Privacy Policy

Last updated: September 9, 2026

1. Information We Collect

We collect information you provide directly when you create an account or use our services:

  • Account Information: Name, email address, and password.
  • Financial Data: Debt balances, interest rates, credit limits, payment history, and income information — whether you type it in or import it from a document.
  • Documents You Upload: Account statements and receipts you choose to import. We read them to fill in a form for you and we do not keep them — see section 4.
  • Questions You Ask: Messages you send to the in-app assistant.
  • Usage Data: Pages visited, features used, and interaction patterns to improve our service.
  • Device Information: Browser type, operating system, and device identifiers for security and compatibility.

2. How We Use Your Information

  • Generate personalized debt payoff strategies and velocity banking recommendations.
  • Sync your data securely across your devices.
  • Send notifications about payment due dates, strategy updates, and account activity.
  • Answer your questions about your plan, and read statements and receipts you upload, using a third-party AI provider — see section 4.
  • Improve the product through anonymized, aggregated analytics.
  • Comply with legal obligations and prevent fraud.

3. Data Security

Your account and financial data are stored with Supabase and served through Vercel. Both encrypt stored data at rest, and every connection between your browser and our services runs over HTTPS.

Where it matters, access is enforced by the database rather than by the app, so a mistake in the interface cannot hand someone else your data:

  • The database itself only returns your own row. Reading, creating, updating or deleting a profile is permitted only for the account it belongs to, enforced by row-level security rather than by the code that asks.
  • Every write to your profile also goes through a database function that refuses the request unless you are the account it belongs to.
  • Profile photos can only be written into your own folder, enforced by storage rules rather than by the code that uploads them.
  • You can see your active sessions in Profile settings and revoke any of them. A revoked session cannot renew itself and stops working when its current token expires.

On the device you are using:

  • We sign you out after a period of inactivity — 30 minutes by default, which you can change in Profile settings.
  • If a different account signs in on the same browser, the previous account’s cached data is cleared before the new one loads.
  • The credentials we use to reach our payment, email and AI providers exist only on our servers and are never sent to your browser.

No system is perfectly secure, and we make no claim to a formal security certification. If you believe you have found a security problem, please tell us at privacy@debtaipro.com rather than disclosing it publicly.

4. AI Features and What They Send

Four features work by sending data to Anthropic, whose Claude models answer your questions and read your documents. They run only when you use them. If you never ask the assistant a question and never upload a document, nothing described in this section is sent anywhere.

Ask about your plan. When you send a message, we send your question together with a summary of your financial position: your first name, your account names, balances, interest rates, minimum payments and credit limits, your monthly surplus, your projected payoff date, the app’s recommendations, and the totals you hold in cash, investments and retirement accounts.

We do not send your email address, your password, or your credit score, and we do not send your individual transactions — the summary describes your position, not your spending history.

Statement, receipt and transaction import. When you upload a document, we send that file to be read. It is sent in full, exactly as you uploaded it: if your statement shows an account number, so does the image we send. We hold the file in memory only for as long as that one request takes, and we never save it — not to our database, not to file storage, not to disk.

When you import a statement of transactions, the check for entries you have already logged runs in your own browser. Your existing transaction history is not sent.

Anthropic processes this data as our service provider. Their handling of it is governed by their own terms and privacy policy, at anthropic.com/legal/privacy.

Nothing an AI feature suggests is saved until you confirm it. Imported figures are shown to you first, alongside the line of the document they were read from, and you can change or discard any of them.

5. Data Sharing

We do not sell, rent, or trade your personal or financial data. We may share limited information with:

  • Service Providers: Cloud hosting (Vercel, Supabase), AI processing (Anthropic, see section 4), analytics, and email services that process data on our behalf under strict confidentiality agreements.
  • Legal Requirements: When required by law, court order, or to protect our rights and safety.

6. Data Retention

We retain your data for as long as your account is active. If you delete your account, we remove your personal and financial data within 30 days, except where retention is required by law. Anonymized, aggregated data may be retained indefinitely for analytics purposes.

Documents you upload are an exception: we never store them at all. A statement or receipt exists in our systems only for the seconds it takes to read it, and only the figures you confirm are kept.

7. Your Rights

  • Access: Request a copy of your stored data at any time.
  • Correction: Update or correct inaccurate information via your Profile settings.
  • Deletion: Request account and data deletion by contacting support.
  • Portability: Export your financial data in standard formats.
  • Opt-out: Disable notifications, email reports, and analytics tracking in your preferences.

8. Cookies & Local Storage

We use localStorage to persist your preferences (dark mode, tool settings) and cache financial data for faster loading. We do not use third-party tracking cookies. Essential cookies are used for authentication sessions only.

9. Changes to This Policy

We may update this policy periodically. Material changes will be communicated via in-app notification or email. Continued use of the service after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or your data, contact us at privacy@debtaipro.com.