Privacy Policy
Last updated: July 22, 2026
Vassant Finance LLC ("Vassant," "we," "us," or "our") is committed to protecting your privacy and maintaining the highest standards of data integrity. This policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our financial tracking and allocation services.
1. Information Collection and Usage
We collect information to provide, operate, and maintain our financial tools.
- Personal Data: When you register, we may collect personally identifiable information such as your name and email address.
- Usage and Device Data: We automatically collect data including IP addresses, browser types, operating systems, access times, and unique device identifiers to improve and personalize our services.
- Financial and Plan Data: We collect the financial information you enter and the information retrieved from accounts you link, including budgets, income and expenses, contribution allocations, investment holdings, targets, purchase history, account balances, and transaction history. This data is stored against your account and is used to provide the service back to you. It is identified data, not anonymous — that is what allows the app to show you your own plan. Where we use this information for product research or aggregate statistics, we do so only after aggregating or de-identifying it.
- Content You Create: Notes, vault pages, conviction scores, and other written content you enter in the app are stored against your account so we can show them back to you. We do not use the content of your notes for advertising, and we do not send it to our analytics provider.
- Push Notification Tokens: If you enable notifications, we store the push token issued to your device so we can deliver alerts you have asked for.
Signing In With Apple, Google, or Facebook: The app offers sign-in through Apple, Google, and Facebook. These providers supply their own software to the app to complete sign-in. If you choose one, that provider receives the fact that you are signing in to Vassant and returns a unique identifier for you, together with the email address and name on file with them, which we store to create or match your account. We do not receive your password with these providers, and we do not use their software for advertising, app-event reporting, or advertising identifiers — those features are disabled in our builds. If you would rather not involve a third party, you can register with an email address and password instead.
Website Analytics & Cookies: Our website uses Google Analytics to understand how visitors use our pages. Analytics cookies and any related identifiers are only set after you accept via our consent banner; until then, analytics runs in a cookieless, consent-denied state (Google Consent Mode). Your choice is remembered across vassantfinance.com and its subdomains, and you can change it at any time by clearing the va_consent cookie in your browser.
In-App Product Analytics: Our mobile app uses PostHog to understand which features are used and where the experience can be improved. Events record in-app navigation and feature usage — for example, which tab you opened, which learning lesson you viewed, or which ticker symbol you looked at — together with device and app metadata (device model, operating system, app version, locale, time zone) and your IP address. Once you sign in, these events are associated with a numeric account identifier rather than your name or email address, and activity recorded before you signed in is linked to that identifier.
We do not send your financial values to PostHog. Account balances, holdings, transaction amounts, and portfolio totals are not included in analytics events. The app does not record your screen, capture your taps, or take session recordings. You can turn off product analytics at any time in the app's settings, which stops events from being sent.
2. Plaid Data Processing & Connectivity
Vassant uses Plaid Inc. ("Plaid") to enable secure bank account connectivity and retrieve your financial data. When you connect your accounts, Plaid acts as a data processor on our behalf.
- Data Collected via Plaid: The categories of data Plaid may access and transmit to us include account holder names, account and routing numbers, balances, and transaction history.
- User Consent: Before using account connectivity features, Vassant will present a clear notice explaining Plaid's role. By proceeding, you consent to Plaid's processing of your data as described in the Plaid End User Privacy Policy.
- Data Minimization: End User Data obtained through Plaid is collected and retained only to the extent required to deliver authorized services. We do not store bank credentials obtained via Plaid beyond what is technically required for the connection.
- No Sale of Data: We do not sell or rent End User Data collected through Plaid to marketers or any third party.
- Managing Connections: You may view and manage your connections or request deletion of your Plaid data by visiting the Plaid Portal.
3. Payment Processing & Subscription Billing
Vassant uses Stripe, Inc. ("Stripe") to process payments and manage recurring subscriptions. By subscribing to our paid services, you agree to the processing of your payment information by Stripe.
- Payment Data: Subscriptions are purchased on a Stripe-hosted checkout page, which opens outside the app. Card details and billing addresses are entered there and go directly to Stripe. Vassant never receives your card number, CVV, expiration date, or the last four digits, and no card data passes through the app. What we store is a Stripe customer and subscription identifier plus subscription status — the plan, the renewal date, and whether it is set to cancel — which is what we need to know whether your account is active.
- Subscription Management: Stripe acts as our merchant of record for billing. This includes handling upgrades, downgrades, and cancellations of your Vassant subscription.
- Security Standards: Stripe has been audited by a PCI-certified auditor and is certified as a PCI Level 1 Service Provider. This is the most stringent level of certification available in the payments industry.
- Privacy Policy: All payment processing is subject to the Stripe Privacy Policy. You acknowledge that Stripe may process your data for its own purposes, including fraud prevention and regulatory compliance.
4. Our Security Commitment
Vassant employs an Information Security Program (ISP) designed to protect user data.
- Least-Privilege Access: We follow a least-privilege access model. All internal systems require per-user named accounts with Multi-Factor Authentication (MFA). Production access is restricted to the CTO.
- Consumer MFA: Multi-Factor Authentication (MFA) is available for all consumer accounts and can be enabled in account settings. When enabled, MFA is required at every login.
- Encryption: Sensitive fields such as financial access tokens are encrypted at rest using application-level encryption. All data in transit is protected by TLS 1.2 or higher, covering all data retrieved via the Plaid API.
- Incident Notification: In the event of unauthorized access to End User Data obtained through Plaid, Vassant will notify Plaid within 24 hours of confirmation at security@plaid.com, notify affected users within 72 hours, and notify regulators as required by applicable law.
- User Responsibility: While we strive to protect your data, no system is 100% secure. You use the app at your own risk and must safeguard your login credentials.
5. Data Rights and Choices
Depending on your location (e.g., CCPA in California, GDPR in the EU/UK, or GLBA in the U.S.), you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Update or correct inaccurate personal information.
- Deletion: Delete your account and its data yourself, at any time, from Account Information > Danger zone > Delete account in the app. This does not require a request to us: it removes your account and everything stored against it — plan, budget, holdings, notes, and connected-account links — immediately and permanently, subject only to the legal retention obligations described in Section 6. You may also email us instead if you prefer.
- Opt-out: Limit certain uses or sharing of your data. Product analytics can be turned off in the app at Settings > Privacy > Share usage analytics.
- Plaid Data Rights: You may also exercise rights over data held by Plaid directly at my.plaid.com.
To exercise the rights above that are not self-service, please email us at support@vassantfinance.com.
6. Data Retention
We retain your data only as long as necessary to provide services, comply with legal obligations, or resolve disputes. Deleting your account in the app removes your data from the production database immediately. Deletion requests sent to us by email are honored within 30 days of receipt. In both cases, backup snapshots containing deleted data expire within 7 days. Data may be retained longer where required by law (e.g., tax obligations, legal holds, or fraud investigations).
When you disconnect a Plaid-linked account or delete your Vassant account, Vassant calls Plaid's /item/remove endpoint to revoke the access token and instruct Plaid to delete the corresponding data on Plaid's side.
7. Third-Party Service Providers (Subprocessors)
Vassant uses the following third-party service providers to operate the Platform. Each processes data on our behalf or as part of delivering the service:
| Provider | Purpose | Data Handled |
|---|---|---|
| Plaid | Financial account aggregation | User identifiers, financial account data (see Section 2) |
| Stripe | Payment processing and subscription billing | Payment tokens, billing metadata (see Section 3) |
| TwelveData | Market data API and company logos | No user PII from our servers. Company logo images are served to your device directly, so TwelveData receives your IP address and the symbol requested |
| Logo.dev | Company logo images | Logos are served to your device directly, so Logo.dev receives your IP address and the symbol requested |
| Sentry | Error and crash reporting | May incidentally contain user identifiers in error context |
| Render | Application hosting and persistent storage | All production data |
| Google (Gmail, Drive) | Company email and document storage | Operational and business data |
| Google Analytics | Website usage analytics (consent-based) | Anonymized usage/device data; cookies only after consent |
| PostHog | In-app product analytics | Account identifier, device/app metadata, IP address, in-app feature usage; no financial values |
| Apple | Sign in with Apple | Sign-in identifier, and the name and email you release to us |
| Google sign-in | Sign-in identifier, name, email address | |
| Meta (Facebook) | Facebook sign-in | Sign-in identifier, name, email address. Advertising features, app-event logging, and advertising identifiers are disabled in our builds |
| Expo / EAS | Mobile app build infrastructure and push notification delivery | Build artifacts contain no production user data. Push delivery handles your device's push token and the contents of notifications sent to you |
We do not sell or rent your personal data to any third party for marketing or advertising purposes.
8. International Users and Transfers
Vassant is based in the United States. If you are located outside the U.S., please note that your information will be processed and stored on U.S. servers. By using the App, you consent to the transfer of your data to the U.S. and the application of U.S. privacy laws, which may differ from those in your jurisdiction.
9. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware of such collection, we will take immediate steps to remove the data.
10. Contact and Updates
We may update this policy periodically and will notify you of material changes via email or in-app messaging.
- Email: support@vassantfinance.com
- Phone: +1 (442) 500-4853
- Address: 3666 Jefferson St, Riverside, California 92504