Privacy choices
Necessary onNecessary cookies are active. Optional analytics stays off unless you choose otherwise.
Legal & Compliance
US-only notice. Voyager Inc. provides a read-only personal finance ledger for US residents 18+ in USD only. This policy explains what we collect via Plaid and Stripe, why, who processes it, and your CCPA/CPRA rights. TEMPLATE — requires privacy counsel approval before production use.
Voyager Inc. (contact: privacy@wyna.app; legal: legal@wyna.app; security: security@wyna.app) operates Voyager, a privacy-first, read-only personal finance ledger at wyna.app, app.wyna.app, and our iOS/Android apps. This policy applies only to US residents aged 18 or older using USD-denominated accounts. We do not target, market to, or knowingly support EU/UK/EEA residents, non-USD billing, or household sharing in this release. If you are outside the US, do not create an account or connect institutions. Voyager is not a bank, broker-dealer, registered investment adviser, CPA, or tax preparer. Plaid provides bank and brokerage aggregation; Stripe provides subscription billing; Supabase provides auth and database. Your institution credentials are entered only in Plaid hosted flows — Voyager never sees, asks for, or stores plain-text banking passwords or MFA codes.
Before your first Plaid connection, finance-web shows a separate, unchecked Financial Data Aggregation Authorization you must affirmatively accept. You authorize Voyager to use Plaid to connect the institution(s) you select and retrieve account identifiers, masks, types, balances, transactions, liabilities, recurring transactions, and — for brokerage accounts — holdings, securities, and investment activities, plus any additional product you expressly enable. Purposes are limited to display, net-worth calculation, budgets, categorization, recurring detection, investment views, reconciliation, and features you select. Sync is continuous while an item stays connected until you disconnect or reauthorization is required. Voyager stores the encrypted provider access token and retrieved data needed to operate the service, never moves money, initiates transfers, or trades on your behalf, and requires your representation that you are authorized to connect each account. Disconnecting stops future collection and revokes provider access per our retention rules; historical normalized data is retained until you delete it or your account, except legal-evidence records described below. The full versioned authorization text with document hash and archive URL is the controlling record — this section is only a summary. Optional marketing or research processing is never bundled into this authorization.
Identifiers and contact: name, email, profile preferences, timezone, device IDs, IP address, user agent, Supabase auth ID. Commercial and billing: Stripe customer/subscription IDs, plan cadence, trial/grace/cancel status, last-four and card brand via Stripe only — we never store full card numbers. Financial information: institution names, account IDs, masks, types, balances and snapshots, transactions with merchants and categories, liabilities, recurring streams, holdings, securities identifiers, investment activities, sync cursors, webhook event IDs, and reconciliation records from Plaid. Internet activity on marketing-web: pages viewed, campaign UTMs (utm_source, utm_medium, utm_campaign, gclid, referral codes), consent tier, and — only with consent — Plausible/PostHog events, Clarity session IDs (_clck, _clsk), and GTM/GA4 events. Inferences: budget pace, goal projections, recurring confidence scores derived from your data. Sources are you directly, your devices automatically, Plaid with your authorization, Stripe for billing, and analytics vendors only under your consent tier. We do not collect precise geolocation, biometrics, or children's data, and we do not use financial data for cross-context behavioral advertising.
We use personal information to provide the read-only ledger, sync and reconcile accounts, detect drift, calculate net worth and budgets, provide exports, operate trials and entitlements, prevent fraud and abuse, secure sessions, debug with redacted logs, and — on marketing-web only — measure campaigns under your consent tier. Under the Gramm-Leach-Bliley Act and FTC Safeguards Rule we treat Plaid financial data as nonpublic personal information used only to deliver the service you directed, with no affiliate marketing use and no joint-marketing sharing. Voyager does not sell financial transaction histories, holdings, balances, or credentials, does not lease them to data brokers, and does not share them for cross-context behavioral advertising. Third-party financial offers, loan widgets, or valuation lookups are disabled in this release; if introduced later they will sit behind the separate Financial Sharing toggle from docs/plans/legal/financial-privacy-enforcement.md and will be filtered server-side for opted-out users. Core Plaid sync is a first-party user-directed service and is unaffected by marketing opt-outs.
We enforce four tiers per the Financial Privacy Enforcement Plan. Tier 1 Required (always active, locked): Supabase auth session, CSRF/state nonces, load-balancer affinity, and voyager_consent itself (365 days, SameSite=Lax, Secure) to remember your choice. No marketing or analytics identifiers live in Tier 1. Tier 2 Product insights (opt-in): coarse, zero-PII telemetry such as chart_type and render_time_ms — never dollar amounts, merchant names, masks, or IDs. Tier 3 Financial sharing (opt-in, currently no partners): gates any future partner embeds. Tier 4 Advertising/marketing (opt-in): voyager_attrib (30 days, first-party UTMs only, XSS-sanitized, no email or financial figures), Clarity Consent API v2, and GTM/GA4 Consent Mode v2 default-denied with update-on-consent. No ad pixel, iframe, or heatmap loads until you accept Tier 4. Clearing cookies resets you to necessary-only. Finance-web (authenticated app) loads zero GTM/GA4/Clarity/Meta/TikTok tags in any tier — only Tier 1 plus Tier 2 if enabled. Full inventory and lifespans are in our Cookie Policy at /legal/cookies.
We disclose personal information only to processors needed to operate Voyager under written contracts: Supabase (auth/database), Plaid (aggregation at your direction), Stripe (billing), Doppler/Dokploy/GHCR hosting, and — on marketing-web with consent — Plausible/PostHog, Microsoft Clarity, and Google Tag Manager/Analytics. Admin support views are reason-captured, role-scoped, MFA-gated, and never expose raw secrets or full provider payloads. We do not disclose financial data to advertisers, brokers, or credit bureaus, and we are not a consumer reporting agency under the FCRA — we do not furnish consumer reports. If you accept Tier 4 marketing cookies on marketing-web, that use may constitute CCPA Sale/Sharing for cross-context advertising; you can opt out at any time via Your Privacy Choices at /legal/cookies#manage or by enabling Global Privacy Control (GPC), which we honor as a valid opt-out of sale/share and which suppresses voyager_attrib and Tier 4 loads. Do Not Track is honored the same way. We never use GPC state or consent state to discriminate against you.
We maintain a written information security program: provider tokens encrypted before persistence with ASP.NET Core Data Protection under the Voyager application scope with keys in an external vault/HSM; PostgreSQL Row-Level Security deny-by-default with owner_user_id tenancy; encryption at rest and TLS 1.3 in transit with HSTS; isolated ingestion subnets and Hangfire worker with no public ingress; short-lived Supabase JWTs validated on issuer, audience, JWKS, and expiry; MFA for operators with zero-standing-privilege access and immutable audit_events without secrets or raw payloads. Logs strip authorization headers and financial bodies. No system is impenetrable — you must use MFA where offered, keep credentials confidential, use only accounts you are authorized to connect, and notify security@wyna.app of suspected compromise or vulnerability. Do not include sensitive financial details in email; encrypt technical reproductions per our contact page.
We retain data only as long as needed for the purposes above: active connections sync continuously; disconnected-item history is retained until you delete it or your account so reconciliations and audits remain explainable; backups age out on rotation; audit, webhook idempotency, sync-job, billing, and security records are retained as legal-evidence per counsel-approved schedule and are excluded from ordinary deletion. You can export your normalized ledger (transactions, balances, holdings, rules, budgets, goals) as versioned JSON/CSV via /api/v1/me/export at any time with zero lock-in. Account deletion triggers a cryptographic wipe of profile, credentials, and snapshots within 30 days, except records we must retain by law (billing disputes, fraud prevention, audit/legal holds) with retention_exception_reason recorded. Disconnecting an institution stops future pulls and revokes provider access but does not by itself delete historical local copies — use deletion or contact privacy@wyna.app to request erasure, and we confirm completion in writing.
If you are a California, Virginia, Colorado, Connecticut, Texas, or other covered-state resident, you have the right to know/access categories, sources, purposes, and recipients; to delete personal information with legal exceptions; to correct inaccuracies; to opt out of sale/sharing and targeted advertising via Your Privacy Choices or GPC with no account-creation requirement; to limit use of sensitive personal information (we do not infer sensitive attributes); to appeal a denial; and to non-discrimination for exercising rights. Submit requests to privacy@wyna.app with subject Access, Deletion, Correction, or Opt-Out from your account email; we verify via Supabase session and respond within 45 days (plus one extension with notice). Authorized agents must present signed permission plus your verification. We disclose metrics and material changes prominently and by direct notice to registered accounts before they take effect. This notice does not create GDPR data-controller, DPO, or EU-representative obligations because the service is US-only in this release.
Voyager is not directed to children under 13 and does not knowingly collect their data; if you believe a child provided data, contact privacy@wyna.app for deletion per COPPA. We may update this policy for security, features, or law changes; material changes get a new lastUpdated date, website notice, and direct notice before effect, with prior versions archived and hashed per docs/plans/legal/completed-financial-data-aggregation-consent/RUNBOOK.md. Continued use after the effective date constitutes acceptance for marketing-web browsing; finance account linking and billing always require affirmative acceptance of the then-current version. Questions, requests, or appeals: Voyager Inc., privacy@wyna.app (privacy), legal@wyna.app (terms/DMCA/arbitration), security@wyna.app (vulnerabilities). For billing disputes also see Terms. DRAFT TEMPLATE — do not publish, seed into any legal registry, or enable production Plaid linking until privacy and financial-services counsel approves entity identity, retention schedule, Plaid disclosures/links, and jurisdictional language.