Effective date: August 6, 2026
Candor is a read-only financial data service for personal agents. This Privacy Policy explains how Candor collects, uses, shares, retains, and protects personal information and financial information.
"Candor", "we", "us", and "our" mean the Candor service and the organization that provides it, including any successor, affiliate, or operator identified in the service or account materials. "You" means the person who uses the service, joins the business waitlist, creates an account, connects a financial account, authorizes an OAuth client, or contacts us.
1. Scope
This policy applies to:
- the public Candor site;
- the business waitlist and self-serve account setup flow;
- web account controls;
- financial account linking;
- connected financial data;
- the local
candorCLI and related APIs; - hosted agent instructions and install flows;
- support, security, and operational communications.
This policy does not control financial institutions, Plaid, agent runtimes, model providers, browser extensions, operating systems, or other third-party services you choose to use.
2. Summary
Candor collects sensitive financial information only to provide the connected financial context and agent-facing service you request.
Candor does not sell your personal information or financial information.
Candor does not use your financial information for targeted advertising.
Candor does not train AI models on your financial information.
Candor is read-only for external financial actions. It does not move money, trade, pay bills, open accounts, cancel subscriptions, or file taxes.
3. Information We Collect
Account and identity information:
- email address;
- name if you provide one;
- authentication identifiers and email verification status;
- service access status;
- account creation, sign-in, and deletion timestamps.
Waitlist information:
- email address;
- product interest, such as personal or business;
- optional agent/tool preference;
- optional context about the agent workflow you already use or what you want your agent to catch;
- referral or page URL where the waitlist request was submitted;
- request source and submission time.
Financial account and connected data:
- connected institution and account details;
- account names, masks, types, subtypes, balances, currency, and status;
- transactions, dates, amounts, merchants, descriptions, categories, pending or posted status, and related details;
- liability, credit-card, loan, mortgage, APR, minimum-payment, due-date, statement, and term details where available;
- holdings and investment transaction data where available;
- sync status, freshness, coverage, caveats, and source identifiers;
- organized financial records, factual summaries, recurring items, budgets, goals, agent-authored follow-up notes, factual changes, and related outputs;
- source details and provider data where needed to operate the service;
- export details.
Agent-authored and user-authored information:
- settings, budgets, goals, agent-authored notes and reminders, corrections, preferences, and linked financial-resource references;
- user-approved imports and selected typed domain details;
- concise action reasons, task labels, approvals, outcomes, and access controls.
OAuth client, CLI, MCP, and API information:
- OAuth client registration, consented scopes, grants, and revocation status;
- CLI version, operating system, architecture, and client label where provided;
- refresh-token and short-lived access-token records needed to authenticate access;
- token creation, expiration, revocation, and use timestamps;
- agent or client labels and technical client details where supplied.
User-visible action history:
- stable action identifiers and operation names;
- bounded action reasons, task/root/parent identifiers, status, outcomes, and causal object or evidence references; and
- timestamps and actor labels.
Restricted audit, security, and operational logs:
- request identifiers;
- command or feature names;
- general data categories and access details;
- approximate record counts;
- troubleshooting summaries;
- timestamps;
- security, authentication, provider, and error details.
Website and product analytics:
- public site, waitlist, onboarding, and hosted control-plane event names;
- page or route category, referrer URL, browser and device metadata, and timestamps;
- frontend interaction metadata such as page views, clicks, form submissions, and masked UI element metadata;
- conversion status, feature-action status, and coarse counts such as whether a connection, export, reset, or approval action succeeded;
- internal account identifiers needed to measure product usage after sign-in.
Analytics events are designed not to include raw financial data, transaction details, account labels, provider credentials, OAuth authorization codes, CLI tokens, raw URL query or fragment values, unmasked element text, or user-entered free text.
Error monitoring:
- exception type, stack trace, runtime surface, release, environment, and request identifiers;
- sanitized page or route path without raw query strings or fragments;
- coarse command or feature names; and
- diagnostic tags needed to debug failures.
Error monitoring is designed not to include raw financial data, transaction details, account labels, provider credentials, OAuth authorization codes, CLI tokens, raw URL query or fragment values, unmasked element text, or user-entered financial text.
Support and communications:
- emails and messages you send us;
- security reports;
- feedback, troubleshooting details, and related information.
4. Financial Account Connections And Plaid
Candor uses Plaid to help you connect financial accounts. Plaid may collect information directly from you and your financial institution during the Link flow. Plaid's own policies govern Plaid's collection and use of information.
When you connect an account, you authorize Candor and Plaid to access and process the information needed to provide Candor. Candor stores provider access credentials in Candor-controlled systems. Provider access tokens do not live on the CLI or agent runtime.
You can manage some Plaid connections through Plaid Portal. You can also use Candor controls to disconnect an institution, revoke OAuth client access, export your data, or delete your Candor data.
5. How We Use Information
We use information to:
- provide, secure, debug, and improve Candor;
- create and manage Candor accounts and connected financial data;
- verify email addresses and service access;
- connect financial accounts with your consent;
- sync, organize, and store financial records;
- generate factual views, summaries, freshness information, caveats, source references, query results, factual changes, and local visual artifacts;
- authorize scoped OAuth clients and issue short-lived API access;
- preserve reason-bearing action history for identified financial reads, writes, refusals, failures, and reversals;
- provide export, disconnect, revoke, reset, delete, and recovery flows;
- process business waitlist requests;
- measure public site, waitlist, onboarding, and hosted control-plane usage;
- communicate about account, security, support, and service access issues;
- investigate abuse, security events, provider issues, and service errors;
- comply with legal, regulatory, contractual, and provider obligations.
6. Agents And Authorized Client Disclosure
Candor exposes data through OAuth clients you authorize. An agent using an authorized CLI or remote MCP client can access the financial data and Candor operations allowed by that client's scopes.
Candor controls custody and API access for connected financial data inside the Candor service. Candor does not control retention, transcripts, logs, screenshots, files, memory, prompts, or model-provider handling inside your chosen agent runtime.
Do not allow an agent to use Candor unless you are comfortable with that agent receiving the returned financial data.
7. How We Share Information
We share information only as needed for the service and as allowed by law.
Service providers. We may share information with providers that host, secure, process, email, authenticate, debug, monitor, analyze, or support the service. These providers may include analytics and error-monitoring providers such as PostHog and Sentry. Candor configures product analytics and error monitoring to avoid raw financial payloads, account labels, approval codes, credential values, raw URL query or fragment values, unmasked element text, and user-entered financial text. Session replay remains disabled unless explicitly enabled in frontend deployment configuration with masking and blocking controls.
Financial data providers and financial institutions. We share information with Plaid and connected financial institutions as needed to connect, maintain, refresh, disconnect, or troubleshoot account connections.
Your agents and clients. We return financial data to the OAuth clients you authorize and to the agents or tools you allow to use those clients.
Legal, safety, and compliance. We may disclose information if we believe it is required by law, legal process, provider requirements, security obligations, or to protect rights, safety, users, Candor, or others.
Business transfers. We may disclose or transfer information in connection with a merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction, subject to appropriate confidentiality and legal requirements.
We do not sell your personal information or financial information. We do not share your financial information for targeted advertising.
8. Financial Privacy Notice
Federal financial privacy law gives consumers the right to know how financial companies collect, share, and protect personal information. Candor provides this notice because it handles sensitive financial information.
Information we collect may include account balances, transaction history, liability and debt details, holdings, account details, connected institution details, OAuth client or session details, and Candor account information you or your agent create.
We collect information from you, your authorized agents, connected financial
institutions, Plaid, the candor CLI, web account controls, and
service providers.
We share information for everyday business purposes, including operating the service, maintaining accounts, processing service requests you make within Candor, auditing access, preventing fraud or abuse, responding to legal process, and using service providers that help us operate Candor.
You cannot opt out of sharing that is necessary to operate Candor, maintain your account, secure the service, use service providers, comply with law, or process your own requested account connections and data access.
We do not share your nonpublic personal information with nonaffiliated third parties for their own marketing. We do not sell or rent account numbers, transaction data, or Candor data.
9. Retention
We keep information for as long as needed to provide, secure, support, audit, debug, and improve Candor; comply with legal and provider obligations; resolve disputes; enforce agreements; and maintain legitimate business records.
Business waitlist records are kept until they are no longer needed for communication, abuse-prevention, or operational purposes, or until you ask us to delete them where deletion is required.
Financial records are kept while your Candor account is active. Disconnecting an institution removes active provider access and disables or deletes provider credentials where supported, but historical records and audit records may remain unless you delete your Candor data.
Data deletion immediately revokes active OAuth access and removes provider credentials, then deletes the deletable online financial workspace, including financial records, agent- and user-authored workspace state, raw source records, and user-visible action history. The completion result reports whether cleanup is still running and how many online records, if any, remain under legal hold.
Unless a legal hold or another legal obligation requires longer retention, Candor applies these concrete periods to the operational records it controls:
- encrypted operation receipts and completed deletion-progress receipts become eligible for deletion after 7 days;
- expired authentication-session records become eligible for deletion 7 days after expiration;
- rate-limit records are retained only through the end of their enforcement window;
- sanitized maintenance and operational logs are retained for up to 90 days; and
- managed database backups expire on provider schedules of up to 14 days.
Eligible operational records are removed by a daily cleanup job, normally within the following 24 hours. Service interruptions may delay a cleanup run.
These records and backups are not part of the online workspace cascade and are not available through the product after deletion. Records subject to a legal hold remain until that hold ends, then return to the applicable deletion or expiration schedule.
10. Your Controls And Rights
Depending on your location and applicable law, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information.
Candor provides practical controls:
- export organized Candor data through the CLI or web account controls;
- disconnect a financial institution;
- revoke OAuth client access;
- delete your Candor data;
- ask us to delete waitlist information;
- contact us about access, correction, or deletion requests.
We may need to verify your identity before fulfilling a request. We may deny or limit a request where allowed by law, including for security, fraud prevention, legal, audit, contractual, or technical reasons.
California residents may have additional rights under California privacy law if Candor is subject to that law. Candor does not sell personal information and does not share personal information for cross-context behavioral advertising.
11. Security
Candor uses administrative, technical, and physical safeguards designed to protect personal and financial information. These include OAuth client consent and revocation, short-lived API access tokens, provider credential custody, encryption controls, reason-bearing action events for financial reads, account disconnect, client revocation, data deletion, and restrictions on raw financial data in logs.
No system is perfectly secure. You are responsible for your email account, local device, CLI environment, and any agent or tool that can access Candor output.
More detail is available in the Candor Security Policy.
12. Children
Candor is not intended for children or minors. You must be at least 18 years old to use Candor.
13. International Use
Candor is designed primarily for United States users. If you use Candor from outside the United States, your information may be processed in the United States and other countries where our service providers operate.
Do not use Candor where doing so would violate applicable law.
14. Changes
We may update this policy from time to time. If changes are material, we will provide reasonable notice through the service, email, or another appropriate channel. The updated policy is effective when posted or when the notice says it takes effect.
15. Contact
Privacy requests: privacy@candor.money
Security reports: security@candor.money
Legal questions: legal@candor.money