Privacy Policy — the Pinch application

Last updated · Version 1.3

This policy covers the Pinch application — the product you sign into at app.pinch.cash and connect your financial accounts to. The waitlist and marketing website have their own, much shorter privacy policy; this one exists because the application handles something the website never touches: your financial data.

Who we are

BYTESIZE, LLC, a Virginia limited liability company operating as Pinch, is the data controller for the information described below.

You can reach us about anything in this policy at privacy@pinch.cash.

What we collect, and why

Almost everything below is collected for one purpose: showing you your own finances. We do not use your data for advertising, we do not build profiles for anyone else’s benefit, and we do not sell, rent, or trade it — to anyone, for any purpose.

Your account. Your email address, a display name, and a password. The password is stored only as a modern cryptographic hash (argon2id) — we cannot read it, and at signup and every change it is checked against known data-breach corpora using a method (k-anonymity) that never sends the password itself anywhere.

Your financial data, via Plaid and MX. When you connect a bank or brokerage, we receive from our data providers: your accounts (names, types, masked account numbers, balances), transactions (dates, amounts, descriptions, merchant details and, where the provider supplies it, location and category), and — for investment accounts — holdings and investment activity. Your bank username and password never touch Pinch. You enter them inside Plaid’s or MX’s own connection window; what Pinch receives and stores is an access credential scoped to reading your data, which we additionally encrypt at the application level before it is stored. We also keep the provider’s original record of each delivery, so a correction can be re-run losslessly and a question about what a provider sent can be answered; it is not shown in the application, and it is deleted with the product when you delete your account.

What you add. Categories, tags, notes, display names, rules, split and transfer designations, manually created accounts and transactions, and any CSV files you import (we keep the raw file so a corrected import can be re-run losslessly — it is deleted with the product when you delete your account).

Your conversations with Penny. If you use the built-in assistant, the conversation transcripts are stored with your account so you can continue them.

Feedback. When you send Feedback from the signed-in app, we collect your Intent (which of bug, idea, praise, or confusion you picked), the body you write, optional Evidence (images — these may depict the Ledger), and a Stamp: your display name, email address, account id, which Ledger, which surface, app version, user-agent, and viewport. Feedback is a report to the operators. It is not shown in the application, and it is not part of the product you see. We keep reports because they are our own record of what people told us about the service, and we rely on our legitimate interest in running and improving Pinch to keep them.

Technical data. Server logs and traces record requests to keep the service working and to investigate problems; sign-in attempts are recorded (keyed by email and IP address) for rate-limiting and abuse prevention; your active sessions are listed so you can see and revoke them.

Cookies. The application uses cookies only to keep you signed in and to protect against request forgery — both strictly necessary. There are no advertising or analytics cookies in the application, and no third-party trackers of any kind.

The AI features, plainly

Two features send data to large-language-model providers, routed through our AI gateway (Pydantic AI Gateway):

  • Automatic categorisation sends a transaction’s description, amount, date, and account name, together with your category list, so a category can be suggested.
  • Penny sends your conversation and the financial data needed to answer the question you asked.
  • CSV import may send the first few lines of a file when our own parser cannot work out the column layout.

This processing happens solely to provide the feature you invoked. The model providers act as processors under their commercial API terms; we do not use your data to train models, and we do not send it to any AI service for any purpose other than answering your request.

Who else processes your data

Each of these acts on our instructions, and none may use your data for its own purposes:

  • Plaid and MX — the providers through which you connect financial institutions. Each also handles your data under its own end-user privacy policy, which applies alongside ours: Plaid’s policy, MX’s policy.
  • Render — hosts the application and the database where your data lives, encrypted at rest.
  • Cloudflare — provides our network edge, DNS, and delivers our transactional email (sent from mail.pinch.cash). Cloudflare R2 stores Evidence attached to Feedback.
  • GitHub — holds the Feedback board: each report’s Intent, body, Stamp, and links to its Evidence. After triage we may open a work item describing the problem in our own words; we do not copy your report, Stamp, or Evidence into that work item.
  • Logfire (Pydantic) — receives our server logs and traces for observability. Traces of the AI features above include the text sent to the model and its reply, which means transaction descriptions and your Penny conversation are recorded there as well as in your account. We keep this deliberately, because when the assistant answers wrongly the prompt is the only way to find out why — but it is a real copy of your data outside the database, so we say so plainly here and put a lifetime on it below.
  • Pydantic AI Gateway and the model providers behind it — as described in the AI section above.

We will not disclose your information to anyone else unless the law requires it of us.

How long we keep it

While your account exists, we keep your financial data so the product can show it to you — that is the product.

When you delete your account, the product goes, immediately and permanently: your financial data (the Ledger), imports and their raw files, rules, tags, Penny conversations, sessions, and the account itself. Before deleting our copy, we revoke our access at the provider side (Plaid and MX), so the data connections themselves are torn down, not orphaned. There is no soft delete, no retention of financial rows, and no backup carve-out — for the product, deleted means deleted, subject only to our database host’s normal backup expiry window. Feedback is kept through account deletion, for the reason above. Evidence attached to Feedback may depict the Ledger, so a picture of your financial data can outlive deletion for up to a year.

A residue outlives deletion, and it is worth being specific about it rather than calling it small:

  • Server logs are kept for 7 days, and traces for about 30 days, by our observability provider. Because those traces include AI prompts and replies, transaction text you sent to Penny can survive your account by up to a month. Deleting your account does not reach backwards into traces already recorded.
  • Backups. Our database host keeps point-in-time recovery snapshots covering the past 3 days, so deleted rows remain restorable from infrastructure backups for that long before ageing out. We do not restore from backup to revive a deleted account.
  • Abuse-prevention records (sign-in attempts keyed by email and IP) are deleted within 24 hours by a nightly job.
  • Feedback. GitHub issues on the Feedback board — Intent, body, Stamp, and links to Evidence — have no automatic expiry. Evidence images attached to Feedback age out at 365 days. Feedback is kept through a privacy@ erasure request as well, for the reason above.

Our full retention schedule — every category of data, its period, and the reason for it — is documented in our Data Retention and Disposal Policy.

Your rights

You can, at any time and without giving a reason:

  • See what we hold about you. The application itself shows you the product — that is what it is for — and you can ask us for a copy. Feedback is not shown in the app. A request for a copy of Feedback is answered from the Feedback board, only when it comes from the email on the Stamp. We do not search the board by name or account id. If you changed the email on your account after sending Feedback, a copy of those reports is still answered from the Stamp email.
  • Correct it — most of it directly in the application. You cannot correct Feedback in the app; a report is one-shot.
  • Delete your account and the product. Email privacy@pinch.cash from your current account address and we will execute the product deletion described above without undue delay, and in any case within 30 days. That request does not take Feedback. A request to delete the reports too is refused, for the reason above, and pointed at this policy. An in-app deletion control is coming; the right does not wait for it.
  • Complain to a data protection authority, depending on where you live.

Email privacy@pinch.cash for any of these. We do not require you to justify the request or speak to anyone first.

Security

Data is encrypted in transit (TLS 1.2 or better, enforced) and at rest, with provider credentials carrying a second layer of application-level encryption. Our full, current security posture — including how to report a vulnerability — is published in our security policy.

Where your information goes

We are a United States company and our providers store and process data in the United States. Where information originates in a jurisdiction that restricts such transfers, our providers use the safeguards required by law.

Children

Pinch is not for children. You must be 18 or older to use the application, and we do not knowingly collect information from anyone under 18.

Changes

This policy carries a version number. If we change it in a way that materially affects you, we will tell you in the application or by email before the change takes effect — not by quietly editing this page. The version and date above always identify the policy in force.