Privacy Policy

Last updated: March 2026

This privacy policy is pending final review by legal counsel prior to public launch. The substance reflects our actual data practices.

1. Introduction

Canopy Financial LLC ("Canopy," "we," "our," or "us") is a Tennessee limited liability company that operates the Canopy Financial OS platform at canopymoneyos.com (the "Service"). Canopy is a personal and family financial dashboard that aggregates your financial accounts, provides AI-powered insights, and helps you budget, track debt, monitor investments, and plan for your goals.

This Privacy Policy explains how we collect, use, disclose, store, and protect your information when you use our Service. By creating an account or using Canopy, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.

2. Information We Collect

2.1 Personal Information

When you create an account, we collect the following through our authentication provider, Clerk:

  • Full name
  • Email address
  • Profile photo (if you sign in with Google OAuth)

We do not collect or store your authentication passwords. Authentication credentials are managed entirely by Clerk.

2.2 Financial Data

When you connect your financial institutions through Plaid, we receive read-only access to:

  • Account information — account name, type (checking, savings, credit card, loan, investment), current and available balances, and account and routing numbers for identity verification purposes
  • Transaction data — amount, date, merchant name, category, pending status, and location (if available)
  • Investment holdings — securities, quantities, current values, and cost basis
  • Liability information — loan balances, annual percentage rates (APR), minimum payment amounts, and payment due dates

Your bank login credentials never touch Canopy servers. All bank authentication is handled directly by Plaid through their secure infrastructure. Canopy receives only the read-only financial data described above.

2.3 Payment Information

If you subscribe to a paid plan, your payment is processed by Stripe. Canopy never receives, processes, or stores your full credit card number, debit card number, or bank account number for payment purposes. Stripe provides us with limited information such as the last four digits of your card, card brand, expiration date, and billing postal code so we can display payment details in your account settings.

2.4 User-Provided Data

You may provide additional information while using the Service, including:

  • Budget categories and spending targets
  • Financial goals (amounts, due dates, descriptions)
  • Manual account entries and balance adjustments
  • Transaction recategorizations and merchant rules
  • Debt details (balances, interest rates, payment amounts)
  • Income source labels and group assignments
  • Preferences, notification settings, and theme choices

2.5 AI Interaction Data

When you use Canopy's AI-powered features (including the Command Center chat, daily financial stories, and automated recommendations), we process portions of your financial data through third-party AI models. See Section 7 for details on how we handle AI processing.

2.6 Usage and Technical Data

We automatically collect certain technical information when you use the Service, including:

  • Pages visited, features used, and actions taken within the Service
  • Browser type, operating system, and device information
  • IP address and approximate geographic location
  • Referring URLs and access timestamps
  • Error logs and performance data

3. How We Collect Information

3.1 Directly From You

We collect information that you voluntarily provide when you create an account, connect financial institutions, configure budgets and goals, interact with the AI chat, or contact our support team.

3.2 From Third-Party Services

We receive financial data from your linked institutions through Plaid, authentication data from Clerk, and payment confirmation data from Stripe. Each of these providers operates under their own privacy policies and security standards.

3.3 Automatically

We collect usage and technical data automatically through server logs, cookies, and similar technologies when you access or use the Service. We use only essential cookies required for authentication and session management. We do not use advertising or tracking cookies.

4. How We Use Your Information

We use the information we collect to:

  • Provide the Service — aggregate and display your financial accounts, balances, transactions, investments, and liabilities in a unified dashboard
  • Generate AI-powered insights — produce personalized financial stories, spending analysis, budget recommendations, debt optimization strategies, and chat responses
  • Detect patterns — identify recurring charges, subscription patterns, and unusual spending activity
  • Support budgeting and goals — track spending against budgets, monitor goal progress, and auto-fund goals from detected savings transfers
  • Forecast cash flow — project upcoming income and expenses over a 30-day window
  • Process payments — manage your subscription billing through Stripe
  • Communicate with you — send daily coffee brief emails, weekly financial summaries, balance nudge reminders, and service-related notifications
  • Maintain security — authenticate users, detect fraud or abuse, and protect the integrity of the Service
  • Improve the Service — analyze usage patterns to develop new features, fix bugs, and enhance performance

We do not sell your personal information or financial data. Your data is never sold, rented, or traded to third parties for marketing, advertising, or any other commercial purpose.

5. How We Share Your Information

We share your information only with the third-party service providers necessary to operate the Service. We do not share your data with data brokers, advertisers, or any parties not listed below.

5.1 Plaid (Financial Data Aggregation)

Plaid connects your bank accounts to our Service and transmits your financial data to us. See Section 6 for a detailed disclosure of Plaid's role.

5.2 Stripe (Payment Processing)

Stripe processes subscription payments on our behalf. Stripe receives your payment method details (credit card number, expiration date, billing address) directly. See Section 8 for details.

5.3 Clerk (Authentication)

Clerk manages user authentication, including account creation, login sessions, and single sign-on (SSO) via Google OAuth. Clerk stores your email address, name, profile photo, and authentication credentials. You can review Clerk's privacy policy at clerk.com/legal/privacy.

5.4 Google Gemini and OpenAI (AI Processing)

Summarized financial data is sent to Google Gemini (primary) and OpenAI (fallback) to generate personalized insights, recommendations, and chat responses. See Section 7 for details on AI processing and data scrubbing.

5.5 Resend (Email Communications)

Resend delivers transactional and summary emails on our behalf, including daily coffee briefs, weekly financial summaries, and service notifications. Resend receives your email address and the content of each email. You can review Resend's privacy policy at resend.com/legal/privacy-policy.

5.6 Supabase (Data Storage)

Supabase provides the PostgreSQL database infrastructure where your financial data, preferences, and account information are stored. All data is encrypted at rest and protected by row-level security policies. You can review Supabase's privacy policy at supabase.com/privacy.

5.7 Vercel (Application Hosting)

Vercel hosts the Canopy application and processes HTTP requests. Vercel may collect standard server logs including IP addresses, request URLs, and timestamps. You can review Vercel's privacy policy at vercel.com/legal/privacy-policy.

5.8 Cloudflare (DNS)

Cloudflare provides DNS routing for our domain. Cloudflare may process IP addresses and request metadata as part of DNS resolution. You can review Cloudflare's privacy policy at cloudflare.com/privacypolicy.

5.9 Other Disclosures

We may also disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a law enforcement request. In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction, and we will notify you via email or a prominent notice on the Service.

6. Plaid Financial Data

Canopy uses Plaid Inc. to connect your financial institution accounts to our Service. When you link an account through Plaid, you authorize Plaid to access your financial data on your behalf and transmit it to Canopy.

6.1 What Plaid Collects

When you connect an account, Plaid may collect and transmit the following information from your financial institutions:

  • Account and routing numbers for identity verification
  • Account balances (current and available)
  • Transaction history (amounts, dates, merchants, categories, pending status)
  • Account owner information (name, address)
  • Investment holdings (securities, quantities, values, cost basis)
  • Liability details (loan balances, APR, minimum payments)

6.2 Plaid's Data Practices

Plaid's use and transfer of information received from financial institutions is governed by the Plaid End User Privacy Policy. We encourage you to review this policy to understand how Plaid handles your data.

6.3 Credential Safety

Your bank login credentials are never transmitted to, stored on, or accessible by Canopy servers. When you link an account, you authenticate directly with your financial institution through Plaid's secure interface. Canopy receives only the read-only financial data described above — we cannot initiate transfers, move money, or make changes to your accounts.

6.4 Managing Your Plaid Connections

You can review and manage your connected financial accounts at any time through:

  • Within Canopy — visit the Accounts page in your dashboard to unlink any connected institution
  • Plaid Portal — visit my.plaid.com to view all applications connected to your financial accounts through Plaid and revoke access to any of them

7. AI Processing Disclosure

Canopy uses artificial intelligence to provide personalized financial insights. We want to be transparent about how your data is processed by AI systems.

7.1 AI Providers

We use Google Gemini as our primary AI model, with OpenAI as a fallback. These providers process financial data summaries to generate:

  • Daily financial stories (Pulse)
  • Chat responses to your financial questions
  • Spending insights and budget recommendations
  • Debt optimization strategies
  • Subscription waste detection
  • Cash buffer and emergency fund recommendations

7.2 Data Scrubbing

Before sending data to AI providers, we scrub personally identifiable information (PII) from the financial summaries. The following categories of information are removed before AI processing:

  • Phone numbers
  • Social Security numbers
  • Full account numbers and routing numbers
  • Physical addresses

AI providers receive aggregated and summarized financial data (such as spending totals by category, account balance ranges, and transaction patterns) rather than raw transaction-level detail wherever possible.

7.3 AI Data Retention

We do not permit AI providers to use your financial data for training their models. Data sent to Google Gemini and OpenAI is processed under their respective API terms of service, which prohibit using API inputs for model training. We use these services through their API interfaces, not consumer-facing products.

8. Stripe Payment Processing

Subscription payments for Canopy's paid plans (Pro at $11.99/month or $119.88/year) are processed by Stripe, Inc. When you subscribe, you provide your payment method details directly to Stripe through their secure payment form. Canopy never receives, transmits, or stores your full card number.

Stripe may collect and store your payment method details, billing address, and transaction history in accordance with their privacy policy. You can review Stripe's privacy practices at stripe.com/privacy.

Stripe is certified as a PCI Level 1 Service Provider, the highest level of certification available in the payments industry.

9. Data Security

We take the security of your data seriously and implement appropriate technical and organizational measures to protect your information, including:

  • Encryption in transit — all data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS)
  • Encryption at rest — all data stored in our database is encrypted at rest using AES-256 encryption
  • Row-level security (RLS) — our database enforces row-level security policies ensuring that each user can only access their own data
  • No credential storage — we never store your bank login credentials, passwords, or full payment card numbers
  • Read-only access — our connection to your financial institutions through Plaid is strictly read-only; we cannot initiate transactions, move money, or modify your accounts
  • Authentication security — user authentication is managed by Clerk, which provides industry-standard session management and supports single sign-on
  • Infrastructure security — our application is hosted on Vercel with automatic security updates, and our database is managed by Supabase with enterprise-grade security controls

While we implement commercially reasonable security measures, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of your data.

10. Data Retention

10.1 Active Accounts

We retain your personal information and financial data for as long as your account is active and as needed to provide you with the Service. Financial transaction data is retained to provide historical reporting, trend analysis, and year-over-year comparisons.

10.2 Account Deletion

If you delete your account, we will delete your personal information and financial data from our active systems within 30 days. This includes:

  • Your profile information and preferences
  • All linked financial account data
  • Transaction history and categorizations
  • Budgets, goals, and debt tracking data
  • AI chat history and generated recommendations
  • Email communication preferences

Certain information may be retained beyond 30 days where required by law (such as billing records for tax purposes) or where necessary to resolve disputes or enforce our agreements. Backup copies may persist in our backup systems for up to 90 days before being automatically purged.

10.3 Plaid Connection Revocation

Deleting your Canopy account will disconnect your linked financial institutions. You can also independently revoke Canopy's access to your financial data through the Plaid Portal.

10.4 Anonymized Data

Aggregated, anonymized data that cannot be used to identify you may be retained indefinitely for analytical and service-improvement purposes.

11. Your Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information:

11.1 Right to Access

You can request a copy of the personal and financial data we hold about you. Much of this data is already accessible directly through your Canopy dashboard.

11.2 Right to Delete

You can request deletion of your account and all associated data. You can initiate account deletion from your Settings page or by contacting us at support@canopymoneyos.com. Deletion will be completed within 30 days.

11.3 Right to Export

Pro and Family plan subscribers can export their financial data in CSV format directly from the Canopy dashboard. If you need a data export in another format, contact us and we will accommodate your request within a reasonable timeframe.

11.4 Right to Correct

You can update or correct inaccurate personal information through your Canopy dashboard Settings page. For corrections to data that cannot be modified through the dashboard, contact us at support@canopymoneyos.com.

11.5 Right to Revoke Financial Access

You can disconnect any linked financial institution at any time through the Accounts page in your dashboard. You can also revoke Canopy's access to your financial data through the Plaid Portal.

11.6 Right to Opt Out of Communications

You can opt out of non-essential email communications (daily coffee briefs, weekly summaries, and balance nudge reminders) at any time through your Settings page or by clicking the unsubscribe link in any email. Service-critical communications (such as security alerts and billing notifications) cannot be opted out of while your account is active.

To exercise any of these rights, contact us at support@canopymoneyos.com. We will respond to your request within 30 days.

12. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

12.1 Categories of Information Collected

In the preceding 12 months, we have collected the following categories of personal information:

  • Identifiers — name, email address, IP address, account identifiers
  • Financial information — bank account details, transaction history, investment holdings, loan information (obtained through Plaid)
  • Commercial information — subscription purchase history, payment records
  • Internet or electronic network activity — browsing history within the Service, feature usage, interaction data
  • Inferences drawn from the above — AI-generated financial insights, spending patterns, budget recommendations

12.2 No Sale of Personal Information

We do not sell your personal information. We have not sold personal information in the preceding 12 months, and we have no plans to sell personal information. We do not share personal information for cross-context behavioral advertising.

12.3 Your CCPA Rights

As a California resident, you have the right to:

  • Know — request that we disclose the categories and specific pieces of personal information we have collected about you
  • Delete — request deletion of your personal information, subject to certain exceptions
  • Correct — request correction of inaccurate personal information
  • Non-discrimination — we will not discriminate against you for exercising any of your CCPA rights

12.4 How to Submit a Request

To submit a CCPA request, email us at support@canopymoneyos.com with the subject line "CCPA Request." We will verify your identity before processing your request and respond within 45 days as required by law.

13. Children's Privacy

Canopy is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. The Service involves financial account management that requires users to be of legal age to hold financial accounts.

If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe that a child under 18 has provided us with personal information, please contact us at support@canopymoneyos.com.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Notify you by email at the address associated with your account
  • Post the updated policy on this page with a revised "Last updated" date
  • Where required by law, seek your consent to the updated terms

Your continued use of the Service after we post changes to this Privacy Policy means you accept those changes. We encourage you to review this page periodically for the latest information on our privacy practices.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Canopy Financial LLC
Email: support@canopymoneyos.com
Website: canopymoneyos.com

We will respond to all privacy-related inquiries within 30 days of receipt.