This Privacy Policy describes how Fahmy Abdi, sole proprietor, carrying on business as Notch ("Notch", "we", "us" or "our"), collects, uses, discloses, safeguards and retains personal information, and the rights available to you in respect of that information. It applies to the Notch web application at app.usenotch.co, the Notch mobile applications, the website at usenotch.co, and all related services we operate. Notch is operated from Ontario, Canada. This policy is drafted to meet our obligations under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
Summary. We collect only the personal information required to operate the Service and none for advertising purposes. Your online banking credentials are entered into Plaid and are never received or stored by Notch. We do not sell, rent or trade personal information. This summary is provided for convenience only and does not modify the sections that follow.
Section 06 describes how bank connections operate. Section 07 describes the optional daily read, which is disabled unless you enable it.
Accountability and contact
Notch is a personal finance application operated by Fahmy Abdi, sole proprietor, based in Ontario, Canada. For the purposes of PIPEDA and applicable provincial privacy legislation, we are the organisation accountable for the personal information under our control, including information transferred to a third party for processing.
We have designated a Privacy Officer who is accountable for our compliance with this policy. The Privacy Officer may be reached at support@usenotch.co. All privacy enquiries, access requests and complaints should be directed to that address.
Scope and definitions
In this policy, "personal information" means information about an identifiable individual, as defined in PIPEDA. "Service" has the meaning given in our Terms of Service. "Plaid" means Plaid Inc. "Linked Institution" means a financial institution to which you have connected an account through the Service.
This policy does not apply to the practices of third parties we do not own or control, including your Linked Institutions, Plaid, or any website reached from a link within the Service. Their handling of your information is governed by their own policies.
Personal information we collect
Information you provide
- Account and identity information. Your email address, display name, and the identifier issued by your sign-in provider (Google, or an email address and password you set), collected to authenticate you and associate your data with your account.
- Financial information you enter. Transactions you record manually, budgets, savings goals and any notes on them, categories, payment-method labels, income sources, recurring charges, and balances you record yourself.
- Preferences. Your country and region, which determine the sales-tax rate applied, together with display currency, category limits and feature settings.
- Correspondence. Any information you send us by email, including support requests and feedback.
Information received from your Linked Institutions
Where you elect to link an account, we receive the following through Plaid: account names, account types and sub-types, the last four digits of the account number, the institution name, current and available balances, and transaction history including the date, amount, merchant or description and category of each transaction, together with the time of day where the institution reports it.
We do not receive or store your online banking credentials at any time. Those are entered directly into an interface operated by Plaid. Our access is read-only: we cannot move money, initiate payments, or view full account or routing numbers.
Information collected automatically
- Device and technical information. Basic device information required to operate and troubleshoot the Service, together with error diagnostics.
- Notification identifiers. Where you enable alerts, a device notification token so that alerts may be delivered to that device. The token is removed when you disable alerts.
Purposes of collection, use and disclosure
We collect, use and disclose personal information only for the purposes set out below. We will identify any new purpose to you and, where required, obtain your consent before using your information for it.
- To provide the Service. Displaying balances and transactions, categorising spending, tracking budgets, goals and recurring charges, calculating amounts available, and synchronising your data across your devices.
- To maintain bank connections. Refreshing data from Linked Institutions and notifying you when a connection requires your attention.
- To communicate with you. Sending service, security and transactional messages, and, where you have enabled them, notifications relating to imported purchases or a disconnected institution.
- To secure the Service. Authenticating users, detecting and preventing fraud or misuse, and investigating security incidents.
- To provide support when you contact us, and to establish, exercise or defend legal claims.
- To comply with law and with our legal, regulatory and contractual obligations.
We do not sell, rent or trade personal information. We do not use financial information for advertising, marketing profiling or credit assessment, and we do not disclose it to advertisers or data brokers.
Consent and withdrawal of consent
We collect, use and disclose personal information with your knowledge and consent, except where the collection, use or disclosure without consent is permitted or required by law. You provide express consent when you create an account, when you link a financial institution, and when you enable an optional feature such as notifications or the daily read.
You may withdraw consent at any time, subject to legal and contractual restrictions and on reasonable notice, by unlinking an institution, disabling a feature, or closing your account. Withdrawal of consent does not affect the lawfulness of any processing carried out before withdrawal. Where withdrawal prevents us from providing part of the Service, we will inform you of the consequences before giving effect to it.
Bank connections through Plaid
We use Plaid Inc. to connect to financial institutions. When you link an account, Plaid collects your credentials directly and exchanges them for an access token that permits us to retrieve account and transaction data on your behalf. That token is stored on our servers, is not exposed to any client application or to any other user, and is deleted when you unlink the institution.
Our access is read-only and limited to balances and transactions. Notch cannot transfer funds, initiate payments, or open or close accounts.
Your use of Plaid is also governed by Plaid's End User Privacy Policy, which describes Plaid's own handling of your information and operates independently of this policy. We recommend that you read it before linking an account.
The optional daily read
The Service includes an optional feature that generates a short written summary of your finances. The feature is disabled unless you enable it and may be disabled again at any time within the Service.
Information transmitted when the feature is enabled
Where the feature is enabled, a summary of your financial data is transmitted to Anthropic PBC, which operates the model that produces the summary. That transmission may include: up to twelve months of transaction records (date, time, amount, merchant, your own description and category for each), your accounts and their balances, the institution and last four digits associated with each account, your savings goals and any notes on them, your income sources, your recurring charges, your category spending limits, and a summary of amounts owed across your credit cards.
The transmission also includes working notes retained between generations so that successive summaries remain consistent. Those notes are stored with your account and are deleted when your account is deleted.
How that information is handled
Anthropic processes this information on our behalf as a service provider, for the sole purpose of returning the summary to you, and under contractual confidentiality and security obligations. Under Anthropic's commercial terms, data submitted through its API is not used to train its models. Anthropic processes data in the United States.
If you do not enable this feature, no financial information is transmitted to Anthropic at any time. If you disable the feature, transmission ceases immediately, and you may request deletion of the stored notes by writing to support@usenotch.co.
Automated processing
The Service categorises transactions and generates projections and written summaries by automated means. These outputs are informational and are presented to you for your own assessment.
We do not use personal information to make any decision that produces a legal effect concerning you or that similarly significantly affects you. In particular, we do not perform credit scoring, lending, insurance underwriting, eligibility assessment or fraud scoring against you, and we do not supply personal information to any party for those purposes.
Service providers and disclosure
We do not sell personal information or disclose it to third parties for their own purposes. We engage the following categories of service provider, each of which processes personal information only on our instructions and under contractual confidentiality and security obligations:
| Provider | Purpose | Processed in |
|---|---|---|
| Cloud infrastructure provider | Authentication, database and backend hosting | United States |
| Plaid Inc. | Financial institution connectivity | United States |
| Anthropic PBC | The daily read, only where enabled by you | United States |
| Push notification provider | Alert delivery, only where enabled by you | United States |
| Transactional email provider | Account, security and support email | United States |
We may also disclose personal information where required or permitted by law, including in response to a valid court order, subpoena, search warrant or lawful request from a government or regulatory authority; where necessary to establish, exercise or defend a legal claim; where necessary to investigate a suspected breach of agreement or contravention of law; or to protect the rights, property or safety of any person.
If we are involved in a merger, acquisition, financing, reorganisation or sale of all or substantially all of our assets, personal information may be disclosed to the counterparty and transferred as part of that transaction, subject to appropriate confidentiality undertakings. We will notify you of any such transfer, and this policy will continue to apply until replaced.
Transfers outside Canada
Notch is operated from Canada. Our service providers store and process personal information on servers located in the United States. While personal information is in a foreign jurisdiction, it is subject to the laws of that jurisdiction and may be accessible to the courts, law enforcement agencies and regulatory authorities of that jurisdiction under those laws.
We remain accountable for personal information transferred to a service provider for processing, and we use contractual and technical measures intended to afford a level of protection comparable to that required under Canadian law. By using the Service you consent to this transfer and processing. We are not presently able to offer the Service on a basis that keeps personal information exclusively within Canada.
Cookies and similar technologies
The marketing website at usenotch.co collects no personal information. It contains no registration form and uses no advertising, analytics or cross-site tracking cookies.
The application at app.usenotch.co uses browser storage and equivalent mechanisms strictly necessary to operate the Service, including to keep you signed in, to hold an encrypted local copy of your ledger so the Service functions offline, and to retain your display preferences. These are not used for advertising or cross-site tracking. Clearing them will sign you out and remove the local copy.
Safeguards
We maintain physical, organisational and technological safeguards proportionate to the sensitivity of the information, including:
- In transit. All traffic between client applications, our backend and our providers is encrypted using TLS 1.2 or higher.
- At rest. Data held on our backend is encrypted at rest by our infrastructure provider using AES-256. The copy of your ledger cached on your device is encrypted with a 256-bit key generated on that device and held in the device keystore.
- Access control. Database rules scope every record to the account that owns it, so one user's data cannot be read by another. Server-only data, including bank access tokens, is neither readable nor writable by any client application.
- Step-up authentication. Connecting, reconnecting or unlinking a financial institution requires biometric confirmation on your device.
- Administrative access. Administrative access is limited to the operator, protected by multi-factor authentication, with credentials held in a managed secret store and never in source code.
No method of transmission or storage is completely secure and we cannot guarantee absolute security. We review our safeguards as the Service develops.
Retention and disposal
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required or permitted by law, after which it is deleted or rendered anonymous.
- Financial and account data is retained while your account remains active.
- Bank access tokens are deleted immediately when you unlink an institution.
- Individual records are deleted when you delete them within the Service.
- All information associated with your account is deleted when you close it. Bank connections are severed immediately, the remaining data is held for thirty (30) days so that the account may be restored if the closure was in error, and it is then permanently erased.
- Device-local data is removed when you sign out, clear the application's data, or uninstall it.
Residual copies may persist for a limited period in encrypted backups held by our infrastructure providers before being overwritten in the ordinary course of business.
Your rights
Subject to the exceptions permitted by law, you have the right to:
- Access the personal information we hold about you, and be informed of how it has been used and to whom it has been disclosed;
- Correct information that is inaccurate or incomplete. Most information may be edited directly within the Service;
- Withdraw consent to any collection, use or disclosure, subject to legal and contractual restrictions;
- Obtain a portable copy of your information. The Service can produce a complete backup file at any time;
- Delete your account and the information associated with it; and
- Complain about our handling of your personal information.
To exercise any of these rights, write to support@usenotch.co. We respond within thirty (30) days of receiving a request. We may require verification of your identity before acting. Access is provided free of charge unless a request is excessive or repetitive, in which case we will advise you of any cost before proceeding. Where we refuse a request in whole or in part, we will give reasons and inform you of your right to complain.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada or to the privacy regulator of your province.
Residents of other jurisdictions
Quebec. Personal information may be communicated outside Quebec as described in section 10. We have conducted an assessment of the privacy-related factors of those transfers. You may request the deindexing or ceased dissemination of information in the circumstances provided by law, and you may request that we cease using automated processing in the circumstances provided by law.
United States. We do not sell personal information or share it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information other than for the purposes set out in section 04. Residents of states with comprehensive privacy legislation may have rights of access, correction, deletion, portability and appeal, exercisable at the address in section 19. We do not discriminate against any person for exercising a privacy right.
Mexico. Where the Ley Federal de Protección de Datos Personales en Posesión de los Particulares applies, this policy serves as our privacy notice, and you may exercise your rights of access, rectification, cancellation and opposition at the address in section 19.
Breach notification
Where a breach of our security safeguards creates a real risk of significant harm to an individual, we will report the breach to the Office of the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible, and will notify any other organisation or government institution that may be able to reduce the risk of harm, as PIPEDA requires. We maintain records of every breach of security safeguards for the period prescribed by law.
Children
The Service is not directed at children and is not intended for use by anyone under the age of sixteen (16). We do not knowingly collect personal information from any person under that age. If you believe that a child has provided us with personal information, write to support@usenotch.co and we will delete it.
Changes to this policy
We may amend this policy as the Service develops. The version number and "last updated" date above will be revised accordingly. Where an amendment materially affects how we handle personal information, we will notify you within the Service or by email before it takes effect and, where the law so requires, obtain your consent again. Prior versions are available on request.
Contact
Privacy Officer
Fahmy Abdi, sole proprietor, carrying on business as Notch
support@usenotch.co
Ontario, Canada
For the terms governing your use of the Service, see our Terms of Service. Third-party names and trade-marks referred to in this policy are acknowledged in section 14 of those Terms.