legal
Privacy policy
Last updated August 15, 2026
Locus connects to your bank through Plaid, stores your transactions, and sends an AI agent through them to work out what each charge actually was. Running that agent means sharing transaction details with a small set of services, named below. This page lists what is stored, who sees it, and how to delete it. It is written to describe what the software actually does, not what a template says.
1Who we are
Locus is a personal finance app built and operated by an individual founder in the United States. It is not an incorporated company at this point, and the product is pre-launch. For anything in this policy, write to security@locus.cash.
2What Locus collects and stores
Account information
You sign in through Clerk, an authentication service. Locus stores the identifier Clerk assigns you, and your email address and name if Clerk provides them. Your password, if you use one, lives with Clerk; it never reaches Locus and Locus never stores one.
Bank data, through Plaid
When you connect a bank, you enter your bank credentials with Plaid, not with Locus. Locus never sees your bank username or password. What Plaid then gives Locus, and what Locus stores, is:
- Transactions: amount, currency, dates (both when a charge was authorized and when it posted, with timestamps when the bank provides them), the raw bank descriptor, the merchant name when Plaid can identify it, Plaid's own category guess, whether the charge is pending, the payment channel, and the city and region Plaid attaches to the charge.
- Balances and account names, read from Plaid when you view your accounts.
- The institution's name, and an access token for each connection that lets Locus keep syncing it.
Locus pulls new and changed transactions when you sync manually, on the schedule you choose in settings, and when Plaid notifies our server that new data is available. Those notifications are cryptographically verified before anything acts on them.
Things you create
Budget categories (their names, monthly amounts, emoji, and colors), categorization rules, standing rulings you give the agent, and any notes, tags, renames, or category and date overrides you put on transactions.
Investigation records
For every investigation the agent runs, Locus stores the verdict (a category, a confidence score, and written reasoning), which model produced it, and a full step-by-step trace: every tool the agent called, what it asked, and what came back. The trace contains transaction details verbatim, plus whatever evidence the agent gathered, including web search results and, if you enabled those integrations, excerpts from email, calendar, or location history. The trace is stored so the app can show you the agent's work.
Settings and logs
Locus stores your preferences: which evidence integrations you enabled, your sync cadence, and whether new transactions are investigated automatically. Our servers also keep operational logs for running and debugging the service; these can include identifiers such as your internal user id, institution names, and error messages.
The email box on our landing page
Honesty requires saying this plainly: the "notify me" form on the landing page currently does not send or store anything, anywhere. There is no backend behind it yet. If that changes, this policy will be updated first.
3How your data is used
To show you your money, keep it in sync with your bank through Plaid, run the agent that investigates and categorizes transactions, apply your rules and rulings, and compute your budgets. That is the whole list. Locus does not sell your data, does not share it with advertisers, and shows no ads. Locus does not train models on your data; it does not train models at all.
5Where your data lives
Your data is stored in a Neon Postgres database in the US East region, reached from serverless functions running on Vercel. Background jobs run on Inngest. Investigations run in Vercel sandboxes that exist only for the investigation. Data moves over encrypted connections (TLS).
6Retention and deletion
Locus keeps your data until you delete it. There is no automatic expiry, and this policy will not pretend there is one.
- Disconnecting a bank in the app revokes that connection at Plaid and deletes its data from Locus: the access token, its transactions, and the investigations attached to them.
- Deleting your account is a single, immediate operation. Every piece of your data in the database carries your ownership and is set to cascade: deleting your account row removes your bank connections and their access tokens, transactions, categories, rules, rulings, investigations and their traces, integration settings, and preferences. It is not a soft delete and there is no recycle bin. Your sign-in identity — the email and name held by Clerk, our sign-in provider — is deleted as the final step, so nothing of your account remains with us or our sign-in provider.
Copies of data may persist for a limited time in our infrastructure providers' standard backups and in operational logs before aging out; we do not restore deleted accounts from them.
7Your choices and rights
- Consent. Before Locus collects anything through Plaid, the app shows a consent screen describing the collection, processing, and storage above. Your agreement — and the version of this policy you agreed to — is recorded with your account, and you will be asked again whenever this policy materially changes.
- Access, export, correction. There is no self-serve export button yet, so these work by email: write to security@locus.cash and we will provide a copy of your data, correct it, or delete it. We will verify the request comes from the account's own address.
- Integrations. Each evidence source (email, calendar, location) is a per-user toggle, off by default. Turning one off stops the agent using it from then on; evidence already recorded in past investigation traces stays in those traces until you delete the data.
- Sync and automation. You choose the sync cadence, including off, and whether new transactions are investigated automatically.
- Overrides. Your own categorizations always outrank the agent's. A category you set by hand is sticky; the agent's later verdicts are recorded beside it as suggestions, never over it.
8Security
What is actually in place: every request to the API must carry a verified sign-in token before any handler runs. Every stored row is tagged with its owner, and the data layer refuses queries against user data that are not scoped to the authenticated user; that boundary is enforced in code and covered by tests. Webhooks from Plaid are signature-verified before they touch anything. Bank credentials never pass through Locus at all. Traffic is encrypted in transit.
What is not in place, said plainly: Locus is a small pre-launch product. It holds no security certifications, and this page will not dress that up in phrases like "bank-level security". If we learn of a breach affecting your data, we will tell you at your account's email address as quickly as we are able.
If you find a vulnerability, please report it to security@locus.cash.
9Children
Locus is not directed to children and is not intended for anyone under 13. If you believe a child has created an account, contact us and it will be deleted.
10Changes to this policy
When this policy changes, the date at the top changes with it. If a change meaningfully affects what is collected or who it is shared with, we will make that change obvious here rather than burying it.
11Contact
Privacy questions and security reports both go to security@locus.cash.