Privacy Policy

Version 1.0 · Effective 2026-09-15

Who we are & scope

This application is a personal dashboard operated by HenryLabs, for a single owner-operator. It is not a public service and does not offer accounts to the general public — access is limited to a small, explicitly authorized allowlist of individuals.

This policy explains what data the application collects, how it is used, and how it is protected, retained, and deleted.

What data we collect

Financial account and transaction metadata, obtained through Plaid, a third-party financial data connection service, using read-only, revocable access tokens. We never see or store bank login credentials — those are handled entirely by Plaid and the connected financial institution.

Email metadata (sender, subject, timestamps, and classification labels) for mailboxes the owner has explicitly connected.

Application and service usage telemetry (call counts, token counts, and associated cost), used to track the operating cost of the tools this application relies on.

How it is used

All collected data is used exclusively to power the owner’s own private dashboard — summarizing account activity, subscriptions, billing, and usage in one place. It is not used for advertising, profiling, or any purpose beyond the owner’s own visibility into their own accounts.

Consent & revocation

The owner personally authorizes each financial connection through Plaid’s consent flow before any data is collected. Consent can be revoked at any time: the owner may disconnect a financial connection through Plaid’s standard /item/remove mechanism, after which the associated access token is deleted and no further data is collected from that connection.

Email and usage data collection can similarly be paused or removed by disconnecting the relevant mailbox or service integration at any time.

Retention schedule

Financial account and transaction data is retained for the operating life of the application on an encrypted volume. Other application data (email metadata and usage telemetry) is retained on access-controlled server storage.

Automated backups are retained on a rolling basis and are automatically deleted after 30 days. A small number of rolling weekly system-level backups are kept for short-term recovery, and monthly encrypted off-site snapshots are kept for disaster recovery.

Financial access tokens are retained only while a connection remains active; once a connection is removed, its token is deleted immediately.

Deletion & disposal

Data tied to a specific financial or email connection is deleted promptly upon request or upon disconnection of that connection.

If the application is ever decommissioned, all active third-party connections are removed, all associated records and backups are deleted, and the encryption keys protecting stored data are destroyed, rendering any residual encrypted data unreadable.

Security measures

All traffic to this application is encrypted in transit (HTTPS with HTTP Strict Transport Security enforced). Financial data at rest is stored on an encrypted volume; all stored data resides on access-controlled, single-tenant server infrastructure.

The dashboard data described in this policy is exposed to the application through a read-only connection — the application cannot write to or modify that underlying data store.

Administrative views of this data are gated behind server-side authentication and an explicit admin allowlist; general application sign-in additionally requires an owner-approved allowlist entry.

Secrets and credentials used by this application (API keys, session-signing secrets, and similar) are kept in a single centrally managed, access-controlled store and are never included in the application’s source code or exposed to end users.

Data is protected by layered backups with a documented, periodically exercised restore process.

No sale or sharing

We do not sell, rent, or share this data with third parties for marketing or any other purpose. The only third parties involved are the service providers necessary to operate the features described above (for example, Plaid for financial connections), each acting under its own privacy and security commitments.

Contact

Questions about this policy or a request to access, export, or delete data may be sent to aj@henrylabs.net.

Back to sign in