Can Cairn move my money?
No. There is no transfer, no payment, and no trade anywhere in the product. Cairn connects to your accounts with read-only access and shows you what it reads. This is a limit built into the code rather than a policy that could quietly change: the capability to move money simply does not exist in Cairn, and the AI has no tool that could touch it either.
Can Cairn see my bank password?
No. When you connect an account you sign in at your bank, through Plaid, and the credential stays with your bank. Cairn receives an access token that can only read the accounts you chose to share. Your username and password never pass through Cairn and are never stored by it.
Does the AI read my transactions?
No. Every number you see in Cairn is computed by its own deterministic planner, ordinary code with no AI in it. When you ask the AI a question, it is handed only the small summary figures the planner produced, and its job is to restate them. It is never given your raw transactions, your account numbers, or your credentials.
The model runs under zero data retention, enforced at the account level with the provider, with prompt logging off, and your data is never used to train anything. Every AI response is labeled as AI, and every call is recorded in an activity trail you can read inside the app.
Does Cairn sell my data?
Never. Not raw, not de-identified, not aggregated. There are no ads, no affiliate recommendations, and no data buyers. Cairn's business model is that you pay for it, which means it never needs to make money from your data, only from your continued trust.
Who can actually see my data?
Cairn is built and run by one person. Your data lives in a Neon Postgres database in the United States, encrypted at rest, and the Plaid access tokens that reach your accounts carry a second layer of encryption at the application level. There is no support team browsing accounts, and nobody reads your data as a matter of course.
Has Cairn been audited?
Not yet. Cairn is young and has not had a third-party security audit. A phrase like “bank-level security” would not mean anything coming from an app this early, so you will not find one here.
What Cairn runs on is independently audited: Plaid, which handles the bank connection, and Neon and Vercel, which store and serve your data, each hold their own certifications such as SOC 2 and ISO 27001. Those belong to them, not to Cairn, and it seems more honest to say so than to borrow the badges. When Cairn has an audit of its own, it will be listed here.
How do I disconnect?
You can disconnect any institution from the Accounts page at any time. You can also revoke Cairn's access from outside the app entirely at Plaid Portal, which does not depend on Cairn cooperating. Deleting your Cairn account and what happens to your data afterward is covered in the Privacy Policy.
Who is behind this?
Cairn is made by nnnsightnnn, a one-person studio. That is worth saying plainly, because at this size trust cannot come from a brand; it can only come from the shape of the thing itself. The shape is: read-only by construction, paid for by you, and transparent about what is not done yet.
Questions about any of this reach a person, not a queue: kjautry@gmail.com.