Kove is live - start your 7-day free trial today.

Get Started

Data

Your Data. Your Rules.

Kove connects to your bank accounts, your transactions, your balances, the most sensitive information you have. If we’re asking for that kind of access, you deserve a straight answer on what happens to it. Here’s the full picture.

What We Collect

Account info to get you set up, name, email, phone number, notification preferences. Your phone number is collected for multi-factor authentication, to help keep your account secure, and isn’t used for marketing. Profile details that let us personalize things properly: date of birth, state of residence, employment or student status, and your university if you’re a student. Date of birth is treated as sensitive and used only to run the Services, it’s never included in a report or shared with anyone.

Then there’s the financial data itself: balances, transactions, investments, and liabilities, pulled in through Plaid when you connect an account. If you upload a bank statement instead, we parse it for transaction data and then let it go, it isn’t stored afterward.

We also collect usage data through Firebase Analytics and PostHog, configured to steer clear of personally identifiable financial information, and your conversations with Kove AI, along with the financial context it pulls in automatically to answer you. More on that on our AI Disclosure page.

What We Never Do

We don’t sell your data. We don’t share your financial data with anyone beyond what it takes to run Kove. Our analytics are set up specifically to avoid capturing identifiable financial information in the first place.

One thing we do use: the Meta Pixel.

In plain terms, it’s a small snippet of code from Facebook/Instagram that runs on our marketing website (not inside the Kove app) and tells us when someone who saw one of our ads visited the site or signed up, like a delivery receipt for an ad. It’s there to measure how our own ad campaigns are performing, to tell us whether our marketing is working, not to hand your Kove account activity over to Meta.

Where Your Data Actually Goes

Every vendor we use exists to do one specific job, and we’re not going to hide who they are:

  • Firebase runs our database, authentication, and hosting.
  • Plaid connects your bank accounts, access tokens live server-side only, never touch your browser, and are revoked the moment you disconnect.
  • Stripe handles payment processing directly; we never see your card number.
  • PostHog powers in-app analytics, and a separate PostHog setup tracks page views and how visitors use this marketing website, never mixed with your financial data.
  • Vercel hosts kovefinance.com, this website, and collects anonymized performance data about the website’s loading and performance.
  • Resend delivers account and billing emails.
  • Anthropic powers Kove AI, your conversations aren’t used to train their models.

That’s the complete list. Nobody else touches your data.

Aggregated & Anonymous Reporting

We also publish aggregated, anonymized reports on financial health and spending trends, no names, no account numbers, nothing traceable back to you. You’re included by default, and you can opt out anytime by emailing support@kovefinance.com with the subject “Reporting Opt-Out,” with zero effect on your access to Kove. Full detail on how these reports work is on our Research page.

Data Retention & Deletion

You’re in control from inside the app. Delete Financial Data clears your Plaid connections and transaction history while keeping your login and profile intact. Delete Account removes everything.

Deletions happen immediately on our live systems. Encrypted backups may hold deleted data for up to 28 days for disaster recovery before it’s permanently purged, those backups aren’t touched for anything else in the meantime. If you came to Kove through an access code that expires or gets revoked without converting to a subscription, your Plaid connections are cut within 3 days and everything else is gone within 14.

Security

Data is encrypted in transit and at rest. Plaid tokens never leave our servers. Our admin systems run on phishing-resistant multi-factor authentication, and database access is locked to authenticated users only. If a breach is ever confirmed, we notify affected users within 72 hours, as required under Washington law.

Your Rights

You can request, correct, or delete your data at any time, email support@kovefinance.com and we’ll respond within 30 days. California residents have additional rights under the CCPA, laid out in full in our Privacy Policy.

Still Have Questions?

This page is the plain-language version. The Privacy Policy has the full legal detail, section by section. If something here isn’t clear, we’d rather you ask than guess.

Contact Us →