← accrU

Privacy and Financial Data Policy

Last updated: September 16, 2026

This policy explains how accrU handles information when you create an account, maintain a ledger, or connect a financial institution.

Information we collect

You provide profile information such as your name and email address, authentication information, settings, and the financial records you enter or import. Your password is stored only as a one-way hash.

When you connect an institution, we receive the account identifiers, account names and types, balances, and transaction details that the provider makes available for the connection you authorize. Transaction details can include dates, amounts, merchant or payee names, descriptions, and pending status.

Plaid and financial institution connections

accrU uses Plaid to connect supported bank and loan accounts. Your financial institution credentials are entered in Plaid's or your institution's consent window. accrU does not receive or store those credentials.

We request Plaid's Transactions product so we can create and update the account and transaction records shown in your ledger. Plaid may collect and process additional identifiers, device information, and financial data as described in the Plaid End User Privacy Policy. You can also manage connections Plaid recognizes through Plaid Portal.

Other service providers

accrU can use SnapTrade as a read-only brokerage connection provider. We also use infrastructure providers for application hosting, database storage, and email delivery. These providers process data to operate the service on our behalf and are subject to their own terms and privacy practices.

How we use information

We use information to authenticate you, maintain your private ledger, synchronize authorized accounts, calculate balances and reports, provide alerts, support the service, prevent abuse, troubleshoot failures, and comply with legal obligations.

We do not sell or rent your personal or financial data. We do not use financial data for advertising.

Security and encryption

Plaid access tokens and SnapTrade user secrets are encrypted with AES-256-GCM before they are stored in our database. Each encrypted value uses a unique initialization vector and an authentication tag. Provider credentials are restricted to server-side code.

Plaid webhook notifications are accepted only after their body digest and ES256 signature are verified with Plaid's published verification key. No system can guarantee absolute security, so you should use a unique password and enable two-factor authentication in Settings.

Sharing and disclosure

We disclose data to Plaid, SnapTrade, your selected financial institutions, and our infrastructure providers only as needed to provide the service. We may also disclose information when required by law, to protect users or the service, or in connection with a business transfer subject to appropriate protections.

Account sharing inside accrU occurs only when an account owner deliberately grants another registered user view or edit access.

Retention, disconnection, and deletion

We retain your profile and ledger data while your account is active and as needed to operate the service or meet legal obligations. When you select Disconnect on the Connections page, accrU asks the provider to revoke the connection, deletes the encrypted provider token and connection mappings, and removes transactions imported through that connection.

The ledger account shell is retained so you can preserve or continue using records you entered independently. You can archive or manage that account separately. Plaid may retain limited data where another active connection, law, fraud prevention, or de-identified data practices permit it, as explained in Plaid's policy.

Your choices and rights

You can disconnect a financial institution at any time from the Connections page, change account-sharing permissions, and update security settings in the application. Depending on where you live, applicable law may provide rights to request access, correction, portability, restriction, objection, or deletion.

For Plaid's own processing, use Plaid Portal or the request methods in Plaid's privacy policy. For accrU privacy questions or requests, email privacy@accru.app. We may need to verify your identity before fulfilling a request.

Children and international use

accrU is not directed to children under 13. Financial institution connections currently support United States institutions. If you use the service elsewhere, your information may be processed in the United States.

Policy changes

We may update this policy as the service or legal requirements change. We will update the date above and provide additional notice when a material change requires it.