Financial data
Used to calculate budgets, forecasts, insights, and account-linked product features.
Privacy Policy
Granite Finance ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application, Granite (the "Service").
Used to calculate budgets, forecasts, insights, and account-linked product features.
Granite does not receive or store bank account login credentials.
Granite does not sell your personal information.
Account and data deletion can be requested through Granite support or the deletion flow.
Optional photos and reviewed voice transcripts are processed only after an in-product disclosure and user action.
This Privacy Policy is a notice describing our data practices; it is not a request for blanket consent. Where consent is the appropriate legal basis, including for optional external AI transaction capture, Granite presents a separate in-product disclosure and records your choice. We are committed to protecting your privacy and handling personal information responsibly.
We collect information in the following ways:
We use the information we collect for the following purposes:
We do not use customer financial data from assistant interactions to train generalized AI models unless we clearly disclose that practice to you and obtain any consent required by applicable law.
Granite may use AI models to turn deterministic budget, transaction, and savings results into plain-language insights. When external AI processing is enabled, Granite may send your prompt and the minimum financial context needed to answer it to an AI provider acting on our behalf. This may include selected transaction summaries, categories, balances, budget context, goals, and assistant tool results.
If you choose AI transaction capture, Granite may send OpenAI the price photo you selected, including surrounding details visible in it, or the final speech-to-text transcript that you reviewed. Granite also sends the categories available for the transaction and limited date or currency context so the model can suggest an item or merchant, amount, date, and category. Granite does not send raw voice audio or bank login credentials to the external AI provider.
External AI processing is used to provide requested insights, improve the clarity of Granite responses, maintain safety and abuse controls, and keep an audit trail of assistant access. Granite does not use AI-assisted outputs to make solely automated legal, credit, insurance, employment, housing, or essential-service eligibility decisions.
Granite identifies AI transaction capture before you use it and presents the result as a suggestion for review. A photo or voice description does not create a transaction by itself. You must confirm the details before Granite saves a manual transaction. AI-assisted outputs can be incomplete or incorrect, so you should review every field.
You can decline optional external AI processing and continue to use available manual entry and deterministic budget features. You may withdraw consent through an available Granite AI control or by contacting us. Withdrawal does not affect processing that was lawful before the withdrawal, and a revised disclosure requires renewed consent before the affected feature can be used.
OpenAI states that API inputs and outputs are not used to train its generalized models by default. Granite does not opt customer content into provider model training. We configure supported requests not to preserve response application state for later retrieval, but the provider may retain limited content and metadata for abuse monitoring for the period permitted by our provider agreement, configuration, and applicable law.
For European users, Granite treats AI-assisted financial insight generation as profiling only to the extent it uses personal financial data to infer spending patterns or budget opportunities. Granite does not use these features for biometric identification, emotion recognition, or solely automated decisions that produce legal or similarly significant effects.
Where the European Economic Area or United Kingdom data protection laws apply, Granite relies on one or more of the following legal bases:
We use administrative, technical, and physical security measures to help protect your personal information. We rely on the security infrastructure of our provider, which includes industry-standard security practices. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that no security measures are perfect or impenetrable.
If you choose to sign in with your Google account, this section explains how we handle your Google data:
If you choose to sign in with your Google account, we access limited profile information provided by Google, specifically your name, email address, and profile image (if available). No other Google user data (such as Gmail, Drive, Calendar, or Contacts) is accessed.
This information is used solely to authenticate your account, personalize your profile within the app, and facilitate secure login. We do not use your Google data for advertising purposes.
We do not share Google user data with any third parties except as required to operate the Service (e.g., our backend server). These providers process data only on our behalf and under strict confidentiality obligations.
Google user data is securely stored on Supabase servers located in the United States. All data is encrypted both in transit (HTTPS/TLS) and at rest. Access is limited to authorized personnel who need the information to operate and maintain the Service.
We retain Google user data only while your account is active. When you delete your account or request data deletion, all associated Google user data is permanently deleted from our servers within 30 days.
To request deletion, email hi@granitefinance.io with the subject line "Delete My Data."
You have the right to review, update, or delete the personal information you provide in your account settings. You can also disconnect your financial accounts at any time. If you wish to permanently delete your account and all associated data, please contact us.
Depending on where you live, you may also have rights to access, correct, export, restrict, or object to certain processing of your personal data. If you are located in the European Economic Area, United Kingdom, or another jurisdiction with similar protections, you may also withdraw consent, object to processing based on legitimate interests, request processing restriction, receive certain information in a portable format, and lodge a complaint with the data protection supervisory authority where you live, work, or believe an infringement occurred. You may request human review where you believe a solely automated decision with legal or similarly significant effects has been made about you. Granite Assistant and AI transaction capture are advisory tools and are not intended to make such decisions.
To exercise a privacy right or withdraw AI-processing consent, use an available in-product control or email hi@granitefinance.io. We may need to verify your identity and will respond within the period required by applicable law. Withdrawing consent does not affect the lawfulness of processing completed before the withdrawal.
Granite is based in the United States, and Granite and its service providers may process personal information in the United States and other countries that may have different data protection laws from your country. This includes hosting, financial-data aggregation, analytics, subscription, support, and optional external AI processing.
Where European or UK law requires a transfer mechanism, Granite relies on an applicable adequacy decision, the European Commission's Standard Contractual Clauses, the UK transfer addendum or international data transfer agreement, or another legally recognized safeguard. You may contact us for information about the safeguard applicable to a particular transfer.
We retain your information as long as your account is active. When you delete your account, Granite schedules the associated account and customer data for deletion within 30 days. Our service providers may require additional processing time to complete deletion or de-identification, and we may retain limited records where required by law or for the legitimate purposes described below.
Automated assistant actions and data-access events are logged for 7 days for user transparency, security, and abuse prevention. We may retain related records longer where necessary to comply with law, investigate misuse, resolve disputes, or preserve evidence in connection with a security or fraud incident.
Granite processes a submitted price photo or reviewed voice transcript for the active transaction-capture request. Granite does not place the raw photo or transcript in your customer account or its completed-result retry cache. For safe retries and duplicate-request protection, Granite may retain a cryptographic request fingerprint and the structured suggested result for up to 24 hours. If you confirm the result, the saved manual transaction remains with your account under the normal account-retention rules.
External AI providers may retain limited request content or metadata for safety and abuse monitoring. Depending on Granite's provider configuration and contractual controls, OpenAI states that these logs may be retained for up to 30 days by default, unless a shorter or zero-data-retention control applies, or longer retention is legally required. Device speech-recognition providers handle audio under their own disclosed retention and platform settings.
Subscriptions purchased through Apple are managed by Apple. Deleting your Granite account does not cancel an Apple subscription. You can manage or cancel Apple subscriptions at https://apps.apple.com/account/subscriptions.
We may retain limited records when required by law or for legitimate business purposes (for example, payment processor transaction records needed for tax, accounting, chargeback, or fraud prevention obligations). These records are access-limited and retained only as long as required.
You can request data deletion at any time by emailing hi@granitefinance.io with the subject line "Delete My Data." You can also submit a request at granitefinance.io/delete-account.
Granite is intended only for people who are at least 18 years old. We do not knowingly collect personal information from children or permit them to create Granite accounts. If you believe a child has provided personal information, contact us so we can investigate and delete it as appropriate.
We use third-party providers like Plaid (see Plaid's Privacy Policy), Supabase for backend hosting and data storage, AI model or inference providers such as OpenAI for external AI processing where enabled, Apple or an available Android service for device speech recognition, Mixpanel for mobile product analytics, Firebase for push notifications, RevenueCat and the applicable app store for subscription management, and Google Analytics for website analytics (only after you consent to analytics cookies).
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. If a change materially expands optional processing that relies on consent, Granite will present a revised disclosure and request a new choice before that processing begins.
Granite Finance is the controller responsible for the personal information described in this policy. If you have a question, privacy request, or complaint, email hi@granitefinance.io.
If Granite appoints a data protection officer or a representative in the European Union or United Kingdom, the applicable contact details will be published in this section before they are required for the relevant offering or processing.
Localized guidance; bank connections currently support the US and Canada.