Privacy policy
CyberBeans LC. Effective September 2026.
This policy covers the FinBeans website, the FinBeans app for iPhone and Android, and AuthBeans, which handles sign-in for both. It says what we collect, why, who else receives it, and what you can make us do about it.
1. What we collect
1.1 Your account, held by AuthBeans
Your email address and a hash of your password. The hash is one-way: your password cannot be recovered from it, including by us. AuthBeans also keeps the sign-in sessions it has issued to you, so that you can stay signed in and so that signing out can revoke them.
AuthBeans receives your password. FinBeans never does, and neither will any other CyberBeans app.
1.2 Your finances, when you connect a bank
- Account names and types, the last few digits your bank displays, and balances
- Transactions: date, amount, description, merchant and category
- For investment accounts, holdings and their cost basis
- For loans and credit cards, the next payment, its due date, the interest rate and the statement balance
1.3 Your subscription, if you pay for one
Whether you have a subscription, how many banks it covers, when it renews, and a running count of any Enrich credits you have bought and used. Stripe's identifier for you as a customer, so we can find your subscription when Stripe tells us it has changed.
Your card number never reaches us. You enter it on a page Stripe serves, and we are told only that a payment succeeded or failed.
1.4 What we do not collect
Your bank transmits more than the above. The following is discarded on receipt and never written to our systems:
- Account and routing numbers
- Property addresses on mortgages
- Loan servicer addresses and guarantors
- Student loan repayment and forgiveness status
We also collect no advertising identifier, no device fingerprint, and no analytics or crash reporting of any kind.
2. Why we collect it
To operate the service you asked for: to show your balances and transactions, to identify recurring bills and income, and to keep you signed in. We do not use your data for any other purpose.
3. What is stored on your device
The FinBeans app stores your sign-in token, in the iOS Keychain or the Android Keystore. Nothing else. There is no database on the device and no cached copy of your transactions, so what you see is fetched while you are looking at it. Signing out deletes the token.
On the web, the same token is held in an httpOnly cookie, which browser JavaScript cannot read.
4. Who else receives your data
4.1 Plaid
Bank connections are made through Plaid. You authenticate at your bank's own page, so we never receive those credentials. Plaid holds your transaction data under its own privacy policy.
Two consequences of using Plaid:
- The merchant logo beside a transaction is loaded from Plaid by the app or your browser. Plaid can therefore see that the logo was requested.
- Categorizing a transaction you typed in or imported yourself means sending its description and amount to Plaid. That happens only when you press the button that says so, and never automatically.
4.2 Resend
Account and invitation emails are delivered through Resend, which processes your email address for that purpose only.
4.3 Stripe
Payments are taken by Stripe. When you subscribe or buy credits, Stripe receives your email address and the card details you type on its page, and holds them under its own privacy policy. Stripe tells us the outcome of the payment and keeps the card on file so that renewals, and any automatic credit top-up you switch on, can be charged without asking you again.
5. What we never do
We do not sell your data. We do not share it for advertising or marketing. We do not use it to train machine learning models, ours or anyone else's. There are no third-party trackers on this site or in the apps, and no recipients beyond the three named above.
6. How long we keep it
For as long as your account exists. We keep no copy after deletion and we do not archive accounts you disconnect.
7. Deleting your data
You can delete everything from two places, and both do the same thing:
- In FinBeans, from your account settings.
- In your AuthBeans account, which removes your sign-in and every CyberBeans app's data along with it.
Deletion removes your accounts, transactions, holdings, schedules and budgets. It is a real deletion rather than a flag.
One thing we cannot do for you: some banks keep their own record of the permission you granted. Chase in particular keeps it in the Chase Security Center, and clearing it there is a separate step you must take. Disconnecting in FinBeans revokes our access token, which is not the same thing.
8. Your rights
Wherever you live, you may ask us what we hold about you, request a copy of it, ask us to correct it, and have it deleted. There is no charge for asking and no penalty for exercising these rights. Write to support@cyberbeans.net.
9. Where it runs, and how it is protected
Our apps run on servers we rent and operate ourselves, in the United States. We do not run them on anyone else's platform. Data is encrypted in transit. Bank access tokens are encrypted at rest with a key held separately from the database.
10. Who may use our apps
You must be at least 18 to use FinBeans. Our apps are not directed at children, we do not knowingly collect information from anyone under 13, and if we learn that we have, we delete it.
11. Changes to this policy
When our policy updates, all users will receive an update by email.
12. Contact
CyberBeans LC
8735 Dunwoody Place #11622
Atlanta, GA 30350, USA
support@cyberbeans.net