Data Retention and Disposal Policy
This policy covers every category of personal and financial data handled by Manu, the iPhone app made by Vritam Labs, and the self-hosted Manu server it connects to. It applies to data obtained through Plaid, SimpleFIN, OFX Direct Connect, statement imports and brokerage connections alike. It is a companion to the Privacy Policy.
1. Principles
- Minimum collection. The server stores only what the app needs to show balances, spending and transaction history. Bank usernames and passwords are never stored; bank sign-in happens on the provider's own page (for Plaid, on Plaid Link).
- Purpose-bound. Financial data is used only to display the user's own finances in the app. It is not sold, shared with advertisers, or used to train models.
- Retention tied to the connection. Data lives only as long as the user keeps the bank or broker connected. Nothing is kept "just in case".
- User control. The server runs on hardware the user controls, so the user can inspect, export or destroy every byte at any time.
2. What is stored and for how long
| Data | Where | Kept until |
|---|---|---|
| Plaid access token (per linked bank), SimpleFIN access URL, OFX login | Server database, encrypted at rest (Fernet, key derived from the server secret) | The bank is removed in the app |
| Account names, masked account numbers, balances, credit limits | Server database | The bank is removed in the app |
| Transactions (date, description, merchant, amount, category) | Server database | The bank is removed in the app |
| Session token, server address, email | iOS keychain on the phone | Sign-out or app deletion |
| Push notification token | Server database | Notifications are disabled or the app is deleted |
| Server logs (request lines, errors; no bank credentials or tokens are written to logs) | Server log files | Rotated; at most 30 days |
3. Deletion procedures
- Removing a bank in the app deletes that bank's accounts and transactions from the server database immediately. For Plaid-linked banks the server also calls Plaid's
/item/removeso Plaid deletes the connection and stops supplying data. For SimpleFIN the user is guided to remove the bank on the SimpleFIN bridge as well, because that protocol has no remote delete. - Signing out removes the session token and server address from the phone's keychain.
- Deleting the app removes everything the app stored on the phone.
- Decommissioning a server: the operator deletes the finance database file (and its write-ahead log) and the environment file holding API keys. Because the database is a single SQLite file, deletion is complete and immediate; disks are erased with the operating system's secure-erase before disposal or resale.
- Requests to us: a user who wants help deleting data, or wants Plaid to delete data it holds, can email nithin@vritam.com or use the Plaid Portal. We respond within 30 days.
4. Backups
Vritam Labs keeps no copies of user financial data. If a server operator makes their own backups of the database file, this policy applies to those copies too: they should be deleted when the source data is deleted, and in any case not kept longer than 90 days.
5. Legal holds and exceptions
Data will be retained beyond the periods above only if required by law or a valid legal order, and only for as long as that requirement lasts.
6. Review
This policy is reviewed at least once a year, and whenever a new data source or storage location is added, by the founder of Vritam Labs, who is responsible for information security. The effective date above is updated on each revision.
Contact
Nithin Gaddam, Founder, Vritam Labs: nithin@vritam.com