Privacy Policy

Last updated: May 2026

MyCashStory is a product operated by LogosBloom Inc., a federally incorporated Canadian company. References to "MyCashStory", "we", "us", or "our" refer to LogosBloom Inc.

1. Information We Collect

We collect the following categories of personal information: Account Information: Your name, email address, and password (stored as a secure hash — we never see your plain-text password). Bank Transaction Data: When you connect your bank via Plaid, we receive read-only access to your transaction history, account balances, and account metadata. We cannot initiate transactions or access your banking credentials. Usage Data: How you interact with MyCashStory, including pages visited, features used, and actions taken. This is collected via PostHog analytics only with your explicit cookie consent. Payment Information: Subscription billing is handled entirely by Stripe. We store only your Stripe customer ID and subscription status — your card number never touches our servers.

2. PIPEDA Compliance (Canada)

MyCashStory complies with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. We obtain your explicit consent when you: • Connect your bank account via Plaid (read-only financial data access) • Send your financial data to Anthropic Claude and xAI Grok APIs for AI narrative generation • Subscribe to email alerts and monthly summaries You have the right under PIPEDA to: • Access the personal information we hold about you • Correct inaccurate information • Withdraw consent (which may limit your ability to use some features) • File a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca For privacy questions contact: privacy@mycashstory.app

3. How We Use Your Information

We use your information solely to provide the MyCashStory service: • To generate AI-powered cash flow narratives from your transaction data • To calculate runway, burn rate, and financial projections • To send you email alerts and monthly summaries (with your consent) • To process your subscription payments via Stripe • To respond to your support requests • To improve the product based on anonymised usage patterns We do not sell your personal information to any third party. We do not use your financial data to train AI models.

4. AI Processing Disclosure

MyCashStory uses artificial intelligence services to generate financial narratives: • Anthropic Claude (claude.anthropic.com): Receives anonymised financial metrics (balances, burn rates, MRR) to generate analysis. Governed by Anthropic's privacy policy. • xAI Grok (x.ai): Receives Claude's analysis to generate warm, readable narratives. Governed by xAI's privacy policy. Your bank credentials and account numbers are never sent to AI services. Only aggregated financial metrics are transmitted. Every AI-generated output is labelled "AI-generated — for reference only." AI narratives are not financial advice. Always consult a qualified professional before making financial decisions.

5. Data Breach Notification

In the event of a breach involving personal or financial data, LogosBloom Inc. will: • Notify affected users by email within 72 hours of becoming aware of the breach • Notify the Office of the Privacy Commissioner of Canada as required by PIPEDA breach of security safeguards regulations • Notify relevant EU supervisory authorities if EU residents are affected (GDPR Article 33) • Provide details of the breach, data affected, and steps taken to remediate To report a security concern: privacy@mycashstory.app

6. International Data Transfers

MyCashStory uses third-party services that may store data outside Canada: • Supabase (database): Servers in the EU and US. We rely on Standard Contractual Clauses (SCCs) and Supabase's Data Processing Agreement for GDPR-compliant transfers. • Stripe (payments): US-based. Governed by Stripe's Privacy Policy and applicable data transfer mechanisms. • Anthropic / xAI (AI): US-based. Data is processed under their respective privacy policies. • Vercel (hosting): US-based. Application code and edge functions run globally. By using MyCashStory, you consent to your data being processed in these jurisdictions as described above.

7. CASL — Canadian Anti-Spam Legislation

We comply with Canada's Anti-Spam Legislation (CASL). We will only send you commercial electronic messages if you have given express or implied consent. You give express consent when you: • Enable email alerts in your account Settings • Subscribe to monthly or weekly financial summaries You can withdraw consent at any time by: • Clicking "Unsubscribe" in any email we send • Disabling email alerts in Settings → Email Alerts → Off Transactional emails (account verification, password reset, payment receipts) are sent regardless of marketing consent as they are necessary to provide the service.

8. Your Rights (GDPR, CCPA, PIPEDA)

Depending on your location, you have the following rights: Right to Access: Request a copy of all data we hold about you. Use Settings → Export My Data for an immediate JSON download. Right to Deletion: Delete your account and all associated data permanently. Use Settings → Delete Account. Deletion is processed within 24 hours. Payment records are retained for 7 years as required by financial regulations. Right to Correction: Contact privacy@mycashstory.app to correct inaccurate information. Right to Portability: Export your data in machine-readable JSON format via Settings → Export My Data. Right to Opt Out of Sale: We do not sell personal information. This right is automatically satisfied. California Residents (CCPA/CPRA): You have the right to know, delete, opt-out of sale (N/A), and non-discrimination. Submit requests to privacy@mycashstory.app. European Residents (GDPR): Contact privacy@mycashstory.app or lodge a complaint with your national supervisory authority.

9. Cookies

We use two categories of cookies: Strictly Necessary: Session cookies that keep you logged in. These cannot be disabled — without them the service does not function. Analytics (Optional): PostHog analytics cookies that help us understand how users use MyCashStory. These are only placed with your explicit consent via the cookie banner shown on first visit. You can change your cookie preferences at any time by clearing your browser cookies and revisiting the site.

10. Data Retention

We retain your data for the following periods: • Account and profile data: Until you delete your account • Bank transaction data: Until you delete your account or disconnect your bank • Financial snapshots and scenarios: Until you delete them or delete your account • Payment records (Stripe): 7 years — required by financial regulations • Error logs (Sentry): 90 days rolling • Analytics events (PostHog): 12 months rolling

11. Contact

LogosBloom Inc. Ontario, Canada Privacy enquiries: privacy@mycashstory.app General support: hello@mycashstory.app Legal notices: legal@mycashstory.app Office of the Privacy Commissioner of Canada: priv.gc.ca / 1-800-282-1376
© 2026 MyCashStory. A product of LogosBloom Inc., a federally incorporated Canadian company. Terms of Service · Home