Seven Financial

Privacy Policy

Last updated 10 August 2026.

Seven Financial shows you your own bank, card, and investment accounts in one place. This page explains exactly what it collects, who it goes to, and how to get rid of it.

What we collect

  • Your account data from your banks — balances, transactions, holdings, and credit-card due dates, retrieved through Plaid.
  • Your identity— the email address or Apple account you sign in with. If you use Sign in with Apple and choose to hide your email, we only ever see Apple's relay address.
  • A device token, if you turn on notifications, so alerts can reach your phone.

What we never see

Your bank username and password. Those are entered directly into Plaid, which is the same service your bank already works with. Seven Financial receives a read-only access token. It can see your balances and transactions; it cannot move money, and it cannot log in as you.

Who your data goes to

  • Plaid connects to your financial institutions. Plaid's privacy policy.
  • Supabase stores your sign-in identity.
  • Vercel and Neon/Supabase Postgres host the service and its database, in the United States.
  • OpenAI receives only the questions you type in the Ask tab and the specific figures needed to answer them. It is not sent your credentials, your account numbers, or your data in bulk, and it is not used to train models on your information.
  • Apple delivers push notifications. Alert text necessarily passes through Apple to reach your device.
  • Google Analytics receives anonymous usage measurement: which screens you open, which steps of setup you complete, whether connecting a bank succeeded or failed, and which plan you chose. It is used to find the parts of the app that are broken or confusing.

Your data is not sold, rented, or shared with advertisers. There is no advertising SDK in the app, and no advertising identifier is read — the analytics library is built specifically without it, which is why the app never asks permission to track you. Nothing you do here is linked to your activity in other companies' apps or websites.

What analytics never receives: your balances, your net worth, any transaction amount, any merchant or payee name, your account or card numbers, your name, or your email address. The figures you estimate during setup are sent only as broad ranges, never as the number you typed. Error messages are reduced to short codes first, so the name of your bank cannot travel inside one.

The public website (this site and the blog — not the app, and never your financial data) uses Google Analytics to count visits and see which pages people find useful. It sets cookies in your browser on those public pages only.

How it's protected

  • Plaid access tokens are encrypted at rest with AES-256-GCM. The encryption key is held as a server environment variable, never in the database and never in the app.
  • Everything travels over HTTPS.
  • On your phone, your session is kept in the iOS Keychain, and the app can be locked behind Face ID.
  • Every request is scoped to your account in the database query itself, so one user's data cannot be returned to another.

Deleting your data

In the app, open Settings → Delete account. This immediately and permanently removes your accounts, transactions, balances, history, and sign-in record, and revokes every Plaid connection. It cannot be undone, and it does not require emailing anyone.

You can also disconnect a single institution at any time without deleting your account.

How long it's kept

Until you delete it. Seven Financial keeps transaction history and a daily net worth reading so it can show you trends over time; both disappear with your account.

Children

Seven Financial is not intended for anyone under 18 and is not directed at children.

Changes

If this policy changes in a way that affects what we collect or who receives it, the app will tell you before the change takes effect.

Contact

Questions, or want your data removed manually? support@sevenfinancial.app