This Privacy Policy explains what personal information Ray ("we", "us", or "Ray") collects, why we collect it, how we use and share it, how long we keep it, and the choices you have. It applies to the website and app at https://ray.sunflower.builders and related APIs (together, the "Platform").
Ray is a personal cash-runway product. To use the core product you create an account and connect bank accounts so we can calculate how many months of cash runway you have from live balances, income, and spending. Undefined terms have the same meaning as in our Terms of Use.
1. Summary of data collection and usage
In short:
- We collect account information (email, name, password or Google account identity), multi-factor authentication status, and settings you enter (income, burn overrides, preferences).
- We collect financial account data you authorize through Plaid (balances, account metadata, and transaction history) so we can classify spend and compute runway.
- We use that data only to operate Ray for you: authenticate you, sync banks, calculate runway and burn, show transactions, and support the product.
- We do not sell your personal information. We do not use your bank data for advertising.
- You can disconnect banks, update settings in the app, and request account deletion by emailing contact@isaiahadekanye.com.
2. Personal information we collect
2.1 Information you provide
- Account and profile: email address, display name, and related profile fields you choose to save.
- Credentials: password when you use email sign-in (stored as a hash by our authentication provider; we do not store plaintext passwords). If you use Google Sign-In, Google authenticates you and we receive your Google account email and basic profile identity via Supabase Auth.
- Security: authenticator (TOTP) enrollment status used for multi-factor sign-in.
- Financial settings you enter: monthly income, income duration, manual burn overrides, lookback preferences, and similar inputs used in runway math.
- Support messages: content you send when you contact us.
2.2 Connected bank and financial data (required for the product)
When you link institutions through our bank-connection provider (Plaid), we receive and store data you authorize, which may include:
- Institution name and identifiers; Item / connection status (including re-authentication signals).
- Account identifiers, names, types/roles you map (chequing, savings, credit, exclude), nicknames, currency, and sort order.
- Current and available balances, and optional fields you set such as overdraft limits.
- Transaction history: amounts, dates, descriptions, merchant names, pending status, and personal finance category fields from the provider.
- Classifications we derive or you override (expense, income, transfer, credit payment, ignore) used for burn and income averages.
Encrypted bank access tokens are stored on our servers only. They are not sent to your browser. Connecting chequing, savings, and credit accounts (as applicable) is required to use live runway.
2.3 Information collected automatically
- Usage: pages and features you use within the app.
- Device and logs: IP address, browser or device type, approximate location derived from IP, timestamps, and diagnostic or error logs needed to run and secure the Platform.
- Cookies and local storage: session and security tokens required to keep you signed in. We do not use advertising cookies.
2.4 Information from service providers
- Supabase Auth: account creation, sessions, and optional Google OAuth tokens needed to sign you in.
- Google: when you choose Continue with Google, Google shares your email and basic profile with Supabase so we can create or open your Ray account. Google Sign-In is optional; email sign-in remains available.
- Plaid: bank connection, balances, and transactions you authorize.
- Google Cloud / Cloudflare: API and website hosting and related operational logs.
3. How we use personal information
We use personal information to:
- Create and secure your account, including multi-factor authentication.
- Connect and refresh bank data; classify transactions; compute auto burn, income, and runway; and show today's action.
- Persist your settings, account roles, and class overrides across devices.
- Provide customer support and respond to your requests.
- Detect fraud, abuse, and security incidents; debug and improve reliability.
- Comply with law and enforce our Terms.
We do not use your connected financial data to train third-party advertising models or to sell ads against your profile.
4. How we share information
We share personal information only as needed to operate the Platform:
- Service providers / processors listed above (Supabase, Plaid, Google Cloud, Cloudflare), under contracts that limit use to providing services to us.
- Legal and safety: if required by law, legal process, or to protect rights, safety, or the Platform.
- Business transfer: if we merge, sell, or reorganize, information may transfer under continued privacy protections.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
5. Retention
- Account and settings: kept while your account is active.
- Bank connections and transactions: kept while linked and for a rolling history needed to compute burn (on the order of several months of transactions; older rows may be pruned as the product evolves).
- Logs: typically retained for a short operational period (days to a few months) unless needed longer for security or legal reasons.
- After account deletion requests, we delete or anonymize personal data within a reasonable period (generally within 30 days), except where law, disputes, or backups require limited retention.
6. Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of financial data, including encrypted transport (HTTPS), server-side encryption of bank access tokens, hashed passwords via our auth provider, and role-restricted API access. No method of transmission or storage is 100% secure.
7. Your choices and rights
- Access and correction: update profile and settings in the app, or email contact@isaiahadekanye.com.
- Bank disconnect: remove or exclude accounts in Ray; you may also revoke access via Plaid or your institution.
- Deletion: email contact@isaiahadekanye.com from your account email and ask us to delete your Ray account. We will confirm and remove associated personal data subject to the retention limits above.
- Depending on where you live (for example Canada under PIPEDA, or other applicable privacy laws), you may have rights to access, correct, delete, or withdraw consent for certain processing. Contact us to exercise those rights. We may verify your identity first.
8. Children
Ray is not directed to children under 18 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided data, contact us and we will delete it.
9. International transfers
We and our processors may store and process information in Canada, the United States, and other countries where our providers operate. Those jurisdictions may have different data-protection laws. By using Ray, you understand your information may be transferred to those locations.
10. Third-party services
Plaid, Supabase, Google Cloud, and Cloudflare have their own privacy policies that govern their processing. Review those policies when you connect banks or create an account.
11. Changes
We may update this Privacy Policy by posting a new version on this page and updating the "Last updated" date. Continued use after changes means you accept the revised policy. If you disagree, stop using Ray and request deletion.
12. Contact
Privacy questions, access requests, or deletion requests: contact@isaiahadekanye.com.
Website: https://ray.sunflower.builders.