We read the receipts. No one else does.
This is the plain-English version of how Brenda handles your data. The short version: we collect what we need to make the app useful, we don't sell it, we don't train models on it, and you can take it back at any time.
§01Who we are
Brenda is a product of Brenda Labs, the data controller for the information described in this policy. When this policy says “we,” “us,” or “Brenda,” we mean Brenda Labs.
If you want to reach a human about anything in this document, write to privacy@usebrenda.com.
§02What we collect
Information you give us
- Account. Email address, first and last name, and your time zone. Brenda has no passwords: you sign in with a one-time code we email you, or with Apple or Google (we receive your email and name from those providers).
- Consents. Whether you accepted this policy and the terms of service.
- Profile content. Goals, budgets, categories, notes you write on transactions, and messages you send to the in-app coach.
- Receipts you scan. If you photograph or upload a receipt or statement, we send the image to our document-AI service to read the line items, store the resulting transactions, and keep the image only briefly — it's deleted within 7 days.
Information we receive from your bank, through Plaid
When you link a bank account, you authenticate directly with your bank through Plaid. Plaid is the regulated data network that brokers the connection. From Plaid, we receive:
- The institution you linked and the account names, types, masks (last-four), and balances.
- Transactions on those accounts: amount, date, merchant name and category from Plaid, the payment channel, and — when the bank provides it — the merchant's street address, city, state, postal code, and country.
We use only the Plaid Auth and Transactions products. We do not pull credit data, income verification, identity documents, or initiate transfers.
Information we collect automatically
- Device. Device model, OS version, app version, and a push-notification token when you opt in.
- Authentication metadata. When you enable Face ID/Touch ID/Android biometrics, we store a public credential identifier — never your biometric data, which stays on the device.
- Activity. A “last active” timestamp and basic event logs to keep the app working and detect abuse.
§03How we use it
- To run the app: show your accounts, transactions, and budgets.
- To generate the coach summaries, monthly wraps, streaks, and insights you see inside Brenda.
- To read receipts and statements you scan and turn them into transactions.
- To search your transactions quickly. We index transaction fields (merchant, amount, category, date, location, notes) into a search service so the search bar is fast.
- To send transactional notifications you've opted into (e.g. a goal milestone, a missed-streak reminder).
- To keep the service secure: rate-limiting, abuse detection, fraud-signal review.
§04What we don't do
- We don't sell your personal information. Not now, not later.
- We don't share your transactions with advertisers or data brokers.
- We don't train AI models on your financial data. The in-app coach and receipt scanning run on Anthropic's Claude via Amazon Bedrock; we send only what's needed for that response, and under Bedrock the provider does not store your prompts or use them to train its models.
- We don't run third-party advertising trackers inside the app.
§05Who we share with
We share data with a small set of vendors that help us run Brenda:
- Plaid — to establish and refresh the bank connection and to deliver transactions. Plaid's handling of your data is governed by Plaid's End User Privacy Policy.
- Apple and Google — only if you choose to sign in with them, to verify your identity.
- Amazon Web Services — hosts our database and search, stores scanned receipt images, and runs the Claude model (via Amazon Bedrock) behind the coach and receipt scanning.
- RevenueCat, Apple, and Google — to manage subscriptions and process payments if you subscribe to Brenda Pro.
- Expo — to deliver push notifications you've opted into.
- Resend — to send the emails Brenda sends you (sign-in codes, account notices).
- Law enforcement — only when compelled by valid legal process. We push back on overbroad requests.
§06Where it lives, how long
Account, budget, and transaction data is stored in our primary database (PostgreSQL) and indexed in a search service (Elasticsearch). Scanned receipt images are held in object storage (Amazon S3) and deleted within 7 days. Everything runs in Amazon Web Services in the United States.
We keep your data while your account is active. When you delete your account, we revoke any Plaid bank connections, then permanently delete your data within 30 days, except where we're legally required to keep a record longer (e.g. fraud or tax obligations).
§07How we protect it
- TLS 1.2+ for everything in transit.
- Bank credentials never touch our servers. Plaid handles authentication; we receive only an access token, which we store on our servers in the United States.
- Brenda has no passwords to steal. You sign in with one-time email codes or with Apple/Google; sessions use short-lived JWTs (15 minutes) with refresh-token rotation.
- Production data access is limited to a small set of engineers and logged.
No system is unbreakable. If a breach affects you, we'll tell you and any required regulator without delay.
§08Your rights
You can, at any time:
- See the data we hold on you — most of it is in the app already.
- Correct profile fields from the Profile screen.
- Disconnect a bank you've linked from inside the app (or email us). We immediately stop receiving new transactions for that connection.
- Delete your account from Profile → Privacy & security → Delete account. We email you a code to confirm; this also revokes Plaid access and removes your records from our search index.
- Export your data — email privacy@usebrenda.com and we'll send a copy.
- Object or restrict certain processing if you live in the EU/UK, or exercise the rights granted by your state if you live in California, Colorado, or another state with a privacy law.
§09Children
Brenda is not for anyone under 18. We don't knowingly collect data from minors. If you believe a minor has signed up, write to us and we'll remove the account.
§10Changes
If we change this policy in a way that affects you, we'll let you know in the app and update the “last updated” date at the top. Material changes get at least 30 days' notice.
§11Contact
Privacy questions: privacy@usebrenda.com
Everything else: hello@usebrenda.com
This document is a draft pending legal review and does not constitute legal advice.