Effective date: September 24, 2026
Candor is a read-only financial data service for personal agents. This Privacy Policy explains how Candor collects, uses, shares, retains, and protects personal information and financial information.
"Candor", "we", "us", and "our" mean the Candor service and the organization that provides it, including any successor, affiliate, or operator identified in the service or account materials. "You" means the person who uses the service, joins the business waitlist, creates an account, connects a financial account, authorizes an OAuth client, or contacts us.
1. Scope
This policy applies to:
- the public Candor site;
- the business waitlist and self-serve account setup flow;
- web account controls;
- financial account linking;
- connected financial data;
- the local
candorCLI and related APIs; - hosted agent instructions and install flows;
- support, security, and operational communications.
This policy does not control financial institutions, Plaid, agent runtimes, model providers, browser extensions, operating systems, or other third-party services you choose to use.
2. Summary
Candor collects sensitive financial information only to provide the connected financial context and agent-facing service you request.
Candor does not sell your personal information for money, and never sells your financial information or shares it with advertising partners.
Candor does not use your financial information for targeted advertising.
Candor and its advertising partners use cookies, pixels, and similar technologies, and Candor may share limited personal information such as hashed contact information with those partners, to measure and improve Candor's advertising. See "Advertising partners" in section 7.
Candor does not train AI models on your financial information.
Candor is read-only for external financial actions. It does not move money, trade, pay bills, open accounts, cancel subscriptions, or file taxes.
3. Information We Collect
Account and identity information:
- email address;
- name if you provide one;
- authentication identifiers and email verification status;
- service access status;
- account creation, sign-in, and deletion timestamps.
Waitlist information:
- email address;
- product interest, such as personal or business;
- optional agent/tool preference;
- optional context about the agent workflow you already use or what you want your agent to catch;
- referral or page URL where the waitlist request was submitted;
- request source and submission time.
Financial account and connected data:
- connected institution and account details;
- account names, masks, types, subtypes, balances, currency, and status;
- transactions, dates, amounts, merchants, descriptions, categories, pending or posted status, and related details;
- liability, credit-card, loan, mortgage, APR, minimum-payment, due-date, statement, and term details where available;
- holdings and investment transaction data where available;
- property addresses and types, ownership shares, mortgage links, paid-off status, and dated property-value and rental estimates or manual observations;
- sync status, freshness, coverage, caveats, and source identifiers;
- organized financial records, factual summaries, recurring items, budgets, goals, agent-authored follow-up notes, factual changes, and related outputs;
- source details and provider data where needed to operate the service;
- export details.
Agent-authored and user-authored information:
- settings, budgets, goals, user- and agent-authored shared notes and reminders, corrections, preferences, and linked financial-resource references;
- user-approved imports and selected typed domain details;
- concise action reasons, task labels, approvals, outcomes, and access controls.
OAuth client, CLI, MCP, and API information:
- OAuth client registration, consented scopes, grants, and revocation status;
- CLI version, operating system, architecture, and client label where provided;
- refresh-token and short-lived access-token records needed to authenticate access;
- token creation, expiration, revocation, and use timestamps;
- agent or client labels and technical client details where supplied.
User-visible action history:
- stable action identifiers and operation names;
- bounded action reasons, task/root/parent identifiers, status, outcomes, and causal object or evidence references; and
- timestamps and actor labels.
Restricted audit, security, and operational logs:
- request identifiers;
- command or feature names;
- general data categories and access details;
- approximate record counts;
- troubleshooting summaries;
- timestamps;
- security, authentication, provider, and error details.
Website and product analytics:
- public site, waitlist, onboarding, and hosted control-plane event names;
- page or route category, referrer URL, browser and device metadata, and timestamps;
- frontend interaction metadata such as page views, clicks, form submissions, and masked UI element metadata;
- conversion status, feature-action status, and coarse counts such as whether a connection, export, reset, or approval action succeeded;
- internal account identifiers needed to measure product usage after sign-in;
- the signed-in account's email address, stored on its PostHog person profile to find the account during support, debug product issues, and analyze usage.
After sign-in, this profile links earlier browsing activity from the same browser on the public Candor site with activity in the signed-in app. The account's email therefore identifies that combined browsing history for support, debugging, and product and acquisition-funnel analysis.
Advertising and marketing:
- device and online identifiers, such as cookie identifiers, advertising and ad click identifiers, IP address, and browser and device information;
- how you arrived at Candor, such as the ad, campaign, or link you clicked and the page you landed on, excluding known authentication-secret fields and fragments;
- actions you take on the public site and during sign-up, such as creating an account, starting a trial, or subscribing, and the plan and price of your subscription; and
- your email address and account identifier, in hashed form.
We do not use financial information for advertising, including financial records, transaction details, account labels, balances, holdings, connected institutions, credentials, form contents, or information you enter about your finances. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of advertising use of your information, including for the account you create from that browser.
Analytics events are designed not to include raw financial data, transaction details, account labels, provider credentials, OAuth authorization codes and signed authorization requests, CLI tokens, URL fragments, the values of authentication, checkout-session, search, and record-identifier URL parameters (masked before capture), unmasked element text, or user-entered free text. Campaign, placement, and landing-page parameters from advertising and referral links stay on captured page URLs so we can attribute visits.
Error monitoring:
- exception type, stack trace, runtime surface, release, environment, and request identifiers;
- sanitized page or route path without raw query strings or fragments;
- coarse command or feature names; and
- diagnostic tags needed to debug failures.
Error monitoring is designed not to include raw financial data, transaction details, account labels, provider credentials, OAuth authorization codes, CLI tokens, raw URL query or fragment values, unmasked element text, or user-entered financial text.
Support and communications:
- emails and messages you send us;
- security reports;
- feedback, troubleshooting details, and related information.
4. Financial Account Connections And Property Estimates
Candor uses Plaid to help you connect financial accounts. Plaid may collect information directly from you and your financial institution during the Link flow. Plaid's own policies govern Plaid's collection and use of information.
When you connect an account, you authorize Candor and Plaid to access and process the information needed to provide Candor. Candor stores provider access credentials in Candor-controlled systems. Provider access tokens do not live on the CLI or agent runtime.
You can manage some Plaid connections through Plaid Portal. You can also use Candor controls to disconnect an institution, revoke OAuth client access, export your data, or delete your Candor data.
When you select automatic property estimates, Candor sends the property address and property type to its estimate provider, currently RentCast, to retrieve property-value and market-rent estimates. Candor retains the selected estimates, provider identifiers, dates, ranges where available, and valuation history. Candor does not send the property name you choose, ownership share, mortgage account or balance, other financial records, or agent notes to RentCast.
You can enter values manually without sending the address to an estimate provider. Switching to manual tracking stops scheduled provider refreshes; removing a property stops tracking while retaining its prior observations. Property records are included in Candor data exports and account deletion. Previously requested estimates and any processing by the provider are subject to that provider's own policies.
5. How We Use Information
We use information to:
- provide, secure, debug, and improve Candor;
- create and manage Candor accounts and connected financial data;
- verify email addresses and service access;
- connect financial accounts with your consent;
- sync, organize, and store financial records;
- generate factual views, summaries, freshness information, caveats, source references, query results, factual changes, and local visual artifacts;
- authorize scoped OAuth clients and issue short-lived API access;
- preserve reason-bearing action history for identified financial reads, writes, refusals, failures, and reversals;
- provide export, disconnect, revoke, delete, and recovery flows;
- process business waitlist requests;
- measure public site, waitlist, onboarding, and hosted control-plane usage;
- advertise Candor, measure and improve our ads, and show them to people who may be interested, without using financial data;
- communicate about account, security, support, and service access issues;
- investigate abuse, security events, provider issues, and service errors;
- comply with legal, regulatory, contractual, and provider obligations.
6. Agents And Authorized Client Disclosure
Candor exposes data through OAuth clients you authorize. An agent using an authorized CLI or remote MCP client can access the financial data and Candor operations allowed by that client's scopes.
Candor controls custody and API access for connected financial data inside the Candor service. Candor does not control retention, transcripts, logs, screenshots, files, memory, prompts, or model-provider handling inside your chosen agent runtime.
Do not allow an agent to use Candor unless you are comfortable with that agent receiving the returned financial data.
7. How We Share Information
We share information only as needed for the service and as allowed by law.
Service providers. We may share information with providers that host, secure, process, email, authenticate, debug, monitor, analyze, or support the service. These providers may include analytics and error-monitoring providers such as PostHog and Sentry. Candor configures product analytics and error monitoring to avoid raw financial payloads, account labels, approval codes, credential values, URL fragments, the values of authentication, checkout-session, search, and record-identifier URL parameters, unmasked element text, and user-entered financial text; campaign and landing-page parameters stay on captured page URLs for attribution. Session replay remains disabled unless explicitly enabled in frontend deployment configuration with masking and blocking controls.
Advertising partners. We work with advertising partners, such as Reddit, Meta, Google, and Whop, to advertise Candor and to measure how our ads perform. These partners may collect information through cookies, pixels, and similar technologies on our public site and sign-up pages, and we may also send information to them directly from our servers. This may include device and online identifiers, IP address, browser information, the ads and pages that led you to Candor, actions such as signing up, starting a trial, or subscribing, and hashed email addresses. Our partners use this information to connect sign-ups and subscriptions to our ads, to show our ads to people who may be interested in Candor, and to avoid showing our ads to existing customers. We do not share your financial information with advertising partners.
Financial data providers and financial institutions. We share information with Plaid and connected financial institutions as needed to connect, maintain, refresh, disconnect, or troubleshoot account connections. When automatic property estimates are selected, we share the property address and type with RentCast or the selected estimate provider to retrieve and refresh those estimates.
Automatic organization. We use service providers to help organize financial records and estimate recurring payment schedules. This processing uses relevant transaction descriptions, categories, amounts, currency, direction, and financial roles. It excludes account credentials, account-number fields, and profile contact fields. These providers process the requests under zero-data-retention settings. Predictions do not authorize external financial actions.
Personalized conversation suggestions. When enabled, we use relevant connected financial observations and shared notes, including optional onboarding answers, to prioritize starting questions for your agent. Notes retain their origin and current authorship. Model interpretations stay in suggestion results unless you or your agent deliberately retains them. The same zero-data-retention requirements apply. You can skip onboarding questions, ask your agent to edit shared context, dismiss suggestions, and browse the full prompt library. These suggestions do not authorize financial actions or establish your intent.
Your agents and clients. We return financial data to the OAuth clients you authorize and to the agents or tools you allow to use those clients.
Legal, safety, and compliance. We may disclose information if we believe it is required by law, legal process, provider requirements, security obligations, or to protect rights, safety, users, Candor, or others.
Business transfers. We may disclose or transfer information in connection with a merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction, subject to appropriate confidentiality and legal requirements.
We do not sell your personal information for money. We do not sell your financial information or share it for targeted advertising.
8. Financial Privacy Notice
Federal financial privacy law gives consumers the right to know how financial companies collect, share, and protect personal information. Candor provides this notice because it handles sensitive financial information.
Information we collect may include account balances, transaction history, liability and debt details, holdings, account details, connected institution details, OAuth client or session details, and Candor account information you or your agent create.
We collect information from you, your authorized agents, connected financial
institutions, Plaid, the candor CLI, web account controls, and
service providers.
We share information for everyday business purposes, including operating the service, maintaining accounts, processing service requests you make within Candor, auditing access, preventing fraud or abuse, responding to legal process, and using service providers that help us operate Candor.
You cannot opt out of sharing that is necessary to operate Candor, maintain your account, secure the service, use service providers, comply with law, or process your own requested account connections and data access.
We do not share your nonpublic personal information with nonaffiliated third parties for their own marketing. We do not sell or rent account numbers, transaction data, or Candor data.
9. Retention
We keep information for as long as needed to provide, secure, support, audit, debug, and improve Candor; comply with legal and provider obligations; resolve disputes; enforce agreements; and maintain legitimate business records.
Business waitlist records are kept until they are no longer needed for communication, abuse-prevention, or operational purposes, or until you ask us to delete them where deletion is required.
Financial records are kept while your Candor account is active. Disconnecting an institution removes active provider access and disables or deletes provider credentials where supported, but historical records and audit records may remain unless you delete your Candor data.
Data deletion immediately revokes active OAuth access and removes provider credentials, then deletes the deletable online financial workspace, including financial records, agent- and user-authored workspace state, raw source records, and user-visible action history. The completion result reports whether cleanup is still running and how many online records, if any, remain under legal hold.
Account deletion also schedules removal of the account's PostHog person profile, linked analytics events, and session recordings. This runs separately from financial-workspace cleanup: the request waits ten minutes for cached sessions and buffered events, and PostHog processes event deletion asynchronously. Failed requests are retried and surfaced for operator cleanup.
Unless a legal hold or another legal obligation requires longer retention, Candor applies these concrete periods to the operational records it controls:
- encrypted operation receipts and completed deletion-progress receipts become eligible for deletion after 7 days;
- expired authentication-session records become eligible for deletion 7 days after expiration;
- rate-limit records are retained only through the end of their enforcement window;
- sanitized maintenance and operational logs are retained for up to 90 days; and
- managed database backups expire on provider schedules of up to 14 days.
Eligible operational records are removed by a daily cleanup job, normally within the following 24 hours. Service interruptions may delay a cleanup run.
These records and backups are not part of the online workspace cascade and are not available through the product after deletion. Records subject to a legal hold remain until that hold ends, then return to the applicable deletion or expiration schedule.
10. Your Controls And Rights
Depending on your location and applicable law, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information.
Candor provides practical controls:
- export organized Candor data through the CLI or web account controls;
- disconnect a financial institution;
- revoke OAuth client access;
- delete your Candor data;
- ask us to delete waitlist information;
- contact us about access, correction, or deletion requests.
We may need to verify your identity before fulfilling a request. We may deny or limit a request where allowed by law, including for security, fraud prevention, legal, audit, contractual, or technical reasons.
California residents may have additional rights under California privacy law if Candor is subject to that law. Candor does not sell personal information for monetary consideration. Our use of advertising partners described above may be considered "sharing" of personal information for cross-context behavioral advertising under California law, or "targeted advertising" under other state laws. You may opt out by enabling Global Privacy Control in your browser or by emailing privacy@candor.money. You may also contact privacy@candor.money to ask about access, deletion, correction, or other privacy rights that apply to you.
11. Security
Candor uses administrative, technical, and physical safeguards designed to protect personal and financial information. These include OAuth client consent and revocation, short-lived API access tokens, provider credential custody, encryption controls, reason-bearing action events for financial reads, account disconnect, client revocation, data deletion, and restrictions on raw financial data in logs.
No system is perfectly secure. You are responsible for your email account, local device, CLI environment, and any agent or tool that can access Candor output.
More detail is available in the Candor Security Policy.
12. Children
Candor is not intended for children or minors. You must be at least 18 years old to use Candor.
13. International Use
Candor is designed primarily for United States users. If you use Candor from outside the United States, your information may be processed in the United States and other countries where our service providers operate.
Do not use Candor where doing so would violate applicable law.
14. Changes
We may update this policy from time to time. If changes are material, we will provide reasonable notice through the service, email, or another appropriate channel. The updated policy is effective when posted or when the notice says it takes effect.
15. Contact
Privacy requests: privacy@candor.money
Security reports: security@candor.money
Legal questions: legal@candor.money