Privacy Policy

Last updated: June 9, 2026

Overview

Potenza (“we,” “us,” or “our”) is a household financial planning application. This Privacy Policy explains what information we collect, how we use it, and how we protect it. By using Potenza, you agree to the practices described below.

Information We Collect

Account information: When you create an account, we collect your email address and a password (stored as a secure hash). You may also provide your name and basic household information (ages, number of children, state of residence) to power your financial plan.

Financial plan data: We store the inputs you enter into your financial plan — income, expenses, assets, debts, and projections. This data is used solely to compute and display your household financial model.

Connected account data (via Plaid): If you choose to connect your bank or investment accounts, we use Plaid to retrieve account balances, transaction history, and holdings. We store a Plaid access token (encrypted at rest using AES-256-GCM) and the financial data returned by Plaid. We do not store your bank login credentials.

Usage data: We may collect basic usage information such as pages visited and features used to improve the product. We do not sell this data.

How We Use Your Information

  • To provide, maintain, and improve the Potenza application
  • To compute your household financial plan and projections
  • To sync and display your connected account balances and transactions
  • To send transactional emails (account creation, password reset)
  • To respond to support requests

We do not sell your personal or financial data to third parties.

Third-Party Services

Potenza relies on the following third-party services to operate:

  • Plaid — used to connect and retrieve data from your financial institutions. Plaid's privacy policy is available at plaid.com/legal.
  • Supabase — our database and authentication provider. Data is stored in the United States and encrypted at rest.
  • Vercel — our hosting provider. All traffic is encrypted in transit via TLS 1.2 or higher.
  • Stripe — used to process subscription payments. We do not store payment card information; it is handled entirely by Stripe.
  • Anthropic — our AI provider, used to power Patty, the in-app financial assistant. Queries sent to Patty may include anonymized financial context from your plan.

Data Security

We take the security of your data seriously:

  • Plaid access tokens are encrypted at rest using AES-256-GCM
  • All data is transmitted over HTTPS (TLS 1.2+)
  • Database access is controlled via row-level security — each user can only access their own data
  • Multi-factor authentication (TOTP) is available and required before connecting financial accounts
  • Production systems are hosted on SOC 2 Type II certified infrastructure

Your Rights

You may request to access, correct, or delete your personal data at any time by contacting us at potenzaplan@gmail.com. You may also delete your account directly from the Settings page, which will remove your data from our systems.

If you have connected financial accounts via Plaid, you can disconnect them at any time from the Connected Accounts page. Disconnecting removes our access token and stops future syncing.

Data Retention

We retain your data for as long as your account is active. Transaction history is automatically pruned after 12 months. If you delete your account, your data is removed from our active systems within 30 days.

Children's Privacy

Potenza is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via email or an in-app notice. Continued use of Potenza after changes are posted constitutes acceptance of the updated policy.

Contact

If you have questions about this Privacy Policy, please contact us at potenzaplan@gmail.com.