← Superbasic Finance
Overview PrivacyTermsData PolicySecurityCookiesPlaid & Data ConnectionsData DeletionBilling TermsAcceptable UseContact

Privacy Policy

Last updated: August 8, 2026

This Privacy Policy explains what information Superbasic Finance collects, how we use and protect it, and the choices and rights you have. Superbasic Finance is a personal finance tool that helps you see your money in plain text.

1. Who we are

Superbasic Finance (“Superbasic Finance,” “we,” “us,” or “our”) is a personal finance application operated by Superbasic Finance. We provide a web and mobile service that lets you connect your financial accounts, view your transactions, organize them, and keep plain-text notes. This policy applies to our marketing website at superbasicfinance.com and to our application at app.superbasicfinance.com (together, the “Service”).

We are the data controller for the personal information described in this policy. If you have questions, contact us at privacy@superbasicfinance.com.

2. Information we collect

Account information

When you create an account we collect your email address and the name you provide. If you sign in with a third-party provider such as Google, Apple, or GitHub, we receive basic profile information (such as your name and email address) from that provider. We store a securely hashed version of your password and never store it in plain text.

Financial account data (via Plaid)

When you connect a bank or financial institution, you do so through Plaid Inc. (“Plaid”). You enter your institution credentials directly with Plaid — we never see or store your online banking username or password. Through your authorization, Plaid provides us with information such as:

  • account names, types, masked account numbers, and balances;
  • transaction history (we request up to 24 months of available history), including amounts, dates, descriptions, merchant names, and categories;
  • the financial institution’s name and identifier.

We currently support U.S. financial institutions only. For details on how these connections work, see our Plaid & Data Connection Policy, and review Plaid’s End User Privacy Policy, which governs Plaid’s own handling of your data.

Information you enter

You can add manual accounts and transactions, create custom groups, filters, sorts, and rules, set budgets and goals, organize your finances into workspaces, and write plain-text notes and sheets. We store this content so the Service can display it back to you.

Files you import

You can import transactions, accounts, budgets, and goals from a CSV, spreadsheet, or JSON file, for example an export from another budgeting app. We process the uploaded file to show you a preview and hold it in temporary staging storage while you review and confirm the import. Where a file contains data we cannot classify, you can choose to keep it as a workspace spreadsheet or note instead of importing it. Staged import files and their parsed rows expire automatically after a short period; only what you choose to commit — accounts, transactions, budgets, goals, and any spreadsheets or notes you convert — is kept as part of your workspace data.

Community feedback

If you post a feature request or bug report to our in-app feedback board, we store the title, details, and votes you submit. New posts are reviewed by us first: until we publish one it stays hidden from other people who use Superbasic Finance, but our authorized moderators can see it — along with the email address on your account — in order to review it. Once published, it is visible to other people who use Superbasic Finance — see How we share your information below.

Payment and billing information

Paid subscriptions are processed by Stripe, Inc. When you subscribe, your card details are collected and processed directly by Stripe — we do not receive or store full card numbers. We store billing records such as your Stripe customer and subscription identifiers, subscription status, the number of connection slots you have purchased, and your current billing period.

Usage, device, and log data

Like most online services, we automatically collect limited technical information when you use the Service, such as your IP address, browser or device type, and timestamps of requests. We use this information to operate, secure, and troubleshoot the Service, including rate limiting and abuse prevention. To protect sign-in and password-reset flows, we use Cloudflare Turnstile for bot detection. We design our security counters so that your raw email address is not stored or logged in connection with these checks.

On Android, sign-in and sign-up in our app may also use Google Play Integrity, which asks Google to attest that the app and device are genuine. That check tells us about the app and device, not about you, and we verify the resulting token with Google rather than storing it.

On our marketing website, we use Plausible Analytics to understand aggregate traffic trends such as page views, referring pages, approximate country, browser, and device type. Plausible does not set analytics cookies, use local storage or persistent identifiers, or create cross-site profiles. Like any web request, an analytics request includes an IP address and user agent. Plausible uses those values transiently with a rotating daily salt to count aggregate daily visitors and states that it does not store the raw values.

Communications

We send transactional emails — such as email verification, password resets, workspace invitations, sign-in alerts when we see a new device, and any budget alerts you turn on — through our email provider, Resend. Budget alert emails can include financial details such as a category name and how much of a budget has been used, and go to the members of the workspace the budget belongs to who are able to see that budget in the app. A member whose access to the underlying accounts or transactions is restricted is not sent the alert, and the figures in each email reflect only what that recipient can already see. A new-device alert describes the sign-in we saw and goes only to you. If you contact support, we keep a record of that correspondence.

Newsletter and product updates

If you submit your email address to our newsletter form, we store that address, the page you subscribed from, and your subscription status so we can send you new posts and product updates. This list is separate from your account: subscribing does not create an account, and deleting your account does not by itself remove you from the list. Every newsletter email includes an unsubscribe link, and you can also ask us to remove you at privacy@superbasicfinance.com. We do not send you marketing email just because you created an account.

3. How we use your information

We use the information we collect to:

  • provide, maintain, and improve the Service;
  • measure aggregate use of our marketing website;
  • retrieve, display, categorize, and organize your financial accounts and transactions;
  • authenticate you and keep your account secure;
  • process subscriptions, payments, and billing;
  • send you service-related communications and respond to your requests;
  • send you our newsletter and product updates, if you have asked for them;
  • run our feedback board so we can prioritize what to build next;
  • detect, prevent, and address fraud, abuse, security, and technical issues; and
  • comply with legal obligations and enforce our terms.

We do not use your financial transaction data to serve third-party advertising, and we do not sell your personal information.

4. How we share your information

We do not sell your personal information. We share information only in the following circumstances:

  • Service providers (sub-processors). We share information with vendors who process data on our behalf to run the Service, under contracts that limit their use of it. These include Plaid (account connectivity), Stripe (payments), Cloudflare Turnstile (bot defense), Google (Play Integrity app and device attestation on Android, and cloud infrastructure), Resend (transactional email and newsletter delivery), Plausible (aggregate website analytics), and database hosting (Neon as our primary database, with Supabase as a disaster-recovery standby).
  • Within your workspaces. If you make a connected bank visible in a workspace, the members of that workspace can see the accounts and transactions made available to it. Sharing your bank is always your choice, but a workspace’s owners and admins — who may be people other than you — manage that workspace’s membership and can invite additional members who will then have the same access.
  • Content you post publicly. Posts and votes you submit to our feedback board are visible to other people who use the Service once we publish them. Do not put anything you want to keep private — account numbers, balances, transaction details, or other personal information — in a feedback post. If you delete your account, your published feedback posts stay on the board but are no longer linked to you.
  • Legal and safety. We may disclose information if required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect the rights, property, or safety of our users, the public, or us.
  • Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your information.

A more operational summary of the data we hold and the providers we rely on is available in our Data Policy.

5. Payments

Payment processing is handled by Stripe and is subject to Stripe’s Privacy Policy. See our Subscription & Billing Terms for how charges, renewals, and cancellations work.

6. Cookies and similar technologies

Our marketing website uses local browser storage to remember your theme preference. Our application uses strictly necessary cookies to keep you signed in and to remember your active workspace, plus a few functional cookies that remember preferences such as your theme and the view you last had open. The marketing website also uses Plausible Analytics, whose standard tracker does not set analytics cookies or use local storage or persistent identifiers. We do not use third-party advertising or cross-site tracking cookies. For details, see our Cookie Policy.

7. Data retention

We keep your information for as long as your account is active or as needed to provide the Service. When you disconnect a bank, the historical data already imported may be retained as manual records unless you delete it. Uploaded import files and their staged rows expire automatically a short time after the import is finished or abandoned. When you delete your account, we delete or de-identify your personal data, except where we must retain certain records to comply with legal obligations, resolve disputes, or enforce our agreements. Two things outlive account deletion by design: feedback-board posts remain on the board with the author removed, and a newsletter subscription is held on a separate list until you unsubscribe. See Data Deletion for how to remove your data.

8. Security

We use technical and organizational measures to protect your information, including encryption of sensitive credentials and data in transit. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Learn more on our Security page.

9. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. You can:

  • view and edit much of your data directly in the app;
  • disconnect a bank or delete data at any time;
  • export a connected bank’s accounts and transactions as CSV from the app;
  • delete your entire account from your account settings, or by contacting us;
  • unsubscribe from our newsletter using the link in any newsletter email; and
  • request access, correction, deletion, or a copy of your data by emailing privacy@superbasicfinance.com.

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know, delete, and correct, and the right not to be discriminated against for exercising them. We do not sell or “share” personal information as those terms are defined under California law. If you are in the European Economic Area or the United Kingdom, you have rights under the GDPR/UK GDPR. We will verify requests and respond within the time required by applicable law, and we will not discriminate against you for making one. You may use an authorized agent where the law allows it. If we decline a request, we will tell you why, and you can ask us to reconsider by replying to that response. You also have the right to lodge a complaint with your local data protection authority.

10. Children’s privacy

The Service is not directed to children or teenagers, and you must be at least 18 years old to use it. We do not knowingly collect personal information from anyone under 18, including children under 13 as defined by the Children’s Online Privacy Protection Act. If we learn that we have collected information from someone under 18, we will delete it and close the account. If you believe a minor has provided us personal information, contact us at privacy@superbasicfinance.com and we will remove it.

11. Where we operate

The Service is operated from, and intended for users in, the United States, and we currently support U.S. financial institutions. Application and account data is processed primarily in the United States. Aggregate marketing-site analytics may be processed on infrastructure in the European Union, depending on whether we use Plausible’s hosted service or our own Plausible instance. If you access the Service from outside the United States, your information may be processed in the United States and the European Economic Area, where data protection laws may differ from those in your country.

12. Third-party links

The Service may link to third-party websites and services that we do not control. This policy does not apply to those third parties, and we encourage you to review their privacy policies.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.

14. Contact us

For privacy questions or to exercise your rights, email privacy@superbasicfinance.com or visit our Contact & Support page.