Cairn
Camp · retention

What we keep, and for how long.

We keep your financial data only as long as we need it to show you your money, and we let it go when you disconnect or close your account.

Effective June 23, 2026 · Version 1.0.

The principle

We keep your financial data only as long as we need it to provide Cairn, and we dispose of data we no longer need securely — no later than two years after your last use of it, and sooner where practical.

What we store, and where

Your account and financial data live in a Postgres database hosted by Neon in a US region. We store:

  • Connected financial data — account and balance info, transactions, investment holdings, and liabilities for the institutions you link
  • Connection credentials — Plaid access tokens, encrypted at rest, used only to maintain the connection
  • Account data — your name and email from Google Sign-In
  • Operational records — security-essential logs and the AI activity trail (model and token counts, never raw financial data)

How long we keep each kind

  • Connected financial data — while your account is active and the institution is connected; deleted within 30 days of disconnection or account closure
  • Plaid access tokens — revoked and deleted when you disconnect the institution or delete your account
  • Account and profile — while your account is active; deleted within 30 days of closure
  • Backups — purged on the routine backup-rotation cycle after deletion

Disconnecting one institution

When you disconnect an institution from Accounts, we call Plaid's /item/remove endpoint to end Plaid's access and delete the stored data and access token for that connection.

Deleting your account

When you delete your account from Settings, we:

  • revoke and delete every Plaid connection (a /item/remove call for each)
  • delete your stored financial data and access tokens
  • delete your profile data, retaining only what the law requires
  • complete deletion within 30 days, with backups purged on rotation

What may survive deletion

We may keep limited information where the law requires it, or in routine encrypted backups until they rotate out. Anything retained stays protected and is not used for any other purpose.

Deleting data Plaid holds

Our deletion removes the data we hold. To manage or delete data held by Plaid, use Plaid Portal or Plaid's data request form. Plaid may retain some data as the law permits or requires; see Plaid's End User Privacy Policy.

How to request deletion

In the app, use Accounts to disconnect a single institution, or Settings to delete your whole account. Or email kjautry@gmail.com — we verify identity before acting on emailed requests.

Secure disposal

Deletion is performed so the data is not readily recoverable. Tokens and sensitive fields are purged from active stores and excluded from new backups.