Privacy Policy
Effective: August 18, 2026 · Applies to the hosted service at oikonome.com and its subdomains. The hosted service is operated by Oikonome LLC, an Idaho limited liability company ("Oikonome", "we", "us"), which is the controller of the personal data described below. If you self-host Oikonome, your data lives on your own server and this policy's data-collection sections do not apply to it.
The short version
- Your financial data is used for one purpose: showing you your own finances.
- We never sell your data, never share it for advertising, and never use it to train models.
- We never see or store your bank credentials — bank connections are made through Plaid.
- You can export or permanently delete your data at any time.
What we collect
- Account information — your email address and a hash of your password (we cannot read the password itself); optional second-factor enrollment data (authenticator/passkey records).
- Financial data you connect or import — account balances, transactions (date, amount, merchant, category), and recurring-bill schedules, retrieved with your consent through Plaid or uploaded by you as files. We never receive your online-banking username or password; those go directly to Plaid.
- Operational records — server logs (IP address, request path, timestamp) kept for security and debugging, and billing records if you subscribe (handled by Stripe; we do not see or store your card number).
How we use it
To operate your dashboard, daily summary email, budgets, and forecasts — the features you signed up for. That's the whole list. We do not sell personal data, share it with data brokers or advertisers, or use it for profiling unrelated to the product.
Service providers
We use a small number of processors to run the service, each receiving only what its role requires:
- Plaid — bank connectivity (see Plaid's end-user privacy policy).
- DigitalOcean — cloud hosting (servers, managed database, encrypted backups).
- Stripe — subscription payments, if you subscribe.
- Postmark — delivery of account and summary emails (open/click tracking is disabled on purpose).
Cookies
The app uses strictly-necessary session cookies to keep you signed in — nothing else. No advertising or analytics cookies, which is why there is no cookie banner.
Security
All traffic is encrypted in transit (TLS). Sensitive stored secrets are encrypted at rest with per-tenant keys. Every account requires a second factor (authenticator app or passkey). Off-site backups are client-side encrypted. Tenant data is isolated with database row-level security. If a breach ever affects your personal data, we will notify you promptly by email with what happened and what we're doing about it, as applicable law requires and regardless of whether it does.
Retention and deletion
Your data is kept while your account is active. You can export everything (standard formats) or delete your account from Settings at any time; deletion permanently removes your data from the live database, and encrypted backups age out on a fixed schedule thereafter.
When a paid subscription ends — because you cancelled or because a payment could not be collected — the bank connections are disconnected immediately and your data is kept, readable but not editable, for 30 days. Resubscribing in that window keeps everything. Otherwise, after two reminders by email, the account and all of its data are deleted at the end of the 30 days. An unpaid free trial follows the same 30-day path. Export stays available for the whole window, so nothing is lost without a way to take it with you.
Your rights
You can access, correct, export, or delete your personal data at any time — the tools are in the product, and anything the tools don't cover we'll handle by email. We honor applicable data-protection rights (including GDPR and state privacy laws) for all users, not just where mandated.
Phone numbers and text messages
If you choose to receive text alerts, we collect the mobile number you enter and a record of when you consented, so we can prove the opt-in was yours. That number is used only to send you the account notifications you asked for — your daily budget verdict and the alerts you configured. It is never used for marketing.
We do not sell, rent, or share your phone number with third parties, and mobile opt-in data is never shared for marketing purposes. The number is passed only to the telecom provider that delivers the message, which cannot use it for anything else. You can stop the texts at any time by replying STOP, or remove the number in the app; consent to texts is never a condition of using Oikonome or of any purchase.
What we don't do
- No advertising, no trackers, no third-party analytics scripts on the app or this site.
- No selling or renting personal data — to anyone, ever. That includes phone numbers and SMS opt-in data, which are never shared for marketing.
- No use of your financial data to train machine-learning models.
Children
Oikonome is not directed to children under 13 and we do not knowingly collect their data.
Changes
If this policy changes materially, we'll notify account holders by email before the change takes effect and keep prior versions available on request.
Contact
Questions or requests: support@oikonome.com
Oikonome LLC · Coeur d'Alene, Idaho, USA