Privacy policy
Your financial information serves you.
This policy explains what SIX may access when the account owner connects a financial institution, why that information is used, and the controls available to the owner.
Effective July 19, 2026
Information accessed
SIX Personal Finance OS (“SIX”) is the local application receiving information when the owner chooses to connect an institution. The current Plaid connection requests:
- account names, types, partial identifiers, balances, and available balances;
- recent and ongoing transaction dates, amounts, merchant or counterparty descriptions, categories, and status; and
- connection status, institution metadata, and record provenance needed to operate, secure, and reconcile the connection.
Investments and Liabilities are not currently requested during Plaid Link. SIX will provide a new notice and obtain any required additional consent before requesting a new product or materially different use. SIX does not ask the owner to provide a bank password to SIX. Plaid Link handles supported institution authentication.
Purpose of access and user authorization
SIX uses the currently requested information for account and transaction review, budgeting and cash-flow analysis, recurring-payment review, summaries, alerts, reconciliation, and connection security. Plaid may continue providing transaction updates and connection-status events until the owner disconnects the institution.
Before opening Plaid Link, SIX presents a just-in-time connection notice and requires the owner to choose to continue. Plaid Link then presents Plaid’s own consent and data-transparency experience. Access begins only if the owner completes Plaid Link.
SIX does not use financial information for advertising, sell it, use it to make lending or eligibility decisions, execute trades, or move money.
Storage and approval controls
Long-lived provider access tokens remain server-side and are stored in encrypted form. They are not stored in browser storage. Core financial processing and records follow a local-first model in the owner-controlled operational environment.
New provider data is staged for review. The owner can inspect records before approving their promotion into the canonical local ledger. These controls reduce accidental trust in incomplete, duplicated, or mismatched provider records, but they do not eliminate every security or data-quality risk.
Retention
Information is retained for as long as it supports the owner’s active use of SIX, the integrity of the canonical financial history, and reasonable security, audit, reconciliation, or legal needs. Disconnecting a provider stops future retrieval through that connection but does not silently erase already approved canonical history.
Unapproved staged data can be removed separately. Limited provenance or audit records may be retained when needed to explain prior imports, prevent duplication, reconcile records, investigate security events, or meet legal obligations.
Your choices: disconnect and deletion
The owner can choose which supported institutions to connect and can disconnect an institution within SIX. Disconnect asks Plaid to remove access, removes SIX’s encrypted provider credential and connection-scoped provider caches, and stops future sync. It does not silently delete approved canonical history.
The owner can reject unapproved staged records so they are not promoted to canonical history and can request deletion or provider-provenance changes by email. Detailed steps and current implementation limits are explained on the Data Deletion page.
Do not send passwords, access tokens, or complete account numbers by email. A deletion request may require reasonable steps to verify the requester and clarify scope before action is taken.
Policy updates and contact
This policy may change as SIX evolves or legal and operational requirements change. Material revisions will be reflected by updating the effective date and publishing the revised policy here.
For privacy questions, disconnect assistance, or deletion requests, email ricardo.suarez@outlook.com.
