Skip to content

OneTruth

Privacy

Your money, your data, never anyone else's. This page summarizes what we collect, what we don't, and how to control everything.

Last updated: May 7, 2026

The promise

OneTruth is built around a simple promise: the data you give us is yours, used only to power your experience, never sold, and never used for advertising — no exceptions, no asterisks. We share it only with the service providers listed under Subprocessors below, each bound by a data processing agreement and none of them permitted to use your data for their own purposes.

  • No advertising trackers, anywhere, ever. No Facebook Pixel, no AdMob, no Branch, no AppsFlyer, no Adjust, no TikTok pixel, no Google Ads conversion tracking. We do not link advertising-tracker SDKs into our app or website.
  • No server-side Conversions APIs. No Meta CAPI, no TikTok Events API, no Google Enhanced Conversions. We do not ship server-to-server event streams to ad platforms.
  • No third-party Google Analytics. No GA4, no Universal Analytics, no Firebase Analytics. (Firebase Analytics was previously linked as a back-end for our own first-party product analytics; it was stripped from the iOS binary in May 2026 to remove any ambiguity about our intent.)
  • No device fingerprinting. Your phone's IDFA is never read. App Tracking Transparency is not linked.
  • No cross-app advertising identifiers. No SKAdNetwork postbacks to third-party ad networks beyond Apple's own first-party Apple Search Ads attribution framework.

What we collect

  • Account information: the bank accounts you choose to link via Plaid (balances + transaction history). Plaid stores your bank credentials; we never see them.
  • App content: the bills, notes, documents, goals, and workspaces you create.
  • Identity: your sign-in identifier from Apple, Google, or email, plus your email address.
  • Diagnostics: crash reports (via Sentry) and pseudonymized usage events (via PostHog; stable user ID only, no PII payload), used to operate, secure, and troubleshoot the service — including diagnosing issues you report. On the web, PostHog also captures masked session replays of on-screen activity to help us find and fix confusing spots — every amount, account detail, and anything you type is hidden on your device before it's sent, so the recording carries no financial data. Both are scrubbed of identifying content before transmission, and neither is ever used for advertising. Where the law requires a legal basis (for example, the EU/UK GDPR), we rely on our legitimate interest in keeping the app reliable and secure.

How it's stored

  • Encrypted at rest with AES-256 on Supabase's managed Postgres.
  • All connections use TLS 1.2+ in transit (TLS 1.3 by default on web).
  • Per-row Row-Level Security ensures one user can only ever read their own data.
  • Backups are encrypted.

How AI works

By default, nothing you ask leaves your phone. On iPhone 15 Pro and newer the assistant runs on Apple Intelligence, on your device. Everywhere else it falls back to a parser that also runs entirely on your phone. Neither one sends anything anywhere.

There is an optional cloud tier for harder questions, and it is built the only way we were willing to build one: it is off, and it cannot turn itself on.It runs only if you explicitly opt in — and until you do, no OneTruth server sends your questions, your transactions, or your balances to any AI provider. You can withdraw that permission whenever you like, and the assistant keeps working without it. Most apps ask you to trust a promise about data they already collect; this one simply doesn't collect it unless you say so.

Your rights

  • Export. Two paths, and between them you can take everything with you. Settings → Privacy → Export my data emails you a ZIP of your account record — profile, subscription, activity history, workspaces and devices — in human-readable JSON. For your financial data, Settings → Export ships presets that cover bills, payment history, income sources, money requests, notes, mileage and category rules as CSV, PDF or Excel, with account numbers redacted by default on anything you send outward.
  • Delete. Settings → Privacy → Delete my account triggers a 24-hour email-confirmation window; on confirmation we cascade-delete every row owned by your account immediately, with backup copies expiring per our backup tier's retention window.
  • Correct. All your data is editable inside the app.
  • Object. Diagnostics and product analytics run on a legitimate-interest basis to keep the app reliable and secure — never for advertising. To object, email us or delete your account, which stops all processing.

Subprocessors

We share data only with the subprocessors required to run the service. Every subprocessor that handles data from your OneTruth account is bound by a data processing agreement, and none of them are permitted to use your data for their own purposes. Every subprocessor handling consumer financial data is SOC 2 Type II certified. The last two entries below — Anthropic and Recraft — are different: they are tools we use for our own marketing rather than to run your account, our privacy agreements with those two are not finished yet, and neither receives anything from your OneTruth account. One of them, Anthropic, does receive what you type into the sample brand-kit demo on our public Reach page if you choose to try it — that is described in its entry below, and it is the only way either of these two tools sees anything from you at all.

  • Plaid, Inc. — bank-data integration (balances, transaction history).
  • Supabase, Inc. — Postgres database, authentication, Edge Functions, encrypted file storage.
  • Apple, Inc. — App Store delivery, Sign in with Apple, Apple Push Notification service (APNs).
  • RevenueCat, Inc. — iOS subscription receipt validation (subscription metadata only — no PII payload).
  • Stripe, Inc. — web card and billing processing for subscriptions purchased on the web.
  • Cloudflare, Inc. — DNS, CDN, email routing for our @onetruth.app domain.
  • Vercel, Inc. — web app + marketing site hosting.
  • Sentry, Inc. — error and crash reporting (PII scrubbed before transmission).
  • Resend, Inc. — transactional email (sign-in confirmations, security alerts, account-deletion confirmations).
  • PostHog, Inc. — first-party product analytics, including masked session replay on the web (pseudonymized; stable user ID only; no PII payload; sensitive content hidden on your device before it's sent; no advertising-platform destinations).
  • Google LLC (Firebase Cloud Messaging). — used in the future for cross-platform push delivery only (NOT Firebase Analytics, NOT Google Analytics, NOT Google Ads). The Firebase Analytics SDK was stripped from the iOS binary in May 2026.
  • GitHub, Inc. — source code hosting (private repository).
  • 1Password (AgileBits). — internal credential storage for the company; no consumer data.
  • Anthropic. — helps us write the wording for OneTruth's own marketing posts, and powers the sample brand kit on our public Reach demo page. If you try that demo, the brand name, category, and vibe you type there are sent to Anthropic to generate your sample — you do not need an account to use it, and we do not connect what you type to any account. For both of these uses, nothing from your OneTruth account — no balances, transactions, bills, or notes — is sent.
  • Recraft. — generates artwork and logo concepts for OneTruth's own marketing material. It works only with our own design prompts; it receives nothing from your OneTruth account.

Some entries above are company tools rather than parts of the app: where we keep our source code and our own passwords, and the tools we use to write and design OneTruth's own marketing. Except where noted above, those tools never receive anything from your account.

Children's privacy

OneTruth is not intended for use by anyone under 13. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we'll delete it within 24 hours.

Changes to this policy

We'll email every active user 30 days before any change that weakens your privacy. Cosmetic changes (rewording, fixing typos) are made silently.

Contact

Questions, requests, or concerns: support@onetruth.app. A real human reads every message.