← Future You

Data Retention & Disposal Policy

Last updated July 6, 2026

Future You collects the minimum data necessary to operate. This policy describes what we retain, for how long, and how it is disposed of when no longer needed or when you request deletion.

Data we hold

Plaid access tokens

When you connect a bank account via Plaid, Future You stores a Plaid access token and your institution name in our database. No account numbers, credentials, or raw transaction data are stored. We use the token solely to fetch your current balance and recent transactions on demand.

Account balance & transaction data

Balance and transaction data are fetched from Plaid in real-time when you open the app. We do not store a history of individual transactions in our database. A short-lived server-side memory cache holds your current-day spending total to avoid redundant Plaid calls; this cache is not persisted to disk and is cleared on server restart or when a new transaction webhook arrives.

Bills and preferences

Bill names, amounts, due dates, and app preferences you enter manually are stored in our database linked to your device identifier.

Device identifier

A randomly generated device identifier (containing no personal information) is stored to associate your app data with your device. It does not identify you personally. On mobile it persists until you uninstall the app or clear app storage. On web it persists until you clear your browser's local storage.

Sessions

If you sign in with Replit, a session record is stored in our database and expires automatically after 7 days of inactivity.

Account credentials

Future You never receives, stores, or has access to your bank username, password, or PIN. Authentication with your bank is handled entirely by Plaid.

Retention periods

Data typeRetention period
Plaid access tokenUntil you disconnect your bank, or upon a verified deletion request
Balance & transaction dataNot persisted to the database; server memory cache cleared on restart or new webhook
Bills and preferencesUntil you delete them individually in-app, or upon a verified deletion request
Device identifierUntil app uninstall / storage clear, or upon a verified deletion request
Sessions7 days from creation; expired sessions are no longer valid
Server logsManaged by our hosting infrastructure (Replit); we do not implement application-level log retention or purging

How to delete your data

Disconnect your bank (in-app)

Go to Profile → Disconnect bank. This immediately calls Plaid's revocation API to remove access on Plaid's end, then deletes the access token and all Plaid-linked records from our database. If the Plaid API call fails, the local record is still deleted so you are not locked in.

Delete individual bills (in-app)

Swipe left on any bill in the Bills tab to delete it immediately and permanently from our database.

Request full data deletion

There is no self-serve full-account deletion in the app. To request deletion of all data we hold — including your device identifier, bills, Plaid connections, and session records — email futureyoufund@gmail.com with the subject "Data Deletion Request." We will manually delete all associated records within 30 days and confirm by email.

Plaid data held by Plaid

Plaid may retain data independently under their own policies. When you disconnect your bank, Future You sends a token revocation request to Plaid. To request deletion of data Plaid holds about you, use Plaid's Privacy Request Form.

Disposal methods

When data is deleted — whether by you in-app or by request — it is hard-deleted from our database. We do not anonymise and retain deleted records. Server logs are written to process stdout and are managed by our hosting provider; we do not operate a separate backup or archive of log output.

Security during retention

All stored data is held in an encrypted, access-controlled database. Data in transit is protected by TLS. Access to production data is restricted to authorised personnel only.

Changes to this policy

We may update this policy to reflect changes in our practices. The date at the top of this page will reflect the most recent revision. Continued use of the app constitutes acceptance of the updated policy.

Contact

Questions about data retention or to submit a deletion request:

futureyoufund@gmail.com