Back

Privacy

Last updated May 26, 2026

The short version

Vigilance shows you your own money. We pull balances from your banks (with your permission, through Plaid), store them row-isolated in our database, and surface insights to help you pay attention. We don't sell, share, or analyze your data for anyone but you.

What we collect

  • Your email — to sign you in.
  • Your bank account data via Plaid — balances, account names, statement dates, interest rates, minimum payments. Read-only; we never see your bank credentials and we can't move money.
  • Your check-ins — which accounts you acknowledged, flagged, or updated, and when.
  • Your reflections — anything you write in the Sunday Reckoning or Monthly Close text fields.

That's it. We don't track you across the web. We don't use marketing or analytics cookies. The only cookie we set is the one that keeps you signed in.

Where it lives

Your data lives in a Supabase Postgres database in the US-West region. Connection-level access is restricted to the Vigilance application. Row-level security policies make sure one user's data can never be returned to another user, even by a programming bug.

The access keys Plaid issues us so we can refresh your balances are encrypted with Supabase Vault using pgsodium. Plain text never persists to disk.

What we do with it

Show it back to you. That's the whole product. We compute your net worth, evaluate the six built-in expert rules against your data to surface hints, and email you weekly + monthly ritual reminders if you have those toggled on.

If you ask Vigilance a question through the “Ask” panel, we send the question plus a context summary (your account names, balances, and active hints) to Anthropic's Claude to compose a response. Anthropic does not store or train on that data per their commercial terms.

What we don't do with it

  • We don't sell your data.
  • We don't share it with advertisers or data brokers.
  • We don't use it to train AI models.
  • We don't profile you for targeted advertising.
  • We don't share it with anyone except the third-party services we need to operate (Plaid for bank connections, Supabase for storage, Anthropic for question answering, Resend for emails).

Your controls

  • Unlink a bank anytime from Settings. We stop pulling new balances and archive the linked accounts.
  • Delete an account from its detail page. The account row + its history archive but stay restorable for 90 days.
  • Turn off email reminders in Settings → Preferences.
  • Delete everything by emailing coo@revarity.com. We'll hard-delete your account, all bank connections, all history, all hints, all reflections — within 14 days.

Security

We use industry-standard encryption (TLS 1.3 in transit, pgsodium-managed AES-256-GCM at rest for access keys). We don't store your bank password — Plaid handles sign-in on your bank's own login page and only returns us a refresh key. We don't store your social security number, your address, or any government identifier. We don't store transactions yet — only balances, account metadata, and what you type into the app.

Changes

If we change how Vigilance handles your data, we'll update this page and email you at the address on file before the change takes effect.

Contact

Questions: coo@revarity.com. Vigilance is operated by Revarity.