DollarScholar

Privacy Policy

What DollarScholar collects about you and your money, who it goes to, how it is protected, and how to get rid of it. This policy is part of the Terms of Service.

Effective August 20, 2026 · Version 2026-08-20 · See also Terms of Service

Short version. We collect what we need to show you your money and nothing else. We never see your bank password. We never sell your data, and we never use your transactions to train AI models. You can delete everything, permanently, from your account settings — without asking us.

1.Short version

  • Your bank login never touches us. It is entered on Plaid’s screens and shared only with your bank.
  • We collect your email and name, the bank accounts and transactions you connect, anything you enter manually, and basic technical logs.
  • We share only with the service providers that make the app run — listed by name in Section 7.
  • We never sell your data, share it with advertisers or data brokers, or use your transactions to train machine-learning models.
  • You are in control. Disconnect a bank at any time; delete your entire account and all data at any time.

2.Scope

This policy explains how [LEGAL ENTITY NAME] (“we”, “us”) handles information in connection with DollarScholar (the “Service”). It forms part of, and is incorporated into, our Terms of Service.

Because the Service handles nonpublic personal financial information, we treat that information in a manner consistent with the safeguarding and confidentiality principles of the Gramm-Leach-Bliley Act, regardless of whether we are formally a “financial institution” under that statute.

3.What we collect

Information you give us

  • Email address and, optionally, a display name.
  • A password, which we store only as a salted bcrypt hash — never in readable form.
  • If you use “Sign in with Google”: your Google email address, name, and profile image, supplied by Google.
  • Manual transactions, categories, categorization rules, recurring entries, goals, and debt goals you create.
  • Notification preferences and your time zone.
  • Anything you write to us at our support address.

Financial information from your banks, via Plaid

When you connect an institution, we receive and store:

  • Institution name, account names and types, and masked account numbers (last four digits).
  • Account balances.
  • Transaction history: amount, date, description or merchant name, pending status, and the institution’s own category labels.
  • An encrypted access token that lets us continue syncing that connection until you disconnect it.

Information collected automatically

  • Standard server logs from our hosting provider: IP address, browser and device type, pages requested, and timestamps.
  • Session and preference cookies (see Section 15). We use no advertising or third-party analytics trackers.

4.What we never collect

We never receive, request, see, or store your online banking username, password, PIN, security questions, or multi-factor codes. Those are entered on Plaid’s own interface and are shared only between you, Plaid, and your financial institution. Nobody at DollarScholar can access them, because they never reach our systems.

We also do not collect full account numbers, Social Security numbers, government identification numbers, payment card numbers, or precise geolocation. We do not ask for them, and you should never send them to us.

5.How we use it

We use your information only to operate the Service for you — specifically to:

  • authenticate you and keep your account secure;
  • retrieve and display your balances, transactions, and cash flow;
  • categorize transactions and apply the rules you create;
  • calculate goals, forecasts, recurring entries, and reports;
  • send the account email and notifications you have enabled — alerts and the daily digest;
  • detect and prevent fraud, abuse, and unauthorized access, and enforce rate limits;
  • diagnose faults, monitor sync health, and improve the Service;
  • comply with legal obligations.

We do not use your information for advertising, profiling for third parties, credit decisioning, or any purpose unrelated to providing the Service to you.

6.AI processing

Automatic categorization and the written summaries in reports are produced using Anthropic’s Claude API. To generate them, we send transaction descriptions, amounts, dates, and your category names to Anthropic for processing.

We do not send bank credentials, access tokens, account numbers, your name, or your email address to our AI provider. Your transaction data is not used to train Anthropic’s models — it is processed under Anthropic’s commercial API terms, which exclude API inputs and outputs from model training by default.

AI suggestions are recorded in an audit trail you can review and undo. See Section 9 of the Terms for the limits of what AI output can be relied on for.

7.Who we share it with

We share information only with the service providers below, only to the extent each needs it to perform its function, and only under contracts requiring them to protect it. This is the complete list.

ProviderWhyWhat it receives
Plaid Inc.Connects your bank accounts and retrieves account balances and transaction history on your behalf.Bank login (entered on Plaid's own screens, never ours), account numbers in masked form, balances, transaction history.
Anthropic PBC (Claude API)Powers automatic transaction categorization and the written summaries in reports.Transaction descriptions, amounts, dates, and category names. No bank credentials, account numbers, name, or email are sent.
ResendDelivers account email — verification links, alerts, and the daily digest.Email address, display name, and the contents of the messages themselves.
Cloudflare, Inc.Manages our domain's DNS and forwards email sent to our support address to our own inbox.The contents of anything you email to support@getdollarscholar.com, plus standard DNS query metadata for our domain.
Vercel Inc.Hosts and serves the application.Standard server logs: IP address, user agent, request paths and timestamps.
Supabase (PostgreSQL hosting)Stores the application database.All account and financial data described in this policy, encrypted at rest.
UpstashRate limiting, to protect sign-in and bank-sync endpoints from abuse.Email addresses and IP addresses, held transiently as counters.
Google LLCOptional 'Sign in with Google' authentication.Only if you choose Google sign-in: your Google email address, name, and profile image.

Each provider’s own privacy policy is linked from its name. Plaid’s handling of your data is governed by the Plaid End User Privacy Policy, which we encourage you to read before connecting an account.

If we are ever involved in a merger, acquisition, or sale of assets, your information may transfer as part of that transaction. We will notify you before it becomes subject to a materially different privacy policy, and you will have the opportunity to delete your account first.

8.We never sell your data

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws. We have never done so. We do not rent or disclose your data to marketers, advertisers, or data brokers.

This is also a binding condition of our access to Plaid’s platform, not merely a policy choice we could quietly reverse.

We may disclose information if we reasonably believe it is required to comply with a law, regulation, subpoena, court order, or other valid legal process; to enforce our Terms; or to protect the rights, property, or safety of our users, the public, or us — including to prevent fraud or a security threat.

Where we are legally permitted to do so, we will make reasonable efforts to notify you before disclosing your information in response to legal process.

10.How we protect it

Measures currently in place include:

  • Bank access tokens encrypted at rest with AES-256-GCM, under a key held separately from the database.
  • Passwords stored as bcrypt hashes, never in readable form, and checked against known-breached password lists at signup.
  • Encryption in transit (HTTPS/TLS) for all traffic.
  • Row-level access controls in the database, so records are reachable only by the account that owns them.
  • Rate limiting on authentication and bank-sync endpoints to blunt automated attacks.
  • Session revocation — “sign out everywhere” genuinely invalidates existing sessions, and a password change forces re-login on every device.
  • Email verification before an account can be used, so an address cannot be registered by someone who does not control it.
  • Periodic security review of the codebase and dependencies.
No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security, and you provide information to us at your own risk.

You play a real part in this: use a strong, unique password, keep your email account secure, and sign out on shared devices.

11.If there is a breach

If we become aware of a security incident affecting your personal information, we will notify you and any required regulator without undue delay, and in any event within the timeframes required by applicable state breach-notification law. Notice will go to the email address on your account and will describe what happened, what information was involved, and what you should do.

12.How long we keep it

  • Account and financial data: for as long as your account is open.
  • Disconnected banks: the access token is revoked and deleted immediately. Transactions already imported are kept by default so your history stays intact — you can delete them yourself at any time.
  • After account deletion: your data is removed from our live systems immediately. We do not currently run automated infrastructure backups, so no delayed copy persists elsewhere once deletion completes.
  • Server logs: retained on a short rolling window by our hosting provider.
  • Records we must keep by law: retained only as long as legally required, and isolated from ordinary use.

13.Deleting your data

You can delete your entire account yourself, at any time, from account settings. You do not need to email us, justify the request, or wait for approval. Deletion removes your transactions, categories, rules, goals, bank connections, and profile.

Account deletion is permanent and cannot be undone. Export any reports you want to keep first.

You can also take narrower steps: disconnect a single institution, delete individual transactions, or turn off notification categories — all without deleting your account.

14.Your privacy rights

Depending on where you live, you may have rights to know what personal information we hold, to access or receive a copy of it, to correct it, to delete it, and to not be discriminated against for exercising those rights. Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have these rights by statute.

Most of these are available to you directly in the app — you can view all of your data, correct it, export reports, and delete everything without contacting anyone. For anything the app does not cover, email support@getdollarscholar.com and we will respond within 45 days. We may need to verify your identity by confirming control of the email address on the account.

You may use an authorized agent to submit a request, subject to verification. If we decline a request, we will explain why, and you may appeal by replying to our response; if we deny an appeal, you may contact your state attorney general.

We do not sell personal information or use it for targeted advertising, so there is nothing for you to opt out of on those grounds. We do not use your information for automated decision-making that produces legal or similarly significant effects.

15.Cookies and tracking

We use a deliberately small number of cookies, all functional:

  • Session cookie — keeps you signed in. Required for the Service to work.
  • Time-zone cookie — records your local time zone so “this month” means the right month for you.
  • Theme preference — stored in your browser’s local storage, not sent to us.

We use no advertising cookies, no third-party analytics, no pixels, and no cross-site trackers. We do not track you across other websites, so there is nothing meaningful for us to change in response to a Do Not Track or Global Privacy Control signal — we already do not do the things those signals ask us to stop.

16.Children

The Service is not directed to anyone under 18, and we do not knowingly collect information from children. If we learn that we have collected information from someone under 18, we will delete it promptly. If you believe a child has provided us information, contact support@getdollarscholar.com.

17.Changes to this policy

We may update this policy as the Service changes. The version and effective date at the top of this page always reflect the current text. If we make a material change — particularly to what we collect, who we share it with, or how long we keep it — we will notify you by email or in-app notice before it takes effect.

We will never begin selling your data or sharing it for advertising under a quiet policy update. If that were ever to change, we would ask for your explicit opt-in consent first.

18.Contact

For any privacy question or request, email support@getdollarscholar.com, or write to [LEGAL ENTITY NAME] at [MAILING ADDRESS]. We are based in [STATE], United States, and the Service is operated from the United States.