Financial data
Used to calculate budgets, forecasts, insights, and account-linked product features.
Privacy Policy
Granite Finance ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application, Granite (the "Service").
Used to calculate budgets, forecasts, insights, and account-linked product features.
Granite does not receive or store bank account login credentials.
Granite does not sell your personal information.
Account and data deletion can be requested through Granite support or the deletion flow.
By accessing or using our Service, you agree to the collection and use of information in accordance with this policy. We are committed to protecting your privacy and ensuring your personal information is handled responsibly.
We collect information in the following ways:
We use the information we collect for the following purposes:
We do not use customer financial data from assistant interactions to train generalized AI models unless we clearly disclose that practice to you and obtain any consent required by applicable law.
Granite may use AI models to turn deterministic budget, transaction, and savings results into plain-language insights. When external AI processing is enabled, Granite may send your prompt and the minimum financial context needed to answer it to an AI provider acting on our behalf. This may include selected transaction summaries, categories, balances, budget context, goals, and assistant tool results. We do not send bank login credentials.
External AI processing is used to provide requested insights, improve the clarity of Granite responses, maintain safety and abuse controls, and keep an audit trail of assistant access. Granite does not use AI-assisted outputs to make solely automated legal, credit, insurance, employment, housing, or essential-service eligibility decisions.
You can enable or disable external AI processing in your account settings. If you disable it, Granite may still provide deterministic budget calculations, but AI-generated summaries or Savings Insights may be unavailable or limited.
For European users, Granite treats AI-assisted savings insight generation as profiling only to the extent it uses personal financial data to infer spending patterns or budget opportunities. Granite is designed to avoid solely automated decisions that produce legal or similarly significant effects. Where required, we will rely on your consent for external AI processing and will provide controls to withdraw that consent.
We use administrative, technical, and physical security measures to help protect your personal information. We rely on the security infrastructure of our provider, which includes industry-standard security practices. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that no security measures are perfect or impenetrable.
If you choose to sign in with your Google account, this section explains how we handle your Google data:
If you choose to sign in with your Google account, we access limited profile information provided by Google, specifically your name, email address, and profile image (if available). No other Google user data (such as Gmail, Drive, Calendar, or Contacts) is accessed.
This information is used solely to authenticate your account, personalize your profile within the app, and facilitate secure login. We do not use your Google data for advertising purposes.
We do not share Google user data with any third parties except as required to operate the Service (e.g., our backend server). These providers process data only on our behalf and under strict confidentiality obligations.
Google user data is securely stored on Supabase servers located in the United States. All data is encrypted both in transit (HTTPS/TLS) and at rest. Access is limited to authorized personnel who need the information to operate and maintain the Service.
We retain Google user data only while your account is active. When you delete your account or request data deletion, all associated Google user data is permanently deleted from our servers within 30 days.
To request deletion, email hi@granitefinance.io with the subject line "Delete My Data."
You have the right to review, update, or delete the personal information you provide in your account settings. You can also disconnect your financial accounts at any time. If you wish to permanently delete your account and all associated data, please contact us.
Depending on where you live, you may also have rights to access, correct, export, restrict, or object to certain processing of your personal data. If you are located in the European Economic Area, United Kingdom, or another jurisdiction with similar protections, you may also request human review where you believe a solely automated decision with legal or similarly significant effects has been made about you. Granite Assistant is designed as an advisory tool and is not intended to make such decisions.
We retain your information as long as your account is active. When you delete your account, all associated data is permanently deleted from our servers within 30 days.
Automated assistant actions and data-access events are logged for 7 days for user transparency, security, and abuse prevention. We may retain related records longer where necessary to comply with law, investigate misuse, resolve disputes, or preserve evidence in connection with a security or fraud incident.
Subscriptions purchased through Apple are managed by Apple. Deleting your Granite account does not cancel an Apple subscription. You can manage or cancel Apple subscriptions at https://apps.apple.com/account/subscriptions.
We may retain limited records when required by law or for legitimate business purposes (for example, payment processor transaction records needed for tax, accounting, chargeback, or fraud prevention obligations). These records are access-limited and retained only as long as required.
You can request data deletion at any time by emailing hi@granitefinance.io with the subject line "Delete My Data." You can also submit a request at granitefinance.io/delete-account.
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children.
We use third-party providers like Plaid (see Plaid's Privacy Policy), Supabase for backend hosting and data storage, AI model or inference providers for external AI processing where enabled, and Google Analytics for product analytics (only after you consent to analytics cookies).
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
If you have any questions about this Privacy Policy, please email hi@granitefinance.io.