← Back to Clarity

Privacy Policy

Last updated: September 2, 2026

The short version

  • Your bank connections are read-only — Clarity can never move your money.
  • Your financial data is never sold and never used to train AI models.
  • AI processing happens server-side; your data isn’t stored on-device beyond your session.
  • Delete your account and your data is deleted with it.

1. Who we are

Clarity (“we”, “us”) operates the Clarity personal-finance application at clarityapp.money and on iOS, from Florida, United States. This policy describes what we collect, why, and the choices you have. Contact: support@clarityapp.money.

2. What we collect

Account information — your email address and authentication data when you sign up.

Financial data — when you connect a financial institution through Plaid, we receive read-only account information: account names, types, and balances, and transaction history (dates, amounts, merchant names, categories). We never see or store your bank username or password — those go directly to Plaid.

Content you create — categories, budgets, forecast entries, rules, notes, tags, receipts you upload, and your conversations with Sterling (chat history is stored so you can revisit it, and you can delete any thread).

Usage and device data — basic logs and diagnostics needed to operate and secure the Service. On the web app this also includes session replay: a masked recording of your screen, on a small sample of sessions and on sessions where an error happens. See “Session replay” in section 5. The iOS app does not record your screen.

3. How we use it

  • To provide the Service: sync accounts, categorize transactions, compute net worth, budgets, forecasts, and reports.
  • To power AI features: when you use Sterling, auto-categorization, or receipt scanning, relevant data is processed by our AI provider to generate the response.
  • To operate billing: subscription status and entitlements.
  • To secure, debug, and improve the Service.

We do not sell your personal information, and we do not share it with third parties for their advertising.

4. AI processing

Sterling and other AI features run server-side. The data needed to answer your request (for example, your transactions or forecast) is sent to our AI provider (Anthropic) to generate the response and is not used to train their models. AI output is generated for you and stored only as part of your chat history, which you control.

5. Service providers

We use a small set of processors, each only for what’s listed:

  • Plaid — connects your financial institutions (read-only). See the Plaid End User Privacy Policy.
  • Supabase — database, authentication, and storage.
  • Anthropic — AI processing for Sterling, categorization, and receipt reading.
  • RevenueCat & Apple — subscription billing and entitlements.
  • Vercel — application hosting.
  • Sentry — crash and error diagnostics, and session replay on the web app. See below.
  • Expo & Apple Push Notification service — delivering push notifications. Notification content passes through them, and that content can include an account name, a balance, or a merchant and an amount.
  • Resend — sending transactional email, such as a household invitation.

Session replay (web app only). On clarityapp.money we record a masked playback of your screen — a small sample of sessions, plus sessions in which an error happens — so we can see how the app is used and what actually went wrong. The iOS app does not record your screen. Every piece of text and every form input is replaced with asterisks before the recording leaves your browser, and images and charts are blocked out entirely rather than masked, so no figure on screen is readable in the recording and the charts arrive as empty rectangles.

Two things masking does not hide, which we would rather state than let you assume otherwise. Replacing text with asterisks preserves its length exactly, so a masked figure still shows how many characters it had — the digits are gone but the rough size of a balance or an amount survives. And everything that is not text comes through intact: the layout of each screen, which screens you visited and in what order, how many accounts and how many rows you have, and where on the page you clicked and scrolled. Nothing in a recording is readable, but a recording is not anonymous either.

What diagnostics record about what you do (web and iOS). Both the website and the iOS app send us crash, error and performance diagnostics, and both attach a trail of what happened just beforehand — which screens you moved between, what you clicked, and which requests your app made. What we record about a click is the kind of element it was and a fixed internal name for it, never the description we write for screen readers, which is where a merchant, an amount, a category or a date would otherwise have appeared. Those descriptions are unchanged for the people who need them; they are kept out of the diagnostics, not out of the app.

A diagnostic report is tied to your account. We attach your account number — an internal identifier, not your email — so that when something breaks we can tell whether it hit one person or everyone, and so we can find your report when you write to us about it. It is the one identifier that travels with every report, and we would rather say so than let the rest of this section imply that diagnostics arrive anonymous. What it never carries is your email address, a merchant, an amount, a balance or a category.

Web addresses, which reach us two ways. In the diagnostics trail an address is filtered on the way out: the endpoint and the names of its parameters are kept and every value is replaced, so a merchant, an amount, a date, an identifier or a search term is removed before it is sent. A session recording is different — it stores the address of the page, and the addresses of the images and links on it, exactly as they stood, and no filter of ours can edit that afterwards. So for recordings we keep the data out of the address in the first place rather than promising to strip it. Nothing in the app now puts a merchant, an amount, a date, a category or a search term into a page address: what you type into a search box stays on the page and never becomes part of its address, and creating a rule from a transaction used to carry the merchant and the category in the address and no longer does. On the website, receipt images are served from our own servers rather than through a link carrying an access key — the iOS app fetches them directly, where there is no recording to put them in. The investments screen sends the tickers you hold in the body of the request rather than in its address, and request bodies are not recorded at all. What can still appear in an address, and so in a recording, is an internal record number — which transaction or which receipt you opened. It says nothing about the merchant, the amount or the date.

One set of addresses we have not cleaned is our own. The internal support and usage screens that only we can reach put a customer’s account number in the address, so that number can appear in a recording of one of our sessions — never of yours, and never alongside a merchant or an amount. We would rather name it than let “no identifier travels inside an address” stand as a claim that is true of your screens and not of ours. Diagnostics and recordings go to Sentry as our processor, are never sold, and are never used for advertising.

6. Security

Data is encrypted in transit and at rest. Bank credentials are handled exclusively by Plaid. Access to your data is scoped to your account through row-level security, and AI/API keys live only on our servers. No system is perfectly secure, but read-only access means the Service cannot initiate movement of your money under any circumstances.

7. Retention and deletion

We keep your data while your account is active. Deleting your account deletes your data — accounts, transactions, forecasts, budgets, rules, chats, and receipts — from our production systems, with residual copies removed from backups on a rolling basis. You can also disconnect a financial institution at any time, or delete individual chat threads, transactions, and receipts in the app. To request deletion or a copy of your data, email support@clarityapp.money.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to certain processing. We honor these requests for all users regardless of jurisdiction — email us and we’ll handle it. We do not discriminate against you for exercising your rights.

9. Children

The Service is for adults. It is not directed to anyone under 18, and we do not knowingly collect data from children. If you believe a minor has created an account, contact us and we will delete it.

10. Changes

We’ll update this policy as the Service evolves. Material changes will be announced in the app or by email, and the date above will change.

See also our Terms of Service.