Fortuna ("Fortuna," "we," "us," or "our") is a personal finance application. References to "the app" or "Fortuna" in this Policy mean both the iOS and Android mobile applications and any associated web properties we operate.
Fortuna is responsible for the personal information you provide to us and determines how and why it is processed.
This Privacy Policy applies to:
This Policy does not apply to third-party services you access through the app (such as Plaid or your bank). Those services have their own privacy policies, which we link where relevant.
This feature is optional and rolling out gradually; it does not apply unless you actively choose to open a savings account. If you do, we collect:
See Section 6 for full detail on this feature and our relationship with Unit.
When you link a bank account, Plaid transmits the following limited data to us:
We do not receive or store: your bank account numbers, routing numbers, login credentials, full transaction history, or account balances.
Plaid access tokens (the server-side credentials that authorize data retrieval) are stored on our servers and are never transmitted to your mobile device or visible to you.
Exception — Autopilot Savings only: if you choose to open an optional Autopilot Savings account (Section 6.6), we additionally request your name, email, and address from Plaid's Identity product to pre-fill the account-opening form. This identity data is requested only at that point, only for that purpose, and is not requested for ordinary Plaid-linked accounts used purely for expense tracking.
If you register or log in using "Sign in with Apple" or Google Sign-In, we receive your email address and name (or an anonymized email relay, if you choose to hide your email via Apple). We use this only to create and identify your account.
| Data Category | Purpose | Basis for Processing |
|---|---|---|
| Account information (name, email) | Create and manage your account; send security notices | Necessary to provide the Service |
| Profile information (occupation, DOB, state, etc.) | Personalize AI coaching; age-appropriate goal-setting | Necessary to provide the Service |
| Financial data you enter | Display expense history; generate summaries; power AI coaching context | Necessary to provide the Service |
| Plaid transaction data | Pre-fill expense entries; send real-time spending alerts | User consent (bank linking is optional) |
| Identity verification data (SSN, address, DOB) | Open and verify an optional Autopilot Savings account through our banking partner, Unit | User consent (opt-in feature); legal obligation (bank KYC requirements) |
| Autopilot Savings transfer activity | Execute and display round-up, scheduled, and goal-completion transfers you configure | User consent (opt-in feature); contract with Unit's partner bank |
| Receipt images and extracted line items | Itemize and categorize a scanned receipt into an expense record | User consent |
| Cost-splitting data | Share expense visibility with collaborators you explicitly invite | User consent |
| AI coaching messages (text and voice) | Generate personalized coaching responses via Anthropic API; maintain session context; convert voice input/output | User consent |
| Push notification token | Deliver notifications you have enabled (expense alerts, coaching reminders, goal/transfer activity, payment notifications from collaborators) | User consent |
| Security and audit logs | Detect fraud; investigate incidents; comply with applicable US law | Legitimate business interest; legal obligation |
| Device/technical information | Maintain app compatibility; diagnose crashes | Legitimate business interest |
We share data only with the following infrastructure providers, each engaged under data processing agreements, and solely to operate the app on your behalf:
| Provider | Role | Data Shared | Privacy Policy |
|---|---|---|---|
| Supabase | Database, authentication, row-level security | All account and financial data (encrypted at rest) | supabase.com/privacy |
| Plaid Inc. | Bank account connection and transaction retrieval | User ID (for Plaid Link); Plaid returns transaction data to us | plaid.com/legal |
| Anthropic, PBC | Large language model powering Aura (AI coach) | Coaching session messages and limited financial context (see Section 7) | anthropic.com/privacy |
| Google Firebase (FCM) | Android push notifications | Push notification token; notification title and body | firebase.google.com/support/privacy |
| Apple Inc. (APNs) | iOS push notifications | Push notification token; notification title and body | apple.com/legal/privacy |
| Render | Backend application hosting | API traffic (processed in memory; not persistently stored by Render) | render.com/privacy |
| Unit Finance Inc. | Banking-as-a-service partner for the optional Autopilot Savings account; performs identity verification and processes transfers through its partner bank | Social Security number, legal name, address, date of birth (only if you open an Autopilot Savings account); transfer instructions and account status | unit.co |
| Text-to-speech provider(s) | Converts Aura's text replies to spoken audio for voice coaching (only if you use voice mode) | The text of Aura's reply being spoken; no financial account credentials | elevenlabs.io (where used) |
If you use the cost-splitting feature, certain information is shared with collaborators you explicitly invite. See Section 8 for full details.
We may disclose your information if we are required to do so by law, court order, or governmental regulation, or if we believe in good faith that such disclosure is necessary to:
We will notify you of any legally compelled disclosure to the extent permitted by law.
If Fortuna is acquired by, merged with, or sold to another entity, your information may be transferred as part of that transaction. We will provide notice via the app or email before your information becomes subject to a different privacy policy. You will have the opportunity to request deletion of your account and data prior to any such transfer.
We may share aggregated, de-identified data (e.g., anonymized spending trends) that cannot reasonably be used to identify you, for research, product improvement, or public reporting.
Plaid is a third-party financial data platform that enables Fortuna to securely connect to your bank account without ever seeing your bank credentials. When you tap "Link a bank account," you are redirected to Plaid's secure interface. Plaid's use of your data is governed by Plaid's Privacy Policy.
As described in Section 3.3, we receive only five data fields per transaction (merchant name, amount, timestamp, category, and approximate location). We do not receive your bank credentials, account numbers, or full account history.
Plaid transaction data is used only to:
Plaid data is not used to make any automated decisions that affect you, and is not shared with third parties beyond the service providers in Section 5.1.
You can disconnect your bank at any time from Settings → Connected Banks → Unlink. Upon unlinking:
/item/remove endpoint to revoke Plaid's access to your account on Plaid's servers;Plaid may independently collect and retain data about your bank account connection in accordance with their own privacy policy. Fortuna does not control and is not responsible for Plaid's independent data practices. For questions about data Plaid holds, contact Plaid directly at plaid.com/legal.
Fortuna offers an optional feature — Autopilot Savings — that lets you open a savings account to fund goals automatically through round-ups, scheduled contributions, and yield-aware allocation. This feature is rolling out gradually and may not yet be available to you. The account itself is issued by an FDIC-insured bank through our banking-as-a-service partner, Unit Finance Inc. ("Unit"), not by Fortuna. Unit and its partner bank process your identity verification and hold and move the funds in that account; Fortuna's role is to let you configure the rules (round-ups, schedules, goals) and to display the resulting balance and activity.
To open an Autopilot Savings account, we collect your Social Security number, legal name, address, and date of birth. Your Social Security number is transmitted directly to Unit for identity verification and is not stored in Fortuna's database; we retain only a confirmation that verification succeeded or failed. Name, address, and date of birth may be pre-filled from identity data already available through your linked Plaid account.
Unit and its partner bank process your identity and account data as required to open, maintain, and service your Autopilot Savings account, including compliance with bank secrecy, anti-money-laundering, and other financial regulations. Unit's use of your data is governed by its own privacy policy and the deposit account agreement presented to you directly during account opening, not by this Policy. Fortuna does not control and is not responsible for Unit's or its partner bank's independent data practices.
You can close an Autopilot Savings account and withdraw its funds from within the app. Closing the account stops future automatic transfers; records of past transfers are retained as described in Section 9 for financial recordkeeping purposes, even after the account is closed.
Aura is Fortuna's AI financial coach, powered by Claude (Anthropic's large language model). When you interact with Aura — asking questions, receiving monthly summaries, or getting habit recommendations — your messages and relevant financial context are sent to Anthropic's API to generate a response.
Each coaching request may include:
We do not send: your full transaction history, your bank credentials, your Plaid access tokens, your email address, or your full legal name in coaching prompts. We use pseudonymized context where possible.
Anthropic processes your messages to generate responses. Anthropic's use of data is governed by their Privacy Policy and API terms. As of the effective date of this Policy, Anthropic does not use data submitted via their API to train their models, per their API usage terms. However, this is subject to Anthropic's own policies, which you should review.
Your coaching conversation history is stored in our database for one (1) year to provide continuity between sessions, after which it is automatically deleted. You may request earlier deletion at any time by contacting us or deleting your account.
Aura is an educational tool. Nothing Aura says constitutes financial advice, investment advice, tax advice, or legal advice. See our Terms of Service for the full disclaimer.
Fortuna allows you to create a shared financial entity (e.g., a shared household budget or expense group) and invite collaborators by email address. Collaborators who accept the invitation gain a read-only or collaborative view of the shared entity.
When you share a financial entity with another user:
The entity owner may remove any collaborator at any time. Upon removal:
Collaborators may leave a shared entity at any time from the app. This has the same effect as being removed by the owner.
| Data Category | Retention Period | Basis for Retention |
|---|---|---|
| Account information and financial records | Until account deletion | Contract; user control |
| Plaid-linked transaction records | Until account deletion | Contract; user control |
| Pending Plaid transaction alerts | 30 days from creation | Automatic purge policy |
| Social Security number (Autopilot Savings) | Not retained — transmitted to Unit for verification, not stored in our database | Data minimization by design |
| Other identity data (name, address, DOB) and Autopilot Savings transfer records | Until account deletion, or longer if required by banking recordkeeping regulations | Contract with Unit's partner bank; legal obligation |
| Receipt images | Until you delete the associated expense record or your account | User control |
| AI coaching conversation history (text and voice) | 1 year from each message date | Data minimization policy |
| Push notification delivery logs | 90 days | Data minimization policy |
| Security and audit logs | 1 year | Security monitoring; legal obligation |
| Anonymized analytics | Indefinitely (not personal data) | Product improvement |
When you delete your account (Settings → Account → Delete Account):
No security system is perfect. While we implement industry-standard protections, we cannot guarantee absolute security. In the event of a breach affecting your personal data, we will notify you as described in Section 15.
Regardless of your location, you have the following rights with respect to your personal information:
You have the right to know what personal data we hold about you. Most of your financial data is visible directly in the app. To request a complete data export, email privacy@api.danielesambu.com with "Data Export Request" in the subject line. We will fulfill your request within 30 days.
You may correct or update most of your information directly in the app (profile settings, expense records). For information you cannot edit directly, contact us.
You may delete your account and all associated data at any time from Settings → Account → Delete Account. This is immediate and irreversible. Alternatively, contact us to request deletion of specific data.
You may request a machine-readable export of your personal data by contacting us. We will provide it in JSON or CSV format within 30 days.
You may object to our processing of your personal data on the basis of legitimate interest, or request that we restrict processing while a dispute is resolved, by contacting us.
Where we rely on your consent to process data (e.g., push notifications, bank linking), you may withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal.
Email: privacy@api.danielesambu.com
We will respond within 30 days. We may ask you to verify your identity before fulfilling a request.
This section applies to California residents. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you additional rights.
In the past 12 months, we have collected the following categories of personal information as defined by the CCPA:
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Name, email address, IP address, device ID | Yes |
| Personal records | Phone number, date of birth, state of residence | Yes (optional) |
| Protected classification characteristics | Marital status | Yes (optional) |
| Commercial information | Expense records, financial entities you create | Yes |
| Financial information | Transaction data received from Plaid (if linked) | Yes (if linked) |
| Internet or network activity | App interaction logs, session data | Yes |
| Geolocation data | Approximate location from Plaid transactions (city-level) | Yes (if linked) |
| Inferences drawn from personal information | Spending patterns, financial health summaries generated by Aura | Yes |
| Biometric information | None — biometric processing occurs on-device only | No |
| Sensitive personal information (SPI) | Social Security Number, financial account numbers | No |
We do not sell your personal information. We do not share your personal information with third parties for cross-context behavioral advertising. Fortuna is an ad-free application.
To exercise your California rights, email privacy@api.danielesambu.com or use the in-app deletion feature. We will respond within 45 days, with one 45-day extension where reasonably necessary.
Fortuna is designed, operated, and offered exclusively for use within the United States. All of our services, features, bank-linking integrations, and coaching content are scoped to US law, US financial institutions, and US residents.
We do not knowingly permit access to the Service from outside the United States. If you are located outside the United States, you are not authorized to use or access Fortuna. We reserve the right to block, suspend, or terminate accounts that we determine are being accessed from outside the United States.
Because we serve only US residents, we do not engage in cross-border personal data transfers subject to frameworks such as GDPR, UK GDPR, or equivalent non-US data protection regimes. If you access the Service in violation of this geographic restriction, you do so at your own risk and you are solely responsible for compliance with any laws of your jurisdiction.
Fortuna does not target individuals in the European Economic Area or the United Kingdom, and does not consider itself subject to the General Data Protection Regulation (GDPR) or UK GDPR. If applicable law in your jurisdiction conflicts with this Policy, please do not use the Service.
In the event of a security breach that affects your personal data, we will:
Fortuna is intended for, and may only be used by, individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18.
Age verification occurs during account setup. If you enter a date of birth that indicates you are under 18, your account will be automatically and permanently deleted immediately, and you will not be permitted to use the Service.
If we discover that we have inadvertently collected personal information from a person under 18, we will delete that information immediately. If you believe an underage person has created an account, please contact us at privacy@api.danielesambu.com.
The app may contain links to third-party websites or services (e.g., Plaid's bank selection interface, legal document pages). This Privacy Policy does not apply to any third-party sites or services. We encourage you to review the privacy policies of any third-party services you access.
We are not responsible for the privacy practices or content of third-party sites or services.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
Continued use of Fortuna after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree to a material change, your sole remedy is to delete your account before the change takes effect.
For privacy questions, data requests, or concerns about this Policy: