← Croft

Privacy Policy

Last updated: October 6, 2026

Croft ("the Service", "we", "us") is a personal-finance and debt-elimination tool operated by [COMPANY/OWNER NAME]. This policy explains what information we collect, why, who we share it with, and the choices you have. We practice data minimization: we collect only what the Service needs to show you your money and project your debt paydown, and we do not sell your data or use it for advertising.

AI processing of your financial data. Croft sends some of your financial data to Anthropic (the maker of Claude) to power its in-app assistant and to automatically categorize your transactions. This is described in detail in the Artificial-intelligence processing section below. Please read it before you link an account.

Information we collect

Identity (via Google Sign-In)

Google is our sole sign-in method. When you sign in, we receive from Google your email address, name, profile image, and whether your email is verified. We do not receive your Google password.

Financial data you add or link

We store the following in our database to operate the Service:

  • Accounts — name, type, balances, interest rate / APR, monthly payment, statement and due dates, and credit limit.
  • Transactions — date, amount, the raw bank descriptor, merchant, category, and enrichment data from Plaid (such as merchant logo, website, and location).
  • Recurring rules — the income and expense patterns you define to drive projections and budgets.
  • Budgets and paydown projections — derived plans and forecasts the Service computes from your rules and balances.
  • Assistant chat history — your full conversation history with the in-app assistant, so it follows you across devices.

Bank data (via Plaid)

If you link a bank, you do so through Plaid. Your bank login credentials are entered directly into Plaid's secure Link flow and are never seen or stored by Croft. We receive from Plaid your account, balance, transaction, and liability data. The access tokens that let us refresh this data are stored encrypted at rest (AES-256-GCM).

Cookies and sessions

We use a single httpOnly session cookie (database-backed sessions via Auth.js) to keep you signed in, plus short-lived OAuth CSRF/callback cookies during the sign-in handshake. We use no analytics, tracking, or advertising cookies — the Service contains none.

How we use your information

  • To authenticate you and keep your session secure.
  • To display your accounts, balances, and transactions, and to compute budgets, projections, and debt-paydown plans.
  • To power the in-app assistant and to categorize your transactions (see below).
  • To maintain, debug, and secure the Service.

We do not sell your personal or financial data, and we do not use it for advertising or for building cross-site profiles.

Artificial-intelligence processing (Anthropic / Claude)

Croft uses Anthropic's Claude models to provide its assistant and categorization features. This means some of your financial data is transmitted to Anthropic for processing.

There are two paths by which data reaches Anthropic:

  • In-app assistant. When you use the assistant, we send your account balances, APRs, recurring income and expenses, and paydown projections to Anthropic. When you ask about specific activity, individual transactions are sent on demand.
  • Background auto-categorizer.To label your spending, the Service automatically sends each transaction's merchant name, bank descriptor, and amount to Anthropic for categorization. This happens in the background, without a separate prompt from you.

Anthropic processes this data to return a response to the Service. Anthropic's API does not train its models on this data by default. Anthropic's own handling of API data is governed by its policies.

Who we share data with (subprocessors)

We share data only with the service providers that run the Service. Each receives only what it needs:

ProviderPurposeWhat it receives
GoogleSign-in (OAuth)Handles authentication; provides us your email, name, profile image, and email-verified status.
PlaidBank linkingYour bank credentials (entered directly into Plaid, never to us); returns account, balance, transaction, and liability data.
AnthropicAI assistant & transaction categorizationAccount balances, APRs, recurring income/expenses, paydown projections, and transaction details (merchant, descriptor, amount). See the AI section above.
VercelHosting, compute, scheduled jobsProcesses requests and runs the Service; data transits its infrastructure.
NeonDatabaseStores your account, transaction, rule, budget, projection, and chat data at rest.

We may also disclose information if required by law, to protect our rights or users' safety, or as part of a business transfer (in which case we will give notice as required).

Data retention

We keep your data for as long as your account is active. When you delete your account (see Your rights), we delete your personal and financial data from our database, and we revoke Plaid access tokens. Residual copies may persist briefly in routine backups before they age out. We may retain limited records where required by law.

How we protect your data

  • Plaid access tokens are encrypted at rest using AES-256-GCM.
  • Data is transmitted over encrypted connections (HTTPS/TLS) and stored with our infrastructure providers.
  • Access is scoped to your own account; the Service is designed so you see only your own data.
  • Sign-in is delegated to Google; we never handle your bank or Google passwords.

No system is perfectly secure, and we cannot guarantee absolute security.

Your rights and choices

  • Access & export. You may request a copy of the data associated with your account.
  • Deletion. You may delete your account and the data we hold about you.
  • Unlink a bank. You may disconnect a linked bank, which stops further data refresh from Plaid.

To make any of these requests, contact us at [CONTACT EMAIL]. Depending on your location, you may have additional rights under laws such as the GDPR or CCPA; we will honor applicable rights.

Children's privacy

The Service is not directed to children. It is intended for adults (18+), and in any case is not for use by anyone under 13. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this policy as the Service evolves. When we do, we will revise the "Last updated" date above, and for material changes we will provide a more prominent notice. Continued use after an update means you accept the revised policy.

Contact

Questions about this policy or your data? Contact [COMPANY/OWNER NAME] at [CONTACT EMAIL].