legal

Privacy policy

Last updated August 15, 2026

Locus connects to your bank through Plaid, stores your transactions, and sends an AI agent through them to work out what each charge actually was. Running that agent means sharing transaction details with a small set of services, named below. This page lists what is stored, who sees it, and how to delete it. It is written to describe what the software actually does, not what a template says.

1Who we are

Locus is a personal finance app built and operated by an individual founder in the United States. It is not an incorporated company at this point, and the product is pre-launch. For anything in this policy, write to security@locus.cash.

2What Locus collects and stores

Account information

You sign in through Clerk, an authentication service. Locus stores the identifier Clerk assigns you, and your email address and name if Clerk provides them. Your password, if you use one, lives with Clerk; it never reaches Locus and Locus never stores one.

Bank data, through Plaid

When you connect a bank, you enter your bank credentials with Plaid, not with Locus. Locus never sees your bank username or password. What Plaid then gives Locus, and what Locus stores, is:

Locus pulls new and changed transactions when you sync manually, on the schedule you choose in settings, and when Plaid notifies our server that new data is available. Those notifications are cryptographically verified before anything acts on them.

Things you create

Budget categories (their names, monthly amounts, emoji, and colors), categorization rules, standing rulings you give the agent, and any notes, tags, renames, or category and date overrides you put on transactions.

Investigation records

For every investigation the agent runs, Locus stores the verdict (a category, a confidence score, and written reasoning), which model produced it, and a full step-by-step trace: every tool the agent called, what it asked, and what came back. The trace contains transaction details verbatim, plus whatever evidence the agent gathered, including web search results and, if you enabled those integrations, excerpts from email, calendar, or location history. The trace is stored so the app can show you the agent's work.

Settings and logs

Locus stores your preferences: which evidence integrations you enabled, your sync cadence, and whether new transactions are investigated automatically. Our servers also keep operational logs for running and debugging the service; these can include identifiers such as your internal user id, institution names, and error messages.

The email box on our landing page

Honesty requires saying this plainly: the "notify me" form on the landing page currently does not send or store anything, anywhere. There is no backend behind it yet. If that changes, this policy will be updated first.

3How your data is used

To show you your money, keep it in sync with your bank through Plaid, run the agent that investigates and categorizes transactions, apply your rules and rulings, and compute your budgets. That is the whole list. Locus does not sell your data, does not share it with advertisers, and shows no ads. Locus does not train models on your data; it does not train models at all.

4The agent, and who your data is shared with

The agent is the heart of the product, and it is also the honest data-sharing story. When Locus investigates a transaction, either automatically for new transactions (if you turned that on) or because you asked, this is what happens:

There are no other recipients. If a new one is ever added, it will be added to this list before it sees anything.

5Where your data lives

Your data is stored in a Neon Postgres database in the US East region, reached from serverless functions running on Vercel. Background jobs run on Inngest. Investigations run in Vercel sandboxes that exist only for the investigation. Data moves over encrypted connections (TLS).

6Retention and deletion

Locus keeps your data until you delete it. There is no automatic expiry, and this policy will not pretend there is one.

Deleting your account lives in the app's settings, behind a confirmation. It first instructs Plaid to revoke every linked bank connection, and only then deletes our copy of your data — if a revocation cannot be completed, nothing is deleted and the app tells you, so a live bank connection is never silently left behind. If you cannot access the app, email security@locus.cash from your account's address and we will do the same on your behalf.

Copies of data may persist for a limited time in our infrastructure providers' standard backups and in operational logs before aging out; we do not restore deleted accounts from them.

7Your choices and rights

8Security

What is actually in place: every request to the API must carry a verified sign-in token before any handler runs. Every stored row is tagged with its owner, and the data layer refuses queries against user data that are not scoped to the authenticated user; that boundary is enforced in code and covered by tests. Webhooks from Plaid are signature-verified before they touch anything. Bank credentials never pass through Locus at all. Traffic is encrypted in transit.

What is not in place, said plainly: Locus is a small pre-launch product. It holds no security certifications, and this page will not dress that up in phrases like "bank-level security". If we learn of a breach affecting your data, we will tell you at your account's email address as quickly as we are able.

If you find a vulnerability, please report it to security@locus.cash.

9Children

Locus is not directed to children and is not intended for anyone under 13. If you believe a child has created an account, contact us and it will be deleted.

10Changes to this policy

When this policy changes, the date at the top changes with it. If a change meaningfully affects what is collected or who it is shared with, we will make that change obvious here rather than burying it.

11Contact

Privacy questions and security reports both go to security@locus.cash.

← back to locus.cash