Fortuna ← Back to Fortuna
Fortuna App

Privacy Policy

Effective date: August 7, 2026 Last updated: August 7, 2026 Version: 3.0
Plain-English Summary We built Fortuna to help you understand and improve your finances — not to profit from your data. We do not sell your personal information, do not use it for advertising, and do not share it with anyone except the infrastructure providers necessary to operate the app. You can delete all your data at any time, instantly and permanently.

1 Who We Are

Fortuna ("Fortuna," "we," "us," or "our") is a personal finance application. References to "the app" or "Fortuna" in this Policy mean both the iOS and Android mobile applications and any associated web properties we operate.

Fortuna is responsible for the personal information you provide to us and determines how and why it is processed.

Data Controller Contact Email: privacy@api.danielesambu.com
Website: api.danielesambu.com/privacy

2 Scope of This Policy

This Privacy Policy applies to:

This Policy does not apply to third-party services you access through the app (such as Plaid or your bank). Those services have their own privacy policies, which we link where relevant.

3 Information We Collect

3.1 Information You Provide Directly

Account Information

Profile Information (collected during onboarding)

Financial Data You Enter

Identity Verification Data (only if you open an Autopilot Savings account)

This feature is optional and rolling out gradually; it does not apply unless you actively choose to open a savings account. If you do, we collect:

See Section 6 for full detail on this feature and our relationship with Unit.

Coaching and AI Interaction Data

3.2 Information Collected Automatically

Device and Technical Information

Security and Audit Logs

3.3 Information Received from Third Parties

From Plaid (only if you choose to link a bank account)

When you link a bank account, Plaid transmits the following limited data to us:

We do not receive or store: your bank account numbers, routing numbers, login credentials, full transaction history, or account balances.

Plaid access tokens (the server-side credentials that authorize data retrieval) are stored on our servers and are never transmitted to your mobile device or visible to you.

Exception — Autopilot Savings only: if you choose to open an optional Autopilot Savings account (Section 6.6), we additionally request your name, email, and address from Plaid's Identity product to pre-fill the account-opening form. This identity data is requested only at that point, only for that purpose, and is not requested for ordinary Plaid-linked accounts used purely for expense tracking.

From Apple or Google (Sign-In)

If you register or log in using "Sign in with Apple" or Google Sign-In, we receive your email address and name (or an anonymized email relay, if you choose to hide your email via Apple). We use this only to create and identify your account.

4 How We Use Your Information

Data CategoryPurposeBasis for Processing
Account information (name, email)Create and manage your account; send security noticesNecessary to provide the Service
Profile information (occupation, DOB, state, etc.)Personalize AI coaching; age-appropriate goal-settingNecessary to provide the Service
Financial data you enterDisplay expense history; generate summaries; power AI coaching contextNecessary to provide the Service
Plaid transaction dataPre-fill expense entries; send real-time spending alertsUser consent (bank linking is optional)
Identity verification data (SSN, address, DOB)Open and verify an optional Autopilot Savings account through our banking partner, UnitUser consent (opt-in feature); legal obligation (bank KYC requirements)
Autopilot Savings transfer activityExecute and display round-up, scheduled, and goal-completion transfers you configureUser consent (opt-in feature); contract with Unit's partner bank
Receipt images and extracted line itemsItemize and categorize a scanned receipt into an expense recordUser consent
Cost-splitting dataShare expense visibility with collaborators you explicitly inviteUser consent
AI coaching messages (text and voice)Generate personalized coaching responses via Anthropic API; maintain session context; convert voice input/outputUser consent
Push notification tokenDeliver notifications you have enabled (expense alerts, coaching reminders, goal/transfer activity, payment notifications from collaborators)User consent
Security and audit logsDetect fraud; investigate incidents; comply with applicable US lawLegitimate business interest; legal obligation
Device/technical informationMaintain app compatibility; diagnose crashesLegitimate business interest
We do not: sell your data, use your data for advertising, profile you for third-party marketing, use your financial data to make lending or credit decisions, or share your data with data brokers.

5 Data Sharing and Disclosure

5.1 Service Providers

We share data only with the following infrastructure providers, each engaged under data processing agreements, and solely to operate the app on your behalf:

ProviderRoleData SharedPrivacy Policy
Supabase Database, authentication, row-level security All account and financial data (encrypted at rest) supabase.com/privacy
Plaid Inc. Bank account connection and transaction retrieval User ID (for Plaid Link); Plaid returns transaction data to us plaid.com/legal
Anthropic, PBC Large language model powering Aura (AI coach) Coaching session messages and limited financial context (see Section 7) anthropic.com/privacy
Google Firebase (FCM) Android push notifications Push notification token; notification title and body firebase.google.com/support/privacy
Apple Inc. (APNs) iOS push notifications Push notification token; notification title and body apple.com/legal/privacy
Render Backend application hosting API traffic (processed in memory; not persistently stored by Render) render.com/privacy
Unit Finance Inc. Banking-as-a-service partner for the optional Autopilot Savings account; performs identity verification and processes transfers through its partner bank Social Security number, legal name, address, date of birth (only if you open an Autopilot Savings account); transfer instructions and account status unit.co
Text-to-speech provider(s) Converts Aura's text replies to spoken audio for voice coaching (only if you use voice mode) The text of Aura's reply being spoken; no financial account credentials elevenlabs.io (where used)

5.2 Other Users (Cost-Splitting Feature)

If you use the cost-splitting feature, certain information is shared with collaborators you explicitly invite. See Section 8 for full details.

5.3 Legal Requirements

We may disclose your information if we are required to do so by law, court order, or governmental regulation, or if we believe in good faith that such disclosure is necessary to:

We will notify you of any legally compelled disclosure to the extent permitted by law.

5.4 Business Transfers

If Fortuna is acquired by, merged with, or sold to another entity, your information may be transferred as part of that transaction. We will provide notice via the app or email before your information becomes subject to a different privacy policy. You will have the opportunity to request deletion of your account and data prior to any such transfer.

5.5 Aggregated or Anonymized Data

We may share aggregated, de-identified data (e.g., anonymized spending trends) that cannot reasonably be used to identify you, for research, product improvement, or public reporting.

6 Bank Linking, Goals & Autopilot Savings (Plaid and Unit)

6.1 What Plaid Does

Plaid is a third-party financial data platform that enables Fortuna to securely connect to your bank account without ever seeing your bank credentials. When you tap "Link a bank account," you are redirected to Plaid's secure interface. Plaid's use of your data is governed by Plaid's Privacy Policy.

6.2 What We Receive from Plaid

As described in Section 3.3, we receive only five data fields per transaction (merchant name, amount, timestamp, category, and approximate location). We do not receive your bank credentials, account numbers, or full account history.

6.3 How We Use Plaid Data

Plaid transaction data is used only to:

Plaid data is not used to make any automated decisions that affect you, and is not shared with third parties beyond the service providers in Section 5.1.

6.4 Disconnecting Your Bank

You can disconnect your bank at any time from Settings → Connected Banks → Unlink. Upon unlinking:

6.5 Plaid's Independent Data Practices

Plaid may independently collect and retain data about your bank account connection in accordance with their own privacy policy. Fortuna does not control and is not responsible for Plaid's independent data practices. For questions about data Plaid holds, contact Plaid directly at plaid.com/legal.

6.6 Autopilot Savings and Our Banking Partner (Unit)

Fortuna offers an optional feature — Autopilot Savings — that lets you open a savings account to fund goals automatically through round-ups, scheduled contributions, and yield-aware allocation. This feature is rolling out gradually and may not yet be available to you. The account itself is issued by an FDIC-insured bank through our banking-as-a-service partner, Unit Finance Inc. ("Unit"), not by Fortuna. Unit and its partner bank process your identity verification and hold and move the funds in that account; Fortuna's role is to let you configure the rules (round-ups, schedules, goals) and to display the resulting balance and activity.

6.7 Identity Verification Data We Collect and Send to Unit

To open an Autopilot Savings account, we collect your Social Security number, legal name, address, and date of birth. Your Social Security number is transmitted directly to Unit for identity verification and is not stored in Fortuna's database; we retain only a confirmation that verification succeeded or failed. Name, address, and date of birth may be pre-filled from identity data already available through your linked Plaid account.

6.8 What Unit Does With Your Data

Unit and its partner bank process your identity and account data as required to open, maintain, and service your Autopilot Savings account, including compliance with bank secrecy, anti-money-laundering, and other financial regulations. Unit's use of your data is governed by its own privacy policy and the deposit account agreement presented to you directly during account opening, not by this Policy. Fortuna does not control and is not responsible for Unit's or its partner bank's independent data practices.

6.9 Closing an Autopilot Savings Account

You can close an Autopilot Savings account and withdraw its funds from within the app. Closing the account stops future automatic transfers; records of past transfers are retained as described in Section 9 for financial recordkeeping purposes, even after the account is closed.

7 AI Coaching (Aura)

7.1 How Aura Works

Aura is Fortuna's AI financial coach, powered by Claude (Anthropic's large language model). When you interact with Aura — asking questions, receiving monthly summaries, or getting habit recommendations — your messages and relevant financial context are sent to Anthropic's API to generate a response.

7.2 What We Send to Anthropic

Each coaching request may include:

We do not send: your full transaction history, your bank credentials, your Plaid access tokens, your email address, or your full legal name in coaching prompts. We use pseudonymized context where possible.

7.3 Anthropic's Use of Your Data

Anthropic processes your messages to generate responses. Anthropic's use of data is governed by their Privacy Policy and API terms. As of the effective date of this Policy, Anthropic does not use data submitted via their API to train their models, per their API usage terms. However, this is subject to Anthropic's own policies, which you should review.

7.4 Coaching History Retention

Your coaching conversation history is stored in our database for one (1) year to provide continuity between sessions, after which it is automatically deleted. You may request earlier deletion at any time by contacting us or deleting your account.

7.5 Not Financial Advice

Aura is an educational tool. Nothing Aura says constitutes financial advice, investment advice, tax advice, or legal advice. See our Terms of Service for the full disclaimer.

8 Cost-Splitting and Shared Financial Entities

8.1 How Cost-Splitting Works

Fortuna allows you to create a shared financial entity (e.g., a shared household budget or expense group) and invite collaborators by email address. Collaborators who accept the invitation gain a read-only or collaborative view of the shared entity.

8.2 What Is Shared with Collaborators

When you share a financial entity with another user:

8.3 What Is Never Shared

8.4 Removing Collaborators

The entity owner may remove any collaborator at any time. Upon removal:

8.5 Leaving a Shared Entity

Collaborators may leave a shared entity at any time from the app. This has the same effect as being removed by the owner.

9 Data Retention

Data CategoryRetention PeriodBasis for Retention
Account information and financial recordsUntil account deletionContract; user control
Plaid-linked transaction recordsUntil account deletionContract; user control
Pending Plaid transaction alerts30 days from creationAutomatic purge policy
Social Security number (Autopilot Savings)Not retained — transmitted to Unit for verification, not stored in our databaseData minimization by design
Other identity data (name, address, DOB) and Autopilot Savings transfer recordsUntil account deletion, or longer if required by banking recordkeeping regulationsContract with Unit's partner bank; legal obligation
Receipt imagesUntil you delete the associated expense record or your accountUser control
AI coaching conversation history (text and voice)1 year from each message dateData minimization policy
Push notification delivery logs90 daysData minimization policy
Security and audit logs1 yearSecurity monitoring; legal obligation
Anonymized analyticsIndefinitely (not personal data)Product improvement

9.1 Account Deletion

When you delete your account (Settings → Account → Delete Account):

10 Security

10.1 Technical Safeguards

10.2 Organizational Safeguards

10.3 Limitations

No security system is perfect. While we implement industry-standard protections, we cannot guarantee absolute security. In the event of a breach affecting your personal data, we will notify you as described in Section 15.

11 Your Rights and Choices

Regardless of your location, you have the following rights with respect to your personal information:

11.1 Access

You have the right to know what personal data we hold about you. Most of your financial data is visible directly in the app. To request a complete data export, email privacy@api.danielesambu.com with "Data Export Request" in the subject line. We will fulfill your request within 30 days.

11.2 Correction

You may correct or update most of your information directly in the app (profile settings, expense records). For information you cannot edit directly, contact us.

11.3 Deletion

You may delete your account and all associated data at any time from Settings → Account → Delete Account. This is immediate and irreversible. Alternatively, contact us to request deletion of specific data.

11.4 Data Portability

You may request a machine-readable export of your personal data by contacting us. We will provide it in JSON or CSV format within 30 days.

11.5 Objection and Restriction

You may object to our processing of your personal data on the basis of legitimate interest, or request that we restrict processing while a dispute is resolved, by contacting us.

11.6 Withdraw Consent

Where we rely on your consent to process data (e.g., push notifications, bank linking), you may withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal.

11.7 How to Submit a Request

Email: privacy@api.danielesambu.com
We will respond within 30 days. We may ask you to verify your identity before fulfilling a request.

12 California Privacy Rights (CCPA / CPRA)

This section applies to California residents. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you additional rights.

12.1 Categories of Personal Information We Collect

In the past 12 months, we have collected the following categories of personal information as defined by the CCPA:

CategoryExamplesCollected?
IdentifiersName, email address, IP address, device IDYes
Personal recordsPhone number, date of birth, state of residenceYes (optional)
Protected classification characteristicsMarital statusYes (optional)
Commercial informationExpense records, financial entities you createYes
Financial informationTransaction data received from Plaid (if linked)Yes (if linked)
Internet or network activityApp interaction logs, session dataYes
Geolocation dataApproximate location from Plaid transactions (city-level)Yes (if linked)
Inferences drawn from personal informationSpending patterns, financial health summaries generated by AuraYes
Biometric informationNone — biometric processing occurs on-device onlyNo
Sensitive personal information (SPI)Social Security Number, financial account numbersNo

12.2 We Do Not Sell or Share Your Personal Information

We do not sell your personal information. We do not share your personal information with third parties for cross-context behavioral advertising. Fortuna is an ad-free application.

12.3 Your California Rights

To exercise your California rights, email privacy@api.danielesambu.com or use the in-app deletion feature. We will respond within 45 days, with one 45-day extension where reasonably necessary.

13 Geographic Restriction — United States Only

Fortuna is available to United States residents only. The Service is not offered to, and may not be used by, individuals located outside the United States.

13.1 US-Only Service

Fortuna is designed, operated, and offered exclusively for use within the United States. All of our services, features, bank-linking integrations, and coaching content are scoped to US law, US financial institutions, and US residents.

13.2 Blocking of International Access

We do not knowingly permit access to the Service from outside the United States. If you are located outside the United States, you are not authorized to use or access Fortuna. We reserve the right to block, suspend, or terminate accounts that we determine are being accessed from outside the United States.

13.3 No Cross-Border Data Transfers

Because we serve only US residents, we do not engage in cross-border personal data transfers subject to frameworks such as GDPR, UK GDPR, or equivalent non-US data protection regimes. If you access the Service in violation of this geographic restriction, you do so at your own risk and you are solely responsible for compliance with any laws of your jurisdiction.

13.4 No GDPR or UK GDPR Obligations

Fortuna does not target individuals in the European Economic Area or the United Kingdom, and does not consider itself subject to the General Data Protection Regulation (GDPR) or UK GDPR. If applicable law in your jurisdiction conflicts with this Policy, please do not use the Service.

14 Data Breach Notification

In the event of a security breach that affects your personal data, we will:

15 Age Requirement

Fortuna is intended for, and may only be used by, individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18.

Age verification occurs during account setup. If you enter a date of birth that indicates you are under 18, your account will be automatically and permanently deleted immediately, and you will not be permitted to use the Service.

If we discover that we have inadvertently collected personal information from a person under 18, we will delete that information immediately. If you believe an underage person has created an account, please contact us at privacy@api.danielesambu.com.

16 Third-Party Links and Services

The app may contain links to third-party websites or services (e.g., Plaid's bank selection interface, legal document pages). This Privacy Policy does not apply to any third-party sites or services. We encourage you to review the privacy policies of any third-party services you access.

We are not responsible for the privacy practices or content of third-party sites or services.

17 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

Continued use of Fortuna after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree to a material change, your sole remedy is to delete your account before the change takes effect.

18 Contact Us

For privacy questions, data requests, or concerns about this Policy:

Fortuna Privacy Team Email: privacy@api.danielesambu.com
Website: api.danielesambu.com/privacy

Response time: We will acknowledge your request within 5 business days and provide a substantive response within 30 days.
Plaid-specific data requests: For inquiries about data that Plaid holds independently (separate from Fortuna), contact Plaid directly at plaid.com/legal.