Privacy Policy

What Otium can see, and what we do with it.

Connecting an account lets Otium read it — balances, transactions, holdings. Nothing more. We never hold your money, we can’t move it, and your accounts stay entirely yours. This page is the full account of what we read, who processes it, and how to remove all of it.

Effective
August 16, 2026
Last updated
August 16, 2026
Controller
Otium Money Inc.

The short version

The full policy below controls, but nothing in it contradicts any of this.

  • We don’t sell your data. Not to data brokers, not to anyone. This isn’t a policy we might quietly change — it’s the point of the product.
  • You pay us, so your data doesn’t have to. Otium is a subscription product. Our revenue comes from people choosing to pay for it, which is what keeps our incentives pointed at you.
  • We never hold or move your money. Otium isn’t a bank, a broker, or a wallet. It reads the accounts you connect and nothing else — we could not initiate a transfer if we wanted to.
  • We collect what the product needs to work, and all of it is listed in §2.
  • Deleting your account deletes your data — right then, not on a schedule. Backups age out within 14 days.
  • A few service providers process data for us. §5 lists every category and what each one gets, names the ones you should know about, and we’ll send the current list of all of them if you ask.

If anything here is unclear, email privacy@otiummoney.com and ask. A real person reads it.

Who we are

Otium Money Inc. is a Delaware corporation. We make personal finance software available on the web and through our iOS app (together, the “Service”).

We are the controller of your personal information — we decide what is collected and why, and we are accountable for it. This policy explains what we collect, why, who processes it on our behalf, and what control you have.

What we collect

Information you give us

Categories of information you provide directly, with examples and the reason each is collected.
CategoryExamplesWhy
Account informationEmail address, display name, passkey credentials, and — if you enable it — a two-factor authentication secretTo create and secure your account
Profile and planning inputsTarget retirement age, savings goals, household details, ZIP code, return and inflation assumptions you setThey are the inputs to every projection the Service produces
Manual entriesAccounts, holdings, balances or transactions you add by handNot everything connects automatically
Documents and files you choosePaystubs, broker CSV exports, and 1099-B formsTo read figures out of them so you don't have to type them
Support messagesWhat you write to usTo answer you and investigate problems

We do not collect your Social Security number, your street address, or your phone number. There is nowhere in the product to enter them.

Social Security Statement imports

If you select a Social Security Statement XML file, your browser reads it on your device. Selecting the file does not provide the file to Otium: the original is not uploaded or stored by us. After you review and approve the match, we receive and keep only the person’s name and date of birth, the Statement date, benefit estimates, and Social Security covered-earnings entries needed to update the plan, including any aggregate period SSA provides. We validate but do not retain Medicare earnings or payroll-tax totals from the file. The official Statement XML format does not include a Social Security number. You can remove the imported record from your Story at any time.

Financial account information

When you connect an account through Plaid or SnapTrade, we receive the categories you authorize during that provider’s connection flow. In practice that is: account names, types and balances; transaction history including dates, amounts, merchant descriptions and categories; holdings and positions for investment accounts; loan balances and rates; and institution names.

We never receive or store your bank username or password. You enter those directly with Plaid or SnapTrade and they are never visible to us. The access tokens we do hold are encrypted before they touch the database, and they grant read access only — there is no code path in the Service that can move money.

Information collected automatically

Categories of information collected automatically, with examples and the reason each is collected.
CategoryExamplesWhy
Device and app dataDevice type, operating system, app version, browser, languageTo make the Service work across devices
Usage dataPages viewed, features used, coarse country, referrerTo understand what's working. Cookieless and not linked to your account
Diagnostic dataCrash reports, error messages, stack traces, performance tracesTo find and fix bugs
Log dataIP address, timestamps, request metadataSecurity, abuse prevention, debugging

When an error occurs, our error reporting may capture a short replay of the session that led to it. All text and form inputs are masked in that recording and media is blocked — it captures layout and interaction, never the figures on screen or anything you typed.

What we don’t collect

  • We don’t buy information about you from data brokers.
  • We don’t track you across other apps and websites.
  • We don’t collect precise geolocation.
  • We don’t use third-party tracking cookies.

How we use your information

We use your information to:

  • Run the Service — display your accounts, calculate net worth, produce projections and insights
  • Keep your account secure — authentication, abuse prevention, audit logging of sensitive actions
  • Support you — answer questions, investigate problems you report
  • Improve the product — understand which features get used, find bugs, fix performance
  • Communicate with you — service notices, security alerts, and (if you opt in) product updates
  • Meet legal obligations — comply with applicable law and respond to lawful requests

We do not sell your financial data, hand it to third parties for their own purposes, or use it for anything unrelated to providing the Service to you.

Otium is a subscription product. We intend to be paid by the people who use it. That is a deliberate choice about incentives: a company paid by its users answers to them, and a company paid by someone else answers to whoever that is. If we ever earn money any other way, we will say so here, plainly, before it starts.

Automated processing and AI

The Service uses a third-party language model — Anthropic’s Claude — to write the plain-English explanations, weekly synthesis and insights you see, and to categorize transactions. This is worth being precise about, because it means some of your financial information leaves our systems.

  • What is sent. Per request, the specific facts that request needs: balances, transaction descriptions and amounts, merchant names, and the planning inputs you provided. Not your email address, and not your name unless you put it in a field the request needs.
  • Training. Anthropic’s commercial terms provide that data submitted through its API is not used to train its models. We have not opted into any arrangement that would change that.
  • Prompt safety. Text that originated with you or your bank is sanitized before it reaches a prompt, so that a merchant description can’t be used to inject instructions into the model.
  • Web search. When the model can’t identify an unfamiliar merchant, it may search the web for that merchant name. Before any such search we screen the string for anything that looks like a personal name — “DBA” entries, Zelle and Venmo descriptions, first-and-last-name patterns — and skip the search entirely rather than send it. The screen is deliberately over-cautious.

These calculations are informational and educational. They do not make decisions that produce legal or similarly significant effects about you, and they are not financial advice. See the Terms of Service for what that means in practice.

Who we share your information with

We do not sell your personal information. We never have, and our revenue model — subscriptions — does not depend on it. The service providers described below process data on our behalf, on our instructions; none of them is buying it.

A small number of service providers process information on our behalf, under contracts limiting them to acting on our instructions. They are not permitted to use your information for their own purposes. These are the categories:

Categories of service provider that process user information on our behalf, and what each category receives.
CategoryWhat it receives
Hosting and infrastructureRequest traffic, including IP address, user agent and request metadata; the database itself; and encrypted nightly backups.
Account connectionsYour institution credentials, entered directly with the provider and never visible to us, plus the read-only account data you authorize.
AI language modelPer request, the specific financial facts that request needs. Not used to train the provider's models. See §3.
Document processingA paystub you choose to upload, for text extraction. Only when you use that feature.
Email deliveryYour email address and the contents of the message being sent to you.
Error and performance monitoringError messages, stack traces and technical context, with automated PII scrubbing applied before transmission. See §6.
Security and abuse preventionA challenge token and the IP address of a request being checked, on public forms.
Market dataTicker symbols only, to price securities. No account identifier is sent.
App distributionWhatever Apple collects as the distributor of the iOS app under its own policy. We receive only aggregate, anonymous statistics.
PaymentsNothing today — no payment flow exists. Once subscriptions launch: card details entered directly with the processor, plus billing contact and subscription status. We would never hold your full card number.

Three of these are worth naming, because you either authorize them yourself or should know your information reaches them:

  • Plaid and SnapTrade — our account-connection providers. You authorize one of them by name when you link an account, and your relationship with them is governed by their own privacy policies as well as this one.
  • Anthropic — the language model described in §3. Financial facts leave our systems on each request, which is worth stating outright rather than leaving to a category.
  • Stripe not yet active — will process subscription payments when paid plans launch. It receives nothing today, and this listing is the advance notice we promise below.

We’ll name every current processor on request — email privacy@otiummoney.com and you’ll get the list. Before any new processor starts handling your information, we’ll update this page.

We may also disclose information:

  • To comply with law — in response to a valid subpoena, court order or legal process. Where we are permitted to notify you, we will.
  • To protect rights and safety — to investigate fraud, security incidents or threats of harm.
  • In a business transfer — if we are acquired or merge, your information may transfer as part of that. We will notify you before your information becomes subject to a different privacy policy.

How we protect your information

What follows describes controls that are actually implemented, not aspirations. Where something isn’t in place, we say so.

  • Encryption in transit. All traffic is served over HTTPS.
  • Encryption at rest. The database is encrypted at rest by our provider. Backups are stored encrypted.
  • Application-layer encryption for secrets. The most sensitive values — financial-institution access tokens, brokerage credentials and two-factor secrets — are encrypted with AES-256-GCM before they are written to the database, using a key held in the application environment and never sent to the database. A stolen database credential alone does not yield them.
  • Authentication. Passkeys (WebAuthn) are the primary sign-in method, with an emailed sign-in link as the recovery path and optional time-based two-factor authentication. Sessions are stored server-side; the browser cookie is an opaque identifier that carries no data of its own.
  • Re-verification for destructive actions. Sensitive operations — deleting your account, disconnecting institutions, changing security settings — require a fresh authentication step even within a valid session, and are written to an audit log.
  • Scrubbed error reporting. Our error monitoring is configured not to auto-collect personal data, every event passes through an additional scrubbing filter before transmission, and session replays mask all text and inputs. Telemetry is tunneled through our own domain rather than sent to a third-party origin.
  • Bot protection and rate limiting on public-facing forms and endpoints.
  • Backups. The database is backed up nightly and retained for 14 days, then deleted.

Otium Money has not completed a SOC 2 audit, a third-party penetration test, or any other external security certification. Some of our vendors hold such certifications; we do not, and we won’t imply otherwise. If that matters to your decision, it should factor in.

No system is perfectly secure. Use a passkey or a strong unique password, turn on two-factor authentication, and tell us immediately at security@otiummoney.com if you suspect unauthorized access. If a breach affects your personal information, we will notify you and any required regulators as the law requires.

How long we keep your information

Retention periods by category of data.
DataHow long we keep it
Account, financial and planning dataWhile your account is active
After you delete your accountDeleted immediately. Deletion cascades across every table holding your data — it is not a flag or a scheduled job
BackupsUp to 14 days, then deleted on the nightly cycle. A deleted account may persist in a backup until it ages out
Uploaded paystubsHeld at most 60 seconds during extraction, then deleted. The figures you confirm are kept; the file is not
Social Security Statement importsThe original file stays on your device and is never stored by Otium. The derived facts you approve are kept while your account is active, or until you remove that record
Records we must keep by lawAs long as the relevant law requires
Aggregated, de-identified dataMay be kept indefinitely — it cannot be tied back to you

Your choices and rights

Wherever you live, you can:

  • Access the information we hold about you
  • Export your data — email us and we will send a machine-readable archive. There is no self-serve export yet
  • Correct anything inaccurate
  • Delete your account and data, from Settings, at any time
  • Disconnect any linked financial account at any time
  • Opt out of marketing email. Service and security messages will continue

Use the controls in the Service or email privacy@otiummoney.com. We respond within the timeframe the law requires, and we will not treat you differently for exercising any of these rights.

If you’re in California

Under the CCPA/CPRA you may request disclosure of the categories and specific pieces of personal information we have collected, the sources, our purposes, and the categories of third parties we share with; deletion; correction; and to limit use of sensitive personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising — both as those terms are defined by that statute. You may use an authorized agent to make a request.

If you’re in Colorado, Connecticut, Virginia, Utah, or another state with a comprehensive privacy law

You have rights to access, correct, delete and port your personal information, and to opt out of targeted advertising, sale and certain profiling. As those laws define them, we do none of the three. Where required, you may appeal a denied request by replying to our response.

If you’re in the EEA or UK

The Service is offered from the United States and is not currently marketed in the EEA or UK. If you use it from there, you have rights of access, rectification, erasure, restriction, portability and objection, and you may lodge a complaint with your local supervisory authority. Your information is processed in the United States.

Financial privacy

Because we handle financial account information, additional protections may apply to us under federal and state financial privacy law, including the Gramm-Leach-Bliley Act.

Regardless of how that question resolves, we treat your financial information as sensitive personal information and apply heightened care to how it is stored, accessed and shared.

Children

The Service is not directed to anyone under 18, and we don’t knowingly collect information from children. If you believe a child has given us personal information, email privacy@otiummoney.com and we will delete it.

Third-party links and services

The Service links to third-party sites and services — your financial institutions, Plaid, SnapTrade and others listed in §5. Their privacy practices are their own and we are not responsible for them. Please read their policies.

Changes to this policy

We may update this policy. For material changes we will give you reasonable advance notice by email or in the Service before they take effect, and you will be asked to review the updated version the next time you sign in. The effective date at the top of this page always reflects the current version.

Contact us

Questions, requests or concerns about privacy:

Otium Money Inc.

Longmont, Colorado
privacy@otiummoney.com

For security reports specifically, use security@otiummoney.com. We read every one of these.

Terms of ServiceWhat Otium Money is, what it isn't, and the agreement between us.

Read the terms