Legal

Privacy Policy

Last updated: May 25, 2025

1. Overview

This Privacy Policy describes how Ctroom ("the App"), a personal finance dashboard created and operated by King Sharif (sharifahmed.dev@gmail.com), handles information. Ctroom is a personal-use application — it is not a commercial product and has no public users other than the owner.

2. Information Collected

The App collects the following data solely for the purpose of displaying personal financial information to its single owner:

  • Bank account information — account names, types, and current balances retrieved via Plaid or Teller bank connection APIs.
  • Transaction data — transaction descriptions, amounts, dates, merchant names, and categories retrieved from connected bank accounts.
  • Manually entered data — budget categories, savings goals, debt entries, and subscription records entered directly by the owner.
  • Authentication data — email address and session tokens used to secure access to the dashboard, managed via Supabase Auth.

3. How Information Is Used

All collected data is used exclusively to:

  • Display account balances, transaction history, and spending trends within the App.
  • Calculate budgets, net worth, and financial health scores.
  • Detect recurring charges and forecast upcoming payments.
  • Power AI-assisted financial insights within the App.

Data is never sold, shared, or used for advertising. No third party has access to this data for their own purposes.

4. Data Storage

All financial data is stored in a private Supabase (PostgreSQL) database accessible only to the App owner. Data is encrypted in transit (TLS) and at rest. No financial data is stored in browser local storage or cookies.

5. Third-Party Services

The App uses the following third-party services, each with their own privacy policies:

6. Cookies & Tracking

The App does not use advertising cookies, analytics trackers, or any third-party tracking scripts. Session cookies are used solely to maintain authenticated access and expire when the browser session ends.

7. Data Retention

Data is retained for as long as the App is in use. The owner may delete all stored data at any time by clearing the database. Bank connection tokens may be revoked at any time through Plaid or Teller's respective dashboards.

8. Security

Access to the App is protected by Supabase authentication. All API communication uses HTTPS. Bank credentials are never stored — only access tokens issued by Plaid or Teller are retained, and these can be revoked at any time.

9. Changes to This Policy

This policy may be updated as the App evolves. The "Last updated" date at the top of this page will reflect the most recent revision.

10. Contact

Questions about this privacy policy can be directed to sharifahmed.dev@gmail.com.