Privacy Policy
This policy explains what data Balance Widget collects, why we collect it, who processes it on our behalf, and how to get it deleted. It is written to be read, not to be survived.
- Who we are
- Data we collect
- How we use your data
- Why we're allowed to
- Storage and security
- Who else sees it
- Retention and deletion
- Your rights
- Children
- Changes to this policy
1Who we are
Balance Widget ("we", "us") is operated by Lava Factory LLC, which builds and runs the app and its backend. We are not a data broker, and no third party has standing access to your information.
For anything in this policy, or to exercise any right described in it, write to support@lavafactory.com.
2Data we collect
Account information
Your email address, and the authentication state that keeps you signed in. Authentication is handled by Supabase Auth. If you sign in with Apple, we receive whatever identifier Apple chooses to share, which may be a private relay address rather than your real email.
Financial data, through Plaid
With your explicit consent, we connect to your financial institution through Plaid to retrieve the account and balance information the app needs to work: account name, account type, the last few digits of the account number, and the current and available balances.
We never receive or store your bank credentials. You sign in to your bank inside Plaid's flow, directly with your institution. Plaid returns a token to us that permits reading the data described above. It does not permit moving money, and it can be revoked by you at any time.
The app has no ability to initiate payments or transfers. If we ever need a broader category of data than the account and balance information described above, we will update this policy and tell you before it takes effect, as set out in section 10.
Plaid's own handling of your data is governed by Plaid's End User Privacy Policy, available at plaid.com/legal.
Usage analytics
We use PostHog to record how the app is used — which widget types get added, which screens get opened, which actions fail. This is pseudonymised: events are tied to an internal user identifier, not to your name, and they never contain balances, account numbers, or institution credentials.
Error reports
We use Sentry to capture crashes and errors so they can be fixed. Reports contain technical context — the app version, the device model, a stack trace. We configure Sentry not to attach financial values to reports.
Support correspondence
If you email us, we keep the email so we can help you and remember the context if you write again.
3How we use your data
- To display your account balances, which is the entire purpose of the app.
- To authenticate you and keep your account secure.
- To enforce the limits of your subscription tier.
- To understand which features are used, so we know what to build and what to remove.
- To diagnose crashes and errors.
- To answer your support requests.
We do not sell your personal information, and we never have. We do not share it for cross-context behavioural advertising. We do not use your financial data to build advertising or marketing profiles, ours or anyone else's.
4Why we're allowed to
Where the GDPR or UK GDPR applies to you, our legal bases are: performance of a contract for the account and balance data that makes the app function; consent for connecting a financial institution, which you give in the Plaid flow and can withdraw by unlinking; and legitimate interests for security, error diagnosis, and product analytics, balanced against your privacy by keeping that data pseudonymised and free of financial values.
5Storage and security
Account and balance data is stored in Postgres on Supabase Cloud, which encrypts data at rest and in transit. Analytics data is stored in PostHog Cloud. Error reports are stored in Sentry. Our servers and databases are hosted in the United States.
Specific measures worth naming:
- Plaid access tokens are encrypted at rest and decrypted only inside a server-side function. They are never sent to the app on your device.
- Our Plaid API secret exists only server-side. It is not present in any shipped binary.
- Row-level security in Postgres scopes every query to the signed-in user, enforced by the database rather than by application code.
- We request the narrowest Plaid permissions the product needs. Data we don't hold can't be lost.
The security overview goes into more detail, including the areas where our controls are not yet where we want them.
6Who else sees it
Only the service providers we need to operate the app. Each processes data on our instructions under its own terms.
| Provider | What it handles | Why |
|---|---|---|
| Plaid | Bank connection, account and balance data | Retrieving your balances |
| Supabase | Email, authentication, balances, subscription state | Database and authentication |
| PostHog | Pseudonymised usage events | Product analytics |
| Sentry | Crash and error reports | Diagnosing faults |
| Apple | Subscription purchase and billing | App Store payments; we never see your card |
| Cloudflare | This website | Hosting and delivery |
Beyond these, we disclose data only where the law requires it, and only to the extent it requires.
7Retention and deletion
How long each category of data is kept, and what happens when you ask us to delete it, is set out in the data retention and deletion policy. In short: unlinking an account revokes our Plaid access immediately, and a deletion request clears your data within 30 days.
8Your rights
Wherever you live, you can ask us to:
- Tell you what personal data we hold about you, and give you a copy.
- Correct anything that's wrong.
- Delete your account and the data attached to it.
- Stop processing your data for analytics.
You can disconnect any linked financial account at any time from inside the app, which revokes our access through Plaid without deleting your Balance Widget account. To exercise any of the above, email support@lavafactory.com. We will respond within 30 days and will not charge you or make the app worse for asking.
If you're in the EEA or UK you may also complain to your local data protection authority. If you're in California, the rights above cover the access, deletion, correction, and opt-out-of-sale rights the CCPA gives you — and since we don't sell personal information, there is nothing to opt out of.
9Children
Balance Widget is not intended for anyone under 18, and we don't knowingly collect data from children. If you believe a child has created an account, write to us and we'll delete it.
10Changes to this policy
We'll update this page as the app changes, and the effective date at the top will change with it. If a change materially affects how we handle your data, we'll tell you in the app or by email before it takes effect rather than quietly editing the page.