CJPERSONAL FINANCE

Privacy Policy

Last updated September 26, 2026

Who this app is for

Personal Finance (personal.christianjamal.com) is a private tool built and used only by its owner, Christian Jamal, to track his own bank accounts, credit cards and loans. It is password-protected, has no other users, and is not offered to the public.

What data is collected

  • Account names, types, the last four digits of account numbers, and balances
  • Transactions: date, merchant, amount and category
  • Credit card and loan details: APR, minimum payment and due date
  • Categories, notes and settings the owner enters in the app

Bank usernames and passwords are never seen or stored by this app. Accounts are connected through Plaid, which handles bank logins directly.

Consent

Data is only collected from accounts the owner chooses to connect. Each connection goes through Plaid Link, where the owner reviews and approves the specific accounts and data being shared before anything is accessed. Plaid's handling of data is described in the Plaid End User Privacy Policy.

How data is used

Only to show the owner where his money goes: spending summaries, a spending plan, recurring charges, debt payoff order, and answers to questions he asks in the app. Data is never sold, shared for advertising, or used for any other purpose. The app has no ads and no tracking or analytics scripts.

Service providers

  • Plaid: connects to financial institutions and provides account data.
  • Vercel: hosts the application.
  • Supabase: stores account and transaction data.
  • Anthropic: when the owner asks a question in the Ask tab, the relevant transaction data is sent to Anthropic's API to generate the answer. Anthropic does not use API data to train its models.

Security

  • All traffic is encrypted with HTTPS (TLS 1.2 or higher).
  • Stored data is encrypted at rest (AES-256).
  • Plaid access tokens are additionally encrypted by the application (AES-256-GCM) and never sent to the browser.
  • Every page and data request requires the owner's password and a one-time code from an authenticator app.
  • Hosting and database accounts are protected with multi-factor authentication.

Retention and deletion

Data is kept only while an account is connected. Disconnecting a bank in the app immediately revokes Plaid's access and permanently deletes that bank's accounts and transactions from the database. The owner reviews connected accounts and this policy at least once a year and after any change to how the app handles data.

Contact

Questions about this policy: admin@christianjamal.com

Privacy Policy · Personal