LEGAL

Privacy Policy

Hunch is a secure cloud web app. This policy explains what we collect, how it’s protected, who we share it with, and the choices you control.

Last updated: July 30, 2026

This Privacy Policy applies to hunch.money, the Hunch web app at app.hunch.money, bank connections made through Plaid, the optional Hunch browser extension, household sharing, support, optional AI features, connections you make to outside AI assistants, paid services, and related services. It should be read together with our Terms of Use.

1. Privacy at a glance

  • We never see your banking password: You connect your bank through Plaid and sign in directly with your bank. Plaid grants Hunch read-only access to your transactions and balances. Your banking password and any MFA codes go to your bank, never to Hunch.
  • Encrypted and isolated to you: Sensitive details — merchant names, account names, descriptions, and notes — are encrypted at rest with a key unique to your account, and every record is isolated so only your account can read it. The token that links your bank is sealed with its own strong encryption.
  • Read-only access: Hunch can read your transactions and balances. It can never move money or make changes at your bank.
  • Sharing is your choice: Hunch only shares your finances with a partner or other household member when you set that up, and you can end the sharing at any time.
  • Optional AI: AI features are off until you turn them on. AI categorization sends only merchant names; the Ask Hunch assistant queries your spending data for the scopes you enable. You can also connect an outside assistant like Claude or ChatGPT — read-only, only the categories you approve, and revocable at any time (see section 22).
  • No sale of data, no ad targeting: We do not sell your personal information, and we do not share it for cross-context behavioural advertising. You can export or delete your data anytime.

2. Accountability and contact

Hunch is responsible for personal information under our control. Questions, privacy requests, and complaints can be sent to privacy@hunch.money.

3. Financial information we store

To provide the service, Hunch stores your financial data in our cloud database. This may include transaction records, account names, account identifiers assigned by an institution, account balances, holdings, categories, budgets, goals, recurring-transaction rules, net worth history, transfer metadata shown by an institution, app settings, and sync state.

This information is encrypted and isolated to your account so that only your account — and anyone you have chosen to share a household with — can access it. You can export all of it or delete your account, which removes your data and disconnects your banks, at any time. If you import CSV or PDF statements instead of connecting a bank, that data is stored the same way.

4. Bank connections through Plaid

When you connect a bank, Hunch uses Plaid to establish the connection. You sign in directly with your bank inside Plaid’s secure flow — Hunch never asks for, sees, or stores your banking password or MFA codes.

Your bank grants read-only access to your transactions and balances, and Plaid returns an access token that Hunch stores encrypted on your behalf. That token can only read data — it cannot move money or change anything at your bank. You can disconnect a bank at any time, which revokes Hunch’s access. Plaid processes information under its own privacy policy.

5. Household and partner sharing

Hunch lets you form a household so you can share finances with a partner or other person you invite. Sharing is entirely optional and off until you set it up. When you create or join a household, the members of that household can view the financial information shared into it — such as accounts, balances, transactions, budgets, goals, and net worth — for as long as the sharing is active, regardless of other settings within the app.

Only invite people you trust with your financial information. If you invite someone to your household, you are responsible for that decision; if you join someone else’s household, the data you contribute may be visible to them. Depending on the permissions in place, a household member may also be able to add, edit, categorize, or remove shared records.

You can leave a household, remove a member, or stop sharing at any time. Ending the sharing stops further access going forward; it does not retroactively erase information a member already saw or exported. Each person’s connected banks and account remain their own — deleting your account removes your data and disconnects your banks, and does not delete another member’s separate account.

6. Information we may collect or process

Depending on the features you use, Hunch or our service providers may process:

  • Account information: email address, account identifiers, authentication metadata, preferences, entitlements, subscription status, household membership, and support history.
  • Billing information: payment status, plan, invoices, tax information, transaction identifiers, and billing contact details handled through our payment provider. We do not store full card numbers.
  • AI request information: merchant descriptions, category prompts, model responses, usage counts, entitlement checks, and technical metadata needed to provide optional AI features.
  • Support communications: messages you send us, attachments you provide, and information needed to investigate or respond.
  • Website and security logs: IP address, user agent, timestamps, requested URLs, device/browser information, error logs, abuse-prevention data, and diagnostics.
  • Product diagnostics: crash reports, sync status, app version, and feature events when needed to secure, troubleshoot, or improve Hunch.
  • Marketing preferences: email subscription status, consent records, unsubscribe records, and communication history.

7. How we use information

We use information for these purposes:

  • to provide, operate, maintain, secure, and troubleshoot Hunch;
  • to sync and display your financial information when you choose to use Hunch features;
  • to enable household sharing when you set it up;
  • to categorize transactions, detect recurring transactions, calculate balances, and generate charts;
  • to provide optional AI categorization and enforce related usage limits;
  • to authenticate accounts, manage subscriptions, process payments, and prevent abuse;
  • to respond to support, security, privacy, and legal requests;
  • to send service messages, security notices, policy updates, and requested product communications;
  • to improve reliability, performance, accessibility, and user experience; and
  • to comply with law and enforce our Terms.

8. De-identified and aggregated data

We may create aggregated or de-identified information that cannot reasonably be used to identify you — for example, overall usage statistics or anonymized trends — and use it to operate, secure, and improve Hunch. We do not attempt to re-identify this information, we do not sell it, and we never use your personal financial data for advertising.

9. Consent and choices

We seek meaningful consent for the collection, use, and disclosure of personal information. Some processing is necessary to provide Hunch when you choose to use a feature. Other processing, such as optional AI categorization, household sharing, marketing emails, and paid account features, can be turned on or off as described in the product or by contacting us.

You may withdraw consent where legally permitted, but doing so may limit or prevent use of features that require the information.

10. Disclosure and service providers

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose information to service providers (sometimes called subprocessors) only as needed to operate Hunch.

Current service providers include:

  • Plaid: secure bank connectivity. You authenticate with your bank through Plaid, which provides Hunch read-only access to your transactions and balances.
  • Cloudflare: application hosting, CDN, DNS, security, and DDoS protection.
  • Neon: the encrypted Postgres database where your data is stored, with per-account isolation.
  • Stripe: checkout, subscription billing, invoices, tax handling, fraud checks, and payment records.
  • AI model providers (via Cloudflare AI Gateway): optional categorization and assistant requests are routed to third-party models such as those from OpenAI, Anthropic, and Google when you choose AI features.
  • Email and analytics: Cloudflare for delivering service and product email, and privacy-conscious analytics (Google Analytics and Cloudflare Web Analytics).

We may also disclose information if required by law, to protect rights and safety, to investigate abuse or security incidents, in connection with a business transaction such as a merger or acquisition, or with your direction or consent. If Hunch is involved in a merger, acquisition, or sale of assets, we will continue to protect your information and notify you of any change in who controls it or how this policy applies.

11. Optional AI categorization

AI categorization is off by default. When you use it, Hunch sends only the information needed for the request. The intended payload is merchant or transaction description text and category context, not bank credentials, full account numbers, card numbers, MFA codes, or full bank statements. Requests are routed through Cloudflare’s AI Gateway to third-party model providers such as OpenAI, Anthropic, and Google.

We do not use your personal financial data to train our own AI models. Where available, we configure third-party AI services to avoid training on your prompts and responses. Third-party AI handling is also governed by the provider’s terms and privacy commitments.

12. Cookies, analytics, and browser storage

Hunch uses cookies and browser storage to keep you signed in and to save settings, session state, security tokens, and preferences needed for the app to function. The marketing site and service providers may use cookies or similar technologies for security, site operation, analytics, fraud prevention, and (where you have consented and local law allows) ads.

See our Cookie Policy for the full list of cookies and similar technologies we use, and to accept, decline, or customize analytics and ad cookies at any time — a “Cookie preferences” link is always available in the site footer. For analytics we use Google Analytics and Cloudflare Web Analytics to understand aggregate usage and improve the product. You can additionally opt out of Google Analytics with Google’s browser add-on at tools.google.com/dlpage/gaoptout. We do not use these tools for cross-site behavioural advertising.

You can also control cookies and browser storage through your browser settings, but disabling or clearing storage may break functionality or sign you out. Because there is no common industry standard for “Do Not Track” browser signals, Hunch does not respond to them; however, we do not sell your data or run cross-site behavioural advertising. We honour Global Privacy Control signals as described in “U.S. state privacy rights” below.

13. Retention and deletion

Your financial data is kept while your account is active so the service can work. You can delete your account at any time, which removes your financial data and revokes Hunch’s access to your connected banks. Some records may persist briefly in encrypted backups before they age out.

Account, billing, support, security, and diagnostic records are retained only as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law, dispute resolution, fraud prevention, tax, accounting, backup, or security needs.

14. Security safeguards

We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information. These may include encryption in transit, encryption at rest for cloud-stored data where applicable, per-account data isolation, access controls, least-privilege practices, origin checks, nonce-bound browser messaging, Content Security Policy, provider review, and security monitoring.

No system is perfectly secure. You are responsible for securing your device, browser profile, operating system, email account, passwords, recovery methods, and any local saved session material.

15. Breach notification

If we determine that a breach of security safeguards involving personal information under our control creates a real risk of significant harm, we will notify affected individuals and applicable privacy regulators as required by law, and we will keep required records.

16. International processing

Hunch and our service providers may process or store information in Canada, the United States, and other countries. Information processed outside your state, province, territory, or country may be subject to foreign laws and lawful access requests.

17. Your privacy rights

Subject to legal limits, you may request access to personal information we hold about you, ask for it to be corrected, request deletion, withdraw consent, object to certain processing, or ask questions about our practices. To make a request, contact privacy@hunch.money.

You can also export a full copy of your data or delete your account directly from the app’s built-in controls at any time.

We may need to verify your identity before acting on a request, and we will respond within the time required by applicable law. If you are not satisfied with our response, you may contact the applicable privacy regulator in your jurisdiction.

18. U.S. state privacy rights

If you are a resident of a U.S. state with a comprehensive consumer privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others — you have additional rights with respect to your personal information, subject to that law’s limits and exceptions:

  • the right to know and access the personal information we collect, use, and disclose about you;
  • the right to request correction of inaccurate personal information;
  • the right to request deletion of your personal information;
  • the right to a portable copy of your personal information in a readily usable format;
  • the right to opt out of the “sale” or “sharing” of personal information and of targeted (cross-context behavioural) advertising; and
  • the right not to receive discriminatory treatment for exercising these rights.

We do not sell your personal information, we do not share it for cross-context behavioural advertising or targeted advertising, and we do not use or disclose sensitive personal information for purposes that require an opt-out. We honour a Global Privacy Control (GPC) browser signal as a valid opt-out request: our cookie banner treats it the same as choosing to decline analytics and ad cookies, in addition to it being a valid opt-out of any “sale” or “sharing” where required by law.

To exercise any of these rights, contact privacy@hunch.money, or use the export and delete controls inside the app. You may use an authorized agent to submit a request on your behalf; we may ask the agent for proof of authority and may ask you to verify your identity directly. We will not discriminate against you for exercising your rights.

If we deny your request, you may appeal by replying to our response and explaining why you disagree; we will respond to your appeal within the time required by applicable law. You may also contact your state attorney general if you have concerns about our handling of your request.

19. Commercial electronic messages

We send marketing emails only where we have consent or another lawful basis. Commercial electronic messages include identification information and an unsubscribe mechanism. You can unsubscribe from marketing emails at any time. We may still send transactional or service messages, such as security, billing, account, and policy notices.

20. Children

Hunch is intended only for adults who can legally manage the financial accounts they connect. Hunch is not directed to children, and we do not knowingly collect personal information from anyone under 18, or under the age of majority in your jurisdiction. If we learn that we have collected such information, we will delete it. If you believe a minor has provided us personal information, contact privacy@hunch.money and we will take appropriate steps to remove it.

21. The Hunch browser extension

Hunch offers an optional browser extension that helps you bring investment holdings into Hunch from brokerage and crypto sites that aren’t available through Plaid. The extension is optional, does nothing until you install it and sign in, and only acts when you click to capture.

The extension does not run in the background, track your browsing, or read pages on its own. When you open it, it checks the address of your current tab so it can tell whether you’re on a supported holdings page. When you choose to capture, it reads the holdings shown on that page — security names, tickers, quantities, and values — and sends them to your Hunch account to add to your portfolio. It does not read other tabs, capture pages you haven’t asked it to, or see your brokerage password or MFA codes.

To attach captures to your account, the extension reads your existing Hunch sign-in from your browser and includes it only in requests to Hunch. Captured holdings are stored exactly like the rest of your financial data — encrypted and isolated to your account — and are never sold or used for advertising. The extension keeps no financial data of its own. You can remove it from your browser at any time; uninstalling it ends all access immediately.

22. Connecting an outside AI assistant

Hunch can be connected to an AI assistant you already use, such as Claude or ChatGPT, so you can ask that assistant questions about your own finances. This is optional and off until you connect it. Nothing is shared with any assistant unless you go through the connection screen and approve it.

A connection is read-only. It cannot move money, make a payment, change a budget, or delete anything in your account. When you connect an assistant you choose which categories of information it may read — your accounts and balances, your transactions, your investments, your budgets and goals — and it can read only the categories you approved. The same plan limit on how far back your history goes applies to the assistant too.

Connecting an assistant means the information it reads is sent to the company that operates it — for example Anthropic for Claude, OpenAI for ChatGPT, or Google for Gemini — and is then handled under that company’s terms and privacy policy rather than this one. This is different from the AI features described in section 11, where Hunch chooses the provider and controls the request. Here you are choosing to send your financial information to an assistant you have your own relationship with. Please read that provider’s policy before you connect.

Anyone can register an application that asks to connect, and Hunch does not verify or endorse those applications. The connection screen shows you the web address the application will send you back to, so you can check it is the assistant you expect. Treat an unfamiliar address as a reason not to approve.

If you are in a household, this can share another person’s information. Approving the household permission lets the assistant read the accounts, balances, and transactions that other members have shared into your household — not only your own — and those members do not separately approve your connection. Because of that, we email the other members of your household when you grant household access, so they know it happened and can talk to you about it. If you do not want to share their information, use the “Share only my data” option on the connection screen. Note that a household member cannot revoke a connection you created; only you can, or they can stop sharing their accounts with the household.

You can see every connected application and disconnect any of them at any time in Settings under Security. Disconnecting stops further access within about a minute. It does not retroactively erase information the assistant or its provider already received, and it does not delete anything held in your history with that assistant — you would need to remove that through the assistant itself.

Your password, two-factor codes, recovery codes, and bank credentials are never shared with a connected assistant.

23. Changes to this policy

We may update this Privacy Policy as Hunch changes or as legal, operational, or security requirements evolve. Material changes will be posted on this page and, if you have an account, may be communicated by email or in-product notice. The updated policy applies when posted unless a later effective date is stated.

24. Contact

Privacy questions, requests, or complaints: privacy@hunch.money.