Last updated August 2026

Privacy policy

Solv Personal is currently in closed testing. This policy explains what we collect, why, and how you stay in control of it — including what "deleting your account" actually does. If anything here is unclear, the Contact screen in Settings reaches us directly.

The short version

We read your bank transactions (through Plaid, read-only) to build your dashboard and reports. We never see or store your bank login credentials. We don't sell or share your data, and we don't use your financial data for advertising. You can export everything we have on you, or delete your account, at any time from Settings.

Solv Personal is in testing

Solv Personal is an early-stage product under active development, distributed to a small invited group. You may be using it before it has been through a full external security audit. Bugs, incomplete features, and occasional downtime are more likely during this phase than they will be later.

Treat Solv's dashboards, reports, and any AI-generated summaries as informational only, not as your system of record — always cross-check important numbers against your bank or card issuer directly. Data-handling details in this policy may be refined as the product matures; if a change would meaningfully affect how your data is handled, we'll surface it in-app or by email rather than only updating this page silently.

Who is responsible for your data

Solv Personal is operated by Mahdi Ahmed, an individual developer in Minnesota. If the app transfers to a company formed to operate it, or to an acquirer, your data transfers with it and this policy continues to apply until it is updated and you are notified. That is described in the "Assignment and transfer" section of the Terms.

Information we collect

Account information you provide directly: your name, email address, and a hashed version of your password (we use bcrypt — Solv never stores or has access to your plaintext password). Optionally, a phone number, your currency and region preference, and a savings goal or monthly spend target you set yourself.

Onboarding answers: what you told us about your financial goal, what prompted you to look for an app like this, and how you heard about Solv. These help us understand our early users; they don't affect what data we collect from your bank.

Financial data via Plaid: once you link a bank or card account, we receive read-only transaction history (up to roughly two years), account balances, and basic account metadata (institution name, account type, last four digits) through Plaid's API. We cannot move money, and we never receive your online banking username or password — Plaid's own secure interface handles that exchange without passing your credentials through Solv's servers.

Corrections you make: when you recategorize a transaction or set a rule for a merchant, we store that choice so the app respects it going forward.

Your time zone: so the summary emails arrive at the hour you asked for and cover the right day. It is read from your browser the first time you open notification settings, and you can see and change it at Settings → Currency & region. Once you set it yourself, we stop taking the browser's word for it. A time zone is a rough location signal, which is why we say so here rather than treating it as a technical detail.

Consent records: the version of these documents you accepted, the date and time you accepted them, and the IP address and browser that submitted the acceptance, so we can evidence what was agreed and from where. These records deliberately outlive your account — an acceptance we cannot show is worth nothing to either of us.

Two-factor authentication: if you enable TOTP-based two-factor login, we store the secret needed to verify your authenticator app's codes.

Session data: a signed, encrypted session cookie that identifies you as logged in. It contains no readable personal data on its own. Using "sign out of all other devices" invalidates every session issued before that point.

Sign-in records: when you log in, we store a coarse description of the browser and operating system you used, along with the IP address of that request. This is how we can tell you when your account is accessed from a device it hasn't been used on before. We keep the browser and IP only so that alert can describe the sign-in to you — "was this you?" is unanswerable without them — and we don't use them to build a profile or track you across sites.

Email delivery records: for each email we send you, we keep the kind of email, its subject line, and what happened to it — delivered, opened, a link clicked, bounced, or marked as spam. Opens are measured with a small tracking pixel and clicks by routing links through our email provider, which is how most email is measured; we use it to tell whether the reports are landing and being read, not to build a profile of you. Blocking remote images in your mail client prevents open tracking.

Communications: if you email or message us for support, we keep that correspondence to help you and to improve the product. Our own staff may also record short notes about your account — for example, what you told us in a support conversation — so we can pick up where we left off.

How we use your information

To build the Dashboard, the reports (General, Subscriptions, Shopping, Income), and Search directly from your transaction history — every figure you see traces back to a real transaction or a straightforward calculation across them, never a guess.

To classify merchants into categories. Most categorization comes from Plaid's own data and a hand-maintained list of common merchants. When a merchant still can't be identified, we send that merchant's name — and nothing else, no amount, no date, no account, nothing about you — to Anthropic's API to ask what kind of business it is. See "Shared merchant reference data" below.

To generate the short, plain-language summaries the app sometimes shows. When enabled, this sends a compact set of already-computed figures — your balance, period totals, and category percentages — to Anthropic's API to produce a couple of sentences of natural-language summary, which we cache rather than regenerating on every visit. No individual transaction is included: not its merchant, not its amount, not its date.

To send transactional email through Resend: a welcome message when you sign up, password resets, security alerts (password or email changes, a sign-in from a new device, a bank connection needing reconnection, a change to these documents), and the daily, weekly and monthly summary emails, which are switched on when you create an account and can be switched off individually at any time from Settings → Notifications or from the unsubscribe link at the bottom of any of them. They are sent at the time of day you choose in Settings and in the time zone set there.

To operate, secure, and improve the product: debugging issues, preventing abuse, and understanding which features are actually used.

We do not use your financial data to train any AI model, and our providers are contractually restricted from using data we send them to train their models.

Shared merchant reference data

Solv keeps a shared reference table of merchant names and the category each belongs to — for example, that a given coffee chain is "dining." When any user's account surfaces a merchant we haven't seen before and we work out its category, that merchant-to-category pairing is saved to this shared table so it's already known the next time it appears for anyone.

This table contains merchant names and categories only. It holds no user identifiers, no amounts, no dates, no account details, and nothing that indicates who transacted with a merchant or whether anyone did. A merchant's category is a fact about that business, not about you.

This is why the app gets more accurate over time and why a later user's first sync is cleaner than an earlier one's. Your own corrections stay on your account and are not written to this shared table.

Bank connections via Plaid

Bank linking is handled entirely by Plaid, a third-party financial data network used by many banking and finance apps. When you connect an account, you authenticate directly with Plaid (or with your bank, through Plaid's interface) — Solv never sees or stores that password.

Plaid handles your information under its own privacy policy and end user terms, which apply directly between you and Plaid and are worth reading. Plaid is not merely acting on our behalf in that relationship.

Access is read-only: Solv cannot initiate transfers, payments, or any change to your accounts. You can unlink any connected account at any time from Settings → Linked accounts, which immediately revokes Solv's access to that account through Plaid.

Who we share information with

We do not sell your personal or financial information, we do not share it for cross-context behavioral advertising, and we do not use it for ad targeting. We have never done any of these things.

We share the minimum necessary data with the service providers that make Solv work: Plaid (bank connectivity), Resend (sending emails on our behalf), Anthropic (merchant classification and the optional AI-written summaries described above), PostHog (product usage analytics), and our hosting and database providers (Railway and our Postgres provider), who store the data described in this policy on our behalf. Each is bound to use it only to provide their service to us.

Solv is run by a very small team, and during testing that team can see your account — your profile, your settings, your activity, and the reports built from your transactions — in an internal admin view. We look when we need to: diagnosing something you have reported, or checking that a change did what it should. It is not anonymous, and we would rather say so than let you assume otherwise.

We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of Solv, our users, or others. Where we are legally permitted to tell you about such a request, we will.

If Solv Personal is transferred to a company formed to operate it, or is acquired or merged, your information transfers as part of that business. You'll be notified, and this policy continues to apply until it is updated.

Analytics and cookies

We use PostHog to understand product usage — page views, session activity, and which features get used — tied to your account so we can see patterns across a signed-in user's activity over time. PostHog receives only an opaque account identifier: not your name, not your email address, and nothing from your bank. This data is used for internal product decisions, not advertising, and is cleared from your browser when you sign out. We also record the time of your most recent visit on your own account record, so we can tell how many people keep using Solv.

We use a small number of cookies: one to keep you signed in (the session cookie described above), and PostHog's own analytics cookies. We don't use third-party advertising cookies.

Data retention and deletion

While your account is active, we retain your account details, your connected-account metadata, and the corrections and preferences you've set. Transaction history is fetched from Plaid rather than warehoused indefinitely, and we hold roughly the trailing two years needed to build your reports and comparisons.

You can export a copy of your own data at any time from Settings, and you can delete your account at any time from the same screen.

Deleting your account tells Plaid to revoke our access to your bank, so the connection is cancelled at Plaid's end and not merely forgotten at ours. We then erase your name, email address, phone number, password hash, any two-factor secret, your onboarding answers, your goals and preferences, your time zone, and the cached AI summary of your spending. We delete your sign-in records (including the IP addresses), your email delivery records, your activity log, your category corrections, any staff notes about your account, and any pending password-reset tokens. You are signed out everywhere, the account no longer appears anywhere in the product, and the email address becomes available for a new signup. Residual copies may persist in encrypted infrastructure backups for a short period before being overwritten on their normal rotation.

After deletion we retain two things. First, an anonymized usage snapshot — aggregate figures only, such as when the account was created, how long it was active, and which report emails it was subscribed to, with no name, email, or other identifying information attached, and nothing traceable back to you or your bank accounts. Second, a minimal record that consent was given and later deleted, which we keep because it is our evidence of having complied with this policy; as noted above, that record includes the IP address and browser that submitted the acceptance. Merchant-to-category pairings already contributed to the shared reference table remain, because they contain no information about you.

Security

Data in transit is encrypted (HTTPS/TLS). Passwords are hashed with bcrypt and never stored in plain text. Sessions use signed tokens rather than storing session data that could be tampered with. Two-factor authentication (TOTP) is available for an extra layer of login security. Bank credentials are never handled by Solv's servers at all — that exchange happens entirely within Plaid's own secure interface.

No method of storage or transmission is 100% secure, and we can't guarantee absolute security — but we design around minimizing what sensitive data we hold in the first place (never touching bank passwords, not warehousing transaction history beyond what reports need) rather than relying solely on defenses after the fact.

If we become aware of a security incident affecting your personal information, we will notify you by email without unreasonable delay, and in any case as required by applicable law, describing what we know, what we're doing about it, and what you should do.

Your rights and choices

You can access, export, or delete your data at any time from Settings — this isn't locked behind a support request. You can unlink any bank account without deleting your Solv account. You can turn daily, weekly, and monthly report emails on or off, and choose the day and time they arrive, from Settings → Notifications. You can enable or disable two-factor authentication, and sign out of all other devices, from Settings → Security.

If you have questions about your data or want to make a request we haven't automated yet, reach us from the Contact screen in Settings and we'll respond within two business days.

California privacy rights

If you are a California resident, the California Consumer Privacy Act as amended gives you the right to know what personal information we collect and why, to access a copy of it, to correct inaccuracies, to delete it, and to limit the use of sensitive personal information. Solv treats financial account information as sensitive personal information and uses it only to provide the app's core function.

We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing for you to opt out of on that front. We will not discriminate against you for exercising any of these rights.

The Settings screen already implements access, export, correction, and deletion — that's the fastest route. For anything else, or to have someone act as your authorized agent, contact us and we'll verify the request against your account email and respond within the statutory timeframe.

Children's privacy

Solv Personal is not directed at, and is not intended to be used by, anyone under 18. We don't knowingly collect information from children. If you believe a child has created an account, contact us and we'll delete it.

Where this policy applies

Solv Personal is operated from Minnesota and currently offered only to users in the United States, and your information is processed and stored in the United States. If that changes, this policy will be updated to reflect any additional obligations that come with serving users elsewhere.

Changes to this policy

We may update this policy as Solv Personal moves out of testing and as the product changes. The "last updated" date at the top of this page always reflects the current version, and material changes are surfaced in-app or by email rather than posted silently: we email every existing user a plain-language summary of what changed. You are asked to accept this policy once, when you sign up; after that we tell you about changes rather than putting a prompt between you and your account, unless a change is significant enough to need your agreement again.

Contact us

Questions about this policy or your data can go through the Contact screen in Settings, or mahdiahmed.official@gmail.com — that's the fastest way to reach us during testing.