Plutara

Privacy Policy

Last updated 26 August 2026

Not yet reviewed by an attorney

This policy is in effect and describes how the app actually handles data today. It has not had legal review, and it will be revised before Plutara is generally available.

The short version

We store what you type in so the app can do its job. We never store bank credentials, card numbers, or government IDs. We do not sell your data. You can export everything, or delete all of it permanently, from inside the app.

What we store

Your email address, and the financial information you enter: debts, bills, income, accounts, transactions, goals, your Financial Identity answers, your settings, and your conversations with the assistant.

What we never store

Bank login credentials. Full card numbers. Social Security numbers. Passport or government ID numbers. Plutara has no feature that asks for any of these, and you should never enter them anywhere in the app.

Who can see it

Only you. Every table enforces owner-only access at the database level, and that isolation is verified by an automated test suite on every change — not by trusting the application code to behave.

The assistant

When you send a message, the server retrieves your own records and sends them, together with your message, to the AI provider that generates the reply. The app itself cannot supply this context, which means it cannot be tricked into sending someone else's data.

We log that a request happened and how large it was. We do not log the content of your messages in analytics or error reporting.

Analytics and error reporting

We record anonymous event names and counts to understand which features get used, and errors to find crashes. Both are scrubbed of anything money-shaped or email-shaped before leaving your device. You can turn analytics off in Privacy & Data.

AI training

Your data is not used to train models. If a future version offers that, it will be off unless you deliberately turn it on.

Your rights

Export everything we hold as a file, or delete your account entirely — both from Privacy & Data inside the app. Deletion cascades across every table and cannot be undone.

Security, honestly

We use TLS everywhere, database-level access control, and store no payment or banking credentials. We are not SOC 2 or PCI certified. That is acceptable only because we hold no bank credentials and move no money. If that ever changes, this page changes first.

Contact

Questions about your data: privacy@plutara.app