Privacy Policy
Effective September 21, 2026
Clementine (“Clementine”, “we”) is a household finance application at clementine.financial. It shows you your bank, card and brokerage activity in one place, keeps a ledger and a budget over it, and lets one other person in your household see the same. This policy explains what we collect, why, who processes it for us, how long we keep it, and how you delete it.
What we collect
Your account
Sign-in is run by WorkOS. We receive your name, email address and a WorkOS user identifier. We never see or store your password.
Your financial data, through Plaid
When you connect a financial institution you do so through Plaid Link. Plaid retrieves, on your behalf, the accounts under that login (names, types, last four digits, balances), their transactions (date, amount, description, merchant, Plaid’s category), and for brokerage accounts the holdings and the investment activity (buys, sells, dividends, fees, transfers). Plaid gives us a token that lets us read this data; that token is stored encrypted, and we never see your bank credentials. Plaid’s handling of your data is governed by Plaid’s End User Privacy Policy.
What you type
Owner labels on accounts, budgets, price targets and watchlist tickers, notes, ledger reclassifications and manual entries, and the messages you send to the assistant.
Billing
Subscriptions are handled by Stripe. Stripe collects and stores your payment card; we receive only a customer identifier, the subscription’s status and dates. We never see your card number.
Technical data
Our servers log request metadata (time, path, status, an IP address) for security and troubleshooting. Error reports go to Sentry with personal data, cookies and request bodies stripped. We use one essential cookie for your session and a few for interface preferences (theme, panel state). We use no advertising or analytics trackers.
How we use it
- To show you your finances: balances, transactions, holdings, statements, budgets and charts.
- To run the assistant when you ask it something (see “The assistant” below).
- To bill your household’s subscription.
- To keep the service secure and working.
We do not sell your data, share it with advertisers, use it to market other products, or use it to train machine-learning models.
Your household
Everything you connect or type is visible only to you until you merge finances with one other person on the Household page, and only after they accept. From then on the two of you see each other’s accounts, transactions, holdings, ledger and budget. Either of you can stop sharing at any time; nothing is copied, so stopping simply ends the other person’s view. Assistant conversations are never shared.
The assistant
The assistant is built on Claude, a model provided by Anthropic. When you ask it something, your message, the conversation so far and the data the assistant looks up to answer (which can include balances, transactions, holdings and budget figures) are sent to Anthropic’s API. Anthropic processes this data to generate the reply and, under its commercial terms, does not use it to train its models. Only your last four account digits, never full account names or identifiers, are included.
Who processes data for us
| Provider | Purpose | What they receive |
|---|---|---|
| Plaid | Connecting to your financial institutions | Your institution login (entered with Plaid, never seen by us); returns your financial data |
| WorkOS | Sign-in and multi-factor authentication | Name, email, authentication factors |
| Stripe | Subscription billing | Name, email, payment card |
| Anthropic | The assistant | Your messages and the financial data the assistant looks up |
| Amazon Web Services | Hosting and the database (United States) | Everything we store |
| Cloudflare | Network security in front of the service | Request metadata, IP address |
| Sentry | Error reporting | Error traces with personal data stripped |
| Yahoo Finance | Market prices for investments | Ticker symbols only, never quantities or values |
Each processes data only to provide its service to us. We disclose data to no one else, except where the law requires it.
How we protect it
- Encrypted in transit everywhere, and at rest in the database and its backups.
- Plaid access tokens are encrypted a second time, at the application level, before they are stored.
- Multi-factor authentication for your sign-in, and for every administrator account behind the service.
- Servers reachable only through Cloudflare; the database reachable only from the application; no remote shell access.
- Every request is checked against your household, so nobody outside it can read your rows.
How long we keep it
- While your account is active, we keep what is needed to show your finances. Disconnecting an institution deletes its accounts, transactions, holdings and ledger immediately and revokes our access at Plaid.
- When you delete your account (Household page → Delete my account), we revoke every Plaid connection, delete your sign-in at WorkOS and erase everything you own, immediately. If you were the only member, your household and its Stripe customer are deleted with it. A partner keeps their own data.
- Backups of the database are kept for 7 days and then expire, so deleted data is gone from backups within a week.
- Stripe keeps invoices and payment records for as long as tax and financial regulation require it to; we hold no copy.
- Logs and error reports are kept for 90 days at most.
- An account whose sign-in is deleted by an administrator, rather than by you, is deactivated at once and erased after 30 days.
Our internal retention policy, which the above summarises, is reviewed every year.
Your choices and rights
- See your data: everything we hold is shown in the application.
- Disconnect an institution: Accounts page → Remove. You can also revoke Plaid’s access to any app at my.plaid.com.
- Delete everything: Household page → Delete my account.
- Correct your name or email: through your sign-in profile; changes reach us automatically.
- Ask us anything, or exercise a right under the law that applies to you (for example, California residents’ rights to know, delete and correct), by writing to [email protected]. We answer within 30 days.
Children
Clementine is for adults. We do not knowingly collect data from anyone under 18.
Changes
If this policy changes in a way that matters, we will say so in the application before the change takes effect. The effective date at the top always tells you which version you are reading.
Contact
Privacy: [email protected]
Security: [email protected]