This Policy explains how Retrac Labs, LLC (“Piggy,” “we,” or “us”) handles information through the Piggy website, iPhone and iPad app, and macOS desktop wrapper. It applies to information Piggy handles for the Service. Plaid, Clerk, Google, Sentry, Resend, Apple, and your financial institutions may also process information under their own terms and notices.
The Retrac Labs General Privacy Policy at https://retraclabs.io/privacy/general/ also applies. This Piggy-specific Policy controls where it differs, subject to applicable law. The Retrac Labs General Terms of Service at https://retraclabs.io/tos/general/ also applies to Piggy.
1. Information we handle
- Account and access: email address, Clerk user ID, sign-in and subscription status, dashboard names, memberships, and invitee email addresses.
- Linked financial data: Plaid connection tokens and IDs; account names, types, masked account numbers and balances; transaction names, merchants, categories, amounts, dates, and pending status.
- Information you create or use: manually added transactions, budgets, recurring charge information, net worth snapshots, questions and relevant conversation context for Ask Piggy, alert reasons and preferences, and dashboard settings.
- Device and technical data: authentication cookies, a cookie for your last dashboard, limited local storage for dismissed alert cards, and error/performance telemetry. When enabled, Piggy handles iOS push tokens and Face ID preference settings.
Piggy does not receive or store your online banking usernames or passwords. Plaid handles the financial account connection flow. Piggy encrypts Plaid access tokens and several sensitive financial fields in its database, including account names and masks and transaction names, merchants, and categories.
2. Where it comes from
We receive data from you and other dashboard members; from Clerk for identity and billing status; from Plaid and connected financial institutions for linked financial data; and from your device and use of the Service. A dashboard member may add another person’s financial information to a managed dashboard even if that person has no Piggy account.
3. How we use it
We use information to authenticate users; connect and refresh financial accounts; display balances and transactions; support manual entries, budgets, net worth, recurring charges, and search; answer Ask Piggy questions; generate high-charge, low-balance, and suspicious-activity alerts; send service and invitation emails or opted-in push notifications; manage subscriptions; secure and troubleshoot the Service; and comply with legal obligations.
Literal transaction search is handled within Piggy. When a literal search has no result, an assisted search may send the query and a limited set of candidate transaction details to Google Gemini for a fuzzy match. Ask Piggy sends your question, recent conversation context, account summaries, and relevant financial records requested by its tools. Suspicious-activity analysis sends transaction context for anomaly review. AI output can be inaccurate or delayed.
4. Who can see or receive information
- Dashboard members: every member has equal access to that dashboard’s financial data. A managed dashboard may contain data about a person who has no Piggy account.
- Clerk: sign-in, user management, and subscription billing.
- Plaid: bank connection and financial data delivery.
- Google Gemini: questions and relevant financial context for Ask Piggy, assisted search, and suspicious-activity analysis.
- Resend: welcome and dashboard-invitation emails, including destination email and message content.
- Sentry: error and performance telemetry.
- Apple: delivery of opted-in iOS push notifications and local Face ID functionality.
- Hostinger: infrastructure for Piggy’s self-managed VPS and PostgreSQL database.
We may also disclose information when required by law or to protect the Service and users, subject to applicable law. Piggy does not use advertising tools or separate product analytics services; Sentry handles error and performance telemetry.
5. Cookies, local storage, and app permissions
Authentication cookies keep you signed in. A Piggy cookie remembers the last dashboard you opened. Limited device local storage remembers dismissed alert cards. The iOS app uses a push token only when notifications are enabled; you can change Piggy alert and push settings and your device notification permission. Face ID preference settings support the optional device lock feature.
6. Your choices and deletion
You can switch alert types and push notifications on or off, remove linked accounts, and delete dashboards. Removing the last account on a Plaid connection or deleting a dashboard triggers a best-effort attempt to revoke the Plaid connection. These actions may not immediately erase data held by vendors, backups, or other dashboard members. Deleting a dashboard does not by itself delete your Piggy or Clerk account. To request access, correction, or full Piggy account deletion, contact carter@retraclabs.io. We may verify your request before acting on it.
7. Retention and security
We retain information while needed to provide the Service and for legitimate legal, security, and operational purposes. Dashboard deletion removes dashboard records from Piggy’s active database. Copies may persist temporarily in backups, logs, and vendor systems under their applicable practices. We use access controls and encryption for Plaid access tokens and several sensitive financial fields. No method of storage or transmission is completely secure.
8. Children, location, and rights
Piggy is available only to people in the United States who are at least 18 years old, and it supports US financial accounts. A managed dashboard may contain information about another person; dashboard members must have authority to provide it. Depending on where you live, you may have rights to access, correct, delete, or receive information, or to appeal a decision. Contact carter@retraclabs.io to make a request.
9. Policy updates and contact
We may update this Policy and will post an updated effective date and provide any notice required by law. Contact Retrac Labs, LLC at carter@retraclabs.io or 3336 Belcaro Drive, Denver, Colorado 80209, USA.
