This page describes our use of financial data accessed through Plaid Inc. ("Plaid") and supplements our Privacy Policy. It is provided pursuant to Plaid's developer requirements.
1. Data We Access via Plaid
- Account & balance — institution, account name & type, mask, current and available balances.
- Transactions — historical and ongoing transaction history with merchant, category, and amount.
- Identity — account holder name, email, phone, and address as on file with the institution.
- Auth — account & routing numbers (only if required for a feature you initiate).
- Income / Employment — verified income or payroll data (only if you opt in).
- Liabilities & Investments — loan balances, holdings, and statements (only for the corresponding phase tool).
We request the minimum scopes necessary for the feature you are using. Linking a bank for Phase 3 (Reserves) does not also pull investment holdings unless you separately enable Phase 5 linking.
2. How We Use Plaid Data
- Auto-populate phase tools (debts, balances, income, expenses).
- Compute scenario projections, milestones, and personalized recommendations.
- Detect when your custom alert thresholds are crossed.
- Generate your PDF phase summaries and master report.
3. How We Do Not Use Plaid Data
- We do not sell, rent, or trade your Plaid data.
- We do not use it for advertising, marketing to third parties, or list brokerage.
- We do not share it with data brokers, credit bureaus (unless you instruct us to), or AI training datasets.
4. Service Providers
We share Plaid-derived data only with infrastructure subprocessors strictly necessary to operate the Service (Supabase for storage, Cloudflare for compute, OpenAI / Anthropic / Google for AI features using only de-identified summaries you trigger). All are bound by written confidentiality and data-protection agreements.
5. Storage & Security
- Plaid access tokens are stored encrypted at rest and are never returned to the browser.
- All data is scoped per user via row-level security; one user cannot read another's data.
- Data in transit is protected with TLS 1.2 or higher.
6. Your Controls
- Disconnect any linked institution at any time from your account settings.
- Request deletion of all imported data via Data Deletion.
- You can also revoke I AM Wealth from my.plaid.com.
7. Retention
On disconnect or account deletion we remove Plaid access tokens immediately and purge cached transactions and balances within 30 days, except where retention is required by law.
8. Plaid's Role
Plaid is an independent data-access network. Plaid's handling of your data is governed by the Plaid End User Privacy Policy.
9. Contact
Questions about how we handle Plaid-accessed data: privacy@iamwealth.app.