Means — Privacy Policy
Last updated: July 27, 2026
1. Overview
Means ("we", "our", "the app") is an AI-powered budgeting application. We are committed to protecting your privacy and financial data. This policy explains what data we collect, how we use it, and your rights.
2. Data We Collect
- Account Information: Email address and encrypted password (if you create an account). Device identifier for anonymous users.
- Financial Data: When you connect your bank accounts through Plaid, we access your account balances, transaction history, and account metadata (account name, type, institution).
- Budget Configuration: Monthly income, bills, and savings targets you enter manually.
- Purchase Information: If you subscribe to a paid plan, we receive your subscription tier, status (such as trialing, active, or expired), and renewal dates from the app stores via RevenueCat. Payment is handled entirely by Apple — we never see your card number or billing details.
- Diagnostics: Crash and error reports (such as error messages and app version) to help us find and fix bugs. These are not linked to your identity and are never used for advertising.
3. How We Use Your Data
- Calculate your daily, weekly, and monthly spendable amounts
- Provide AI-powered spending analysis and answers about your own transactions. Means is a budgeting tool, not a financial adviser, and does not provide financial, investment, tax, or legal advice
- Detect spending patterns and recurring transactions
- Send push notifications about your budget status (with your permission)
4. Plaid Integration
We use Plaid to securely connect to your financial institutions. When you link a bank account:
- Your bank login credentials are entered directly into Plaid's secure interface — we never see or store your bank username or password.
- Plaid provides us with an access token that allows us to retrieve your account and transaction data.
- Access tokens are encrypted using AES-256-GCM before being stored in our database.
- You can disconnect your bank accounts at any time.
Plaid's privacy policy: https://plaid.com/legal
5. Data Security
- All data is transmitted over HTTPS/TLS encryption.
- Financial access tokens are encrypted at rest using AES-256-GCM.
- User passwords are hashed using bcrypt with salt rounds.
- We use JWT tokens for authentication with automatic expiration.
- Our servers are hosted on secure cloud infrastructure with regular security updates.
6. Data Sharing
We do not sell or rent your data, and we never share it for advertising or marketing.
We share data only with the service providers below, strictly to operate the app:
- Plaid: To retrieve your bank account and transaction data.
- Anthropic (Claude AI): Means uses Anthropic's Claude in two ways. Automatically: when your transactions sync, we send merchant names and categories so spending can be labelled and tidied — this happens as part of normal syncing, whether or not you ever open an AI feature. When you ask: the AI chat and spending insights send the financial context needed to answer you, which can include recent transactions (merchant names, amounts, dates, and categories), your budget figures, and the messages you type. In neither case do we send your name, email, or account numbers. Anthropic processes this data only to generate the response and does not use it to train its models. Anthropic's privacy policy: https://www.anthropic.com/legal/privacy
- RevenueCat: Our subscription-management processor. RevenueCat receives your app user ID and store purchase receipts to keep your subscription status in sync across devices. It does not receive your financial data. RevenueCat's privacy policy: https://www.revenuecat.com/privacy
- Expo: If you turn on notifications, your device's push token is shared with Expo's push service solely to deliver those notifications. Push messages carry no transaction details, balances or amounts.
- Amazon Web Services: Our hosting and email provider. Your data is stored in AWS in the United States, and account emails (verification, password reset) are delivered through Amazon SES.
- Law enforcement: Only when legally required by court order or subpoena.
7. Data Retention
- Your data is retained as long as your account is active.
- You can delete your account and all associated data at any time through the app's Settings.
- Upon account deletion, all data including encrypted tokens, transactions, and settings are permanently removed within 30 days.
8. Your Rights
You have the right to:
- Access all data we have about you
- Request deletion of your data
- Disconnect bank accounts at any time
- Opt out of push notifications
- Export your transaction data
9. Children's Privacy
Means is not intended for users under 18 years of age. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify users of significant changes through the app.
11. Contact
For privacy questions or data requests, contact us at: privacy@means.finance