Legal
Privacy Policy
Last updated: May 25, 2025
1. Overview
This Privacy Policy describes how Ctroom ("the App"), a personal finance dashboard created and operated by King Sharif (sharifahmed.dev@gmail.com), handles information. Ctroom is a personal-use application — it is not a commercial product and has no public users other than the owner.
2. Information Collected
The App collects the following data solely for the purpose of displaying personal financial information to its single owner:
- Bank account information — account names, types, and current balances retrieved via Plaid or Teller bank connection APIs.
- Transaction data — transaction descriptions, amounts, dates, merchant names, and categories retrieved from connected bank accounts.
- Manually entered data — budget categories, savings goals, debt entries, and subscription records entered directly by the owner.
- Authentication data — email address and session tokens used to secure access to the dashboard, managed via Supabase Auth.
3. How Information Is Used
All collected data is used exclusively to:
- Display account balances, transaction history, and spending trends within the App.
- Calculate budgets, net worth, and financial health scores.
- Detect recurring charges and forecast upcoming payments.
- Power AI-assisted financial insights within the App.
Data is never sold, shared, or used for advertising. No third party has access to this data for their own purposes.
4. Data Storage
All financial data is stored in a private Supabase (PostgreSQL) database accessible only to the App owner. Data is encrypted in transit (TLS) and at rest. No financial data is stored in browser local storage or cookies.
5. Third-Party Services
The App uses the following third-party services, each with their own privacy policies:
- Plaid — used to connect bank accounts and retrieve transaction data. Plaid Privacy Policy
- Teller — alternative bank connection provider. Teller Privacy Policy
- Supabase — database and authentication infrastructure. Supabase Privacy Policy
- Google (Gemini API) — used to generate AI summaries of commit history and financial insights. Google Privacy Policy
6. Cookies & Tracking
The App does not use advertising cookies, analytics trackers, or any third-party tracking scripts. Session cookies are used solely to maintain authenticated access and expire when the browser session ends.
7. Data Retention
Data is retained for as long as the App is in use. The owner may delete all stored data at any time by clearing the database. Bank connection tokens may be revoked at any time through Plaid or Teller's respective dashboards.
8. Security
Access to the App is protected by Supabase authentication. All API communication uses HTTPS. Bank credentials are never stored — only access tokens issued by Plaid or Teller are retained, and these can be revoked at any time.
9. Changes to This Policy
This policy may be updated as the App evolves. The "Last updated" date at the top of this page will reflect the most recent revision.
10. Contact
Questions about this privacy policy can be directed to sharifahmed.dev@gmail.com.