PART I
Terms of Use
Agreement and eligibility
By creating an account, accepting these terms, or using Financial BFF, you agree to this policy. You must be at least 18 and legally able to enter an agreement. A workspace administrator represents that they are authorized to invite members and connect selected accounts.
The service
Financial BFF organizes, displays, categorizes, and analyzes user-authorized information. It is not a bank, money transmitter, broker-dealer, investment adviser, tax preparer, accountant, law firm, credit bureau, or fiduciary. It does not hold funds, execute transactions, or guarantee outcomes.
Your responsibilities
You are responsible for accurate information, protecting passwords and MFA devices, managing authorized users, reviewing imported data, and reporting suspected misuse. You may connect only accounts you own or are authorized to access.
Acceptable use
You may not attempt unauthorized access, disrupt the service, evade controls, introduce malicious code, misuse another person’s data, violate law or third-party rights, or use the service for fraud or other unlawful activity.
Third parties and availability
The service depends on Plaid, AWS, Cloudflare, institutions, identity, and communications providers. Their policies apply. Availability and accuracy may be affected by maintenance, consent expiration, account changes, or network conditions. We may update or suspend features for security, compliance, or maintenance.
Disclaimers and liability
To the maximum extent permitted by law, the service is provided “as is” and “as available,” without implied warranties of merchantability, fitness, title, or non-infringement. We do not warrant that data, categories, forecasts, alerts, reports, or AI-assisted answers are complete, current, or correct.
To the maximum extent permitted by law, Financial BFF and its operators are not liable for indirect, incidental, special, consequential, exemplary, or punitive damages, lost profits, lost opportunities, or decisions made using the service. Aggregate liability is limited to the greater of fees paid during the preceding twelve months or US $100. These limits do not apply where prohibited or to liability that cannot legally be limited.
Termination and law
We may restrict access to protect users, investigate abuse, comply with law, or address nonpayment. You may stop using the service and request deletion. These terms are governed by applicable United States law and, where permitted, Florida law. Mandatory consumer protections remain unaffected.
PART II
Privacy Policy
Information processed
We process registration details, contact information, address, workspace membership, roles, and policy acceptance. With authorization, we process institution and account identifiers, balances, transactions, categories, account masks, investments, and connection status. We also process security, audit, device, network, support, and service-usage information.
Purposes and sources
We use information to authenticate users, isolate workspaces, connect and synchronize selected accounts, generate features, answer questions, provide support, prevent abuse, monitor reliability, comply with law, and improve the service. Information comes from users, workspace administrators, Plaid and connected institutions at user direction, identity providers, and infrastructure.
Sharing
We disclose information only as needed to operate the service, follow user instructions, protect rights and safety, comply with law, or complete a business transaction with safeguards. Providers may include Plaid, AWS, Cloudflare, identity, communications, monitoring, and professional advisers. We do not sell personal information or use connected financial data for third-party behavioral advertising.
Retention and security
Pending registrations expire after 24 hours. Authentication sessions expire after no more than 12 hours. Active workspace and user-authorized financial data remain until a connection or workspace is deleted. Generated exports expire after 30 days; operational and edge logs after 90 days; closed support requests after two years; and recovery backups no later than 35 days after deletion. Pseudonymized security audit and deletion evidence may be retained for seven years for security, dispute, and legal purposes. We use MFA, encryption, access controls, tenant isolation, monitoring, backups, and secure development practices, but no measure eliminates all risk. The schedule is reviewed at least annually and after material legal, vendor, or system changes.
Deletion process
Deleting a workspace disconnects its Plaid Items, stops synchronization, deletes application state, accounts, transactions, assets, reports, alerts, users, sessions, and support records, and anonymizes identities in retained security audit evidence. A non-identifying deletion certificate records completion. Encrypted backup copies age out automatically within 35 days and are not restored except for disaster recovery; if restored during that period, the deletion request must be reapplied.
Choices and rights
Users may disconnect sources, correct certain information, manage workspace access, export their workspace, and delete it through Admin Settings. Other privacy requests can be sent to [email protected]. Disconnecting a Plaid Item removes the associated imported accounts and transactions and stops future synchronization. The service is not directed to people under 18 and currently processes data in the United States.
PART III
Financial and AI Disclaimer
Financial BFF provides organizational tools, estimates, forecasts, alerts, reports, and educational information—not investment, financial, tax, accounting, insurance, credit, or legal advice. Data may be delayed, incomplete, duplicated, or misclassified, and automated outputs may contain errors.
Verify information against official institution records and consult qualified professionals before acting. Forecasts and predicted returns are not promises. “Unusual” flags are observations, not fraud determinations. Financial BFF does not continuously monitor accounts for emergencies and does not replace bank fraud alerts.
PART IV
Plaid Connection Notice
When connecting an account, you authorize Financial BFF and Plaid to process the information you select for requested features. Financial BFF does not receive bank credentials entered in Plaid Link. Review Plaid’s End User Privacy Policy and manage supported connections at Plaid Portal.
CONTACT
Questions and requests
Email [email protected] for privacy, account, legal, support, or security inquiries. Never email passwords, MFA codes, full account numbers, or access tokens.
