Data Retention and Disposal Policy

Effective 15 September 2026 · Vritam Labs · Reviewed at least annually

This policy covers every category of personal and financial data handled by Manu, the iPhone app made by Vritam Labs, and the self-hosted Manu server it connects to. It applies to data obtained through Plaid, SimpleFIN, OFX Direct Connect, statement imports and brokerage connections alike. It is a companion to the Privacy Policy.

1. Principles

2. What is stored and for how long

DataWhereKept until
Plaid access token (per linked bank), SimpleFIN access URL, OFX loginServer database, encrypted at rest (Fernet, key derived from the server secret)The bank is removed in the app
Account names, masked account numbers, balances, credit limitsServer databaseThe bank is removed in the app
Transactions (date, description, merchant, amount, category)Server databaseThe bank is removed in the app
Session token, server address, emailiOS keychain on the phoneSign-out or app deletion
Push notification tokenServer databaseNotifications are disabled or the app is deleted
Server logs (request lines, errors; no bank credentials or tokens are written to logs)Server log filesRotated; at most 30 days

3. Deletion procedures

4. Backups

Vritam Labs keeps no copies of user financial data. If a server operator makes their own backups of the database file, this policy applies to those copies too: they should be deleted when the source data is deleted, and in any case not kept longer than 90 days.

5. Legal holds and exceptions

Data will be retained beyond the periods above only if required by law or a valid legal order, and only for as long as that requirement lasts.

6. Review

This policy is reviewed at least once a year, and whenever a new data source or storage location is added, by the founder of Vritam Labs, who is responsible for information security. The effective date above is updated on each revision.

Contact

Nithin Gaddam, Founder, Vritam Labs: nithin@vritam.com