← Superbasic Finance
Overview PrivacyTermsData PolicySecurityCookiesPlaid & Data ConnectionsData DeletionBilling TermsAcceptable UseContact

Data Policy

Last updated: August 8, 2026

This Data Policy is a plain-language companion to our Privacy Policy. It summarizes the categories of data we hold, where they live, how long we keep them, and the controls you have.

Our approach

Superbasic Finance is built around radical simplicity, and we apply the same principle to data: we collect what the Service needs to work, and little else. We do not sell your data, and we do not use your financial transactions for advertising. This page describes how we handle data operationally; for your formal rights and our legal commitments, see the Privacy Policy.

What we store

CategoryExamplesSource
AccountEmail, name, hashed password, sign-in providerYou / your identity provider
Financial connectionsConnected institution, accounts, balances, transactions (up to 24 months)Plaid, with your authorization
Manual entriesAccounts and transactions you add yourselfYou
OrganizationWorkspaces, groups, filters, sorts, rules, budgets, goals, notes, sheetsYou
ImportsCSV / spreadsheet / JSON files you upload and the rows parsed from them, held in temporary staging while you review the importYou
FeedbackFeature requests, bug reports, and votes you post to the feedback board — visible to other people who use the Service once publishedYou
NewsletterEmail address, the page you subscribed from, and subscription status — a list kept separately from your accountYou, if you subscribe
BillingStripe customer and subscription IDs, status, slot count, billing periodStripe
TechnicalIP address, device/browser type, request logs, and — on Android — a Google Play Integrity verdict about the app and deviceAutomatically collected
Website analyticsAggregate page views, referring pages, approximate country, browser, and device typePlausible Analytics

We do not store your online banking username or password — those are entered directly with Plaid. We do not store full payment card numbers — those are handled by Stripe.

For marketing-site analytics, Plausible uses the IP address and user agent included with a web request transiently, together with a rotating daily salt, to calculate aggregate daily visitor counts. Plausible states that it does not store those raw values or use cookies, local storage, or persistent identifiers. See the Plausible Data Policy for details.

Where your data lives

Your data is stored in managed PostgreSQL databases — hosted on Neon as our primary database, with a standby copy on Supabase kept in sync for disaster recovery — and the application runs on cloud infrastructure (such as Google Cloud) in the United States. Sensitive credentials, such as the access tokens that allow us to refresh your bank connections, are encrypted at rest. See our Security page for the safeguards we apply.

Hosted Plausible processes aggregate marketing-site analytics on infrastructure in the European Union.

Who we share it with

We rely on a small set of vendors (sub-processors) to run the Service. Each processes data on our behalf under contract:

ProviderPurpose
PlaidConnecting your financial institutions and retrieving data
StripeSubscription payments and card processing
CloudflareBot defense (Turnstile) on authentication flows
ResendTransactional email and newsletter delivery
PlausibleAggregate, cookieless marketing-site analytics
NeonPrimary PostgreSQL database hosting
SupabaseStandby PostgreSQL database for disaster recovery
GoogleCloud infrastructure for running the application, and Play Integrity app/device attestation on Android

Members of a workspace can see the accounts and transactions you make available to that workspace. Sharing a bank is your choice, but each workspace’s owners and admins — who may be people other than you — control that workspace’s membership.

We review new feedback-board posts before they appear to anyone else. Until then a post is hidden from other people who use the Service, though our authorized moderators can see it — with the email address on your account — in order to review it; once we publish it, it is visible to everyone who uses the Service. Keep account numbers, balances, and transaction details out of those posts.

How long we keep it

  • While your account is active: we keep your data so the Service can show it to you.
  • When you disconnect a bank: the historical data already imported can remain as manual records so your history is preserved, until you delete it.
  • When you permanently delete a bank: its accounts and transactions are removed.
  • Imported files: the uploaded file and its staged rows expire automatically a short time after the import finishes or is abandoned. Only what you commit is kept — the accounts, transactions, budgets, and goals you import, plus any spreadsheets or notes you choose to convert unclassified data into.
  • When you delete your account: we delete or de-identify your personal data, except records we must retain for legal, accounting, or dispute-resolution purposes.
  • Two exceptions that outlive account deletion: feedback-board posts stay on the board with the author removed, and a newsletter subscription stays on its separate list until you unsubscribe.

See Data Deletion for step-by-step instructions.

Your controls

  • View and edit your accounts, transactions, and notes in the app.
  • Disconnect or permanently delete any connected bank.
  • Export your bank accounts and transactions as CSV from the app.
  • Delete your entire account from your account settings.
  • Unsubscribe from the newsletter using the link in any newsletter email.
  • Request access, correction, or deletion by emailing privacy@superbasicfinance.com.