Privacy Policy
This describes what Dough collects, who it is shared with, and what you can do about it. It is written to match what the software actually does.
Who operates this service
Dough is operated by [OPERATING ENTITY — set LEGAL_ENTITY]. For any question about this policy, or to make a request about your data, contact [CONTACT ADDRESS — set LEGAL_CONTACT_EMAIL].
What we collect
Information you give us
- Account details — your username, your email address if
you provide one, and a password. Passwords are stored only as a
scrypthash; we never store or transmit the password itself. - Financial records you enter or upload — transactions, account balances, budgets, categorization rules, investment holdings, and any notes you attach to them, including CSV statements you import.
- Settings — your theme, filters, and similar preferences.
Information from your financial institutions
If you connect an account, we receive from that institution — through Plaid — your account names and types, balances, and transaction history including dates, amounts, merchant names and descriptions. We also receive the account holder identity details the institution reports.
Information generated automatically
- Session and security records — a signed session cookie, and an audit trail of security-relevant events (sign-in, sign-out, failed sign-in, password change, invitations, token issue and revocation, rate limits reached). Audit entries record what happened, who did it and when; they are append-only and are not deleted in the normal course of use.
- Application logs — request paths, timing and errors. Credentials and message bodies are deliberately excluded from these.
- Product usage — which screens you open, how long a screen was on-screen, and which of a fixed list of controls you use, so we can tell which parts of Dough are worth keeping and which are not. These records hold the name of a screen or a button, never the contents of one: no amounts, no transaction descriptions, no merchant names, no text you typed, and no web addresses. They are used only to improve Dough, are never sold or shared, and are deleted on a rolling 90 day schedule.
We do not use advertising trackers, we do not sell personal information, and we do not share it with third parties for their own marketing.
Plaid
Bank and brokerage connections are made through Plaid Inc. When you link an institution, you enter your credentials on Plaid's own interface. Dough never sees, receives or stores your banking username or password.
What we receive and store is an access token issued by Plaid, which permits reading the account data described above. That token is encrypted at rest with an authenticated cipher (AES-128-CBC with HMAC), so the database file, a backup of it, or a copy obtained by any means does not yield a usable credential without the separate encryption key.
Plaid's handling of your information is governed by Plaid's own privacy policy, linked above. Disconnecting an institution in Dough removes the stored token.
AI processing
Dough's assistant is built on models provided by Anthropic. When you use a feature that asks the assistant a question — chat, dashboard insights, the investment brief, or rule suggestions — a summary of your financial data is sent to Anthropic as part of the prompt. Depending on the feature, that can include transaction descriptions, amounts, dates, categories, balances and holdings.
Your prompts and the assistant's replies are not stored in our audit trail or written to our application logs. We record only that a request happened, which feature it came from, which model answered, and how many tokens it used.
Assistant output is generated by a language model and can be wrong. It is not financial, tax, legal or investment advice. See the Terms of Service.
If you supply an address, we use it to send account email: address verification, password resets, and confirmation when your address changes. Delivery is handled by Postmark, which receives the recipient address and the message. We do not send marketing email.
Households and shared data
Dough organizes data into households. Everyone in a household can see that household's financial data — that is what a household is for. If you accept an invitation to join one, the people already in it will be able to see the records you add. An owner can remove a member; removing a member does not remove the household's financial records, which belong to the household rather than to the person who entered them.
How long we keep it
- Your account and financial data — until you delete your account, or until the household is deleted.
- Backups — the database is snapshotted on a schedule and a limited number of recent snapshots are retained, so data you delete may persist in a backup for a short period before those snapshots age out.
- Audit records — retained for security purposes. These record events, not financial data.
- Product usage records — 90 days, after which they are permanently deleted. Unlike audit records, these are not kept for security purposes and are not retained beyond that window.
Your choices
- Export — you can download everything we hold for your account as a JSON file, from your settings.
- Deletion — you can delete your account from the same page. This removes your personal details, your sessions and API tokens, and your institution connections. Where you are the last member of a household, the household's financial records are deleted with it.
- Correction — you can edit or remove individual records at any time in the application.
- Disconnecting an institution — you can remove a connection at any time, which deletes the stored access token.
Depending on where you live you may have additional rights over your personal data, including rights of access, correction, deletion and portability. Contact [CONTACT ADDRESS — set LEGAL_CONTACT_EMAIL] to make a request.
Security
Passwords are hashed, institution tokens and password-reset tokens are encrypted or hashed at rest, sessions expire, and changing your password invalidates every existing session and API token. Access to one household's data from another is blocked at the database query layer rather than per-page.
No system is perfectly secure, and we do not claim otherwise.
Children
Dough is not intended for use by anyone under 18, and we do not knowingly collect information from children.
Changes
If this policy changes materially we will update the date at the top and, where we have your address and the change is significant, tell you by email.