SageFinSageFin

Privacy Policy

Last updated: September 6, 2026

At SageFin, we take your privacy seriously. Please read this Privacy Policy to learn how we treat your personal and financial data. By using or accessing our services in any manner—including the website at sagefin.app, the product app, and the SageFin mobile companion—you acknowledge that you accept the practices and policies outlined below, and you consent to our collecting, using, and disclosing your information as described in this Privacy Policy.

SageFin ("SageFin," "we," "us") provides personal finance tools. This policy describes what we collect, why we collect it, and how it is stored and shared, based on how the product is built and operated today.

1. Who this applies to

This policy applies to people who visit our marketing site, create or use a SageFin account (web or mobile), connect financial institutions, or contact us for support. SageFin is currently offered as a private / invite-only beta.

2. Information we collect

Account and identity

When you sign up or are invited, we process identifiers such as your email address, identity-provider subject ID, and optional display name. Login is handled by Clerk (including passwordless email one-time codes when enabled).

Household membership

Financial data in SageFin is organized by household. If you join or create a household, members of that household can see shared accounts, balances, transactions, budgets, and related settings for that household. Notifications remain associated with your user account.

Bank and payment account data (Plaid)

If you link a bank or similar institution through Plaid, we receive and store account metadata (institution, account names/types, balances), transaction history (amounts, dates, merchant/name, categories, pending status, and where Plaid reports it, the merchant location a transaction occurred at — street address, city, state, postal code, country and store number, but not GPS coordinates), and technical tokens needed to keep that connection syncing (such as access tokens, item IDs, and sync cursors). Bank login credentials are entered in Plaid's interface and are not collected by SageFin.

Apple Card and Wallet data

On supported iPhones, with your consent and Apple's FinanceKit entitlement, SageFin can read eligible Apple Wallet financial data (for example Apple Card balances and transactions) on device and send that data to our API so it can appear alongside your other accounts. Separately, if you use SageFin's Apple Card capture / export flow on the web, we may store encrypted session material needed to complete that export and the resulting transaction data.

Retail order history

If you connect supported retail accounts (such as Amazon, Walmart or Costco), we may store order, receipt and item details (including amounts, dates, merchants/products, and related metadata) and encrypted session secrets required to refresh that data.

Budgets, rules, preferences, and notifications

We store budgets, categories, tags, merchant mappings you customize, alert rules, household preferences (such as timezone and currency), and in-app notifications generated by the product.

AI and chat inputs

When we categorize transactions or answer chat questions, we send relevant financial context to our AI providers—typically merchant or transaction names, amounts, dates, category lists, your prompt, and tool results returned from your household's data (for example spending summaries). Chat requests are processed to generate a response; we do not currently persist full chat transcripts as a long-lived history store.

Technical and operational data

We collect standard technical logs and telemetry needed to run and secure the service (for example request metadata, error traces, and performance metrics). We aim not to put sensitive personal financial details into application logs.

Help center searches

When you search the help center we record what you typed and how many results it returned, so we can see which articles are missing. This is not linked to you or to any account — we store the words and a count, and nothing else. Searches that look like they contain a card or account number, or an email address, are discarded rather than stored, and what we do keep is deleted after 90 days.

3. How we use information

  • Authenticate you and manage invite-only access
  • Sync and display balances, transactions, and connected accounts
  • Categorize spending, normalize merchants, track budgets, and surface insights or alerts
  • Power conversational AI features that query your household data
  • Provide CSV export and account connection management tools
  • Secure, debug, and improve reliability of the service
  • Respond to support requests

4. How sharing and third parties work

We do not sell your personal information. We share data with processors that help us provide SageFin:

  • Clerk — authentication and account identity (including login emails / one-time codes)
  • Plaid — bank linking, account/transaction sync, and related webhooks
  • Apple — FinanceKit / Wallet access on device (with your consent) and Apple Card–related flows where applicable
  • AI providers — such as Azure OpenAI or other configured model endpoints used for categorization and chat
  • Amazon / Walmart / Costco — when you connect those retail integrations; we may also use anti-bot/solving providers (for example CapSolver) solely to complete those connector flows
  • Hosting and edge — application and database hosting (currently Hetzner Cloud in the United States) and Cloudflare for DNS / secure edge access
  • Observability — operational telemetry via OpenTelemetry to Grafana Cloud

To improve categorization quality, SageFin may reuse high-confidence merchant-to-category mappings derived from transaction enrichment across users. Those mappings are about merchants/categories, not a dump of your full transaction history.

5. FinanceKit and financial data on iOS

If you use SageFin's iOS companion with FinanceKit enabled, Apple requires that we explain Wallet financial data use clearly. With your permission, SageFin reads eligible account, balance, and transaction information from FinanceKit on your device and transmits it to SageFin's servers so we can store it with your household, show it in the app, categorize it, and include it in budgets, alerts, and AI-assisted insights—just like other linked accounts. You control which accounts and time ranges Apple lets the app access. You can disconnect Apple Card / Wallet sync in the product; you can also revoke access in iOS Settings.

6. Storage, security, and location

Production application data is stored in PostgreSQL operated as part of our hosted environment (currently in the United States). Secrets such as retail/Apple Card session material are protected with application-level encryption (ASP.NET Data Protection). Plaid access tokens and similar connection credentials are stored server-side and are not exposed to browsers or mobile clients. Access to household financial APIs is scoped to authenticated members of that household. No security measure is perfect; if we become aware of a breach that affects you, we will take appropriate steps and notify you where required.

7. Retention

We keep account, household, and connected financial data for as long as your account remains active and the data is needed to provide SageFin. You can disconnect linked institutions (which removes the associated synced transactions for that connection) and delete eligible manual accounts. Transaction CSV export is available in the product.

You can delete your account yourself. In the app, go to Settings → Security → Delete account and confirm with your email address. This permanently deletes your SageFin data — accounts, transactions, budgets, goals, rules, receipts and the rest — without contacting us. If you share a household with other members and you own it, transfer ownership or remove them first; if you are not the owner, deleting your account leaves the household and the remaining members keep their data.

Your sign-in identity goes too. It is held by Clerk, our authentication provider, and deleting your account asks Clerk to remove it — so there is nothing left to sign in with.

One thing outlives that deletion, and we would rather say so than imply otherwise. Encrypted backups may hold a copy of your data for up to 60 days before they expire on their own; if we ever restore from a backup, we re-apply deletions. Operational logs may also retain limited records for a short period. You can still write to [email protected] about any of this — you just do not have to in order to delete your account.

8. Your choices

  • Connect or disconnect banks, retail accounts, and Apple Card sync
  • Override categories and manage budgets, rules, and preferences
  • Export transactions (CSV) where the product provides export
  • Leave a household (subject to household ownership rules)
  • Delete your account and its data yourself, in Settings → Security
  • Contact us to correct information
  • For FinanceKit, manage or revoke iOS permission in system settings

9. Children

SageFin is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

10. Changes

We may update this policy as the product or our practices change. We will post the updated policy here and revise the "Last updated" date. Material changes may also be communicated in the product or by email when appropriate.

11. Contact

Questions about privacy or this policy: [email protected].

Operator: SageFin / Bytefoo — domain sagefin.app.