Privacy Policy
Last updated: September 28, 2026
Hapibit Finance is a private finance application operated by Hapibit. This policy explains what information we collect, how we use it, and the choices you have.
Information We Collect
Depending on which features you use, Hapibit Finance may collect:
- Account information such as your name, email address, account identifier, and optional profile image.
- Bank and credit-card account information you choose to connect through Plaid, including institution and account names, account identifiers and masked digits, balances, available balances, and credit limits when provided.
- Transaction dates, merchants, descriptions, amounts, currencies, categories, and pending status. A bank-provided transaction location may include an address or latitude and longitude for a physical purchase. The app does not request device GPS access.
- Finance categories, notes, rules, shared group information, and app settings.
- Google account profile information when you sign in or connect Google, such as your email address and basic profile details.
- Gmail message identifiers, subjects, senders, dates, snippets, and message text when you connect Gmail and use receipt matching. Search results may contain unrelated information; matching filters cannot guarantee that every retrieved message is relevant.
- Sign-in and security events, synchronization status, category-change history, error details, and technical information such as IP address, browser or device information, and service interactions processed by our infrastructure and connection providers.
- Information you include when contacting support or requesting account deletion.
How We Use Information
We use information to:
- Authenticate your account and keep your session secure.
- Import, categorize, review, and summarize financial transactions.
- Match Gmail receipts, invoices, subscriptions, and order emails to transactions.
- Improve transaction details and reduce manual data entry.
- Show cash and credit balances, cashflow estimates, and the information you choose to share with a group.
- Maintain app security, troubleshoot issues, and prevent abuse.
Google User Data
If you connect Gmail, Hapibit Finance requests read-only Gmail access using the
https://www.googleapis.com/auth/gmail.readonly scope. We use this access only to
search for potentially relevant receipt, order, payment, invoice, and subscription emails,
retrieve message text, filter likely matches, and generate short transaction detail notes
such as product or service names. Message text and transaction context for candidate matches
are sent to OpenAI for this feature. Generated details and explanations may be saved with
the transaction. Connecting Gmail is optional; you can use other Finance features without it.
We do not sell Google user data. We do not use Google user data for advertising. We do not allow humans to read Gmail content except when necessary for security, debugging, legal compliance, or with your explicit direction.
Hapibit Finance's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy , including the Limited Use requirements.
How We Share Information
We use Supabase for authentication, database and file storage, Vercel for hosting, Plaid for bank connectivity, Google for the optional Gmail connection, Typesafe (Jev) for AI categorization and cashflow recurrence estimates, and OpenAI for AI detail generation, receipt matching and the Recurring tab's recurring-charge analysis. Categorization sends relevant transaction fields, account labels, categories, rules and manual examples to Typesafe. Cashflow forecasting sends up to two years of relevant bank transaction history for series active in the last 180 days, including names, merchants, dates, amounts and categories, to Typesafe to estimate each payment cycle's probability, or the probability of one next movement in a 30-day window when its date is uncertain. These probabilities are estimates, not confirmed payments. Only probabilities of at least 60% are included automatically; manual forecast plans are separate. Detail generation and recurring analysis send relevant transaction fields and examples to OpenAI; receipt matching additionally sends candidate email content to OpenAI.
Finance asks for permission before these optional AI features run. Gmail receipt matching has separate permission describing email access and transfer to OpenAI. Permission is remembered for your account in the current tab for up to 24 hours and cleared on sign-out. While this permission is active, cashflow recurrence analysis can update automatically when bank history or the forecast date changes. Your latest cashflow assessment is stored with your account in our database so it can be shown on any device when you return. It includes the merchant or payee names of every assessed transaction group with their probabilities, and the estimated movements with their amounts, dates and explanations. In the app, only your signed-in account can see it. Each new assessment replaces it, and it is deleted when you disconnect a bank or when your account deletion is completed. A stored assessment drives the cash forecast only while it matches your current history; otherwise it is shown for reference until you run a new assessment. Declining AI processing does not prevent you from connecting accounts, viewing balances, syncing transactions or making manual edits. Provider retention and processing terms still apply; permission does not imply immediate deletion by a provider. See OpenAI's API data controls.
Plaid also handles information under its End User Privacy Policy, including connection, security, technical, and service-improvement processing. That policy describes Plaid's own uses and retention. A provider's practices are not limited to the copies of data displayed in Finance.
If you create or join a group, group members can see membership information and the financial accounts and records made available to that group according to their permissions. An invitation uses the email address you supply. Review the accounts you share before adding them to a group.
Uploaded profile photos are stored at public image URLs. Anyone who has a photo's URL can view it without signing in, so do not upload a sensitive image. Financial records are not published through these image URLs.
Data Retention and Account Deletion
We retain account, transaction, and app data for as long as needed to operate Hapibit Finance or as required by law. Request deletion in Settings → Delete account or use our account deletion page without reinstalling the app. The request covers your shared Hapibit account and associated personal data, including Finance and other Hapibit services using the same account. It does not immediately delete the account or disconnect your banks.
The Hapibit team reviews connected services and shared records, then communicates the expected completion date and outcome to your registered email. You do not need to send a separate email after submitting in Settings. If information must be retained for legal obligations, security, dispute handling, or a provider's backup cycle, we explain the information, reason, and applicable retention period. Logging out or uninstalling the app does not delete server data.
Security
We use access controls, authentication, row-level security, and infrastructure safeguards to protect information. No internet service can guarantee absolute security, but we work to limit access to the minimum needed for the app to function.
Your Choices
- You can disconnect Gmail by revoking access in your Google Account permissions.
- You can disconnect bank accounts within the app where supported.
- You can request account deletion online or in Settings. Contact us if you cannot sign in or want to request removal of particular Finance data.
Contact
Questions or requests can be sent to daniel@hapibit.com. Visit our support page for help with the app.