1. What Patrn Does
Patrn helps users understand their personal finances by connecting financial accounts and turning account, balance, transaction, spending, budget, savings, and debt information into app views and insights.
Patrn uses Plaid Link to help users connect financial accounts. Plaid may ask you to authenticate with your financial institution and authorize the data you want to share with Patrn. Patrn does not receive or store your bank login credentials.
2. Information We Collect
Account Information
We may collect information you provide when creating or managing an account, such as:
- Name
- Email address
- Authentication and session information
- Account preferences
- Consent records and security settings
Patrn uses Supabase Auth as its consumer identity provider. Supabase may process authentication-related information to create sessions and verify email addresses. Patrn does not currently offer an in-app consumer multi-factor-authentication enrollment flow.
Financial Information From Plaid
With your consent, Patrn may collect financial information made available through Plaid, including:
- Financial institution name
- Account names, account type, subtype, and masked account number
- Account balances
- Transaction names, dates, categories, amounts, merchant names, and currency
- Plaid item, account, and transaction identifiers
- Plaid sync cursors and connection metadata needed to keep your data up to date
We use this information to power linked accounts, budgets, spending analysis, transaction views, savings goals, debt summaries, and personalized insights.
AI Coaching Information
AI coaching is available by default, but Patrn sends information to an AI provider only when you submit a coaching message or otherwise request an AI-generated response. Depending on your request, this may include:
- The messages in your current coaching conversation
- Relevant financial context from Patrn, such as account types and balances, transaction amounts, dates, merchants, descriptions and categories, budgets, goals, debts, and summaries derived from that information
- Limited technical and safety information needed to process, secure, and troubleshoot the request
Patrn does not send bank login credentials, Plaid access tokens, Supabase or Apple authentication secrets, or payment-card credentials to the AI provider.
App Usage And Device Information
We may collect limited technical information needed to operate, secure, debug, and improve the service, such as:
- App version, platform, and device type
- Approximate request metadata, such as timestamps and IP-derived security signals
- Server logs, error information, and security audit events
- User actions related to account linking, disconnecting, deletion, and authentication
Patrn does not currently use financial data for third-party advertising or cross-context behavioral advertising.
3. How We Use Information
We use information to:
- Create and manage your Patrn account
- Authenticate users and protect access to financial data
- Connect accounts through Plaid Link with your consent
- Sync account and transaction information
- Display budgets, spending, linked accounts, savings goals, debts, and transactions
- Generate personalized financial summaries and insights
- Detect, prevent, and investigate fraud, abuse, security incidents, and unauthorized access
- Maintain audit logs and comply with legal, regulatory, and contractual obligations
- Respond to support, security, privacy, and deletion requests
- Improve reliability, performance, and product quality
We do not sell your personal financial data. We do not use Plaid access tokens, bank credentials, or financial transaction data for unrelated advertising.
4. Plaid And Connected Financial Accounts
When you choose to connect an account, Patrn opens Plaid Link. Plaid may collect information directly from you and your financial institution to authenticate your account and provide data to Patrn according to your consent.
Patrn receives data from Plaid only after you authorize the connection. Patrn stores a Patrn connection identifier in the app and stores Plaid access tokens only on the server side. Plaid access tokens are encrypted before persistence and are never exposed to the mobile app.
You may review Plaid's own privacy disclosures in Plaid Link and at Plaid's privacy pages. Plaid's practices are governed by Plaid's privacy terms, not this Patrn Privacy Policy.
5. How We Share Information
We may share information with:
- Supabase for authentication and application data storage
- Vercel and related infrastructure providers for application hosting and request processing
- Plaid, when you use Plaid Link or when we revoke, update, or sync a Plaid connection
- Anthropic, when you submit an AI coaching request, to process your messages and the relevant financial context needed to generate a response
- OneSignal for push-notification delivery and RevenueCat for App Store subscription management
- Other service providers that help us operate Patrn, such as security, infrastructure, and support providers
- Legal, regulatory, or safety recipients when required by law or necessary to protect rights, safety, security, or the integrity of the service
- Successor organizations if Patrn is involved in a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality and privacy protections
We require service providers to use information only to provide services to Patrn and to protect it appropriately.
6. Security
Patrn uses administrative, technical, and organizational safeguards designed to protect personal and financial information. Current safeguards include:
- Supabase Auth for user authentication
- Email verification before Plaid Link is surfaced
- Platform secure storage for mobile sessions
- Device passcode and biometric protections supplied by the operating system when users enable them
- Server-side-only Plaid token exchange and Plaid access-token handling
- Application-layer envelope encryption for Plaid access tokens
- Supabase Row Level Security to scope financial rows to the owning user
- HTTPS/TLS for non-local client-server traffic
- CORS allowlists, request size limits, rate limits, audit logging, and redacted server errors
- Restricted administrative access and MFA requirements for critical systems
No method of transmission or storage is perfectly secure. If we identify a security incident that affects your information, we will take appropriate steps to investigate, mitigate, and notify affected users or regulators when required.
7. Data Retention
We retain personal information for as long as needed to provide Patrn, maintain your account, comply with legal obligations, resolve disputes, protect the service, and enforce agreements.
Financial account and transaction data is retained while you have an active linked account. If you disconnect a Plaid account or request deletion of your financial data, Patrn revokes Plaid access and deletes synced account and transaction rows from active systems. Residual copies may remain temporarily in disaster-recovery backups until those backups rotate, and are not returned to the active product except when required for recovery, security, or legal compliance.
Security audit records and deletion request records may be retained for a limited period to document compliance, prevent abuse, and resolve disputes.
Patrn does not currently persist AI coaching conversation text in its application database. The active conversation is held in the app while you use it and can be removed with Clear AI history. Anthropic states that standard API inputs and outputs are deleted from its backend within 30 days, except where a different retention arrangement applies or longer retention is required for legal or usage-policy enforcement purposes.
8. Your Choices And Controls
You may:
- Choose whether to connect a financial account through Plaid
- Decline Plaid consent before linking
- Disconnect a linked account
- Request deletion of synced financial data
- Turn AI coaching off or back on in Settings; turning it off stops future AI requests
- Choose whether to submit a message while AI coaching is on
- Clear the current AI coaching history in the app
- Sign out of the app
- Use device-level protections such as passcode or biometric unlock
- Contact us about access, correction, deletion, or privacy questions
Disconnecting an account stops future syncing through Patrn and deletes synced financial rows. It may not delete information separately retained by Plaid or your financial institution.
9. Account Deletion
If you request account deletion or deletion of your financial data, Patrn will:
- Revoke active Plaid connections where technically available
- Delete synced account and transaction rows associated with your user ID
- Record a deletion request for audit and compliance purposes
- Allow residual backup copies to age out under the applicable disaster-recovery backup lifecycle unless legally required otherwise
Some information may be retained where necessary for security, fraud prevention, legal compliance, dispute resolution, or enforcing rights.
10. AI And Automated Insights
AI coaching is available by default. Merely creating an account or viewing the AI screen does not send your financial data to Anthropic. When you submit a coaching request, Patrn sends the messages in the current conversation and the relevant financial context described above to Anthropic's commercial API to generate the response.
Patrn does not use your AI messages or personal financial data to train a Patrn general-purpose AI model, and Patrn does not opt in to allowing Anthropic to use them for general model training. Anthropic states that it does not use inputs or outputs from its commercial API to train its models by default. Anthropic may process or retain information for safety, abuse prevention, legal compliance, and service operation under its applicable commercial terms and privacy practices.
AI-generated insights may be incomplete, inaccurate, or outdated. They are intended to help you understand patterns in your finances and are not financial, investment, tax, legal, accounting, credit, lending, or debt-management advice. Patrn does not use AI output to make decisions about credit eligibility, employment, housing, insurance, or other decisions that produce legal or similarly significant effects, and Patrn does not use AI coaching to move money or execute transactions.
AI coaching is on by default. You can opt out at any time by turning off AI financial coaching in Settings under Privacy & data. Turning it off records your preference and stops future AI requests until you turn it on again. You can also clear the current coaching history in Settings, delete synced financial data, or delete your Patrn account. Contact us at admin@patrn.ai if you have questions or want to exercise an applicable privacy right concerning AI processing.
For additional information about Anthropic's commercial API practices, review its model-training disclosure and commercial data-retention disclosure.
11. Children's Privacy
Patrn is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to Patrn, contact us so we can take appropriate action.
12. State And Regional Privacy Rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, or restriction of certain personal information. You may also have the right to appeal certain privacy decisions.
To exercise privacy rights, contact us at admin@patrn.ai. We may need to verify your identity before responding. We will not discriminate against you for exercising privacy rights.
Patrn does not sell personal information or share personal information for cross-context behavioral advertising as those terms are commonly used in U.S. state privacy laws.
13. International Users
Patrn is currently intended for users in the United States. If you use Patrn from outside the United States, your information may be processed in the United States or other locations where our service providers operate.
14. Changes To This Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the app, website, email, or another reasonable method. The "Effective date" above indicates when this policy was last updated.
15. Contact Us
For privacy, security, or deletion questions, contact:
Patrn Adminadmin@patrn.ai