Legal
PRIVACY POLICY
Last updated: June 27, 2026 · Effective date: June 27, 2026
REYES ("we", "us", "our") provides a personal finance organizing tool. This policy explains what we collect, how we use it, who we share it with, how we protect it, and the choices you have. It applies to reyes.app, the REYES mobile app, and any related services that link to this policy.
1. Information we collect
We collect only what we need to run the product you asked for.
- Account information: name, email address, phone (optional), authentication identifiers, and account preferences.
- Profile data you enter: household details, income, taxes, debts, financial goals, vehicles, properties, and similar facts you choose to add.
- Bank and credit data via Plaid: if you connect an account, our aggregator (Plaid Inc.) returns read-only account metadata, balances, and transaction history. REYES never sees or stores your bank login credentials. Plaid uses bank-issued OAuth or tokenized access; we receive a short-lived access token tied to your REYES account.
- Credit-bureau data: if you opt in to score monitoring, our credit data provider returns score, factor codes, and a tradeline summary. We do not perform hard pulls without your explicit consent at the point of the action.
- Tax and identity documents: tax forms, IDs, statements, and receipts you upload to your Vault.
- Payment information: Stripe processes subscription payments. We receive a customer identifier, the plan you chose, and the last four digits of your card. We never see the full PAN.
- Privacy-sweep inputs: name, prior addresses, phone, email, and date of birth used only to submit data-broker opt-out requests on your behalf.
- Device and usage data: IP address, user-agent, OS, and timestamps for security, fraud prevention, and basic operation.
- Analytics (opt-in): anonymous aggregate events about which features get used, only if you accept the analytics banner.
2. How we use your information
- To operate, secure, and improve REYES — the refund finder, credit tools, privacy sweep, Captain assistant, tax package, and similar features.
- To personalize recommendations and surface money-back opportunities for you.
- To send transactional emails (sign-in, receipts, security alerts) and, only if you opt in, product updates.
- To prevent fraud, detect abuse, and meet our legal obligations.
- To process subscription payments through Stripe and apply your plan entitlements.
We do not use your bank or credit data to train general-purpose AI models, and we do not feed identifiable financial data into third-party advertising systems.
3. We do not sell your data
REYES does not sell personal information, does not share it with advertisers, and does not participate in cross-context behavioral advertising. We use first-party, privacy-respecting analytics that you can disable from Privacy settings.
4. How Plaid works inside REYES
When you connect a financial account, you authenticate directly with your bank or card issuer through Plaid's secure interface. Plaid returns to REYES a token, never your password. Using that token, REYES requests only the data the connected feature needs — typically balances, account metadata, and transactions. The connection is read-only: REYES cannot move money, change account settings, or initiate transfers from your bank.
You can disconnect any institution at any time from Settings → Linked accounts. Disconnecting revokes the token at Plaid and ends new data sync; previously stored transaction history is deleted from REYES within 30 days unless you ask us to retain it for your records.
Plaid's handling of your data is governed by Plaid's own privacy policy, available at plaid.com/legal.
5. Who we share with
- Subprocessors that run the service. Each is bound by a data-processing agreement and uses your data only to perform the service we contract for:
- Plaid Inc. — bank, card, and brokerage data aggregation.
- Stripe Inc. — subscription billing and payment processing.
- Lovable Cloud (managed Supabase / Postgres) — application database, authentication, file storage.
- Resend — transactional email delivery.
- Lovable AI Gateway — model inference for the Captain assistant. We do not send raw bank credentials, full account numbers, or government IDs to AI providers.
- Google reCAPTCHA / equivalent — abuse and bot protection on auth flows.
- Law enforcement only when legally required to respond and after we have reviewed the request.
- Successor entities in the event of a merger, acquisition, or asset sale; you will be notified before your data transfers.
6. Security and storage
- All traffic to REYES is encrypted in transit with TLS 1.2 or higher.
- Data at rest is encrypted with AES-256 on the managed Postgres database and object-storage buckets.
- Sensitive fields (SSN, full account numbers) are stored with additional application-layer protection and are revealed only after a re-prompt for your passcode or device biometric.
- Bank login credentials are never sent to or stored by REYES — Plaid handles that exchange.
- Database access is restricted by row-level security so each signed-in user can read and write only their own rows.
- Privileged backend operations (background automation, daily briefings, dispute escalations) run only from server endpoints that require a service credential and are not callable from the browser.
- App Lock with passcode and optional Face ID / fingerprint can be enabled from Settings → Security.
No system is perfectly secure. If we ever experience a breach affecting your personal information, we will notify you and the appropriate regulators in line with applicable law.
7. Data retention
- Account data — retained while your account is active.
- Bank-connection transactions — deleted within 30 days of disconnecting the institution, unless you ask us to retain them for your tax records.
- Tax records and uploaded documents — retained for as long as you keep them in your Vault. You can delete individually at any time.
- Account deletion — initiates a 30-day deletion window during which the account is recoverable; after that, personal data is removed from production systems within an additional 30 days. Records we are legally required to keep (tax, payment, fraud) are retained per the applicable statutory period.
- Backups — encrypted backups expire on rolling 35-day cycles.
8. Your rights
You can:
- Access, export, or correct your data from Settings.
- Delete your account at any time — starts the 30-day deletion window described above.
- Disable analytics from Privacy settings.
- Disconnect any linked financial account from Linked accounts.
California residents (CCPA / CPRA): you have the right to know, delete, correct, and limit use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising. To exercise these rights, email support@e2v.ai.
EEA, UK, and Swiss residents (GDPR / UK GDPR): the legal bases we rely on are contract (to provide the service), legitimate interests (security, fraud prevention, product improvement), consent (analytics, marketing email), and legal obligation (tax, anti-fraud). You have rights of access, rectification, erasure, restriction, portability, and objection. Where we process based on consent, you can withdraw it at any time without affecting prior processing.
9. International transfers
REYES is operated from the United States. If you access REYES from outside the US, your data will be transferred to and processed in the US. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.
10. Children
REYES is not intended for users under 18 and we do not knowingly collect data from children. If you believe a child has provided us information, email support@e2v.ai and we will delete it.
11. Cookies and similar technologies
REYES uses strictly-necessary cookies for sign-in and security, preference cookies you control from settings, and opt-in analytics cookies. We honor the browser's Do Not Track signal. See our Cookie Notice for the full list.
12. Changes
We will post material changes here and, where required, notify you by email. The "Last updated" date at the top of this page always reflects the current version.
13. Contact
Privacy questions, data-access requests, deletion requests, or complaints — email support@e2v.ai.
