CyberBeans

Privacy policy

CyberBeans LC. Effective September 2026.

This policy covers the FinBeans website, the FinBeans app for iPhone and Android, and AuthBeans, which handles sign-in for both. It says what we collect, why, who else receives it, and what you can make us do about it.

1. What we collect

1.1 Your account, held by AuthBeans

Your email address and a hash of your password. The hash is one-way: your password cannot be recovered from it, including by us. AuthBeans also keeps the sign-in sessions it has issued to you, so that you can stay signed in and so that signing out can revoke them.

AuthBeans receives your password. FinBeans never does, and neither will any other CyberBeans app.

1.2 Your finances, when you connect a bank

1.3 Your subscription, if you pay for one

Whether you have a subscription, how many banks it covers, when it renews, and a running count of any Enrich credits you have bought and used. Stripe's identifier for you as a customer, so we can find your subscription when Stripe tells us it has changed.

Your card number never reaches us. You enter it on a page Stripe serves, and we are told only that a payment succeeded or failed.

1.4 What we do not collect

Your bank transmits more than the above. The following is discarded on receipt and never written to our systems:

We also collect no advertising identifier, no device fingerprint, and no analytics or crash reporting of any kind.

2. Why we collect it

To operate the service you asked for: to show your balances and transactions, to identify recurring bills and income, and to keep you signed in. We do not use your data for any other purpose.

3. What is stored on your device

The FinBeans app stores your sign-in token, in the iOS Keychain or the Android Keystore. Nothing else. There is no database on the device and no cached copy of your transactions, so what you see is fetched while you are looking at it. Signing out deletes the token.

On the web, the same token is held in an httpOnly cookie, which browser JavaScript cannot read.

4. Who else receives your data

4.1 Plaid

Bank connections are made through Plaid. You authenticate at your bank's own page, so we never receive those credentials. Plaid holds your transaction data under its own privacy policy.

Two consequences of using Plaid:

4.2 Resend

Account and invitation emails are delivered through Resend, which processes your email address for that purpose only.

4.3 Stripe

Payments are taken by Stripe. When you subscribe or buy credits, Stripe receives your email address and the card details you type on its page, and holds them under its own privacy policy. Stripe tells us the outcome of the payment and keeps the card on file so that renewals, and any automatic credit top-up you switch on, can be charged without asking you again.

5. What we never do

We do not sell your data. We do not share it for advertising or marketing. We do not use it to train machine learning models, ours or anyone else's. There are no third-party trackers on this site or in the apps, and no recipients beyond the three named above.

6. How long we keep it

For as long as your account exists. We keep no copy after deletion and we do not archive accounts you disconnect.

7. Deleting your data

You can delete everything from two places, and both do the same thing:

Deletion removes your accounts, transactions, holdings, schedules and budgets. It is a real deletion rather than a flag.

One thing we cannot do for you: some banks keep their own record of the permission you granted. Chase in particular keeps it in the Chase Security Center, and clearing it there is a separate step you must take. Disconnecting in FinBeans revokes our access token, which is not the same thing.

8. Your rights

Wherever you live, you may ask us what we hold about you, request a copy of it, ask us to correct it, and have it deleted. There is no charge for asking and no penalty for exercising these rights. Write to support@cyberbeans.net.

9. Where it runs, and how it is protected

Our apps run on servers we rent and operate ourselves, in the United States. We do not run them on anyone else's platform. Data is encrypted in transit. Bank access tokens are encrypted at rest with a key held separately from the database.

10. Who may use our apps

You must be at least 18 to use FinBeans. Our apps are not directed at children, we do not knowingly collect information from anyone under 13, and if we learn that we have, we delete it.

11. Changes to this policy

When our policy updates, all users will receive an update by email.

12. Contact

CyberBeans LC
8735 Dunwoody Place #11622
Atlanta, GA 30350, USA
support@cyberbeans.net