Who we are
Otium Money Inc. is a Delaware corporation. We make personal finance software available on the web and through our iOS app (together, the “Service”).
We are the controller of your personal information — we decide what is collected and why, and we are accountable for it. This policy explains what we collect, why, who processes it on our behalf, and what control you have.
What we collect
Information you give us
| Category | Examples | Why |
|---|---|---|
| Account information | Email address, display name, passkey credentials, and — if you enable it — a two-factor authentication secret | To create and secure your account |
| Profile and planning inputs | Target retirement age, savings goals, household details, ZIP code, return and inflation assumptions you set | They are the inputs to every projection the Service produces |
| Manual entries | Accounts, holdings, balances or transactions you add by hand | Not everything connects automatically |
| Documents and files you choose | Paystubs, broker CSV exports, and 1099-B forms | To read figures out of them so you don't have to type them |
| Support messages | What you write to us | To answer you and investigate problems |
We do not collect your Social Security number, your street address, or your phone number. There is nowhere in the product to enter them.
Social Security Statement imports
If you select a Social Security Statement XML file, your browser reads it on your device. Selecting the file does not provide the file to Otium: the original is not uploaded or stored by us. After you review and approve the match, we receive and keep only the person’s name and date of birth, the Statement date, benefit estimates, and Social Security covered-earnings entries needed to update the plan, including any aggregate period SSA provides. We validate but do not retain Medicare earnings or payroll-tax totals from the file. The official Statement XML format does not include a Social Security number. You can remove the imported record from your Story at any time.
Financial account information
When you connect an account through Plaid or SnapTrade, we receive the categories you authorize during that provider’s connection flow. In practice that is: account names, types and balances; transaction history including dates, amounts, merchant descriptions and categories; holdings and positions for investment accounts; loan balances and rates; and institution names.
We never receive or store your bank username or password. You enter those directly with Plaid or SnapTrade and they are never visible to us. The access tokens we do hold are encrypted before they touch the database, and they grant read access only — there is no code path in the Service that can move money.
Information collected automatically
| Category | Examples | Why |
|---|---|---|
| Device and app data | Device type, operating system, app version, browser, language | To make the Service work across devices |
| Usage data | Pages viewed, features used, coarse country, referrer | To understand what's working. Cookieless and not linked to your account |
| Diagnostic data | Crash reports, error messages, stack traces, performance traces | To find and fix bugs |
| Log data | IP address, timestamps, request metadata | Security, abuse prevention, debugging |
When an error occurs, our error reporting may capture a short replay of the session that led to it. All text and form inputs are masked in that recording and media is blocked — it captures layout and interaction, never the figures on screen or anything you typed.
What we don’t collect
- We don’t buy information about you from data brokers.
- We don’t track you across other apps and websites.
- We don’t collect precise geolocation.
- We don’t use third-party tracking cookies.
How we use your information
We use your information to:
- Run the Service — display your accounts, calculate net worth, produce projections and insights
- Keep your account secure — authentication, abuse prevention, audit logging of sensitive actions
- Support you — answer questions, investigate problems you report
- Improve the product — understand which features get used, find bugs, fix performance
- Communicate with you — service notices, security alerts, and (if you opt in) product updates
- Meet legal obligations — comply with applicable law and respond to lawful requests
We do not sell your financial data, hand it to third parties for their own purposes, or use it for anything unrelated to providing the Service to you.
Otium is a subscription product. We intend to be paid by the people who use it. That is a deliberate choice about incentives: a company paid by its users answers to them, and a company paid by someone else answers to whoever that is. If we ever earn money any other way, we will say so here, plainly, before it starts.
Automated processing and AI
The Service uses a third-party language model — Anthropic’s Claude — to write the plain-English explanations, weekly synthesis and insights you see, and to categorize transactions. This is worth being precise about, because it means some of your financial information leaves our systems.
- What is sent. Per request, the specific facts that request needs: balances, transaction descriptions and amounts, merchant names, and the planning inputs you provided. Not your email address, and not your name unless you put it in a field the request needs.
- Training. Anthropic’s commercial terms provide that data submitted through its API is not used to train its models. We have not opted into any arrangement that would change that.
- Prompt safety. Text that originated with you or your bank is sanitized before it reaches a prompt, so that a merchant description can’t be used to inject instructions into the model.
- Web search. When the model can’t identify an unfamiliar merchant, it may search the web for that merchant name. Before any such search we screen the string for anything that looks like a personal name — “DBA” entries, Zelle and Venmo descriptions, first-and-last-name patterns — and skip the search entirely rather than send it. The screen is deliberately over-cautious.
These calculations are informational and educational. They do not make decisions that produce legal or similarly significant effects about you, and they are not financial advice. See the Terms of Service for what that means in practice.
Our legal bases for processing
Where the law requires us to identify a legal basis (including for users in the EEA and UK), we rely on:
- Contract — processing needed to provide the Service you signed up for
- Consent — connecting financial accounts, uploading documents, and optional marketing email. You can withdraw consent at any time
- Legitimate interests — securing the Service, preventing abuse, and improving the product, balanced against your privacy
- Legal obligation — where the law requires us to retain or disclose information
Who we share your information with
We do not sell your personal information. We never have, and our revenue model — subscriptions — does not depend on it. The service providers described below process data on our behalf, on our instructions; none of them is buying it.
A small number of service providers process information on our behalf, under contracts limiting them to acting on our instructions. They are not permitted to use your information for their own purposes. These are the categories:
| Category | What it receives |
|---|---|
| Hosting and infrastructure | Request traffic, including IP address, user agent and request metadata; the database itself; and encrypted nightly backups. |
| Account connections | Your institution credentials, entered directly with the provider and never visible to us, plus the read-only account data you authorize. |
| AI language model | Per request, the specific financial facts that request needs. Not used to train the provider's models. See §3. |
| Document processing | A paystub you choose to upload, for text extraction. Only when you use that feature. |
| Email delivery | Your email address and the contents of the message being sent to you. |
| Error and performance monitoring | Error messages, stack traces and technical context, with automated PII scrubbing applied before transmission. See §6. |
| Security and abuse prevention | A challenge token and the IP address of a request being checked, on public forms. |
| Market data | Ticker symbols only, to price securities. No account identifier is sent. |
| App distribution | Whatever Apple collects as the distributor of the iOS app under its own policy. We receive only aggregate, anonymous statistics. |
| Payments | Nothing today — no payment flow exists. Once subscriptions launch: card details entered directly with the processor, plus billing contact and subscription status. We would never hold your full card number. |
Three of these are worth naming, because you either authorize them yourself or should know your information reaches them:
- Plaid and SnapTrade — our account-connection providers. You authorize one of them by name when you link an account, and your relationship with them is governed by their own privacy policies as well as this one.
- Anthropic — the language model described in §3. Financial facts leave our systems on each request, which is worth stating outright rather than leaving to a category.
- Stripe not yet active — will process subscription payments when paid plans launch. It receives nothing today, and this listing is the advance notice we promise below.
We’ll name every current processor on request — email privacy@otiummoney.com and you’ll get the list. Before any new processor starts handling your information, we’ll update this page.
We may also disclose information:
- To comply with law — in response to a valid subpoena, court order or legal process. Where we are permitted to notify you, we will.
- To protect rights and safety — to investigate fraud, security incidents or threats of harm.
- In a business transfer — if we are acquired or merge, your information may transfer as part of that. We will notify you before your information becomes subject to a different privacy policy.
How we protect your information
What follows describes controls that are actually implemented, not aspirations. Where something isn’t in place, we say so.
- Encryption in transit. All traffic is served over HTTPS.
- Encryption at rest. The database is encrypted at rest by our provider. Backups are stored encrypted.
- Application-layer encryption for secrets. The most sensitive values — financial-institution access tokens, brokerage credentials and two-factor secrets — are encrypted with AES-256-GCM before they are written to the database, using a key held in the application environment and never sent to the database. A stolen database credential alone does not yield them.
- Authentication. Passkeys (WebAuthn) are the primary sign-in method, with an emailed sign-in link as the recovery path and optional time-based two-factor authentication. Sessions are stored server-side; the browser cookie is an opaque identifier that carries no data of its own.
- Re-verification for destructive actions. Sensitive operations — deleting your account, disconnecting institutions, changing security settings — require a fresh authentication step even within a valid session, and are written to an audit log.
- Scrubbed error reporting. Our error monitoring is configured not to auto-collect personal data, every event passes through an additional scrubbing filter before transmission, and session replays mask all text and inputs. Telemetry is tunneled through our own domain rather than sent to a third-party origin.
- Bot protection and rate limiting on public-facing forms and endpoints.
- Backups. The database is backed up nightly and retained for 14 days, then deleted.
Otium Money has not completed a SOC 2 audit, a third-party penetration test, or any other external security certification. Some of our vendors hold such certifications; we do not, and we won’t imply otherwise. If that matters to your decision, it should factor in.
No system is perfectly secure. Use a passkey or a strong unique password, turn on two-factor authentication, and tell us immediately at security@otiummoney.com if you suspect unauthorized access. If a breach affects your personal information, we will notify you and any required regulators as the law requires.
How long we keep your information
| Data | How long we keep it |
|---|---|
| Account, financial and planning data | While your account is active |
| After you delete your account | Deleted immediately. Deletion cascades across every table holding your data — it is not a flag or a scheduled job |
| Backups | Up to 14 days, then deleted on the nightly cycle. A deleted account may persist in a backup until it ages out |
| Uploaded paystubs | Held at most 60 seconds during extraction, then deleted. The figures you confirm are kept; the file is not |
| Social Security Statement imports | The original file stays on your device and is never stored by Otium. The derived facts you approve are kept while your account is active, or until you remove that record |
| Records we must keep by law | As long as the relevant law requires |
| Aggregated, de-identified data | May be kept indefinitely — it cannot be tied back to you |
Your choices and rights
Wherever you live, you can:
- Access the information we hold about you
- Export your data — email us and we will send a machine-readable archive. There is no self-serve export yet
- Correct anything inaccurate
- Delete your account and data, from Settings, at any time
- Disconnect any linked financial account at any time
- Opt out of marketing email. Service and security messages will continue
Use the controls in the Service or email privacy@otiummoney.com. We respond within the timeframe the law requires, and we will not treat you differently for exercising any of these rights.
If you’re in California
Under the CCPA/CPRA you may request disclosure of the categories and specific pieces of personal information we have collected, the sources, our purposes, and the categories of third parties we share with; deletion; correction; and to limit use of sensitive personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising — both as those terms are defined by that statute. You may use an authorized agent to make a request.
If you’re in Colorado, Connecticut, Virginia, Utah, or another state with a comprehensive privacy law
You have rights to access, correct, delete and port your personal information, and to opt out of targeted advertising, sale and certain profiling. As those laws define them, we do none of the three. Where required, you may appeal a denied request by replying to our response.
If you’re in the EEA or UK
The Service is offered from the United States and is not currently marketed in the EEA or UK. If you use it from there, you have rights of access, rectification, erasure, restriction, portability and objection, and you may lodge a complaint with your local supervisory authority. Your information is processed in the United States.
Financial privacy
Because we handle financial account information, additional protections may apply to us under federal and state financial privacy law, including the Gramm-Leach-Bliley Act.
Regardless of how that question resolves, we treat your financial information as sensitive personal information and apply heightened care to how it is stored, accessed and shared.
Children
The Service is not directed to anyone under 18, and we don’t knowingly collect information from children. If you believe a child has given us personal information, email privacy@otiummoney.com and we will delete it.
Third-party links and services
The Service links to third-party sites and services — your financial institutions, Plaid, SnapTrade and others listed in §5. Their privacy practices are their own and we are not responsible for them. Please read their policies.
Changes to this policy
We may update this policy. For material changes we will give you reasonable advance notice by email or in the Service before they take effect, and you will be asked to review the updated version the next time you sign in. The effective date at the top of this page always reflects the current version.
Contact us
Questions, requests or concerns about privacy:
Longmont, Colorado
privacy@otiummoney.com
For security reports specifically, use security@otiummoney.com. We read every one of these.