Legal

Privacy Policy

Last updated: April 14, 2026

Overview

Finance OS is a private financial operating system built and operated by Ryan DeCook. This policy describes how data is collected, stored, and used within the platform. Finance OS is not a public SaaS product and does not sell, share, or monetize any user data.

What data is collected

Finance OS processes and stores the following types of data:

  • Entity and account registry information (names, types, institution details)
  • Financial transactions imported via CSV or connected bank feeds
  • Documents uploaded to the vault (statements, receipts, tax forms, formation docs)
  • Review actions, audit trail events, and reporting period status
  • Basic session information for authentication

How data is stored

All operational data is stored in a Supabase-hosted PostgreSQL database. Uploaded documents are stored in Supabase Storage. The database and storage are provisioned in a single Supabase project with access restricted to the application's service role credentials.

Third-party services

Finance OS integrates with the following third-party services:

  • Supabase — database hosting, file storage, and authentication infrastructure
  • Vercel — application hosting and deployment
  • Plaid — bank account connectivity (currently sandbox mode only)

No data is shared with advertising networks, analytics platforms, or data brokers.

Data retention

Financial records, documents, and audit trail data are retained indefinitely to support tax filing, audit readiness, and historical record-keeping. Session data expires automatically after 8 hours of inactivity.

Your rights

As the primary operator and data owner, Ryan DeCook retains full control over all data in the system. Data can be exported, modified, or deleted at any time through the application or directly through database access.

Contact

For questions about this privacy policy or data handling practices, contact the system operator directly.