings goals, and category rules. This data is either entered by you, imported from a CSV you upload, or fetched read-only from a financial institution you choose to link through Plaid (see "Third parties").
- AI input data. Vekfinance has one AI feature, the assistant (it appears as the chat, the monthly close insight, and the portfolio analysis). When you use it, we send Anthropic, our AI processor, only a de-identified summary of your finances (coarse money bands, rounded ratios, generic category labels, and relative time periods) plus the text of the question you type. We never send raw transactions, merchant or payee names, account names or numbers, exact balances, tickers, or any image. See the AI Disclosure for the full field list and "Third parties" below.
- Cookies. An HTTP-only, same-site session cookie is set when you sign in. We also set a short-lived first-party attribution cookie that records how you arrived (referrer and any UTM parameters) so we can understand which channels work. We do not use advertising or cross-site tracking cookies.
- Privacy-friendly page-view analytics. We use Cloudflare Web Analytics to count page views and referrers. Cloudflare Web Analytics does not use cookies, does not collect personal information, does not fingerprint visitors, and is GDPR and CCPA compliant by default. See Cloudflare's analytics privacy notice at cloudflare.com/web-analytics-privacy/.
- First-party usage analytics. We record a small set of product events tied to your account (for example: sign-in, CSV import, an AI feature being used, a bank connected) so we can see which features get used and fix what breaks. These events stay on our own servers, are never sold, and are never shared with advertisers or data brokers.
- Funnel analytics. We send a short list of conversion events (landing view, signup start, signup complete, bank link start, bank link complete, first insight viewed, Pro upgrade) to PostHog Cloud US for funnel analysis. Each event carries only your internal user id (no email, no transactions, no amounts, no Stripe or Plaid identifiers, no PII). Autocapture is disabled, session recording is disabled, all input fields are masked, and Do-Not-Track is respected. See PostHog's privacy policy at https://posthog.com/privacy.
- Server logs. Our reverse proxy records standard request metadata (IP address, requested path, status code, timestamp) for operational and security purposes. Logs are retained on a rolling short-term basis (approximately 7 days), then age out automatically.
How we use information
In plain English
To run the Service, secure your account, and answer support requests. We do not sell your data and we do not train AI on it.
- To provide and operate the Service.
- To generate the budgeting, debt-payoff, forecast, and AI features you request.
- To secure your account and prevent abuse (rate limits, login throttling).
- To respond to support requests you initiate.
We do not sell your data. We do not use your financial data to train AI models.
Third parties
In plain English
Anthropic processes AI requests, Plaid handles bank and investment connections, PostHog Cloud US receives anonymized funnel events, and our hosting provider runs the servers. No advertisers, no brokers.
We share data with the following service providers, only as needed to operate the Service:
- Anthropic, PBC (Anthropic) processes the financial-snapshot data described above when you trigger an AI feature. Anthropic states it does not train on data submitted via their API. See Anthropic's privacy policy at https://www.anthropic.com/legal/privacy.
- Plaid Inc. (Plaid) is our account-connectivity provider for banks, credit cards, brokerages, and loans. When you link an institution, you enter your credentials directly into Plaid Link; Vekfinance never sees or stores them. Plaid returns an opaque, read-only access token that we store encrypted and use to fetch your balances, transactions, investment holdings, and liability details on your behalf. Plaid's handling of your data is governed by Plaid's End User Privacy Policy at plaid.com/legal. You can disconnect a linked institution at any time from Settings, and you can manage or revoke Plaid's access directly through your Plaid dashboard at my.plaid.com.
- Our hosting provider stores the Service's database and serves requests. We choose hosting providers with industry-standard security practices.
- PostHog, Inc. (PostHog) processes anonymized funnel-conversion events for us, hosted in the US. PostHog receives only your internal user id and an event name (for example, signup_complete or pro_upgrade), never your email, transactions, balances, account identifiers, or any PII. Autocapture and session recording are disabled in our configuration; all input fields are masked. See PostHog's privacy policy at https://posthog.com/privacy.
We do not share your data with advertisers, data brokers, or analytics companies. We may disclose information when required by valid legal process, and we will notify you when permitted by law.
Data retention
In plain English
Your data sticks around until you delete your account. Delete is permanent. We keep limited authentication logs for up to 12 months from when they were recorded.
We retain your account and financial data as long as your account is active. You can delete your account at any time, which permanently removes your account row, all associated financial data, sessions, and category rules; the deletion cascade is verified by an automated check. We may retain limited records (e.g., authentication logs) for security and legal compliance for up to 12 months from the date the event was recorded, and operational and request logs on a rolling short-term basis (approximately 7 days). To enforce our one-free-trial-per-person policy, we also keep a one-way, non-reversible hash of the email address used for a free trial; it cannot be turned back into a readable email and stores no other personal data. This retention and deletion policy is reviewed at least annually for compliance with applicable privacy laws.
Your rights
In plain English
GDPR and CCPA rights apply. Email us to exercise them; we respond within 30 days.
Depending on your jurisdiction (notably the EU/UK under GDPR and California under CCPA/CPRA), you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (the "right to be forgotten").
- Export your data in a portable format (the Service's export feature provides this).
- Object to or restrict certain processing.
- Opt out of the sale of personal information (we do not sell personal information).
To exercise any of these rights, email us at the address below. We will respond within 30 days.
Security
In plain English
Encrypted at rest and in transit, bcrypt cost 12 for passwords, optional two-factor authentication, HTTP-only SameSite-strict session cookies, parameterized SQL, rate limiting, cross-origin rejection. No system is perfect; if something looks wrong, write to [email protected].
We protect your data with defense in depth:
- Encryption in transit. All connections use TLS 1.2 or higher with HSTS enforced.
- Encryption at rest. The database is encrypted at rest with AES-256. Highly sensitive fields, including financial-institution access tokens and two-factor secrets, are additionally encrypted with AES-256-GCM using keys held separately from the database key.
- Authentication. Passwords are hashed with bcrypt (cost factor 12), require at least 12 characters, and are screened against known breach corpora. A passkey (WebAuthn) is required before you can link a financial institution, and we re-verify it at the moment you connect. Optional TOTP two-factor authentication is also available as an extra login factor, though it is not the bank-link gate.
- Application hardening. HTTP-only, SameSite-strict, Secure session cookies, parameterized SQL, server-side input validation on every action, rate limiting on authentication and AI endpoints, and cross-origin request rejection.
No security measure is perfect; you are responsible for keeping your password confidential. If you believe your account has been compromised, email [email protected] immediately.
Age requirement
In plain English
18 or older. If you believe a minor has an account, tell us.
You must be at least 18 years old to use the Service. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.
Changes to this policy
In plain English
The effective date at the top is the latest revision date. Material changes will be announced through the Service or by email.
We may update this Privacy Policy from time to time. The "Effective" date at the top of this page reflects the latest revision. Material changes will be announced via the Service or by email to the address on file.
Contact
In plain English
[email protected] for anything privacy-related.
For any privacy-related question, request, or complaint:
[email protected]
Get in touch
Privacy requests and complaints