Privacy Policy

Last updated: July 24, 2026

1. What we collect

Account data — your name, email address, and a hash of your password.

Financial data — accounts, balances, and transactions you add manually or that are retrieved from institutions you connect through our data aggregator (currently Plaid Inc.).

Technical data — session information (such as IP address and browser user agent) used to keep your account secure.

Billing data — if you subscribe, payment is handled by Stripe, Inc.; we store a Stripe customer reference and your subscription status, never card numbers.

Connected AI apps — if you connect an AI assistant (via MCP), every change it makes is recorded in an audit log with the app's identity and a before/after snapshot. You can revoke an app's access at any time from Settings → Profile → Connected apps.

2. How we use it

Solely to operate the Service for you: displaying your accounts and activity, computing budgets and net worth, keeping your session secure, and syncing with institutions you have connected. We do not sell your data, share it with advertisers, or use it to build profiles for anyone else.

3. Bank data and Plaid

Connections to financial institutions are made through Plaid. Your bank username and password are entered with Plaid, not with us — we never receive or store them. Plaid issues us an access token, which we store encrypted (AES-256-GCM) and use only to retrieve your account and transaction data. Plaid's handling of your information is governed by their end-user privacy policy, available at plaid.com/legal. You can also review and revoke your Plaid connections at any time at my.plaid.com (Plaid Portal).

4. Storage and security

Data is stored in an encrypted PostgreSQL database and, for uploaded receipts, private object storage — both on Amazon Web Services infrastructure operated by Honeycomb Robotics, Inc. (dba dtz). Encrypted database backups are kept for up to 90 days. Aggregator access tokens are additionally encrypted at the application layer; passwords are hashed; transport is encrypted in production deployments. Service providers we rely on: AWS (hosting), Plaid (bank connections), Stripe (payments), and our transactional email provider. No system is perfectly secure — use a strong, unique password and consider enabling two-factor authentication in Settings.

5. Retention and deletion

Your data is retained while your account exists. Deleting your account removes your user record, and cascading deletion removes your bank connections, accounts, transactions, and budgets; deleted data then ages out of backups within 90 days. If your workspace has other members, you'll be asked to remove them first so their shared data isn't destroyed with your account. Disconnecting a bank connection revokes our access with the aggregator and removes its synced data.

6. Your rights

You can access and correct your data in the app, and delete your account at any time from Settings → Profile — deletion removes your account and all of its financial data, revokes bank connections, and deletes uploaded receipts. To export your data, email privacy@dtz.life. Depending on where you live, you may have additional statutory rights (such as under GDPR or CCPA) — requests can be made to the operator of this instance.

7. Changes

We may update this policy from time to time; the date above reflects the latest revision. Material changes will be communicated through the Service.

8. Contact

dtz.life is operated by Honeycomb Robotics, Inc. (dba dtz), Fresno, California. Privacy questions and requests: privacy@dtz.life. See also our Terms of Service.