← OutlayerPrivacyTerms

Privacy Policy

Last updated 13 September 2026

Draft — not yet reviewed by a lawyer. This describes what Outlayer actually does with data, written from the source code. It is accurate but it is not legal advice, and it has not been reviewed by counsel. Have a lawyer review it before you rely on it, and before submitting it with a Plaid production application.

Outlayer helps businesses find recurring charges in their bank and card statements. This policy explains what we collect, why, where it lives, and how to get rid of it.

1. What we collect

Account information

Your email address, and optionally a company name. We use email-based sign-in links, so we never ask for or store a password.

Financial transaction data

If you connect a bank or card account, we use Plaid to read your transaction history. This access is read-only. We cannot move money, make payments, or cancel anything on your behalf.

From that history we store, for each recurring charge we detect:

  • the merchant or vendor name
  • the amount and how often it recurs
  • the date it was last charged
  • a spending category
  • an identifier linking it back to the source transaction

We also store the institution name, account name, and the last four digits only of any connected account. We do not store full account numbers.

Billing information

Payments are handled by Stripe. We never see or store your card number. We keep a Stripe customer ID, a subscription ID, your plan, and your subscription status.

2. Who else sees your data

We do not sell your data, and we do not share it for advertising. We use these processors to run the service:

ProcessorWhat it handles
SupabaseDatabase and authentication (hosted in AWS us-west-2)
VercelApplication hosting
PlaidRead-only bank and card connections
StripeSubscription billing
AnthropicThe in-app assistant (see below)

About the in-app assistant

When you ask the assistant a question, we send your question along with your list of recurring charges — vendor names, amounts, categories and dates — to Anthropic's API to generate a reply. We do not send your raw transaction history, your account numbers, or your Plaid credentials. If you would rather no charge data left our systems, do not use the assistant.

3. How your data is protected

  • Every table holding customer data has row-level security enabled, scoped to your own user ID, so one account cannot read another's rows.
  • Plaid access tokens are held in a separate table that is not readable by any signed-in user — only by the server itself.
  • Traffic is encrypted in transit. Data is encrypted at rest by our hosting providers.

We do not hold a SOC 2 report or any other third-party security certification, and we do not claim to. If that is a requirement for you, we are not the right fit yet.

4. How long we keep it

  • While your account is open: we keep your charges so we can show you trends over time.
  • If you disconnect a bank: we delete the stored access token immediately. Charges already detected stay until you delete them.
  • If you close your account: we delete your profile, charges, connected-account records and access tokens within 30 days.
  • Billing records are retained as long as tax and accounting rules require.

5. Your choices

  • Delete any individual charge from your dashboard at any time.
  • Disconnect a bank connection at any time; this revokes our access through Plaid.
  • Request a copy of your data, or ask us to delete your account entirely.

Depending on where you live you may have additional rights over your personal data, including access, correction, deletion and portability. Contact us and we will honour them.

6. Contact

subsightsupport@gmail.com

7. Changes

If we change this policy we will update the date at the top, and for material changes we will email you before the change takes effect.