Fortuneer

Privacy Policy

Effective July 28, 2026 · Last updated July 28, 2026

1. The short version

Fortuneer is a personal-finance app. To be useful it has to hold some genuinely sensitive information about you — your bank balances, what you spend money on, what you are saving for. This page explains, in plain English, exactly what we collect, why, and who else touches it.

The three things worth knowing up front: we do not sell your data, we do not share it with advertisers, and deleting your account deletes your data — including revoking the connections to your banks.

Fortuneer is operated from the United States and intended for users in the United States who are 18 or older.

2. What we collect

Everything below is either something you gave us or something you asked us to fetch.

Account information

  • your email address, and your name if you provide one;
  • your password — handled by our authentication provider, stored only as a salted hash. We never see, store, or have any way to recover your actual password;
  • a profile picture, if you upload one, and any custom logo you upload for an account.

Profile and preferences you enter

  • a preferred name, and what brought you to the app (your onboarding choices);
  • optionally, your city and state — state is used to add state tax to equity estimates, and both give Vera geographic context;
  • optionally, your approximate annual income and federal filing status, used only to estimate a tax bracket for equity vesting;
  • display and behavior preferences: currency, light/dark theme, sidebar order and hidden items, whether pending transactions count, whether unvested equity counts toward net worth, notification settings, and whether you want the “What’s New” popup.

Financial data from connected institutions (via Plaid)

When you link a bank or brokerage, you authorize the connection yourself inside Plaid Link, and you enter your bank credentials with Plaid — not with us. We never see or store your bank username or password. What we receive and store is:

  • the institution name and logo, and account names, types, and masks (last four digits);
  • current and available balances, and a history of balance snapshots over time;
  • transactions: date, amount, merchant or description, category, and pending status;
  • investment holdings: securities, quantities, prices, and cost basis.
  • the access token that keeps the connection alive — stored encrypted in Supabase Vault, not in our regular tables.

Data you enter yourself

  • manual accounts and manual transactions, including crypto holdings;
  • equity compensation grants (company, ticker, share counts, vesting schedule, notes);
  • budgets, savings goals and contributions, projection scenarios, and recurring items;
  • categories, categorization rules, tags, and notes you add to transactions;
  • transactions you import from a CSV file (for example an export from Mint, Monarch, YNAB, Rocket Money, or Copilot), along with a record of which import they came from;
  • messages you send us through the in-app support form.

Vera conversations

  • your chat history with Vera — your messages and her replies — stored in our database so you can revisit conversations;
  • a log of changes Vera makes at your request (for example setting a budget), so those changes can be reviewed and undone.

Technical and operational records

  • AI token usage per request — how many tokens a Vera request consumed, and on which platform. This is a count for cost and abuse monitoring; it is not tied to what you and Vera talked about;
  • logs of our scheduled background jobs (how many users were processed, how many notifications were sent, and any errors), and logs of our own calls to Plaid (endpoint, success, timing — no account contents);
  • application error logs and administrative event logs used to operate and debug the service.

We do not use advertising trackers, third-party analytics, or cross-site tracking cookies. The cookies we set are the ones that keep you signed in.

3. How we use it

  • To run the app — syncing your connected accounts, categorizing transactions, tracking budgets and goals, calculating net worth, detecting recurring charges, building reports and projections, and answering your questions through Vera;
  • To send you what you asked for — budget alerts, bill reminders, goal milestones, unusual-transaction alerts, stale-connection warnings, and the weekly digest. Email delivery follows your notification preferences and every digest email has a one-click unsubscribe link;
  • To send account and service messages — approval, denial, or support replies, and occasional notices about the service itself;
  • To keep the service working and secure — debugging, monitoring costs and abuse, and reviewing access requests during the invite-only beta;
  • To improve Fortuneer — understanding which features are used and where things break, so we can fix and build the right things.

We do not use your financial data to build advertising profiles, and we do not use your data to train AI models.

4. Who we share it with

We use a small number of service providers to run Fortuneer. Each gets only what it needs to do its job, and each is bound by its own agreement with us. This is the complete list:

  • Plaid Technologies, Inc. — connects your financial institutions and syncs account, transaction, and holdings data. You authorize the connection directly in Plaid Link, and Plaid handles your bank credentials. Plaid’s handling of your data is governed by Plaid’s End User Privacy Policy.
  • Groq, Inc. — runs the AI model behind Vera. Your messages and the financial context needed to answer them are sent to Groq. Before anything leaves our servers it passes through a filter that removes credentials and direct identifiers — access tokens and API keys, account and routing numbers, email addresses, and your full name. Merchant names, amounts, categories, and dates are deliberately kept, because without them Vera cannot answer anything useful. Groq does not use data submitted through its API to train models.
  • Resend — delivers our email. Resend receives your email address and the contents of the message we are sending you (for example, your weekly digest).
  • Supabase — provides our database, authentication, and file storage. Your data lives here. It is encrypted at rest and in transit, isolated per user by row-level security, and Plaid access tokens get an additional layer of encryption in Supabase Vault.
  • Vercel — hosts and serves the application. Server logs may contain IP addresses and request metadata.
  • Market data providers — to price your holdings we request quotes from public market-data endpoints (currently Yahoo Finance for stocks and indices, CoinGecko for crypto). These requests contain a ticker or coin symbol only — never your identity, your holdings, or how much of anything you own.

Beyond these providers, we may disclose information if we are legally required to (a subpoena, court order, or similar), or where necessary to investigate fraud, abuse, or a security incident. If Fortuneer were ever transferred to a new owner, your data would transfer with it, and this policy would continue to apply until you were told otherwise.

5. What we don’t do

  • We never sell your personal information — to anyone, for any price.
  • We never share your data with advertisers, data brokers, or marketing networks, and we do not run ads.
  • We never share your financial data with anyone beyond the providers listed in Section 4, each of which is there to make a feature you use work.
  • We do not let anyone train an AI model on your data, including us.

6. How your data is protected

Data is encrypted in transit and at rest. Every table that holds your data is protected by row-level security, so one account cannot read another’s. Plaid access tokens are held encrypted in Supabase Vault and are never exposed to the browser. Passwords are salted and hashed by our authentication provider.

No system is perfectly secure, and we cannot guarantee absolute security. Protecting your account also depends on you: keep your password strong and private, and turn on additional login protections such as multi-factor authentication when we make them available.

7. How long we keep it

We keep your data for as long as your account exists. There is no automatic expiry — your transaction history and balance snapshots are the product, so we keep them until you tell us otherwise.

Deleting your account deletes your data. You can delete your account yourself from Settings. Doing so revokes every connection to your financial institutions through Plaid, then permanently removes your profile, accounts, transactions, balance history, holdings, equity grants, budgets, goals, categories, rules, tags, notes, notification preferences, notifications, and Vera conversations. This is immediate and cannot be undone — export anything you want to keep first.

Two things outlive deletion. Operational logs that are not tied to your identity — job run counts, aggregated token usage, error traces — may persist for up to 30 days before rotating out. And routine encrypted database backups may hold residual copies for a short period before they expire on their normal schedule.

8. Your choices and controls

  • See what we hold — everything we have about you is visible in the app, and you can export your transactions to CSV at any time;
  • Correct it — edit your profile, accounts, transactions, and preferences directly in Settings and throughout the app;
  • Disconnect a bank — remove a linked institution from the Accounts page without deleting your account;
  • Control notifications — choose which alerts you get and whether they arrive by email, in Settings → Notifications, or unsubscribe straight from a digest email;
  • Delete conversations — remove individual Vera chats from the Vera page;
  • Delete everything — delete your account from Settings, as described in Section 7.

9. California privacy rights

If you are a California resident, the California Consumer Privacy Act (as amended) gives you specific rights. You have:

  • The right to know what personal information we collect, where it comes from, why we collect it, and who we share it with — Sections 2 through 4 describe all of it;
  • The right to access a copy of that information — it is visible in the app, and exportable to CSV;
  • The right to correct inaccurate personal information — you can edit it directly;
  • The right to delete your personal information — use “Delete account” in Settings, or ask us and we will do it;
  • The right to opt out of the sale or sharing of personal information, and the right to limit use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we use your sensitive information only to provide the service you asked for — so there is nothing to opt out of. We are stating the right here for completeness;
  • The right not to be discriminated against for exercising any of these rights. We will not deny you the service, charge you a different price, or degrade what you get.

To exercise any of these rights, use the controls in Settings or email us at support@fortuneer.app. We will verify your request against the email address on your account and respond within the timeframe the law requires. You may use an authorized agent to make a request on your behalf.

10. Age restriction

Fortuneer is for adults. You must be 18 or older to create an account. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has given us information, email us at support@fortuneer.app and we will delete the account and its data.

11. Changes to this policy

We will update this page when what we do with your data changes, and the “last updated” date at the top will tell you when that happened. If a change is material, we will let you know in the app rather than relying on you to check.

12. Contact us

Questions about privacy, or a request about your data? Email support@fortuneer.app, or use the support form inside the app. Your use of Fortuneer is also governed by our Terms & Conditions.

Terms & Conditions·Back to sign in