Updated September 13, 2026
Privacy
Canly is your financial accountability partner. This page is what we actually collect and what we do not.
Bank data (Plaid)
If you connect a bank, we use Plaid as a secure third party. The product requested is Transactions only (recent transactions, read-only). That is all we pull. We use those recent transactions to hold you to a habit or rule. That is the only reason we connect. We never request transfer, payment initiation, Auth, Identity, or Credit. We never move money and we cannot make charges. You can disconnect anytime from Account.
Canly never receives your bank username or password. You type those in Plaid Link, not in this app. We do not keep bank login credentials.
Plaid access tokens and item ids live in an httpOnly cookie, encrypted at rest with AES-GCM. When you sign in, the same encrypted token is stored on the server keyed by your user id so a new phone can restore the bank. A short-lived encrypted ledger cache may sit on the server so we do not keep a plaintext transaction file. Account numbers are stored as last four digits only. The access token is not your bank login.
Accounts and email
Sign-in uses a 6-digit code or a magic link sent through Resend. We store your email, a signed-in session cookie (`ss_account`), and any bound encrypted Plaid item. We send transactional mail only: sign-in, a short note when you set a habit rule, and at most one accountability reminder path (manual or the evening cron).
SMS (opt-in)
Text alerts are off until you enter a mobile number on Account and confirm a 6-digit code. We store that number encrypted at rest (AES-GCM) and only use it to text a saved rule: when you set one, when you ask for a reminder, or on the evening Chicago cron. We do not text suggested cards you have not accepted. We do not send marketing texts. Turn SMS off anytime on Account.
Delivery uses Twilio. The current From number is a trial line (last four 3478). Until the Twilio account is paid and 10DLC is registered, Twilio will only deliver to numbers you have verified in Twilio. We never log a full phone number or a Twilio token.
What stays on this device
Decide logs, dogfood numbers, goals, and keep/cut reminders stay in this browser (localStorage) until you sign in. Signing in does not upload your full impulse log.
Coach
Ask and the morning brief send a ledger digest to Anthropic (Claude) when an API key is configured. We do not send access tokens. Without a key, those screens refuse to invent an answer.
Retention
The Plaid session cookie (`ss_plaid`, path `/`) lasts up to 30 days from your last visit. A signed-in account with a bound bank also opens Decide, even if that cookie was cleared. Disconnect removes the Plaid Item, the cookie, and the bound token. Start fresh on Account clears local data and signs you out of this phone.
Deletion
Use Disconnect bank and Start fresh - clear this phone on Account. To ask us to delete anything we still hold, email jebenawings@gmail.com.