Effective Date: January 1, 2025 · Last Reviewed: March 25, 2026
This policy defines how Finance AI (“the Company”) retains, archives, and deletes personal and financial data. It ensures that data is kept only as long as necessary to fulfill the purposes for which it was collected, and that deletion is performed securely and in compliance with applicable data privacy laws including the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR), and other relevant regulations.
This policy applies to all personal data, financial data, and metadata collected, processed, or stored by the Company, whether in production databases, backups, logs, or third-party systems.
The following table defines retention periods for each category of data:
| Data Category | Retention Period | Trigger for Deletion |
|---|---|---|
| Account profile (name, email) | Duration of active account | Account deletion request |
| Plaid access tokens (encrypted) | Until bank account is disconnected or account is deleted | Disconnect action or account deletion |
| Financial data (transactions, balances) | Duration of active account | Account deletion request |
| Manually entered data (stocks, mortgages) | Duration of active account | User deletion or account deletion |
| AI chat history | Duration of active account | Account deletion request |
| Stripe customer & subscription data | As required by tax/financial regulations (up to 7 years) | End of legal retention obligation |
| Application logs & analytics | 90 days (anonymized) | Automatic rolling deletion |
| Database backups | 30 days | Automatic rolling deletion |
Users may request deletion of their account and all associated data at any time by contacting privacy@financeai.app. Upon receiving a verified request:
When a user disconnects a linked bank account, the associated Plaid access token is immediately revoked and deleted. Historical transaction data from that account is retained on the user’s dashboard unless the user explicitly requests its removal.
All deletion operations are permanent and irreversible. Data is deleted from the database (not merely soft-deleted or archived). Encrypted tokens are destroyed along with access to the corresponding encryption keys where applicable.
For questions about this policy or to request data deletion, contact privacy@financeai.app.