What we will never do
These are product commitments, not settings.
- Selling or renting personal financial data
- Showing advertising, or sharing data with advertisers
- Using your financial data to train advertising or third-party models
- Putting financial figures, account numbers or institution names in emails or logs
Where your financial information comes from
From you, when you type it in. Or, if you choose, from your financial institutions through Plaid.
When you connect an institution, you sign in with Plaid, not with us: Buttercup never sees or stores your bank username or password. Plaid then shares account, balance, transaction and liability information with us, and we use it only to show and project your plan. Plaid's handling of your information is described in its own End User Privacy Policy: plaid.com/legal/#end-user-privacy-policy
Connecting is optional. The service works with information you enter by hand.
What else we collect
Your name, email address and password hash for sign-in; the browser and platform of each signed-in device, so you can see and sign out your own sessions; the answers you give in onboarding; and the preferences you set. Your date of birth and your home address are never asked for.
Who can see your plan
You. Information is stored so that each person's records are readable only under that person's identity; the application itself cannot read across accounts. If you share a household plan, what is counted in the plan and what another person can see are separate choices you make.
Service providers
These companies receive personal information to provide one part of the service, and each one's terms limit its use of that information to providing that service. No one else receives it, other than as the law requires.
- Vercel, hosting: requests to the site, and server logs that carry no figure, token or account number.
- Supabase, database and sign-in: your account, your plan and your connected records, encrypted at rest; your email and password hash for sign-in.
- Plaid, connecting institutions: your sign-in at the institution, which we never see, and returns account, balance, transaction and liability information.
- Resend, email delivery: your email address and the message, which never carries a figure.
- Stripe, payments (planned, not yet in use): billing details when membership goes live; card numbers go to Stripe, never to us.
- Sentry, error monitoring (planned, not yet in use): error reports with personal information removed before they are sent.
How long information is kept
Your account, plan, history and connected records are kept while the account exists and deleted with it. Institution access tokens are invalidated at Plaid and removed when you disconnect or delete the account. Webhook receipts, which hold no figures, are kept 90 days; server logs 30 days; database backups 7 days. Billing records, once billing exists, are kept as tax and accounting law requires, then deleted.
Deleting your account
From your account settings. Your plan becomes read-only that day and is deleted in full after 14 days, at Plaid and at the sign-in provider too; during the 14 days one press keeps the account with everything as you left it. What survives is the fact that an account existed and was deleted, without personal data, and any billing record the law requires. Backups holding deleted data expire within 7 days.
Federal financial-privacy notice
Financial companies choose how they share your personal information, and federal law gives you the right to limit some sharing. Here is what we do.
What we collect: your name and email; the financial information you enter; account, balance and transaction information from institutions you choose to connect.
How we share it:
- For our everyday business purposes, such as keeping your account and your plan, and responding to your requests: yes, with the service providers above. This sharing cannot be limited because the service cannot run without it.
- For our marketing purposes: no.
- For joint marketing with other financial companies: no.
- For affiliates or nonaffiliates to market to you: no. We have no affiliates.
- As the law requires, such as in response to a valid legal process: yes.
Your rights and how to use them
Wherever you live, you can export everything the service holds about you and you can delete it, from your account settings, without asking anyone. To correct something, change it in your plan; a correction never rewrites history, it adds to it.
A request by email to support@withbuttercup.com is verified against the email on the account before anything is done, and answered within 30 days, or sooner where your state's law says so.
Personal information is never sold or shared for advertising, so a browser's Global Privacy Control signal asks for nothing we are not already doing; we treat it as honored.
Age
Buttercup is for adults, and creating an account includes confirming that you are 18 or older. We do not knowingly collect personal information from anyone under 18, and we do not collect dates of birth. If we learn that we hold information about someone under 18, we delete it.
Contact
Privacy questions: support@withbuttercup.com. Buttercup is operated by Mouliom Holdings LLC. Mailing address: Mouliom Holdings LLC, 5343 Belleville Crossing St Unit #1354, O'Fallon, IL 62226.
Changes to this policy
Not written yetWhat is missing:
- How much notice is given before a change, and how. The intended practice is notice by email; the period is not decided.