CountHouse — Privacy Policy
Effective date: 2026-05-06 | Last updated: 2026-05-06
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the choices and rights you have.
1. Who we are
CountHouse ("CountHouse," "we," "us," "our") is a personal finance management service operated by CountHouse Inc. ("the Company").
- Website: https://pocket-change-rebirth.vercel.app
- Contact for privacy: info@counthouse.ai
- Contact for security: info@counthouse.ai
- Phone: +44 7301 214096
- Postal address: San Francisco, CA, USA
2. Scope
This Policy applies to:
- The CountHouse website at https://pocket-change-rebirth.vercel.app and any subdomains.
- The CountHouse web application (the "Service").
- Any features, integrations, or communications we provide in connection with the Service.
It does not apply to:
- Third-party services we link to or integrate with (e.g., Plaid, your bank, Anthropic, OpenAI). Those services have their own privacy policies, which we encourage you to read.
3. The data we collect
3.1 Account data
When you create an account, we collect:
- Email address.
- A hashed password (we never see your password in plain text — authentication is handled by Supabase Auth).
- Optional profile information you choose to provide (name, time zone, base currency, theme preference).
3.2 Financial data you connect via Plaid
CountHouse uses Plaid Inc. ("Plaid") to securely connect to your financial institutions. When you connect an account through Plaid:
- You authenticate directly with your bank inside Plaid Link. Your bank login credentials are submitted to your bank through Plaid; we never see, store, or have access to your bank username or password.
- After successful authentication, Plaid provides us with an access token, which we store encrypted in Supabase Vault and use only to retrieve the data described below.
- We then receive from Plaid:
- Account metadata (institution name, account name, account type and subtype, masked account number, currency).
- Account balances (current and available).
- Transaction history (date, amount, description, merchant, category, location).
- Item status information (e.g., when your connection needs re-authentication).
Your use of Plaid is also governed by Plaid's End User Privacy Policy (https://plaid.com/legal/#end-user-privacy-policy), which we encourage you to review.
3.3 Financial data you provide manually or via CSV
You may also enter or import financial data directly:
- Manual entry of transactions, accounts, debts, recurring expenses, planned expenses, and income sources.
- CSV import of transaction data, which may include fields such as date, amount, description, merchant, category, account, currency, and transfer flags.
This data is stored in your account and treated with the same protections as Plaid-sourced data.
3.4 AI interaction data
If you use the AI assistant, voice transcription, or receipt-scanning features:
- The text or voice content you submit is processed by us and forwarded to Anthropic (Claude) for chat and vision tasks, or OpenAI (Whisper) for voice transcription, under each provider's commercial API terms.
- Per our agreements with these providers, your inputs and outputs are not used to train their models.
- Your AI conversation history (messages, tool calls, results) is stored in our database under your account, and you can delete conversations at any time.
3.5 Usage and device data
We automatically collect limited technical information when you use the Service:
- IP address (collected by our hosting provider, Vercel, for security and operational purposes).
- Browser type and version, operating system, device type.
- Pages viewed, features used, and timing.
- Error and performance telemetry to help us diagnose issues.
We use PostHog for product analytics. PostHog events are configured to exclude Restricted financial data (transaction amounts, balances, tokens) and to use a pseudonymous user identifier.
3.6 Cookies and similar technologies
We use a small number of cookies and equivalent storage mechanisms:
- Strictly necessary cookies for session authentication and security (set by Supabase Auth and our application).
- Functional local-storage entries to remember your preferences (theme, currency display).
- Analytics identifiers (PostHog) where permitted via consent.
We provide a cookie consent banner for EU/UK visitors. Non-essential cookies (analytics) are only set after explicit user consent.
3.7 Payment data
CountHouse is currently free to use. When we introduce a paid tier in the future, payment processing will be handled by a PCI-compliant payment processor (e.g., Stripe). We will not store full card numbers; only billing metadata will be retained.
3.8 Information we do not collect
- We do not collect or store your bank login credentials.
- We do not knowingly collect data from children under 16 (see §11).
- We do not collect special categories of personal data (e.g., health, biometric, political opinions) unless you voluntarily include them in a transaction note or AI message — and we discourage you from doing so.
4. How we use your data
We use your data to:
- Provide the Service — display your accounts, transactions, balances, debts, budgets, projections, and analytics.
- Sync and update — periodically refresh your Plaid-connected accounts and store the results.
- Power AI features — generate categorizations, insights, summaries, and assistant responses you request.
- Communicate with you — send transactional emails (account verification, security alerts, re-authentication prompts, important policy changes). We will not send marketing email without your consent.
- Secure the Service — detect and prevent fraud, abuse, and unauthorized access.
- Improve the Service — diagnose issues, understand aggregate feature usage, prioritize improvements.
- Comply with law — respond to lawful requests, enforce our Terms, protect our rights.
5. Legal bases for processing (EU/UK/EEA users)
If you are in the EU, UK, or EEA, we rely on the following legal bases under the GDPR / UK GDPR:
- Contract (Art. 6(1)(b)) — to provide the Service you signed up for, including connecting accounts, syncing data, and operating AI features.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud, conduct limited analytics, and improve our product. Where we rely on legitimate interests, we have considered your rights and freedoms.
- Legal obligation (Art. 6(1)(c)) — where we must process data to comply with applicable law.
- Consent (Art. 6(1)(a)) — where required, e.g., for non-essential cookies or marketing communications. You can withdraw consent at any time.
6. Who we share your data with
We do not sell your personal data. We share it only with the categories of recipients listed below, each acting as a sub-processor under data-processing agreements that require appropriate safeguards.
| Recipient | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication, secret storage, edge compute | All user-stored data (encrypted at rest); Plaid access tokens (in Vault) |
| Vercel | Application hosting, edge runtime, scheduled jobs | Data in transit through API routes; technical logs |
| Plaid | Bank-data connectivity | The access token Plaid issued to us, plus our requests for transactions/balances on your behalf |
| Anthropic | Claude LLM for the AI assistant, vision, and transaction categorization | Only the content you submit to AI features (chat messages, tool inputs, image data), plus context we attach to those calls |
| OpenAI | Whisper API for voice-to-text transcription | The audio you submit to the voice feature |
| PostHog | Product analytics | Pseudonymous event metadata; no Restricted financial data |
| GitHub | Source code and CI | No production user data |
| Resend | Transactional email | Email address, message content |
| Stripe (future) | Payment processing | Billing metadata; we never receive full card numbers |
We may also disclose data:
- To comply with legal obligations — court orders, lawful subpoenas, regulatory requirements.
- To protect rights and safety — ours, yours, or others'.
- In a corporate transaction — if CountHouse is involved in a merger, acquisition, or sale of assets, your data may be transferred to the surviving or acquiring entity, subject to this Policy or notice of any material change.
We do not share your data with advertising networks or data brokers.
7. International data transfers
CountHouse and several of our sub-processors are located in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States and other jurisdictions where our sub-processors operate.
For transfers from the EU/UK/EEA to the United States, we rely on:
- Standard Contractual Clauses issued by the European Commission, where required.
- The EU-US Data Privacy Framework and UK Extension where the recipient is certified under it.
- Vendor-specific safeguards published by our sub-processors.
You can request a copy of the relevant safeguards by emailing info@counthouse.ai.
8. How long we keep your data
| Data | Retention |
|---|---|
| Account data | For the lifetime of your account. |
| Plaid-sourced data | For the lifetime of your account, unless you disconnect the institution (in which case the access token is revoked). |
| AI conversation history | For the lifetime of your account, or until you delete the conversation. |
| Application logs | 7 days (via Vercel and Supabase default retention). |
| Database backups | 7 days (Supabase Point-in-Time Recovery default). |
When you delete your account, we delete your personal data from our production systems within 30 days and from backups within 7 days. We may retain limited information after deletion if required by law (e.g., for fraud investigation) or for legitimate security purposes.
9. How we protect your data
A summary of our security practices (see our internal Information Security Policy for full detail):
- TLS 1.2+ in transit on all endpoints.
- AES-256 encryption at rest for the database, Vault, and object storage.
- Plaid access tokens stored in Supabase Vault and accessed only by service-role code paths.
- Postgres Row-Level Security on every table, scoping every row to its user (or organization).
- Multi-factor authentication required on all administrative accounts.
- Least-privilege access controls and quarterly access reviews.
- Code review, type-checking, and dependency scanning on every change.
- Annual policy review and incident-response plan.
No method of transmission or storage is perfectly secure. If you believe your account has been compromised, contact info@counthouse.ai immediately.
10. Your rights
Subject to your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion — ask us to delete your data, subject to limited exceptions.
- Restriction — ask us to restrict processing in specific circumstances.
- Objection — object to processing based on legitimate interests.
- Portability — receive a copy of your data in a structured, machine-readable format.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Lodge a complaint — with your local data-protection authority (EU/UK) or the California Privacy Protection Agency.
10.1 California residents (CCPA/CPRA)
If you are a California resident, you also have the right to:
- Know the categories of personal information we collect, the sources, the purposes, and the categories of third parties we share with.
- Request deletion of your personal information.
- Correct inaccurate personal information.
- Opt out of "sale" or "sharing" of personal information — we do not sell or share your personal information for cross-context behavioral advertising.
- Limit the use of sensitive personal information — we use sensitive personal information only as needed to provide the Service.
- Be free from discrimination for exercising your rights.
You may submit a verifiable consumer request by emailing info@counthouse.ai. We will respond within the timeframes required by law.
10.2 How to exercise your rights
Email info@counthouse.ai from the email address associated with your account. We may need to verify your identity before fulfilling certain requests. You can also delete most data directly from inside the application.
11. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact info@counthouse.ai and we will delete it.
12. Automated decision-making and AI
We use AI to categorize transactions, summarize spending, generate insights, and answer your questions. These features:
- Are intended to support your decisions, not replace them.
- May produce inaccurate, incomplete, or out-of-date results — you should verify any output before relying on it.
- Do not constitute financial, tax, legal, or investment advice.
We do not use solely automated decision-making with legal or similarly significant effects on you within the meaning of GDPR Article 22.
13. Links to third-party sites
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies.
14. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top.
- Provide notice through the Service or via email at least 30 days before the change takes effect, unless the change is required by law to take effect sooner.
Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
15. Contact
For privacy questions or to exercise your rights:
- Email: info@counthouse.ai
- Phone: +44 7301 214096
For security issues, including suspected breaches:
- Email: info@counthouse.ai