Effective August 14, 2026
Candor, LLC ("Candor," "we," "us," or "our") provides the Candor mobile application, its supporting services, and the candorfinance.app website (together, the "Services"). This Privacy Policy explains the information we collect, how we use and disclose it, and the choices available to you. It does not govern a third party's own website, application, or service.
Account and authentication information. We collect your email address, account identifiers, authentication provider, and optional display name. If you enable SMS multi-factor authentication, Firebase processes your phone number, verification information, and enrollment state. Firebase Authentication—not Candor's PostgreSQL database—handles passwords and other authentication credentials. Sign in with Apple may provide an Apple account identifier, email relay address, and name according to your Apple choices.
Financial information and user content. When you connect an account through Plaid, we receive the financial data you authorize, which may include account and institution details, transactions, balances, investments, liabilities, and related identifiers. Plaid receives bank credentials directly; Candor does not receive or store those credentials. We also process information you enter or import, including manual and CSV transactions, account names and balances, categories, notes, rules, recurring-payment choices, debt and retirement inputs, Mindful Mode responses, preferences, and household information.
Purchases and subscriptions. Apple processes payment instruments. Candor receives purchase and subscription records needed to provide and restore access, such as product and transaction identifiers, purchase and expiration dates, renewal state, and signed App Store transaction information. Candor does not receive your payment-card number.
Technical, usage, and consent information. We process Firebase and Candor user IDs, a Candor-generated install identifier, app version and platform, sync and last-active timestamps, policy and age confirmations, request paths, request timing and status, IP address, user agent, bank-connection health, and security and operational events. Firebase Crashlytics and Installations may receive crash traces, installation and session identifiers, device and OS information, app version, and related diagnostics. Candor does not attach its own account ID or custom user-data fields to Crashlytics in the current app.
Information that stays on the device. In the current version, an optional profile photo, biometric templates and results, transaction search terms, local notification content, and certain Mindful Mode details remain on your device. Candor stores only the Face ID or Touch ID enablement choice, not your biometric measurements. Original CSV files are read locally; financial rows created from an import can sync to Candor's server.
We receive information from you, your device and use of the Services, Apple, Firebase, Plaid and connected financial institutions, a household partner, and service providers that support authentication, hosting, email, reliability, and security.
We use information to authenticate and manage accounts; provide financial views, sync, categorization, reflections, household sharing, exports, and subscriptions; send verification, password-reset, household, and service messages; secure and troubleshoot the Services; prevent abuse; understand reliability and feature operation; comply with legal obligations; and enforce our terms. We limit connected financial data to what is reasonably necessary to provide the features you request. We do not use personal information for targeted advertising, cross-selling unrelated products or services, or sale.
If you join a two-person household, the other member can see shared financial records and household information, including the member name and email shown in the household experience. Shared information can include transactions, categories, connected-account balances and wealth data, rules, preferences, and planning records. Certain records remain individual, including authentication credentials, the local profile photo, and the ability to reconnect or disconnect a bank connection linked by the other member.
We use Apple for App Store purchases, StoreKit subscription reporting, Sign in with Apple, and Apple Push Notification service support.
We use Google Firebase for authentication, optional SMS MFA, Crashlytics, and installation diagnostics.
We use Plaid for bank connection and authorized financial data.
We use Railway for backend hosting, PostgreSQL storage, backups, and operational logs.
We use Better Stack for centralized server and security logs.
We use Resend for verification, password-reset, and household-invitation email.
We use GitHub Pages for hosting the public website.
We use Finicity/Mastercard only to identify and delete a historical connection if a legacy record remains. Candor does not offer new Finicity connections.
These providers process information under their own terms, privacy notices, and our applicable service arrangements. When a provider receives user data from Candor, we use applicable contracts and service terms to require it to use the data only for authorized services and to maintain protections consistent with this Policy and applicable law.
We disclose information to the providers above as needed to operate, secure, and support the Services; to the other member of a household as described above; when you direct or consent to a disclosure; to comply with law or valid legal process; to protect rights, safety, and the Services; and in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law. We may use information that has been aggregated or de-identified so it no longer reasonably identifies you.
We do not disclose nonpublic personal financial information to affiliates or nonaffiliated third parties for their own marketing or for joint marketing. Disclosures to nonaffiliated service providers are limited to authorized services and other purposes permitted by law.
Candor does not sell personal information, use it for third-party advertising, or track you across apps or websites owned by other companies for advertising or advertising measurement. Candor does not collect personally identifiable information about your online activities over time and across third-party websites or online services for tracking, and we do not knowingly permit another party to do so through the Services. Because Candor does not engage in that tracking, browser Do Not Track or Global Privacy Control signals do not change how the Services behave. Service providers may collect technical information for functionality, security, and diagnostics as described in this Policy. Disclosing information to service providers so they can operate Candor is not the same as promising that information is never shared.
Candor uses measures designed to protect information, including TLS for data in transit, iOS Data Protection for the local app store, encrypted server storage, certificate or public-key pinning for the Candor API, Keychain storage for sensitive local values, and AES-256-GCM envelope encryption for Plaid access tokens. We also use access controls, rate limits, audit logging, session protections, and provider cleanup safeguards. No security measure can guarantee absolute protection.
We generally retain account and financial records while your account is active or as needed to provide the Services. Some user-requested deletions are recoverable for a limited period before permanent removal. When you delete your Candor account, the active account and associated primary database records are removed, and provider deletion work for Firebase, Plaid, and any legacy Finicity record is queued and retried until confirmed or flagged for review. Deleting Candor does not cancel an App Store subscription, which must be managed through Apple.
Operational logs, security records, transactional-email records, backups, and provider-held records can remain for limited periods under configured retention schedules, legal requirements, fraud and security needs, dispute resolution, and each provider's deletion process. Records that no longer need to identify you may be retained in aggregated or de-identified form. Files you export or share are controlled by you and the destination you choose.
You can update profile information, manage MFA, disconnect bank accounts, export available data, leave a household subject to ownership rules, and delete your account in Settings. A successful bank disconnect asks Plaid to revoke Candor's connection and stops future retrieval through that connection; information already held by Candor is handled under the retention and deletion section above. You can manage or cancel the separate App Store subscription through Apple. Depending on where you live and subject to applicable exceptions, you may have rights to request access, correction, deletion, or portability of personal information, and to appeal a denied request. Contact privacy@candorfinance.app. We may need to verify your identity before completing a request.
The Services are intended for people age 18 and older. We do not knowingly collect personal information from anyone under 18. Contact us if you believe a minor has provided information to Candor.
We may update this Policy as the Services and legal requirements change. We will post the updated version and effective date and provide additional notice when required by law.
Candor, LLC
Roeland Park, KS 66205
privacy@candorfinance.app