Privacy Policy
Effective July 12, 2026
Summary
Pipit is a personal finance tool. To do its job, we collect the financial and account information necessary to show it back to you — nothing more. We do not sell your data, we do not run advertising, and we do not use tracking or analytics scripts on Pipit's own pages. The rest of this page spells out exactly what we collect, why, who we share it with, and how to get it deleted.
What this Privacy Policy covers
This Privacy Policy covers how we treat Personal Data (any information that identifies or relates to you) that we collect when you access or use Pipit (the “Services”). It does not cover the practices of companies we don't own or control, such as your bank or the third-party services listed below. Your use of the Services is also subject to our Terms of Use.
Categories of Personal Data we collect
Over the course of providing the Services, we collect:
- Account data — your email address, hashed password, and (if enabled) an encrypted two-factor authentication secret. We never store your password in recoverable form.
- Profile data — your name, and settings you configure (notification preferences, display preferences).
- Financial and transaction data — account balances, transactions, and investment holdings for accounts you connect via Plaid or enter manually, plus budgets, goals, rules, tags, categories, and notes you create.
- Payment data — if you subscribe to Pipit Plus, a customer/subscription reference ID and subscription status from our payment processor, Stripe. We never receive or store your actual card number.
- Household data — if you create or join a household, your membership in it, and whichever specific accounts, goals, and transactions you or other members explicitly choose to share within it.
- Optional demographic data — birth year and ZIP code, only if you choose to provide them (Settings → General), used for net-worth percentile benchmarking and optional anonymized peer comparison.
- Device and log data — IP address, browser/device type, and standard request logs collected automatically by our hosting infrastructure (Netlify, Supabase) for security and debugging purposes.
- Other information you provide — anything you send us directly, such as a support email.
We do not knowingly collect Sensitive Personal Data as defined by U.S. state privacy laws (e.g., health, biometric, precise geolocation, or similar data) — nothing in Pipit's features asks for it.
Where this data comes from
Directly from you (when you sign up, enter data, or contact us); automatically through your use of the Services; from your financial institutions, via Plaid, when you connect a bank account (see below); and from other members of a household you belong to, for whatever they've chosen to share with that household.
Why we collect and use this data
To provide, operate, and improve the Services: creating and managing your account; processing subscription payments; syncing and displaying your financial data; computing budgets, goals, and insights; providing customer support; securing your account and detecting fraud or abuse; and responding to you when you contact us. We do not use your data for advertising, and we don't use it for any purpose materially different from these without telling you first.
Bank connections (Plaid)
When you link a bank account, you do so through Plaid, which collects your financial institution credentials directly — Pipit never sees or stores your bank username or password. Plaid provides Pipit with account balances, transactions, and investment holdings. Plaid's handling of your data is described in the Plaid End User Privacy Policy. Access tokens for your bank connections are stored encrypted (AES-256-GCM) at rest.
Payments (Stripe)
If you subscribe to Pipit Plus, your payment is handled entirely by Stripe. Pipit never receives or stores your card number — Stripe passes us only a customer/subscription reference and your subscription status (active, canceled, etc.), which we use to determine what features your account has access to.
Who we share data with
We disclose Personal Data only to the following categories of parties, and never sell it:
- Service providers who help us operate the Services: Plaid (bank connections), Stripe (subscription billing), Supabase (database hosting), Netlify (application hosting), Twelve Data (market price lookups — only ticker symbols are shared, never your identity or amounts), and Resend (transactional email).
- Household membersyou've chosen to share specific accounts, goals, or transactions with — see “Household sharing” below.
- Legal and safety purposes — if required to comply with law, legal process, or to protect the rights, property, or safety of you, Pipit, or others.
- Business transfers — if Pipit is involved in a merger, acquisition, or sale of assets, your data may transfer as part of that transaction, subject to this Privacy Policy (or one at least as protective).
Household sharing
If you create or join a household, other members can see whichever specific accounts, goals, and transactions you (or they) explicitly mark as shared — sharing is opt-in per item, not automatic, and only the owner of an item can share or unshare it. If you're added to a household, be aware that other members can see the data you or they choose to share, and Pipit isn't able to mediate disputes between members of the same household over shared data.
Aggregated, de-identified data
If you opt in to anonymized peer benchmarking (Settings → Preferences), we may include your data — stripped of anything that identifies you — in aggregated statistics shown to other users (for example, net-worth percentile comparisons). This is gated behind a minimum group size so a single opted-in user's data can never be reverse-identified, and you can opt out at any time. We may also use aggregated, de-identified data more generally to analyze and improve the Services.
Cookies
Pipit itself uses a single session cookie to keep you signed in. There are no advertising or tracking cookies, no analytics scripts, no session-replay technology, and no third-party trackers on Pipit's own pages. If you subscribe to Pipit Plus, Stripe's hosted checkout page (which you're briefly redirected to) sets its own cookies under Stripe's domain, governed by Stripe's privacy policy, not this one.
What Pipit does NOT do
Your financial data is never sold, rented, shared with advertisers, or used for any purpose other than showing it back to you and operating the Services. We do not run ads, and we do not engage in cross-context behavioral advertising or “sale” or “sharing” of your data as those terms are defined under U.S. state privacy laws.
Data security
We use appropriate technical and organizational measures to protect your data, including encryption of bank access tokens and password hashing. No method of transmitting or storing data online is completely secure, so we can't guarantee absolute security — but we work to keep it as safe as reasonably possible.
Data retention
We retain your Personal Data for as long as you have an account with us, so we can provide the Services. When you delete your account (see “Data deletion” below), we delete your data immediately, except where retaining it briefly is required by law (for example, financial transaction records Stripe/our payment processor is separately obligated to retain) or necessary to resolve a dispute or enforce our agreements.
Children's privacy
Pipit is not directed at, and is not knowingly used by, anyone under 18 (see the Eligibility section of our Terms of Use). We don't knowingly collect Personal Data from children under 18; if we learn we have, we'll delete it as quickly as possible. If you believe a child under 18 has provided us Personal Data, contact us at benjamin.kadison@gmail.com.
Your U.S. state privacy rights
Depending on where you live (including under laws such as the Texas Data Privacy and Security Act, the California Consumer Privacy Act, and similar laws in other states), you may have the right to: request access to the Personal Data we hold about you; request a portable copy of it; request that we correct inaccurate data; and request that we delete it. Because we don't sell your data or use it for targeted advertising, there is nothing to opt out of on that front — but we honor these rights for every user, regardless of state, as a matter of policy rather than only where legally required.
To exercise any of these rights: delete your entire account yourself at any time from Settings → General (see “Data deletion” below), or email benjamin.kadison@gmail.com for access, correction, or portability requests. We'll ask for enough information to verify it's really you before acting on a request. We won't discriminate against you (with different pricing or service quality) for exercising these rights. You may also designate an authorized agent to submit a request on your behalf, or, if we deny a request, contact your state Attorney General's office.
Data deletion
You can disconnect bank connections at any time from Settings → Institutions, which revokes Pipit's access at Plaid. You can permanently delete your entire account — profile, connections, transactions, budgets, goals, everything — immediately and yourself, at any time, from Settings → General. This isn't a request queue; it takes effect right away, no waiting period.
Changes to this Privacy Policy
We may update this Privacy Policy as Pipit changes. We'll update the date at the top of this page when we do, and for material changes, try to notify you directly. Continued use of the Services after a change takes effect means you accept the update.
Contact
Questions about this policy, or to exercise any of your privacy rights: benjamin.kadison@gmail.com