Privacy Policy
Last updated 19 July 2026
Wuxby handles financial data, so this policy tries to be specific rather than reassuring. Where a third party receives your information, we name them and say what they get.
The short version
- We do not sell your data, and we run no advertising or tracking of any kind.
- Bank access is read-only. We never see your bank username or password.
- Features you explicitly use that are powered by AI send some of your financial details to an external model provider. The detail is in AI features — please read it.
- You can delete your account yourself, and it cascades to all your data.
What we collect
Account details. Your name, email address, and — if you sign in with Google — your Google profile image. If you use a password, we store only a hash of it, never the password itself.
Session details. When you sign in we record your IP address and browser user-agent against the session, so you can review and revoke active sessions.
Financial data you enter or sync. Accounts and balances, transactions (date, description, merchant, category, amount, and any notes), recurring bills and income, budgets and envelopes, goals, scenarios, and daily net-worth snapshots.
Retirement planning inputs. If you use the retirement planner, this includes your birth year, target retirement age, life expectancy assumption, and expected annual spending.
An activity log. We keep a record of changes to your accounts and connections, including the before and after values, so you can audit what changed and when.
Bank connections
Wuxby connects to financial institutions through SimpleFIN Bridge. You obtain a setup token from SimpleFIN and paste it into Wuxby. Your bank credentials are handled by SimpleFIN and are never transmitted to, or stored by, Wuxby.
Access is read-only. Wuxby only ever reads account and transaction data; it cannot initiate transfers or payments.
What we retrieve depends on the sync mode you choose for each connection. In balances mode we retrieve balances only. In transactions or both mode we also retrieve posted transactions from the last 90 days at first connection, and we store each transaction's description, payee, and any memo text your bank supplies. We do not request pending transactions.
The access credential SimpleFIN issues is encrypted before storage using AES-256-GCM.
Disconnecting is not the same as revoking. Removing a connection in Wuxby deletes our stored credential and stops all syncing, but it does not revoke Wuxby's access at SimpleFIN, and it does not delete transactions already synced. To fully revoke access, do so from SimpleFIN directly. To remove the data, delete your account or use the reset option in settings.
AI features
Several optional features use a large language model: the assistant, natural-language entry of bills and scenarios, forecast explanations, and the weekly digest summary. These requests leave our systems — they are routed through an AI gateway service to a third-party model provider.
The specific gateway and model we use may change over time as these services evolve. If you want to know which provider is handling your requests at any given moment, email us and we will tell you.
These requests contain real financial details, not just anonymous aggregates. Depending on the feature, the prompt may include your account names, types and current balances; the names and amounts of your recurring bills and income; envelope names, balances and targets; merchant names and amounts from detected subscriptions; your net worth and projected cash position; and whatever you typed into the feature yourself.
What is not sent: your name, your email address, your bank credentials, and your transaction history in bulk. Individual merchant names and amounts can nonetheless reach the model through subscription findings and digest summaries.
The model never authors figures. All projections, balances and calculations are produced by Wuxby's own deterministic code; the model only writes explanatory text around them, or converts what you typed into structured input.
If you would rather no financial data left our systems for this purpose, avoid the AI features and enter bills and scenarios manually — every AI feature has a manual equivalent. You can also turn off subscription insights in settings.
Who else receives your data
SimpleFIN Bridge — receives only the authentication credential for your connection. No Wuxby account data is shared with them.
ZeptoMail — our email provider. Transactional and opt-in emails pass through them. The weekly check-in email, if you have it enabled, contains a financial snapshot: your name, upcoming bills and income with names, dates and amounts, and highlighted insights that may include merchant and account names.
Google — only if you choose to sign in with Google. We receive your name, email address and profile image. If your profile image is displayed, your browser loads it from Google, which means Google can observe your IP address at that point.
Our hosting and infrastructure providers — who store the database and cache that run the service.
We do not sell your personal information, and we do not share it with advertisers or data brokers.
Analytics and tracking
There are none. Wuxby runs no analytics platform, no advertising pixels, no session recording, and no third-party error-tracking service. We set no tracking cookies, which is why you are not being asked to dismiss a cookie banner.
Cookies
We set one cookie: your session token, which keeps you signed in. It is HTTP-only, restricted to same-site requests, and served over HTTPS in production. Sessions expire after 7 days of inactivity. Clearing it signs you out.
Keeping and deleting your data
We keep your data for as long as your account exists. Activity logs and net-worth snapshots accumulate over time to give you history, and are not currently pruned on a schedule.
You can delete your account yourself from Settings → Security. Deletion requires your password and is immediate and permanent: it removes your accounts, transactions, bills, scenarios, goals, envelopes, snapshots, activity log and stored bank credentials. There is no recovery period and no undo, so save anything you want to keep before you delete. Wuxby does not currently offer a self-serve data export — if you need a copy of your data, email us before deleting and we will provide one.
Settings also offers a partial reset if you want to clear accounts or bills without deleting your account.
Two honest caveats. Cached AI-generated summaries may persist in our cache for up to 24 hours after deletion before expiring automatically. And as noted above, account deletion does not revoke Wuxby's access at SimpleFIN — do that from SimpleFIN.
Security
Passwords are hashed. Bank access credentials are encrypted at the application level with AES-256-GCM. All traffic is served over HTTPS with strict transport security, and the app sets a restrictive content security policy.
To be precise about what that does and does not mean: your balances, transactions and other financial records are stored in our database in ordinary form, protected by our hosting provider's storage encryption and by access controls, rather than being individually encrypted by Wuxby. Every request is scoped to your user account so that one user's data is never reachable from another's session.
No system is perfectly secure, and we would rather tell you what we actually do than imply more.
Your rights
You can access and correct your data in the app, delete it as described above, and turn off optional emails and insights in settings. Depending on where you live, you may have additional rights over your personal data, including the right to obtain a copy of it. Email us and we will help.
Changes and contact
If we change this policy materially we will update the date at the top and tell account holders by email. Questions, requests, or concerns: